Collegium
Reference

Environment

The variables the app and its provisioning read from the environment.

What the app process reads from its environment at boot. Under Compose most of these are set by docker-compose.yaml itself; .env supplies the rest.

APP_HOSTstringrequired

The address the app binds to. Under Compose this is 0.0.0.0, and the port is published on the loopback alone unless APP_BIND_HOST widens it.

APP_PORTnumber

The port the app listens on, and the port Mattermost and the trigger endpoints are reached through.

APP_PUBLIC_URLstring

The address Mattermost calls back on to deliver approval decisions, slash commands, and triggers. Defaults to the bind address, which is right only when the app is reached where it binds; a deployment whose Mattermost is a container of its own — or a server elsewhere — must state this.

CALLBACK_TOKENstringrequired

A shared secret the Mattermost plugin presents on POST /commands, and the key that signs each approval decision callback. A second control beside keeping APP_PORT off the public network (§6.4), not a replacement for it. Generate it with openssl rand -hex 32; rotate it by changing the value and redeploying the app and the plugin together.

CONFIG_PATHstringrequired

Path to config.json, the declaration of the agents, channels, and grants this deployment runs.

DATABASE_URLstringrequired

A file: URL naming the SQLite store, absolute and without a host — file:///data/prod.db. Its parent directory is created and taken over on boot.

MATTERMOST_LOCAL_URLstringrequired

Where the app reaches Mattermost, over http or https. Local names who uses it, not where the server is: for a server you already run it is usually the public address. Not where people open Mattermost, which is its Site URL — for the bundled Mattermost, MATTERMOST_PUBLIC_URL.

MATTERMOST_TEAMstringrequired

The team this deployment occupies, by handle — the name in its URL. Created on first start if absent.

PLUGINS_ROOTstringrequired

The directory holding one plugin per subdirectory, each named for the plugin it holds. Mounted read-only: a plugin is code the operator installs, and nothing the framework runs writes here.

RESOURCES_ROOTstring

The directory holding the files config.json names by relative path, such as the HTML template outbound mail is wrapped in. Mounted read-only, and needed only when config names such a file.

TRIGGER_TOKENstring

A shared secret a trigger sender presents on POST /triggers, and nothing else: it cannot run a command or answer an approval, so a webhook integration never holds Mattermost’s credential. Leave it unset to disable HTTP trigger intake; every request is then refused. Generate it as for CALLBACK_TOKEN, and never reuse that value here.

WORKSPACE_ROOTstringrequired

The directory holding one workspace per agent. Everything an agent writes through a tool is confined beneath its own.

Provisioning

The administrator provisioning signs in as. These reach the provisioning subprocess and no further: the container entrypoint drops them from the environment before the app itself is imported.

MATTERMOST_ADMIN_EMAILstring

Email of the administrator provisioning signs in as, and creates the account with on a Mattermost that has no users yet. Unread when a token is given.

MATTERMOST_ADMIN_PASSWORDstring

Password of that administrator.

MATTERMOST_ADMIN_TOKENstring

A personal access token belonging to a system administrator that already exists, given in place of the three variables above. The only credential a Mattermost server someone else runs should be provisioned with: it creates no account, and it is what an administrator with MFA enabled can offer, since Mattermost refuses those a password login over the API.

MATTERMOST_ADMIN_USERNAMEstring

Username of that administrator — also how you log in to Mattermost yourself.

Compose only

.env also sets COMPOSE_PROFILES, APP_BIND_HOST, MATTERMOST_PORT and POSTGRES_PASSWORD, which docker-compose.yaml reads and the app never sees: COMPOSE_PROFILES decides whether the bundled Mattermost and its database start at all, and APP_BIND_HOST is the interface that port is published on, the loopback by default. The CONFIG_PATH there is the host-side path Compose mounts into the container.