Tera Router

Configuration

Environment variables, make targets, and the built-in limits of the server and dashboard.

Server (apps/server)

The server reads .env in apps/server when run via make run.

VariableDefaultNotes
MACHINE_ID— (required)Unique machine ID (16-bit number, must not be 0)
APP_SECRET— (required)Signs JWTs and derives the credential encryption key
PORT8080Port for the gateway + dashboard API
ENVproductiondevelopment enables dev behavior (sample key seeding)
DEBUGfalsetrue/1 enables debug mode
DATABASE_PATHterarouter.dbSQLite file location
MIGRATE_ON_BOOTtrueRun migrations on start
SEED_ON_BOOTtrueSeed initial data (roles, admin, Default plan)
ADMIN_EMAIL[email protected]Initial admin email
ADMIN_PASSWORDadmin123 (dev)Admin password — required in production
CORS_ALLOWED_ORIGINS*Comma-separated origin list, e.g. http://localhost:5173,http://localhost:3001
APP_NAMEtera-router-serverApplication name
SENTRY_DSN—Enables error tracking when set

APP_SECRET is the house key

Provider credentials are encrypted with a key derived from APP_SECRET. Changing the secret makes every stored credential unreadable. Change it only before data exists, and keep it safe.

Make targets (apps/server)

TargetNotes
make runRun the API server (reads .env)
make installSet up the Go toolchain
make migrate/upRun migrations
make migrate/downRoll back migrations
make migrate/refreshReset the database
make seedSeed production data
make seed/devSeed the "Dev" sample key (plaintext printed once)
make testTests
make vetStatic analysis
make build/apiBuild the server binary

Dashboard (apps/web-ui)

VariableDefaultNotes
VITE_API_URLhttp://localhost:8080API server address
VITE_APP_NAMETera RouterDisplay name
BETTER_AUTH_URLhttp://localhost:5173Auth base URL
BETTER_AUTH_SECRET—Auth secret

The dashboard runs on port 5173 (pnpm dev in apps/web-ui).

Built-in limits

LimitValue
Maximum request body size32 MiB
Server read timeout20 seconds
Server write timeout3 minutes
Unary request deadline90 seconds
Stream deadline3 minutes
SSE heartbeat15 seconds
Gateway concurrency (in-flight)100
Dashboard rate limit100 req/min per IP
Key verification cache5 minutes
Retries per request (max)10
Account cooldown (429 / auth fail)30 seconds / 5 minutes

On this page