Settings
rendimiento is configured only through environment variables, read once at startup in cmd/rendimiento/main.go. On a cluster, they come from the rendimiento ConfigMap and a few Secrets (deploy/rendimiento.yaml has example values; keep a real cluster's values in a private overlay, see How the platform is deployed). To change a setting, edit the ConfigMap and run kubectl -n rendimiento-system rollout restart deploy/rendimiento.
Core
| Variable |
Default |
Example |
Meaning |
DATABASE_URL |
(required) |
from Secret rendimiento-db |
Postgres connection string |
BASE_URL |
http://localhost:8080 |
https://rendimiento.example.com |
public URL; used for OAuth callbacks, webhooks and links in GitHub checks |
BOOK_URL, BOOK_URL_ES |
(empty: no link) |
https://learn.example.com/, https://aprende.example.com/ |
the book in English and in Spanish, linked from the welcome page that people see before they sign in |
ALLOWED_USERS |
(empty: nobody) |
your-github-login |
GitHub logins allowed to sign in (comma- or space-separated) |
SETUP_TOKEN |
— |
from Secret rendimiento-setup |
protects /api/setup/github until the GitHub App exists |
NAMESPACE |
rendimiento-system |
|
where the platform and its Secrets live |
LISTEN |
:8080 |
|
HTTP address (API, UI, webhooks) |
METRICS_ADDR |
:9090 |
|
Prometheus metrics (controller-runtime) |
LEADER_ELECTION |
true |
false |
one active replica; off because one Recreate replica never overlaps |
GitHub
| Variable |
Default |
Meaning |
GITHUB_APP_NAME |
rendimiento |
the App's name, used when creating it with the manifest flow (rendimiento here) |
GITHUB_SECRET |
rendimiento-github |
the Secret the App's credentials are saved in after setup |
Builds
| Variable |
Default |
Example |
Meaning |
REGISTRY |
registry.example.lan:5000 |
|
where images and build caches are pushed |
REGISTRY_INSECURE |
true |
|
registry over plain HTTP |
BUILD_NAMESPACE |
rendimiento-builds |
|
where build and test pods run |
BUILDKIT_POOL |
(empty) |
buildkitd-pool.devops-tools.svc.cluster.local |
headless Service of the daemon pool; images are spread across it by rendezvous hashing |
BUILDKIT_ADDR |
tcp://buildkitd.devops-tools.svc.cluster.local:1234 |
|
the single daemon, used when there is no pool or the pool can't be resolved |
BUILDKIT_IMAGE |
moby/buildkit:v0.18.2 |
|
image of the buildctl client in build pods |
MAX_PARALLEL_STEPS |
2 |
4 |
steps running at once, across all runs |
STEP_TIMEOUT |
45m |
|
longest one step may run (≥ 1m) |
BUILD_EXCLUDE_NODES |
(empty) |
gpu-node |
nodes build pods must avoid |
RAILPACK_IMAGE |
(empty: Railpack off) |
registry.example.lan:5000/rendimiento-railpack:0.40.0 |
the Railpack CLI image, for services without a Dockerfile |
RAILPACK_FRONTEND |
(empty) |
ghcr.io/railwayapp/railpack-frontend:v0.40.0 |
the BuildKit frontend matching that version |
TEST_POSTGRES_IMAGE |
postgres:17-alpine |
|
the throwaway database of tests with postgres: true |
TEST_CACHE_STORAGE_CLASS |
(empty: the cluster's default) |
local-path |
storage class of the volumes of tests with cache: true; a node-local class is fastest (the test then runs on that node) |
TEST_CACHE_SIZE |
10Gi |
|
size of each of those volumes |
Rendering apps
| Variable |
Default |
Meaning |
INGRESS_CLASS |
nginx |
ingressClassName of app Ingresses |
CLUSTER_ISSUER |
letsencrypt-prod |
cert-manager issuer for app certificates |
STORAGE_CLASS |
longhorn |
storage class of volume: claims and needs: databases |
VOLUME_LABELS |
(empty) |
KEY=value pairs (comma-separated) added to every app volume claim, e.g. recurring-job.longhorn.io/source=enabled,recurring-job-group.longhorn.io/backup-nightly=enabled to back them up nightly |
GPU_RESOURCE |
(empty) |
resource name requested by gpu: services (nvidia.com/gpu) |
GPU_RUNTIME_CLASS |
(empty) |
runtime class for GPU pods (nvidia) |
GPU_HOST_PATHS |
(empty) |
host folders mounted read-only into GPU pods (driver libraries) |
GPU_ENV |
(empty) |
KEY=value;KEY=value added to GPU containers |
GPU_SHARED_MEMORY |
(empty) |
size of /dev/shm for GPU pods |
DNS
Taken from the optional Secret rendimiento-dns. Without a token, DNS automation is off (dns.Noop).
| Variable |
Default |
Meaning |
CLOUDFLARE_API_TOKEN |
— |
token with Zone:DNS:Edit |
DNS_TARGET |
— |
where app hostnames point; an IP turns on dynamic DNS |
DNS_ZONE |
— |
the default zone offered in the wizard (example.com) |
DNS_PROXIED |
false |
create records behind Cloudflare's proxy (true here) |
DDNS_INTERVAL |
5m |
how often dynamic DNS checks the public IP (≥ 1m) |
Uptime checks
| Variable |
Default |
Meaning |
UPTIME_INTERVAL |
1m |
How often every service is checked (Reliability); 0 turns checks off. At least 10s. |
VERIFY_WINDOW |
5m |
How long each new release is watched before it counts as verified (verifying releases); 0 turns verification and automatic rollback off. At least 1m. |
Notifications
| Variable |
Default |
Example |
Meaning |
NOTIFY_EMAIL_TO |
(empty: off) |
[email protected] |
who gets notification emails, comma-separated |
NOTIFY_LANG |
en |
es |
the language of the emails: en, or es for Mexican Spanish |
NOTIFY_EMAIL_FROM |
rendimiento <[email protected]> |
|
the sender; must be on a Resend-verified domain |
RESEND_API_KEY |
— |
from Secret rendimiento-notify |
the Resend API key |
Public stats
| Variable |
Default |
Example |
Meaning |
PUBLIC_STATS |
false |
true |
serve GET /api/public/stats without login |
STATS_LISTEN |
(empty: on the main listener) |
:8081 |
serve the public stats only on this internal port, not on the public listener |
PUBLIC_STATS_ORIGINS |
(none) |
|
browser origins allowed to fetch it (CORS); not needed when it's fetched server-side |
PUBLIC_STATS_TZ |
UTC |
America/New_York |
the time zone its days are counted in |
PUBLIC_ACTIVITY |
false |
true |
show Right now on the welcome page: what is building and the latest releases, by app name (GET /api/public/activity) |
Visits (Umami)
| Variable |
Default |
Example |
Meaning |
UMAMI_URL |
(empty: off) |
http://umami.umami.svc.cluster.local:3000 |
Umami inside the cluster, read for the Visits tab and the dashboard's visitors panel |
UMAMI_PUBLIC_URL |
(empty: no links) |
https://umami.example.com |
Umami's public address, for "Open in Umami" links |
UMAMI_USERNAME, UMAMI_PASSWORD |
— |
from the rendimiento-umami Secret |
a view-only Umami user in the team that owns the websites |
Days and hours are counted in PUBLIC_STATS_TZ.
Log archive
| Variable |
Default |
Example |
Meaning |
LOG_ARCHIVE_ENDPOINT |
(empty: off) |
garage.garage.svc.cluster.local:3900 |
S3-compatible host:port that step logs are archived to |
LOG_ARCHIVE_BUCKET |
rendimiento-logs |
|
the bucket |
LOG_ARCHIVE_SECURE |
false |
|
use HTTPS |
LOG_ARCHIVE_ACCESS_KEY, LOG_ARCHIVE_SECRET_KEY |
— |
from Secret rendimiento-logs |
credentials of a user allowed to use the bucket |
LOG_RETENTION_DAYS |
365 |
|
archived logs are deleted after this many days (a lifecycle rule on the bucket) |
Add-ons
| Variable |
Default |
Meaning |
ADDONS_REPO |
p0dxD/gitops |
the git repository add-ons are declared in (addons/*.yaml) |
ADDONS_IDENTITY |
system:serviceaccount:<NAMESPACE>:rendimiento-addons |
the identity add-on objects are applied as (impersonation) |
Secret (in rendimiento-system) |
Keys |
Written by |
rendimiento-db |
password |
you, once |
rendimiento-setup |
token |
you, once |
rendimiento-github |
App ID, private key, webhook secret, OAuth client |
the setup flow |
rendimiento-dns |
CLOUDFLARE_API_TOKEN, DNS_TARGET |
you |
rendimiento-notify |
RESEND_API_KEY |
you |
rendimiento-logs |
LOG_ARCHIVE_ACCESS_KEY, LOG_ARCHIVE_SECRET_KEY |
you (a storage key limited to the bucket) |