Reference
Settings and environment
Generated app, worker, and migration configuration names, ownership, defaults, and validators.
Each deployable reads only its own typed settings model. Secret values and credentials embedded in local development URLs are intentionally omitted; use the environment's approved secret manager for production values.
Settings
| Owner model | Environment name | Field | Required | Type | Default behavior | Validation |
|---|---|---|---|---|---|---|
MigrationSettings | DATABASE_ADMIN_URL | database_admin_url | yes | string | Required | — |
MigrationSettings | LUMEN_ENVIRONMENT | deployment_environment | no | DeploymentEnvironment | "local" | values local, preview, staging, production |
ObservableEnvironmentSettings | OTEL_EXPORTER_OTLP_ENDPOINT | otel_exporter_otlp_endpoint | no | string | null | null | — |
ObservableEnvironmentSettings | OTEL_EXPORTER_OTLP_HEADERS | otel_exporter_otlp_headers | no | string | null | null | string: format password |
ObservableEnvironmentSettings | OTEL_EXPORTER_OTLP_TIMEOUT_SECONDS | otel_exporter_otlp_timeout_seconds | no | integer | 5 | minimum 1; maximum 30 |
ObservableEnvironmentSettings | OTEL_METRIC_EXPORT_INTERVAL_SECONDS | otel_metric_export_interval_seconds | no | integer | 60 | minimum 5; maximum 300 |
ObservableEnvironmentSettings | OTEL_DEPLOYMENT_ENVIRONMENT | otel_deployment_environment | no | string | "development" | pattern ^[a-z][a-z0-9_-]{0,31}$ |
ObservableEnvironmentSettings | LUMEN_ENVIRONMENT | deployment_environment | no | DeploymentEnvironment | "local" | values local, preview, staging, production |
Settings | OTEL_EXPORTER_OTLP_ENDPOINT | otel_exporter_otlp_endpoint | no | string | null | null | — |
Settings | OTEL_EXPORTER_OTLP_HEADERS | otel_exporter_otlp_headers | no | string | null | null | string: format password |
Settings | OTEL_EXPORTER_OTLP_TIMEOUT_SECONDS | otel_exporter_otlp_timeout_seconds | no | integer | 5 | minimum 1; maximum 30 |
Settings | OTEL_METRIC_EXPORT_INTERVAL_SECONDS | otel_metric_export_interval_seconds | no | integer | 60 | minimum 5; maximum 300 |
Settings | OTEL_DEPLOYMENT_ENVIRONMENT | otel_deployment_environment | no | string | "development" | pattern ^[a-z][a-z0-9_-]{0,31}$ |
Settings | LUMEN_ENVIRONMENT | deployment_environment | no | DeploymentEnvironment | "local" | values local, preview, staging, production |
Settings | DATABASE_APP_URL | database_app_url | no | string | Local development connection (credentials omitted) | — |
Settings | DATABASE_GATEWAY_URL | database_gateway_url | no | string | Local development connection (credentials omitted) | — |
Settings | ARTIFACT_ROOT | artifact_root | no | string | .lumen-data/artifacts | format path |
Settings | ARTIFACT_STORAGE_PROVIDER | artifact_storage_provider | no | filesystem | r2 | "filesystem" | values filesystem, r2 |
Settings | R2_ENDPOINT | r2_endpoint | no | string | null | null | — |
Settings | R2_STAGING_ACCESS_KEY_ID | r2_staging_access_key_id | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | R2_STAGING_SECRET_ACCESS_KEY | r2_staging_secret_access_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | R2_APP_READ_ACCESS_KEY_ID | r2_app_read_access_key_id | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | R2_APP_READ_SECRET_ACCESS_KEY | r2_app_read_secret_access_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | R2_STAGING_BUCKET | r2_staging_bucket | no | string | null | null | string: pattern ^[a-z0-9](?:[a-z0-9-]{1,61}[a-z0-9])$ |
Settings | R2_ARTIFACT_BUCKET | r2_artifact_bucket | no | string | null | null | string: pattern ^[a-z0-9](?:[a-z0-9-]{1,61}[a-z0-9])$ |
Settings | PUBLIC_API_ORIGIN | public_api_origin | no | string | "http://127.0.0.1:8000" | absolute HTTP(S) origin without a path, query, or fragment |
Settings | PRIVATE_WORKER_ORIGIN | private_worker_origin | no | string | "http://127.0.0.1:8080" | absolute HTTP(S) origin without a path, query, or fragment |
Settings | AUTH_PROFILE | auth_profile | yes | development | supabase | Required | values development, supabase |
Settings | DEVELOPMENT_BEARER_TOKEN | development_bearer_token | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | SUPABASE_URL | supabase_url | no | string | null | null | — |
Settings | CURSOR_SIGNING_KEY | cursor_signing_key | yes | string | Not displayed; supply through an approved secret store. | minimum length 32; format password |
Settings | ATTEMPT_CAPABILITY_SIGNING_KEY | attempt_capability_signing_key | no | string | null | Not displayed; supply through an approved secret store. | string: minimum length 32; format password |
Settings | ATTEMPT_INFERENCE_PROFILE_ID | attempt_inference_profile_id | no | AttemptInferenceProfileId | "openai.gpt-5-6-terra.v1" | values openai.gpt-5-6-terra.v1, fake.managed-canary.v1 |
Settings | OPENAI_API_KEY | openai_api_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | ANTHROPIC_API_KEY | anthropic_api_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | PARALLEL_API_KEY | parallel_api_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | EXA_API_KEY | exa_api_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
Settings | GITHUB_CONNECTOR_TOKEN | github_connector_token | no | string | null | Not displayed; supply through an approved secret store. | string: minimum length 1; maximum length 1024; format password |
Settings | GITHUB_CONNECTOR_REPOSITORIES | github_connector_repositories | no | array of string | — | maximum items 100 |
Settings | EVENT_REPLAY_MAX_EVENTS | event_replay_max_events | no | integer | 10000 | minimum 100; maximum 1000000 |
Settings | RUNTIME_PROFILE_DIGEST | runtime_profile_digest | no | string | "sha256:1111111111111111111111111111111111111111111111111111111111111111" | pattern ^sha256:[0-9a-f]{64}$ |
Settings | CORS_ORIGINS | cors_origins | no | array of string | http://127.0.0.1:5173, http://localhost:5173 | minimum items 1; absolute HTTP(S) origin without a path, query, or fragment |
WorkerSettings | OTEL_EXPORTER_OTLP_ENDPOINT | otel_exporter_otlp_endpoint | no | string | null | null | — |
WorkerSettings | OTEL_EXPORTER_OTLP_HEADERS | otel_exporter_otlp_headers | no | string | null | null | string: format password |
WorkerSettings | OTEL_EXPORTER_OTLP_TIMEOUT_SECONDS | otel_exporter_otlp_timeout_seconds | no | integer | 5 | minimum 1; maximum 30 |
WorkerSettings | OTEL_METRIC_EXPORT_INTERVAL_SECONDS | otel_metric_export_interval_seconds | no | integer | 60 | minimum 5; maximum 300 |
WorkerSettings | OTEL_DEPLOYMENT_ENVIRONMENT | otel_deployment_environment | no | string | "development" | pattern ^[a-z][a-z0-9_-]{0,31}$ |
WorkerSettings | LUMEN_ENVIRONMENT | deployment_environment | no | DeploymentEnvironment | "local" | values local, preview, staging, production |
WorkerSettings | DATABASE_WORKER_URL | database_worker_url | no | string | Local development connection (credentials omitted) | — |
WorkerSettings | ARTIFACT_ROOT | artifact_root | no | string | .lumen-data/artifacts | format path |
WorkerSettings | ARTIFACT_STORAGE_PROVIDER | artifact_storage_provider | no | filesystem | r2 | "filesystem" | values filesystem, r2 |
WorkerSettings | R2_ENDPOINT | r2_endpoint | no | string | null | null | — |
WorkerSettings | R2_WORKER_ACCESS_KEY_ID | r2_worker_access_key_id | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
WorkerSettings | R2_WORKER_SECRET_ACCESS_KEY | r2_worker_secret_access_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
WorkerSettings | R2_STAGING_BUCKET | r2_staging_bucket | no | string | null | null | string: pattern ^[a-z0-9](?:[a-z0-9-]{1,61}[a-z0-9])$ |
WorkerSettings | R2_ARTIFACT_BUCKET | r2_artifact_bucket | no | string | null | null | string: pattern ^[a-z0-9](?:[a-z0-9-]{1,61}[a-z0-9])$ |
WorkerSettings | PRIVATE_API_ORIGIN | private_api_origin | no | string | "http://127.0.0.1:8000" | absolute HTTP(S) origin without a path, query, or fragment |
WorkerSettings | PRIVATE_WORKER_ORIGIN | private_worker_origin | no | string | "http://127.0.0.1:8080" | absolute HTTP(S) origin without a path, query, or fragment |
WorkerSettings | TEMPORAL_ADDRESS | temporal_address | no | string | "127.0.0.1:7233" | — |
WorkerSettings | TEMPORAL_NAMESPACE | temporal_namespace | no | string | "default" | — |
WorkerSettings | TEMPORAL_TASK_QUEUE | temporal_task_queue | no | string | "lumen-control-plane-v1" | — |
WorkerSettings | TEMPORAL_WORKER_BUILD_ID | temporal_worker_build_id | no | string | "development" | minimum length 1; maximum length 128; pattern ^[A-Za-z0-9][A-Za-z0-9._-]{0,127}$ |
WorkerSettings | TEMPORAL_API_KEY | temporal_api_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
WorkerSettings | TEMPORAL_TLS | temporal_tls | no | boolean | false | — |
WorkerSettings | WORKER_HEALTH_HOST | worker_health_host | no | string | "0.0.0.0" | minimum length 1; maximum length 255 |
WorkerSettings | WORKER_HEALTH_PORT | worker_health_port | no | integer | 8080 | minimum 1; maximum 65535 |
WorkerSettings | WORKER_HEALTH_RECONCILIATION_STALE_SECONDS | worker_health_reconciliation_stale_seconds | no | integer | 90 | minimum 5; maximum 3600 |
WorkerSettings | ATTEMPT_CAPABILITY_SIGNING_KEY | attempt_capability_signing_key | no | string | null | Not displayed; supply through an approved secret store. | string: minimum length 32; format password |
WorkerSettings | ATTEMPT_SANDBOX_PROVIDER | attempt_sandbox_provider | no | unconfigured | local_docker | daytona | "unconfigured" | values unconfigured, local_docker, daytona |
WorkerSettings | ATTEMPT_INFERENCE_PROFILE_ID | attempt_inference_profile_id | no | AttemptInferenceProfileId | "openai.gpt-5-6-terra.v1" | values openai.gpt-5-6-terra.v1, fake.managed-canary.v1 |
WorkerSettings | KERNEL_RUNTIME_PROVIDER | kernel_runtime_provider | no | unconfigured | local_docker | daytona | "unconfigured" | values unconfigured, local_docker, daytona |
WorkerSettings | RUNTIME_PROFILE_DIGEST | runtime_profile_digest | no | string | "sha256:1111111111111111111111111111111111111111111111111111111111111111" | pattern ^sha256:[0-9a-f]{64}$ |
WorkerSettings | RUNTIME_BUILD_ID | runtime_build_id | no | string | null | null | string: minimum length 1; maximum length 128 |
WorkerSettings | RUNTIME_IMAGE_REFERENCE | runtime_image_reference | no | string | null | null | — |
WorkerSettings | RUNTIME_IMAGE_ID | runtime_image_id | no | string | null | null | string: pattern ^sha256:[0-9a-f]{64}$ |
WorkerSettings | LOCAL_DOCKER_BINARY | local_docker_binary | no | string | null | null | string: format path |
WorkerSettings | LOCAL_DOCKER_HOST | local_docker_host | no | string | null | null | — |
WorkerSettings | LOCAL_DOCKER_CLIENT_CONFIG_DIRECTORY | local_docker_client_config_directory | no | string | null | null | string: format path |
WorkerSettings | LOCAL_DOCKER_PLATFORM | local_docker_platform | no | linux/amd64 | linux/arm64 | null | null | linux/amd64 | linux/arm64: values linux/amd64, linux/arm64 |
WorkerSettings | RUNTIME_PLATFORM | runtime_platform | no | linux/amd64 | linux/arm64 | null | null | linux/amd64 | linux/arm64: values linux/amd64, linux/arm64 |
WorkerSettings | DAYTONA_API_URL | daytona_api_url | no | string | null | null | — |
WorkerSettings | DAYTONA_API_KEY | daytona_api_key | no | string | null | Not displayed; supply through an approved secret store. | string: format password |
WorkerSettings | DAYTONA_TARGET | daytona_target | no | string | null | null | string: pattern ^[a-z0-9][a-z0-9._-]{0,62}$ |
WorkerSettings | DAYTONA_EGRESS_POLICY | daytona_egress_policy | no | unverified | block_all | "unverified" | values unverified, block_all |
Validator inventory
The typed models also enforce cross-field and normalization rules. This inventory is
generated from Pydantic's registered decorators; the function name identifies the owning
rule in src/lumen_research/config.py.
| Owner model | Kind | Fields | Rule | Mode |
|---|---|---|---|---|
MigrationSettings | model | all model fields | validate_deployment_profile | after |
ObservableEnvironmentSettings | field | otel_exporter_otlp_endpoint, otel_exporter_otlp_headers | normalize_empty_telemetry_value | before |
ObservableEnvironmentSettings | field | otel_exporter_otlp_endpoint | validate_telemetry_endpoint | after |
ObservableEnvironmentSettings | field | otel_exporter_otlp_headers | validate_telemetry_headers | after |
ObservableEnvironmentSettings | model | all model fields | validate_telemetry_configuration | after |
Settings | field | attempt_capability_signing_key, development_bearer_token, openai_api_key, anthropic_api_key, parallel_api_key, exa_api_key, github_connector_token, r2_endpoint, r2_app_read_access_key_id, r2_app_read_secret_access_key, r2_staging_access_key_id, r2_staging_secret_access_key, r2_staging_bucket, r2_artifact_bucket | normalize_empty_app_secret | before |
Settings | field | github_connector_repositories | normalize_empty_github_repositories | before |
Settings | field | otel_exporter_otlp_endpoint, otel_exporter_otlp_headers | normalize_empty_telemetry_value | before |
Settings | field | cors_origins | validate_cors_origins | after |
Settings | field | github_connector_repositories | validate_github_repositories | after |
Settings | field | private_worker_origin | validate_private_worker_origin | after |
Settings | field | public_api_origin | validate_public_origin | after |
Settings | field | r2_endpoint | validate_r2_endpoint | after |
Settings | field | supabase_url | validate_supabase_url | after |
Settings | field | otel_exporter_otlp_endpoint | validate_telemetry_endpoint | after |
Settings | field | otel_exporter_otlp_headers | validate_telemetry_headers | after |
Settings | model | all model fields | validate_artifact_storage | after |
Settings | model | all model fields | validate_attempt_inference_profile | after |
Settings | model | all model fields | validate_auth_profile | after |
Settings | model | all model fields | validate_deployment_profile | after |
Settings | model | all model fields | validate_github_connector | after |
Settings | model | all model fields | validate_telemetry_configuration | after |
WorkerSettings | field | local_docker_binary, local_docker_client_config_directory, local_docker_host, local_docker_platform, runtime_platform, daytona_api_url, daytona_target, runtime_build_id, runtime_image_id, runtime_image_reference | normalize_empty_runtime_value | before |
WorkerSettings | field | otel_exporter_otlp_endpoint, otel_exporter_otlp_headers | normalize_empty_telemetry_value | before |
WorkerSettings | field | r2_artifact_bucket, r2_endpoint, r2_staging_bucket, r2_worker_access_key_id, r2_worker_secret_access_key, temporal_api_key, attempt_capability_signing_key, daytona_api_key | normalize_empty_worker_secret | before |
WorkerSettings | field | daytona_api_url | validate_daytona_api_url | after |
WorkerSettings | field | private_api_origin | validate_private_api_origin | after |
WorkerSettings | field | private_worker_origin | validate_private_worker_origin | after |
WorkerSettings | field | r2_endpoint | validate_r2_endpoint | after |
WorkerSettings | field | otel_exporter_otlp_endpoint | validate_telemetry_endpoint | after |
WorkerSettings | field | otel_exporter_otlp_headers | validate_telemetry_headers | after |
WorkerSettings | field | temporal_address | validate_temporal_address | after |
WorkerSettings | field | worker_health_host | validate_worker_health_host | after |
WorkerSettings | model | all model fields | validate_artifact_storage | after |
WorkerSettings | model | all model fields | validate_attempt_inference_profile | after |
WorkerSettings | model | all model fields | validate_deployment_profile | after |
WorkerSettings | model | all model fields | validate_production_telemetry | after |
WorkerSettings | model | all model fields | validate_telemetry_configuration | after |
WorkerSettings | model | all model fields | validate_temporal_transport | after |
Unknown environment names are ignored by each model. A process must receive only the configuration owned by its role; the migration model is for the migration job, not an app or worker runtime.