Lumen
Reference

Settings and environment

Generated app, worker, and migration configuration names, ownership, defaults, and validators.

Each deployable reads only its own typed settings model. Secret values and credentials embedded in local development URLs are intentionally omitted; use the environment's approved secret manager for production values.

Settings

Owner modelEnvironment nameFieldRequiredTypeDefault behaviorValidation
MigrationSettingsDATABASE_ADMIN_URLdatabase_admin_urlyesstringRequired—
MigrationSettingsLUMEN_ENVIRONMENTdeployment_environmentnoDeploymentEnvironment"local"values local, preview, staging, production
ObservableEnvironmentSettingsOTEL_EXPORTER_OTLP_ENDPOINTotel_exporter_otlp_endpointnostring | nullnull—
ObservableEnvironmentSettingsOTEL_EXPORTER_OTLP_HEADERSotel_exporter_otlp_headersnostring | nullnullstring: format password
ObservableEnvironmentSettingsOTEL_EXPORTER_OTLP_TIMEOUT_SECONDSotel_exporter_otlp_timeout_secondsnointeger5minimum 1; maximum 30
ObservableEnvironmentSettingsOTEL_METRIC_EXPORT_INTERVAL_SECONDSotel_metric_export_interval_secondsnointeger60minimum 5; maximum 300
ObservableEnvironmentSettingsOTEL_DEPLOYMENT_ENVIRONMENTotel_deployment_environmentnostring"development"pattern ^[a-z][a-z0-9_-]{0,31}$
ObservableEnvironmentSettingsLUMEN_ENVIRONMENTdeployment_environmentnoDeploymentEnvironment"local"values local, preview, staging, production
SettingsOTEL_EXPORTER_OTLP_ENDPOINTotel_exporter_otlp_endpointnostring | nullnull—
SettingsOTEL_EXPORTER_OTLP_HEADERSotel_exporter_otlp_headersnostring | nullnullstring: format password
SettingsOTEL_EXPORTER_OTLP_TIMEOUT_SECONDSotel_exporter_otlp_timeout_secondsnointeger5minimum 1; maximum 30
SettingsOTEL_METRIC_EXPORT_INTERVAL_SECONDSotel_metric_export_interval_secondsnointeger60minimum 5; maximum 300
SettingsOTEL_DEPLOYMENT_ENVIRONMENTotel_deployment_environmentnostring"development"pattern ^[a-z][a-z0-9_-]{0,31}$
SettingsLUMEN_ENVIRONMENTdeployment_environmentnoDeploymentEnvironment"local"values local, preview, staging, production
SettingsDATABASE_APP_URLdatabase_app_urlnostringLocal development connection (credentials omitted)—
SettingsDATABASE_GATEWAY_URLdatabase_gateway_urlnostringLocal development connection (credentials omitted)—
SettingsARTIFACT_ROOTartifact_rootnostring.lumen-data/artifactsformat path
SettingsARTIFACT_STORAGE_PROVIDERartifact_storage_providernofilesystem | r2"filesystem"values filesystem, r2
SettingsR2_ENDPOINTr2_endpointnostring | nullnull—
SettingsR2_STAGING_ACCESS_KEY_IDr2_staging_access_key_idnostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsR2_STAGING_SECRET_ACCESS_KEYr2_staging_secret_access_keynostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsR2_APP_READ_ACCESS_KEY_IDr2_app_read_access_key_idnostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsR2_APP_READ_SECRET_ACCESS_KEYr2_app_read_secret_access_keynostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsR2_STAGING_BUCKETr2_staging_bucketnostring | nullnullstring: pattern ^[a-z0-9](?:[a-z0-9-]{1,61}[a-z0-9])$
SettingsR2_ARTIFACT_BUCKETr2_artifact_bucketnostring | nullnullstring: pattern ^[a-z0-9](?:[a-z0-9-]{1,61}[a-z0-9])$
SettingsPUBLIC_API_ORIGINpublic_api_originnostring"http://127.0.0.1:8000"absolute HTTP(S) origin without a path, query, or fragment
SettingsPRIVATE_WORKER_ORIGINprivate_worker_originnostring"http://127.0.0.1:8080"absolute HTTP(S) origin without a path, query, or fragment
SettingsAUTH_PROFILEauth_profileyesdevelopment | supabaseRequiredvalues development, supabase
SettingsDEVELOPMENT_BEARER_TOKENdevelopment_bearer_tokennostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsSUPABASE_URLsupabase_urlnostring | nullnull—
SettingsCURSOR_SIGNING_KEYcursor_signing_keyyesstringNot displayed; supply through an approved secret store.minimum length 32; format password
SettingsATTEMPT_CAPABILITY_SIGNING_KEYattempt_capability_signing_keynostring | nullNot displayed; supply through an approved secret store.string: minimum length 32; format password
SettingsATTEMPT_INFERENCE_PROFILE_IDattempt_inference_profile_idnoAttemptInferenceProfileId"openai.gpt-5-6-terra.v1"values openai.gpt-5-6-terra.v1, fake.managed-canary.v1
SettingsOPENAI_API_KEYopenai_api_keynostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsANTHROPIC_API_KEYanthropic_api_keynostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsPARALLEL_API_KEYparallel_api_keynostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsEXA_API_KEYexa_api_keynostring | nullNot displayed; supply through an approved secret store.string: format password
SettingsGITHUB_CONNECTOR_TOKENgithub_connector_tokennostring | nullNot displayed; supply through an approved secret store.string: minimum length 1; maximum length 1024; format password
SettingsGITHUB_CONNECTOR_REPOSITORIESgithub_connector_repositoriesnoarray of string—maximum items 100
SettingsEVENT_REPLAY_MAX_EVENTSevent_replay_max_eventsnointeger10000minimum 100; maximum 1000000
SettingsRUNTIME_PROFILE_DIGESTruntime_profile_digestnostring"sha256:1111111111111111111111111111111111111111111111111111111111111111"pattern ^sha256:[0-9a-f]{64}$
SettingsCORS_ORIGINScors_originsnoarray of stringhttp://127.0.0.1:5173, http://localhost:5173minimum items 1; absolute HTTP(S) origin without a path, query, or fragment
WorkerSettingsOTEL_EXPORTER_OTLP_ENDPOINTotel_exporter_otlp_endpointnostring | nullnull—
WorkerSettingsOTEL_EXPORTER_OTLP_HEADERSotel_exporter_otlp_headersnostring | nullnullstring: format password
WorkerSettingsOTEL_EXPORTER_OTLP_TIMEOUT_SECONDSotel_exporter_otlp_timeout_secondsnointeger5minimum 1; maximum 30
WorkerSettingsOTEL_METRIC_EXPORT_INTERVAL_SECONDSotel_metric_export_interval_secondsnointeger60minimum 5; maximum 300
WorkerSettingsOTEL_DEPLOYMENT_ENVIRONMENTotel_deployment_environmentnostring"development"pattern ^[a-z][a-z0-9_-]{0,31}$
WorkerSettingsLUMEN_ENVIRONMENTdeployment_environmentnoDeploymentEnvironment"local"values local, preview, staging, production
WorkerSettingsDATABASE_WORKER_URLdatabase_worker_urlnostringLocal development connection (credentials omitted)—
WorkerSettingsARTIFACT_ROOTartifact_rootnostring.lumen-data/artifactsformat path
WorkerSettingsARTIFACT_STORAGE_PROVIDERartifact_storage_providernofilesystem | r2"filesystem"values filesystem, r2
WorkerSettingsR2_ENDPOINTr2_endpointnostring | nullnull—
WorkerSettingsR2_WORKER_ACCESS_KEY_IDr2_worker_access_key_idnostring | nullNot displayed; supply through an approved secret store.string: format password
WorkerSettingsR2_WORKER_SECRET_ACCESS_KEYr2_worker_secret_access_keynostring | nullNot displayed; supply through an approved secret store.string: format password
WorkerSettingsR2_STAGING_BUCKETr2_staging_bucketnostring | nullnullstring: pattern ^[a-z0-9](?:[a-z0-9-]{1,61}[a-z0-9])$
WorkerSettingsR2_ARTIFACT_BUCKETr2_artifact_bucketnostring | nullnullstring: pattern ^[a-z0-9](?:[a-z0-9-]{1,61}[a-z0-9])$
WorkerSettingsPRIVATE_API_ORIGINprivate_api_originnostring"http://127.0.0.1:8000"absolute HTTP(S) origin without a path, query, or fragment
WorkerSettingsPRIVATE_WORKER_ORIGINprivate_worker_originnostring"http://127.0.0.1:8080"absolute HTTP(S) origin without a path, query, or fragment
WorkerSettingsTEMPORAL_ADDRESStemporal_addressnostring"127.0.0.1:7233"—
WorkerSettingsTEMPORAL_NAMESPACEtemporal_namespacenostring"default"—
WorkerSettingsTEMPORAL_TASK_QUEUEtemporal_task_queuenostring"lumen-control-plane-v1"—
WorkerSettingsTEMPORAL_WORKER_BUILD_IDtemporal_worker_build_idnostring"development"minimum length 1; maximum length 128; pattern ^[A-Za-z0-9][A-Za-z0-9._-]{0,127}$
WorkerSettingsTEMPORAL_API_KEYtemporal_api_keynostring | nullNot displayed; supply through an approved secret store.string: format password
WorkerSettingsTEMPORAL_TLStemporal_tlsnobooleanfalse—
WorkerSettingsWORKER_HEALTH_HOSTworker_health_hostnostring"0.0.0.0"minimum length 1; maximum length 255
WorkerSettingsWORKER_HEALTH_PORTworker_health_portnointeger8080minimum 1; maximum 65535
WorkerSettingsWORKER_HEALTH_RECONCILIATION_STALE_SECONDSworker_health_reconciliation_stale_secondsnointeger90minimum 5; maximum 3600
WorkerSettingsATTEMPT_CAPABILITY_SIGNING_KEYattempt_capability_signing_keynostring | nullNot displayed; supply through an approved secret store.string: minimum length 32; format password
WorkerSettingsATTEMPT_SANDBOX_PROVIDERattempt_sandbox_providernounconfigured | local_docker | daytona"unconfigured"values unconfigured, local_docker, daytona
WorkerSettingsATTEMPT_INFERENCE_PROFILE_IDattempt_inference_profile_idnoAttemptInferenceProfileId"openai.gpt-5-6-terra.v1"values openai.gpt-5-6-terra.v1, fake.managed-canary.v1
WorkerSettingsKERNEL_RUNTIME_PROVIDERkernel_runtime_providernounconfigured | local_docker | daytona"unconfigured"values unconfigured, local_docker, daytona
WorkerSettingsRUNTIME_PROFILE_DIGESTruntime_profile_digestnostring"sha256:1111111111111111111111111111111111111111111111111111111111111111"pattern ^sha256:[0-9a-f]{64}$
WorkerSettingsRUNTIME_BUILD_IDruntime_build_idnostring | nullnullstring: minimum length 1; maximum length 128
WorkerSettingsRUNTIME_IMAGE_REFERENCEruntime_image_referencenostring | nullnull—
WorkerSettingsRUNTIME_IMAGE_IDruntime_image_idnostring | nullnullstring: pattern ^sha256:[0-9a-f]{64}$
WorkerSettingsLOCAL_DOCKER_BINARYlocal_docker_binarynostring | nullnullstring: format path
WorkerSettingsLOCAL_DOCKER_HOSTlocal_docker_hostnostring | nullnull—
WorkerSettingsLOCAL_DOCKER_CLIENT_CONFIG_DIRECTORYlocal_docker_client_config_directorynostring | nullnullstring: format path
WorkerSettingsLOCAL_DOCKER_PLATFORMlocal_docker_platformnolinux/amd64 | linux/arm64 | nullnulllinux/amd64 | linux/arm64: values linux/amd64, linux/arm64
WorkerSettingsRUNTIME_PLATFORMruntime_platformnolinux/amd64 | linux/arm64 | nullnulllinux/amd64 | linux/arm64: values linux/amd64, linux/arm64
WorkerSettingsDAYTONA_API_URLdaytona_api_urlnostring | nullnull—
WorkerSettingsDAYTONA_API_KEYdaytona_api_keynostring | nullNot displayed; supply through an approved secret store.string: format password
WorkerSettingsDAYTONA_TARGETdaytona_targetnostring | nullnullstring: pattern ^[a-z0-9][a-z0-9._-]{0,62}$
WorkerSettingsDAYTONA_EGRESS_POLICYdaytona_egress_policynounverified | block_all"unverified"values unverified, block_all

Validator inventory

The typed models also enforce cross-field and normalization rules. This inventory is generated from Pydantic's registered decorators; the function name identifies the owning rule in src/lumen_research/config.py.

Owner modelKindFieldsRuleMode
MigrationSettingsmodelall model fieldsvalidate_deployment_profileafter
ObservableEnvironmentSettingsfieldotel_exporter_otlp_endpoint, otel_exporter_otlp_headersnormalize_empty_telemetry_valuebefore
ObservableEnvironmentSettingsfieldotel_exporter_otlp_endpointvalidate_telemetry_endpointafter
ObservableEnvironmentSettingsfieldotel_exporter_otlp_headersvalidate_telemetry_headersafter
ObservableEnvironmentSettingsmodelall model fieldsvalidate_telemetry_configurationafter
Settingsfieldattempt_capability_signing_key, development_bearer_token, openai_api_key, anthropic_api_key, parallel_api_key, exa_api_key, github_connector_token, r2_endpoint, r2_app_read_access_key_id, r2_app_read_secret_access_key, r2_staging_access_key_id, r2_staging_secret_access_key, r2_staging_bucket, r2_artifact_bucketnormalize_empty_app_secretbefore
Settingsfieldgithub_connector_repositoriesnormalize_empty_github_repositoriesbefore
Settingsfieldotel_exporter_otlp_endpoint, otel_exporter_otlp_headersnormalize_empty_telemetry_valuebefore
Settingsfieldcors_originsvalidate_cors_originsafter
Settingsfieldgithub_connector_repositoriesvalidate_github_repositoriesafter
Settingsfieldprivate_worker_originvalidate_private_worker_originafter
Settingsfieldpublic_api_originvalidate_public_originafter
Settingsfieldr2_endpointvalidate_r2_endpointafter
Settingsfieldsupabase_urlvalidate_supabase_urlafter
Settingsfieldotel_exporter_otlp_endpointvalidate_telemetry_endpointafter
Settingsfieldotel_exporter_otlp_headersvalidate_telemetry_headersafter
Settingsmodelall model fieldsvalidate_artifact_storageafter
Settingsmodelall model fieldsvalidate_attempt_inference_profileafter
Settingsmodelall model fieldsvalidate_auth_profileafter
Settingsmodelall model fieldsvalidate_deployment_profileafter
Settingsmodelall model fieldsvalidate_github_connectorafter
Settingsmodelall model fieldsvalidate_telemetry_configurationafter
WorkerSettingsfieldlocal_docker_binary, local_docker_client_config_directory, local_docker_host, local_docker_platform, runtime_platform, daytona_api_url, daytona_target, runtime_build_id, runtime_image_id, runtime_image_referencenormalize_empty_runtime_valuebefore
WorkerSettingsfieldotel_exporter_otlp_endpoint, otel_exporter_otlp_headersnormalize_empty_telemetry_valuebefore
WorkerSettingsfieldr2_artifact_bucket, r2_endpoint, r2_staging_bucket, r2_worker_access_key_id, r2_worker_secret_access_key, temporal_api_key, attempt_capability_signing_key, daytona_api_keynormalize_empty_worker_secretbefore
WorkerSettingsfielddaytona_api_urlvalidate_daytona_api_urlafter
WorkerSettingsfieldprivate_api_originvalidate_private_api_originafter
WorkerSettingsfieldprivate_worker_originvalidate_private_worker_originafter
WorkerSettingsfieldr2_endpointvalidate_r2_endpointafter
WorkerSettingsfieldotel_exporter_otlp_endpointvalidate_telemetry_endpointafter
WorkerSettingsfieldotel_exporter_otlp_headersvalidate_telemetry_headersafter
WorkerSettingsfieldtemporal_addressvalidate_temporal_addressafter
WorkerSettingsfieldworker_health_hostvalidate_worker_health_hostafter
WorkerSettingsmodelall model fieldsvalidate_artifact_storageafter
WorkerSettingsmodelall model fieldsvalidate_attempt_inference_profileafter
WorkerSettingsmodelall model fieldsvalidate_deployment_profileafter
WorkerSettingsmodelall model fieldsvalidate_production_telemetryafter
WorkerSettingsmodelall model fieldsvalidate_telemetry_configurationafter
WorkerSettingsmodelall model fieldsvalidate_temporal_transportafter

Unknown environment names are ignored by each model. A process must receive only the configuration owned by its role; the migration model is for the migration job, not an app or worker runtime.

On this page