.env file itself — supply these
through whatever starts the binary: a shell, a systemd environment file or credential store,
container configuration, or a hosting platform.
The convention: CUSTOS_-prefixed variables are ours. Third-party credentials keep their own
upstream names (RESEND_API_KEY, the OTEL_* family).
Required
Control plane
CUSTOS_ENCRYPTION is Custos’s own hybrid X25519 payload sealing between the API and its clients. It
is separate from HTTPS/TLS and from at-rest vault encryption, and turning it off disables neither.
It is commonly off in local development.Invitations, password resets, and email
OpenTelemetry
Setting the one general endpoint enables logs, traces, and metrics over OTLP HTTP/protobuf. The exporters append/v1/logs, /v1/traces, or /v1/metrics as appropriate.
Use the signal-specific variables only when exporting selected signals, and leave the general
endpoint empty. If every endpoint is empty, OTLP export is disabled and JSON logs still go to
stderr.
Daemons need no OTLP variables of their own — see Observability.
Client-side value
CUSTOS_SERVER_TRANSPORT_PUBLIC_KEY is generated by custoscp gen-keys and configured on every
client that calls the API — for the web app, as a container environment variable. The control-plane
process never reads it.