Configuration
Both backend services validate environment variables during startup. Invalid required values stop the process before it begins accepting work. Keep local .env files and runtime secret injection aligned with these schemas.
Manager settings
| Variable | Required / default | Purpose |
|---|---|---|
NODE_ENV | local | local, development, production, or test |
PORT | required | Manager HTTP port; local examples use 4400 |
CORS_ORIGIN | required | Allowed browser origin; use an explicit origin outside local development |
DATABASE_URL | required | PostgreSQL or postgres connection URI |
DATABASE_SSL | false | Enable database TLS |
NATS_SERVERS | required | Comma-separated NATS URLs |
NATS_CONNECTION_NAME | required | Connection identity shown by NATS |
NATS_USER_JWT | required | Manager user JWT under the same NATS account as enrolled Workers |
NATS_USER_SEED | required | Private NKey seed matching the Manager user JWT |
NATS_ACCOUNT_SIGNING_SEED | required | Account seed used to issue per-Worker user JWTs |
WORKER_NATS_SERVERS | required | NATS URLs reachable from Workers; must address the same operator-mode NATS account |
WORKER_PUBLIC_URL | required | HTTPS Manager URL reachable from Workers; loopback HTTP is permitted only outside production |
TRANSCODE_CPU_ONLY | false | Restrict dispatch to certified CPU execution paths; set true for a CPU-only installation |
NATS_JETSTREAM_REPLICAS | 1 | Positive stream replica count |
WORKER_ENROLLMENT_TOKEN_PEPPER | required, min 32 chars | HMAC key for enrollment-token hashes |
WORKER_SUSPECTED_AFTER_MS | 15000 | Heartbeat age before suspected connectivity |
WORKER_OFFLINE_AFTER_MS | 30000 | Must be greater than suspected threshold |
WORKER_ORPHAN_AFTER_MS | 120000 | Must be greater than offline threshold |
Manager telemetry
| Variable | Default | Purpose |
|---|---|---|
OTEL_SDK_DISABLED | false | Disable all telemetry when true |
OTEL_SERVICE_NAME | encode-flow-manager | Resource service name |
OTEL_EXPORTER_OTLP_PROTOCOL | http/protobuf | The only accepted protocol |
OTEL_EXPORTER_OTLP_ENDPOINT | local Collector default | Base OTLP/HTTP endpoint |
OTEL_EXPORTER_OTLP_HEADERS | empty | URL-encoded exporter headers |
OTEL_EXPORTER_OTLP_TRACES_ENDPOINT | derived | Signal-specific trace URL |
OTEL_EXPORTER_OTLP_METRICS_ENDPOINT | derived | Signal-specific metrics URL |
OTEL_EXPORTER_OTLP_LOGS_ENDPOINT | derived | Signal-specific logs URL |
OTEL_TRACES_SAMPLER_ARG | runtime default | Number from 0 through 1 |
OTEL_BSP_EXPORT_TIMEOUT | runtime default | Positive batch span timeout in ms |
OTEL_BSP_MAX_QUEUE_SIZE | runtime default | Positive batch span queue size |
OTEL_METRIC_EXPORT_INTERVAL | runtime default | Positive periodic export interval in ms |
OTEL_SHUTDOWN_TIMEOUT | runtime default | Positive shutdown flush timeout in ms |
OTEL_RESOURCE_ATTRIBUTES | empty | Comma-separated resource attributes |
OTEL_LOG_LEVEL | info | none, error, warn, info, debug, verbose, or all |
Signal-specific endpoints, protocols, and headers override their general equivalents. When telemetry is enabled in production, the exporter endpoint must use HTTPS.
Worker settings
| Variable | Required / default | Purpose |
|---|---|---|
NODE_ENV | local | Runtime environment |
PORT | 3000 | Worker health/runtime HTTP port |
ENCODE_FLOW_WORKER_TOKEN | first start | Manager-issued enrollment token; the Worker then persists its NKey and renews its lease |
The Worker stores its identity and recovery spool in /var/lib/encode-flow.
The Manager lease supplies the work directory, S3 access for each attempt, and
the capacity derived from certification and the Worker profile cap. Set the
profile cap to one concurrent job when Manager, Worker, Web, and Admin share a
CPU host.
Output storage and recovery deployment
Configure an existing destination bucket, endpoint, region, path-style setting, and credentials in the project storage override or organization default. A configured profile without a bucket blocks new portal submissions. Without either profile, outputs use Manager storage. Source uploads and previews always stay in Manager storage.
Each submitted portal job saves its destination and encrypted credentials. Later profile edits affect future submissions. Keep encryption keyring entries needed by existing jobs. External MP4 downloads stream through the authenticated portal, and HLS results are read through the saved connection. Direct execution-plan API jobs keep their explicit S3 URI behavior.
Apply AddOutputStorage1791000000000 and AddIncrementalRecovery1791100000000 with yarn nx run @encode-flow/manager:migration:run, then deploy updated Manager, Workers, Web, and Admin. External outputs require Workers advertising separate-output-storage-v1; new portal jobs require incremental-output-recovery-v1. Persist both /var/lib/encode-flow and the supplied work directory so checkpoints and encoded files survive restarts.
See job lifecycle and resume uploads for retention and recovery behavior.
Local examples
# apps/manager/.env
PORT=4400
CORS_ORIGIN=http://localhost:4500
DATABASE_URL=postgresql://postgres:postgres@localhost:5432/encode_flow
NATS_SERVERS=nats://localhost:4222
NATS_CONNECTION_NAME=encode-flow-manager
NATS_USER_JWT=<from docker/nats/generated/manager.env>
NATS_USER_SEED=<from docker/nats/generated/manager.env>
NATS_ACCOUNT_SIGNING_SEED=<from docker/nats/generated/manager.env>
WORKER_NATS_SERVERS=nats://localhost:4222
WORKER_PUBLIC_URL=http://localhost:4400
TRANSCODE_CPU_ONLY=true
NATS_JETSTREAM_REPLICAS=1
WORKER_ENROLLMENT_TOKEN_PEPPER=replace-with-at-least-32-characters
OTEL_EXPORTER_OTLP_ENDPOINT=http://localhost:4318
# apps/worker/.env
ENCODE_FLOW_WORKER_TOKEN=<Manager-issued enrollment token>