Skip to content

UI configuration options#

This documentation applies to Piler enterprise edition 2.0.0

Revision #1

Publication date: 2025-SEP-09


PILER_KEY#

Default value: /etc/piler/piler.key

Description: Path to the private key file used by Piler for signing and cryptographic operations.


RETRIEVER_METHOD#

Default value: direct

Description: Defines how archived emails are retrieved. Options:

  • direct: Read directly from storage
  • socket: Use a UNIX domain socket connection
  • s3: Retrieve from Amazon S3 or compatible storage

LOG_LEVEL#

Default value: INFO

Description: Sets the logging verbosity level. Possible values: DEBUG, INFO, WARN, ERROR.


LOG_FORMAT#

Default value: json

Description: Output format of logs. Options: json, plain.


USERNAME#

Default value: ""

Description: Username for the UI to run when started as root.


LICENSE_FILE#

Default value: ./license.jwt

Description: Path to the license file containing a signed license token.


LISTEN_ADDR#

Default value: :3000

Description: Address and port where the Fiber web application will listen for HTTP requests.


TRUSTED_PROXIES#

Default value: 127.0.0.1

Description: Comma-separated list of trusted proxy IP addresses for handling forwarded headers.


PROXY_HEADER#

Default value: X-Forwarded-For

Description: HTTP header used to extract the real client IP address when behind a proxy.


RETRIEVER_SOCKET#

Default value: /var/piler/sockets/retriever.sock

Description: Path to the UNIX domain socket used when RETRIEVER_METHOD=socket.


MYSQL_USER#

Default value: piler

Description: MySQL database username.


MYSQL_PASSWORD#

Default value: piler123

Description: MySQL database password.


MYSQL_HOST#

Default value: localhost:3306

Description: Host and port of the MySQL server.


MYSQL_MAX_OPEN_CONN#

Default value: 50

Description: Maximum number of open MySQL connections per child process.


MYSQL_MAX_IDLE_CONN#

Default value: 20

Description: Maximum number of idle MySQL connections in the connection pool.


MYSQL_CONN_MAX_LIFETIME#

Default value: 300s

Description: Maximum lifetime of a MySQL connection before it is recycled.


MYSQL_USE_TLS#

Default value: false

Description: Enable TLS for the connection to MySQL/MariaDB.


MYSQL_TLS_CA_CERT#

Default value: ""

Description: Path to a CA certificate file, used to verify a self-signed or custom CA when MYSQL_USE_TLS is enabled.


MYSQL_TLS_SKIP_VERIFY#

Default value: false

Description: Skip verification of the MySQL server's TLS certificate. Only use for testing.


DSN#

Default value: piler:piler123@tcp(127.0.0.1:3306)/?parseTime=true

Description: MySQL connection DSN used by the MS Teams archiving module. The main application's own database connection is still assembled from MYSQL_USER, MYSQL_PASSWORD and MYSQL_HOST.


MANTICORE_DSN#

Default value: piler:piler123@tcp(localhost:9306)/?parseTime=true

Description: DSN for connecting to Manticore search engine (read/write).


MANTICORE_READONLY_DSN#

Default value: piler:piler123@tcp(localhost:9307)/?parseTime=true

Description: DSN for connecting to Manticore search engine (read-only).


REDIS_ADDR#

Default value: 127.0.0.1:6379

Description: Redis server address.


TENANT_RATE_LIMIT_PER_MINUTE#

Default value: 20000

Description: Maximum number of requests allowed per tenant per minute.


IO_RATE_LIMIT_PER_ROUTE#

Default value: 200

Description: I/O rate limit for routes that retrieves emails or attachments from the storage, eg. view, download, attachments (requests per second).


DEV_MODE#

Default value: false

Description: Enables development mode with relaxed security and verbose logging.


NODE_TYPE#

Default value: master

Description: Role of the current node in a multi-node setup. Options: master, worker.


WORKERS#

Default value: ""

Description: List of worker node addresses (for multi-node setups).


STANDBY_NODES#

Default value: ""

Description: List of standby node addresses, used for multi-node high-availability failover.


JWT_SECRET#

Default value: ""

Description: Secret key used to sign JWT tokens.


SESSION_DURATION#

Default value: 3h

Description: How long an authenticated user session remains valid before requiring re-login.


ENABLE_CATEGORY#

Default value: true

Description: Enable or disable category handling in the UI.


ENABLE_REDACT#

Default value: true

Description: Enable or disable text redaction in the UI.


LANGUAGES#

Default value: de,en,es,fr,it,zh

Description: List of supported UI languages.


LOCALE#

Default value: en-US

Description: Default locale used for formatting dates and text.


Default value: /assets/images/login-logo.svg

Description: Path to the logo displayed on the login page.


Default value: /assets/images/logo-header.svg

Description: Path to the logo displayed in the application header.


Default value: /assets/images/logo-round.svg

Description: Path to the logo used in toast notifications.


Default value: ""

Description: Custom link displayed in the application header.


Default value: ""

Description: Title text for the header link.


MAX_CONTENT_LENGTH_TO_DISPLAY#

Default value: 30000

Description: Maximum content size (in bytes) to render in the UI. Longer messages are truncated in the message preview, but other than that the message is still intact.


RT_INDEX#

Default value: true

Description: Enable or disable real-time indexing.


EXTRA_NOTES#

Default value: ""

Description: Custom notes displayed in the login page.


MULTITENANCY#

Default value: false

Description: Enable or disable multi-tenant mode.


MULTINODES#

Default value: false

Description: Enable or disable multi-node mode.


CSS#

Default value:

<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/bootstrap@5.3.3/dist/css/bootstrap.min.css" integrity="sha384-QWTKZyjpPEjISv5WaRU9OFeRpok6YctnYmDr5pNlyT2bRjXh0JMhjY6hW+ALEwIH" crossorigin="anonymous"> 
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/bootstrap-icons@1.11.3/font/bootstrap-icons.min.css"> 
<link rel="stylesheet" href="/assets/css/style.css">

Description: Built-in CSS includes for styling the UI.


CUSTOM_CSS#

Default value: ""

Description: Custom CSS overrides for the UI.


LEADER_ELECTION_ENABLED#

Default value: false

Description: Enable Redis-based leader election, used to coordinate scheduled/background jobs in multi-master deployments so only one node runs them at a time.


LEADER_REDIS_KEY#

Default value: piler:leader

Description: Redis key used to hold the leader lock.


LEADER_LOCK_TTL#

Default value: 30s

Description: Time-to-live of the leader lock. If the current leader fails to renew it within this time, another node can take over.


LEADER_RENEW_INTERVAL#

Default value: 10s

Description: Interval at which the current leader renews its lock.


LEADER_RETRY_INTERVAL#

Default value: 5s

Description: Interval at which non-leader nodes retry to acquire leadership.


ENABLE_SLACK#

Default value: false

Description: Internal flag automatically set to true when the license includes the slack feature. Not intended to be set directly.


ADMIN_GROUP#

Default value: ""

Description: LDAP or SSO group mapped to administrators.


AUDITOR_GROUP#

Default value: ""

Description: LDAP or SSO group mapped to auditors.


RESTRICTED_AUDITOR_GROUP#

Default value: ""

Description: LDAP or SSO group mapped to restricted auditors.


DATAOFFICER_GROUP#

Default value: ""

Description: LDAP or SSO group mapped to data officers.


ENABLE_GOOGLE_AUTH#

Default value: false

Description: Enable Google OAuth2 authentication.


GOOGLE_CLIENT_ID#

Default value: ""

Description: Google OAuth2 client ID.


GOOGLE_CLIENT_SECRET#

Default value: ""

Description: Google OAuth2 client secret.


GOOGLE_REDIRECT_URL#

Default value: ""

Description: Redirect URL for Google OAuth2 login.


ENABLE_AZURE_AUTH#

Default value: false

Description: Enable Microsoft Azure OAuth2 authentication.


AZURE_CLIENT_ID#

Default value: ""

Description: Azure OAuth2 client ID.


AZURE_CLIENT_SECRET#

Default value: ""

Description: Azure OAuth2 client secret.


AZURE_TENANT_ID#

Default value: ""

Description: Azure Active Directory tenant ID.


AZURE_REDIRECT_URL#

Default value: ""

Description: Redirect URL for Azure OAuth2 login.


ENABLE_GENERIC_OAUTH_AUTH#

Default value: false

Description: Enable generic OAuth2 authentication.


GENERIC_OAUTH_CLIENT_ID#

Default value: ""

Description: Client ID for generic OAuth2 provider.


GENERIC_OAUTH_CLIENT_SECRET#

Default value: ""

Description: Client secret for generic OAuth2 provider.


GENERIC_OAUTH_REDIRECT_URL#

Default value: ""

Description: Redirect URL for generic OAuth2 login.


GENERIC_OAUTH_AUTH_URL#

Default value: ""

Description: Authorization URL for generic OAuth2 provider.


GENERIC_OAUTH_TOKEN_URL#

Default value: ""

Description: Token URL for generic OAuth2 provider.


GENERIC_OAUTH_USERINFO_URL#

Default value: ""

Description: User info URL for generic OAuth2 provider.


ENABLE_AUTHENTICATOR#

Default value: true

Description: Enable TOTP authenticator usage for 2FA.


ENABLE_PASSKEY#

Default value: false

Description: Enable WebAuthn/passkey-based login as a 2FA/authentication method.


DATE_FORMAT#

Default value: YYYY/MM/DD

Description: Default date format used in the UI.


TIMEZONE#

Default value: Europe/Budapest

Description: Default timezone used by the application.


MAX_DOWNLOAD_MESSAGES#

Default value: 100

Description: Maximum number of messages that can be downloaded at once.


MAX_PURGE_BATCH_SIZE#

Default value: 1000

Description: Maximum number of messages deleted in a single purge batch.


SMARTHOST#

Default value: ""

Description: SMTP relay host (smarthost) used for restoring emails.


SMARTHOST_PORT#

Default value: ""

Description: Port number for the smarthost.


SMTP_USERNAME#

Default value: ""

Description: Username used to authenticate with the smarthost, if required.


SMTP_PASSWORD#

Default value: ""

Description: Password used to authenticate with the smarthost, if required.


SMTP_USE_TLS#

Default value: false

Description: Connect to the smarthost using implicit TLS.


SMTP_USE_STARTTLS#

Default value: false

Description: Upgrade the smarthost connection to TLS using STARTTLS.


SMTP_SKIP_VERIFY#

Default value: false

Description: Skip verification of the smarthost's TLS certificate. Only use for testing.


NOREPLY_EMAIL_ADDRESS#

Default value: no-reply@archive.example.com

Description: Default "no-reply" email address for the UI when restoring email messages.


ENABLE_LDAP_AUTH#

Default value: false

Description: Enable LDAP authentication.


LDAP_HOST#

Default value: ""

Description: LDAP server host and port.


LDAP_BASE_DN#

Default value: ""

Description: Base DN for LDAP searches.


LDAP_BIND_DN#

Default value: ""

Description: Bind DN used for LDAP authentication.


LDAP_BIND_PASSWORD#

Default value: ""

Description: Password for LDAP bind DN.


LDAP_ACCOUNT_OBJECTCLASS#

Default value: ""

Description: LDAP object class for user accounts.


LDAP_ACCOUNT_MAIL_ATTR#

Default value: ""

Description: LDAP attribute for user email addresses.


LDAP_ACCOUNT_USERID_ATTR#

Default value: ""

Description: LDAP attribute for user ID.


LDAP_ACCOUNT_USERNAME_ATTR#

Default value: ""

Description: LDAP attribute for username.


LDAP_DISTRIBUTIONLIST_OBJECTCLASS#

Default value: ""

Description: LDAP object class for distribution lists.


LDAP_DISTRIBUTIONLIST_MAIL_ATTR#

Default value: ""

Description: LDAP attribute for distribution list email addresses.


LDAP_USE_TLS#

Default value: true

Description: Use TLS (LDAPS) when connecting to the LDAP server.


ENABLE_IMAP_AUTH#

Default value: false

Description: Enable IMAP authentication.


RESTORE_OVER_IMAP#

Default value: true

Description: Allow restoring messages to user mailboxes over IMAP.


IMAP_SERVER#

Default value: ""

Description: IMAP server address.


IMAP_FOLDER#

Default value: INBOX

Description: IMAP folder where restored emails are delivered.


IMAP_USE_TLS#

Default value: true

Description: Use TLS for IMAP connections.


IMAP_ENCRYPT_KEY#

Default value: ""

Description: Key used to encrypt/decrypt stored IMAP authentication credentials.


ENABLE_POP3_AUTH#

Default value: false

Description: Enable POP3 authentication.


POP3_SERVER#

Default value: ""

Description: POP3 server address.


POP3_USE_TLS#

Default value: true

Description: Use TLS for POP3 connections.


MAILCOW_HOST#

Default value: ""

Description: Mailcow server address.


MAILCOW_API_KEY#

Default value: ""

Description: API key for Mailcow integration.


CAUTION_TEXT#

Default value: Caution: This message was sent from outside the company.<br />Please do not click links or open attachments unless you<br />recognize the source of this email and know the content is safe!

Description: Warning banner displayed on external messages.


GOTENBERG_ADDR#

Default value: ""

Description: Address of Gotenberg service used for document PDF export.


ENABLE_EXPORT#

Default value: true

Description: Enable export functionality for messages.


MIN_SIZE_TO_ENABLE_EXPORT#

Default value: 10000000000

Description: Minimum storage size (bytes) required before export is enabled.


MAX_EXPORT_MESSAGES#

Default value: 20000

Description: Maximum number of messages included in a single export.


MAX_EXPORT_SIZE_BYTES#

Default value: 5368709120 (5 GB)

Description: Maximum total size (in bytes) of a single export job.


EXPORT_TIMEOUT#

Default value: 300s

Description: Timeout duration for export jobs.


ADMIN_CAN_MANAGE_EXPORTS#

Default value: true

Description: Allow administrators to manage export jobs.


DIR_EXPORT#

Default value: /var/piler/export

Description: Directory where exported files are stored.


EXPORT_WARNING_TEXT#

Default value: Exported files will be auto removed in 7 days. Please download them in their scheduled period

Description: Warning text shown to users about export retention.


EDISCOVERY_MAX_GLOBAL_EXPORTS#

Default value: 3

Description: Maximum number of eDiscovery export jobs that can run concurrently across the whole instance.


EDISCOVERY_MAX_TENANT_EXPORTS#

Default value: 1

Description: Maximum number of eDiscovery export jobs that can run concurrently for a single tenant.


EDISCOVERY_WORKERS#

Default value: 4

Description: Number of worker goroutines processing eDiscovery export jobs.


ENABLE_DELETE#

Default value: false

Description: Enable delete functionality for messages.


NEED_TO_APPROVE_DELETE#

Default value: false

Description: Require data officer approval before message deletion.


ENABLE_DELETE_FOR_USERS#

Default value: false

Description: Allow non-admin users (not just admins/data officers) to delete their own messages, when ENABLE_DELETE is also enabled.


APP_TRACE_NAME#

Default value: ""

Description: Application trace name (used for distributed tracing).


TRACE_ADDR#

Default value: ""

Description: Trace collector address (e.g., OpenTelemetry backend).


TURNSTILE_SITE_KEY#

Default value: ""

Description: Cloudflare Turnstile site key.


TURNSTILE_SECRET_KEY#

Default value: ""

Description: Cloudflare Turnstile secret key.


TIKA_URL#

Default value: http://127.0.0.1:9998/tika

Description: Apache Tika server endpoint for content extraction.


HEADER_LINE_TO_HIDE#

Default value: ""

Description: Comma separated Email header lines (without the colon!) to hide in the UI.

Example: HEADER_LINE_TO_HIDE=Received,Delivered-To#

SPAM_HEADER_LINE#

Default value: X-Spam-Flag: YES

Description: Email header line (name and value) used to detect whether a message was flagged as spam.


SAML_CERT_FILE#

Default value: saml.crt

Description: Path to the SAML certificate file.


SAML_KEY_FILE#

Default value: saml.key

Description: Path to the SAML private key file.


SAML_METADATA_URL#

Default value: ""

Description: Metadata URL for SAML IdP.


TSA_PUBLIC_KEY_FILE#

Default value: ""

Description: Path to public key used to verify timestamp authority signatures.


JWT_ED25519_PUBLIC_KEYS_DIR#

Default value: ""

Description: Directory containing ED25519 public keys for validating externally-issued JWT tokens (external JWT authentication).


CONTENT_SECURITY_POLICY#

Default value:

default-src 'self'; script-src 'self' 'unsafe-eval' 'sha256-ZswfTY7H35rbv8WC7NXBoiC7WNu86vSzCDChNWwZZDM=' 
'sha256-Sc84R3QT4gTYLl5M2SIYCramZDi3OcEjJiog35/7ydU=' https://cdn.jsdelivr.net https://challenges.cloudflare.com ; 
style-src 'self' https://cdn.jsdelivr.net; img-src 'self' data: https://cdn.jsdelivr.net https://challenges.cloudflare.com; 
font-src 'self' https://cdn.jsdelivr.net; frame-src https://challenges.cloudflare.com; connect-src 'self'; 
object-src 'none'; base-uri 'none'; form-action 'self'; frame-ancestors 'none';

Description: Content Security Policy (CSP) header applied by the application.


S3_ENDPOINT#

Default value: ""

Description: S3-compatible storage endpoint, eg. s3.eu-central-003.backblazeb2.com


S3_ACCESS_KEY#

Default value: ""

Description: Access key for S3 storage.


S3_SECRET_KEY#

Default value: ""

Description: Secret key for S3 storage.


S3_USE_SSL#

Default value: true

Description: Enable SSL/TLS for S3 connections.


S3_REGION#

Default value: ""

Description: S3 region name.


S3_BUCKET_PREFIX#

Default value: ""

Description: Prefix applied to S3 buckets.


S3_USE_SUBDIRS#

Default value: true

Description: Store objects in subdirectories within the S3 bucket.


S3_RETRY_MAX_ATTEMPTS#

Default value: 3

Description: Maximum retry attempts when the scanner encounters a missing S3 object.


S3_RETRY_INITIAL_DELAY#

Default value: 2s

Description: Initial delay between S3 retry attempts; doubles after each attempt.


DEMO_MODE#

Default value: false

Description: Enable demo mode with restricted functionality.


ALLOWED_CIDRS#

Default value: 127.0.0.0/8,172.18.0.0/16,172.19.0.0/16,172.20.0.0/16

Description: Defines CIDR blocks allowed to access the /metrics and /healthz endpoints.


BILLING_SERVER_URL#

Default value: https://billing1.mailpiler.com,https://billing2.mailpiler.com

Description: Comma-separated list of billing/telemetry server URLs that encrypted usage reports are POSTed to.


AFTTER_START_REPORT_DELAY#

Default value: 600s

Description: Delay after application startup before the first telemetry report is sent. (Note: the variable name retains a typo from the original implementation.)


ANALYTICS_ENABLED#

Default value: true

Description: Enable collection of analytics data used by the dashboard and billing reports.


ANALYTICS_SYNC_INTERVAL#

Default value: 3600s

Description: Interval at which the analytics background worker syncs aggregated usage data.


QUOTA_NOTIFICATION_INTERVAL#

Default value: 86400s

Description: Interval at which the quota-notification background worker checks and sends storage/usage quota notifications.


METRICS_AGGREGATOR_DELAY#

Default value: 60s

Description: Delay between processing each tenant while aggregating health metrics (not a total run duration).


SMART_INSIGHTS_ENABLED#

Default value: false

Description: Enable the Smart Insights scanner, which detects sensitive information (SSN, credit card, IBAN, passport, etc.) in archived emails. See docs/SCANNER-CONFIGURATION-GUIDE.md.


SCAN_ATTACHMENTS#

Default value: false

Description: Also scan message attachments (not just body text) for sensitive information.


SCAN_RATE_LIMIT#

Default value: 100

Description: Maximum scanner throughput, in messages per second.


MIN_CONFIDENCE#

Default value: 0.80

Description: Minimum detector confidence score (0.0-1.0) required for a Smart Insights match to be reported.


ENABLED_DETECTORS#

Default value: ssn,credit_card,passport,iban

Description: Comma-separated list of Smart Insights detectors to run. The SSN detector has a high false-positive rate in technical environments; consider disabling it there (see docs/SCANNER-CONFIGURATION-GUIDE.md).


SECURITY_RISK_ENABLED#

Default value: false

Description: Enable security risk scoring for scanned messages.


RISK_ALERT_THRESHOLD#

Default value: 60

Description: Security risk score (0-100) above which an alert (email/SIEM) is triggered.


COMPLIANCE_RISK_ENABLED#

Default value: false

Description: Enable compliance risk scoring for scanned messages.


COMPLIANCE_ALERT_THRESHOLD#

Default value: 50

Description: Compliance risk score (0-100) above which an alert (email/SIEM) is triggered.


PERCOLATE_CATEGORIES_ENABLED#

Default value: false

Description: Enable percolate-query-based automatic categorization of messages during scanning.


SCANNER_THREADS#

Default value: 1

Description: Number of worker threads used by the scanner to process messages in parallel.


ML_PHISHING_ENABLED#

Default value: false

Description: Enable the dependency-free Go-based ML phishing detector.


ML_PHISHING_MODEL_PATH#

Default value: /var/piler/models/phishing_detector.json

Description: Path to the phishing detection model file.


ML_PHISHING_THRESHOLD#

Default value: 0.5

Description: Confidence threshold (0.0-1.0) above which a message is flagged as phishing.


SEMANTIC_SEARCH_ENABLED#

Default value: false

Description: Globally enable AI-powered semantic search (required for embedding generation and hybrid search). Requires the sutoj/piler-ui:semantic image. See the Semantic Search section of CLAUDE.md / project docs.


SEMANTIC_SEARCH_DIMENSIONS#

Default value: 384

Description: Dimensionality of the embedding vectors (must match the embedding model, e.g. 384 for all-MiniLM-L6-v2).


SEMANTIC_SEARCH_MAX_TOKENS#

Default value: 1000

Description: Maximum number of tokens from a message (subject + body) used to generate its embedding.


SEMANTIC_SEARCH_SCORE_THRESHOLD#

Default value: 0.65

Description: Cosine-distance score threshold (0.0-1.0) for semantic search results; lower is stricter (more relevant, fewer results).


SEMANTIC_SEARCH_KNN_EF#

Default value: 100

Description: HNSW query-time ef parameter controlling semantic search quality vs. speed trade-off; higher is more accurate but slower.


SEMANTIC_SEARCH_ENDPOINT_URL#

Default value: ""

Description: URL of the OpenAI-compatible embeddings endpoint used to generate vectors (e.g. http://ollama:11434/v1/embeddings). Required for semantic search.


SEMANTIC_SEARCH_ENDPOINT_MODEL#

Default value: ""

Description: Model name sent in the request body to the embeddings endpoint.


SEMANTIC_SEARCH_ENDPOINT_API_KEY#

Default value: ""

Description: Bearer token for the embeddings endpoint; leave empty for unauthenticated servers.


SEMANTIC_SEARCH_DOC_PREFIX#

Default value: ""

Description: Text prepended to email content before indexing, required by asymmetric embedding models (e.g. multilingual-e5's "passage: "). Leave empty for symmetric models (BGE-M3, all-MiniLM, etc.).


SEMANTIC_SEARCH_QUERY_PREFIX#

Default value: ""

Description: Text prepended to search queries at query time, required by asymmetric embedding models (e.g. multilingual-e5's "query: "). Leave empty for symmetric models.


CAPACITY_WARNING_THRESHOLD_GB#

Default value: 1024 (1 TB)

Description: Total stored-data size, in GB, above which a capacity warning is shown in provider/tenant analytics.


LLM_BASE_URL#

Default value: http://localhost:11434

Description: Base URL of the Ollama (or compatible) API used for LLM-powered features such as message summarization.


LLM_MODEL#

Default value: llama3.1:8b

Description: Model name used for LLM summarization requests.


LLM_ENABLED#

Default value: false

Description: Enable LLM-powered features (e.g. message summarization, natural-language search).


LLM_CACHE_EXPIRY_MINUTES#

Default value: 15

Description: Redis cache expiry, in minutes, for LLM-generated results.


NL2QUERY_PROMPT_FILE#

Default value: ""

Description: Path to a custom prompt template used to translate natural-language search input into Manticore search syntax. Leave empty to use the embedded default prompt.


TEAMS_ENABLED#

Default value: false

Description: Enable Microsoft Teams message archiving.


TEAMS_ATTACHMENT_STORAGE#

Default value: local

Description: Storage backend for Teams attachments: local (filesystem) or s3.


TEAMS_S3_ENDPOINT#

Default value: ""

Description: S3-compatible endpoint used for Teams attachment storage, when TEAMS_ATTACHMENT_STORAGE=s3.


TEAMS_S3_BUCKET_PREFIX#

Default value: ""

Description: Prefix prepended to the Teams S3 bucket name, e.g. acme- → bucket acme-teams-<tenantID>.


TEAMS_S3_BUCKET#

Default value: teams

Description: Base bucket name used for Teams attachment storage (combined with the prefix and tenant ID).


TEAMS_S3_ACCESS_KEY#

Default value: ""

Description: Access key for Teams attachment S3 storage.


TEAMS_S3_SECRET_KEY#

Default value: ""

Description: Secret key for Teams attachment S3 storage.


TEAMS_S3_USE_SSL#

Default value: true

Description: Enable SSL/TLS for Teams attachment S3 connections.


TEAMS_S3_REGION#

Default value: us-east-1

Description: S3 region used for Teams attachment storage.


TEAMS_RETENTION_ENABLED#

Default value: false

Description: Enable automatic deletion of Teams messages/attachments once their retention period expires.


TEAMS_RETENTION_DAYS#

Default value: 2555 (7 years)

Description: Number of days Teams messages/attachments are retained before automatic deletion.


TEAMS_RETENTION_CHECK_INTERVAL#

Default value: 86400s

Description: Interval at which the Teams retention job checks for expired data.


SLACK_ENABLED#

Default value: false

Description: Enable the Slack archiving UI and related settings panel.


SLACK_WORKSPACE_ID#

Default value: ""

Description: ID of the Slack workspace being archived.


SLACK_APP_ID#

Default value: ""

Description: Slack App ID used for the archiving integration.


SLACK_BOT_TOKEN#

Default value: ""

Description: Slack bot token used by the Slack collector to access workspace data.


SLACK_USER_TOKEN#

Default value: ""

Description: Slack user token used by the Slack collector, where elevated/user-level scopes are required.


SLACK_SYNC_INTERVAL_MINUTES#

Default value: 10

Description: Interval, in minutes, at which the Slack collector syncs new messages.


SLACK_ARCHIVE_CHANNELS#

Default value: true

Description: Archive public/private channel conversations.


SLACK_ARCHIVE_DMS#

Default value: true

Description: Archive direct messages (1:1 conversations).


SLACK_ARCHIVE_GROUP_DMS#

Default value: true

Description: Archive group direct messages (multi-person DMs).


SLACK_DOWNLOAD_FILES#

Default value: true

Description: Download and archive files shared in Slack conversations.


SLACK_ATTACHMENT_STORAGE#

Default value: file

Description: Storage backend for Slack attachments: file (filesystem) or s3.


SLACK_ATTACHMENT_PATH#

Default value: /var/piler/slack

Description: Local filesystem path used to store Slack attachments, when SLACK_ATTACHMENT_STORAGE=file.


SLACK_S3_ENDPOINT#

Default value: ""

Description: S3-compatible endpoint used for Slack attachment storage, when SLACK_ATTACHMENT_STORAGE=s3.


SLACK_S3_BUCKET_PREFIX#

Default value: ""

Description: Prefix prepended to the Slack S3 bucket name, e.g. acme- → bucket acme-slack-<tenantID>.


SLACK_S3_BUCKET#

Default value: slack

Description: Base bucket name used for Slack attachment storage (combined with the prefix and tenant ID).


SLACK_S3_ACCESS_KEY#

Default value: ""

Description: Access key for Slack attachment S3 storage.


SLACK_S3_SECRET_KEY#

Default value: ""

Description: Secret key for Slack attachment S3 storage.


SLACK_S3_USE_SSL#

Default value: true

Description: Enable SSL/TLS for Slack attachment S3 connections.


SLACK_S3_REGION#

Default value: us-east-1

Description: S3 region used for Slack attachment storage.


SLACK_PARALLEL_CONVERSATIONS#

Default value: 3

Description: Number of Slack conversations whose history is fetched concurrently during sync.


SLACK_PARALLEL_THREADS#

Default value: 5

Description: Number of Slack thread-reply fetches performed concurrently during sync.


SLACK_PARALLEL_FILES#

Default value: 3

Description: Number of Slack file downloads performed concurrently during sync.


SLACK_RETENTION_ENABLED#

Default value: false

Description: Enable automatic deletion of Slack messages/files once their retention period expires.


SLACK_RETENTION_DAYS#

Default value: 2555 (7 years)

Description: Number of days Slack messages/files are retained before automatic deletion.


SLACK_RETENTION_CHECK_INTERVAL#

Default value: 86400s

Description: Interval at which the Slack retention job checks for expired data.


SHOW_USER_SETTINGS#

Default value: true

Description: Show the user settings menu/page in the UI.


SHOW_LOGOUT_BUTTON#

Default value: true

Description: Show the logout button in the UI.


SHOW_IMPORT_MENU#

Default value: true

Description: Show the import menu in the UI.