Configuration
Environment variables, make targets, and the built-in limits of the server and dashboard.
Server (apps/server)
The server reads .env in apps/server when run via make run.
| Variable | Default | Notes |
|---|---|---|
MACHINE_ID | — (required) | Unique machine ID (16-bit number, must not be 0) |
APP_SECRET | — (required) | Signs JWTs and derives the credential encryption key |
PORT | 8080 | Port for the gateway + dashboard API |
ENV | production | development enables dev behavior (sample key seeding) |
DEBUG | false | true/1 enables debug mode |
DATABASE_PATH | terarouter.db | SQLite file location |
MIGRATE_ON_BOOT | true | Run migrations on start |
SEED_ON_BOOT | true | Seed initial data (roles, admin, Default plan) |
ADMIN_EMAIL | [email protected] | Initial admin email |
ADMIN_PASSWORD | admin123 (dev) | Admin password — required in production |
CORS_ALLOWED_ORIGINS | * | Comma-separated origin list, e.g. http://localhost:5173,http://localhost:3001 |
APP_NAME | tera-router-server | Application name |
SENTRY_DSN | — | Enables error tracking when set |
APP_SECRET is the house key
Provider credentials are encrypted with a key derived from APP_SECRET. Changing the secret makes
every stored credential unreadable. Change it only before data exists, and keep it safe.
Make targets (apps/server)
| Target | Notes |
|---|---|
make run | Run the API server (reads .env) |
make install | Set up the Go toolchain |
make migrate/up | Run migrations |
make migrate/down | Roll back migrations |
make migrate/refresh | Reset the database |
make seed | Seed production data |
make seed/dev | Seed the "Dev" sample key (plaintext printed once) |
make test | Tests |
make vet | Static analysis |
make build/api | Build the server binary |
Dashboard (apps/web-ui)
| Variable | Default | Notes |
|---|---|---|
VITE_API_URL | http://localhost:8080 | API server address |
VITE_APP_NAME | Tera Router | Display name |
BETTER_AUTH_URL | http://localhost:5173 | Auth base URL |
BETTER_AUTH_SECRET | — | Auth secret |
The dashboard runs on port 5173 (pnpm dev in apps/web-ui).
Built-in limits
| Limit | Value |
|---|---|
| Maximum request body size | 32 MiB |
| Server read timeout | 20 seconds |
| Server write timeout | 3 minutes |
| Unary request deadline | 90 seconds |
| Stream deadline | 3 minutes |
| SSE heartbeat | 15 seconds |
| Gateway concurrency (in-flight) | 100 |
| Dashboard rate limit | 100 req/min per IP |
| Key verification cache | 5 minutes |
| Retries per request (max) | 10 |
| Account cooldown (429 / auth fail) | 30 seconds / 5 minutes |