ar.io Logoar.io Documentation

Environment Variables

Default Values: Most variables have defaults that suit a typical gateway. Set a variable only to change its behavior.

Set these in the .env file next to docker-compose.yaml. The Default column is what you get under the shipped docker-compose.yaml. Where Docker Compose sets a different default from the gateway's own code, the cell gives both, and the code's value applies only when you run the gateway outside Docker.

A few variables have a different name in .env from the one the service reads, because Docker Compose renames them (for example CORE_LOG_LEVEL becomes the core service's LOG_LEVEL). The tables use the .env name.

Core ar.io Node

The main ar.io Gateway service that handles data retrieval, indexing, and serving.

Server Configuration

VariableTypeDefaultDescription
CORE_PORTnumber4000Host port for the core service. Inside its container, the core service listens on 4000; outside Docker, set PORT
NODE_ENVstringproductionNode.js environment
CORE_LOG_LEVELstringinfoLogging level (error, warn, info, debug). LOG_LEVEL outside Docker
CORE_LOG_FORMATstringsimpleLog format (simple, json). LOG_FORMAT outside Docker
CORE_LOG_FILTERstring{"always":true}Log filtering configuration. LOG_FILTER outside Docker
CORE_LOG_ALL_STACKTRACESbooleanfalseInclude full stack traces in logs. LOG_ALL_STACKTRACES outside Docker
INSTANCE_IDstring-Unique instance identifier

Authentication & Security

VariableTypeDefaultDescription
ADMIN_API_KEYStringGeneratedAPI key for admin endpoints (generated at startup if not set). The ClickHouse auto-import service uses it too
ADMIN_API_KEY_FILEString-Path to file containing admin API key

HTTP Message Signatures (RFC 9421)

Configure response signing to provide cryptographic proof that your gateway produced a given response.

If OBSERVER_KEYPAIR_PATH or OBSERVER_PRIVATE_KEY is set, the observer's Ed25519 Solana key signs responses directly. The key's Solana address is already in the on-chain Gateway Registry, so verifiers can confirm the signer with a single GAR lookup. If neither is set, the gateway auto-generates a standalone Ed25519 key at HTTPSIG_KEY_FILE; responses are still signed but can't be tied back to the registry. Setting both at once is rejected at startup as ambiguous.

VariableTypeDefaultDescription
HTTPSIG_ENABLEDbooleantrueEnable RFC 9421 response signing
HTTPSIG_KEY_FILEstringdata/keys/httpsig.pemPath to standalone Ed25519 private key PEM. Auto-generated on first startup if missing. Ignored when OBSERVER_KEYPAIR_PATH or OBSERVER_PRIVATE_KEY is set
HTTPSIG_BIND_REQUESTbooleantrueInclude request method and path in signature (prevents replay)
OBSERVER_KEYPAIR_PATHstring-Path to a 64-byte Solana keypair JSON file (e.g. solana-keygen new output). When set, used as the HTTPSIG signing key. The observer reads it too
OBSERVER_PRIVATE_KEYstring-Alternative to OBSERVER_KEYPAIR_PATH: base58-encoded 64-byte Solana secret key (the format Phantom and other browser wallets export)

Network Configuration

VariableTypeDefaultDescription
TRUSTED_NODE_URLstringhttp://envoy:3000; https://arweave.net outside DockerTrusted Arweave node URL. Under Docker, requests go through Envoy, which forwards them to TRUSTED_NODE_HOST
TRUSTED_GATEWAY_URLstring-A single trusted gateway URL. When set and TRUSTED_GATEWAYS_URLS is not, it becomes the only trusted gateway
TRUSTED_GATEWAYS_URLSJSON{"https://turbo-gateway.com": 1, "https://arweave.net": {"priority": 2, "trusted": false}}Weighted trusted gateway URLs. With TRUSTED_GATEWAY_URL set, the default is that URL alone
TRUSTED_GATEWAYS_REQUEST_TIMEOUT_MSnumber10000Request timeout for trusted gateways
GATEWAYS_THROTTLE_BACKOFF_ENABLEDbooleantrueRelease 85: skip a trusted gateway that answers 429 until its Retry-After has passed
GATEWAYS_THROTTLE_BACKOFF_DEFAULT_MSnumber30000Release 85: how long to skip a gateway whose 429 has no usable Retry-After
GATEWAYS_THROTTLE_BACKOFF_MAX_MSnumber300000Release 85: the longest a Retry-After may make the gateway skip a trusted gateway
ARWEAVE_NODE_IGNORE_URLSstring-Comma-separated URLs to ignore

Chunk Management

VariableTypeDefaultDescription
CHUNK_POST_MIN_SUCCESS_COUNTnumber3Min successful chunk posts required
CHUNK_POST_RESPONSE_TIMEOUT_MSnumber-Chunk POST response timeout
CHUNK_POST_ABORT_TIMEOUT_MSnumber-Chunk POST abort timeout

Data Sources

VariableTypeDefaultDescription
ON_DEMAND_RETRIEVAL_ORDERstringtrusted-gateways,ar-io-network,chunks-offset-aware,tx-dataOn-demand data retrieval priority
BACKGROUND_RETRIEVAL_ORDERstringchunksBackground data retrieval priority

CDB64 Root Transaction Index

The CDB64 index looks up which root Arweave transaction holds a data item, in one read. The gateway ships three pre-built indexes by default. See CDB64 Root TX Index for what they cover and how to use them.

VariableTypeDefaultDescription
ROOT_TX_LOOKUP_ORDERstringdb,gateways,graphql,hyperbeam,cdbComma-separated root TX lookup sources: db, peers, gateways, graphql, hyperbeam, cdb, turbo. With local indexes, such as Index Sharing bands, put cdb right after db
CDB64_ROOT_TX_INDEX_SOURCESstringthe three shipped resources/ indexesComma-separated CDB64 sources: local files, directories (including a directory of bands), HTTP URLs, Arweave TX IDs, or bundle data items. When you add a source, list the shipped ones too if you want to keep them
CDB64_ROOT_TX_INDEX_DATA_PATHstring./data/cdb64-root-tx-indexHost directory mounted at data/cdb64-root-tx-index in the core container, for your own index files
CDB64_ROOT_TX_INDEX_WATCHbooleantrueWatch every local CDB64 directory source, so new files load without a restart
CDB64_REMOTE_RETRIEVAL_ORDERstringchunksData sources for fetching remote CDB64 files: gateways, chunks, tx-data
CDB64_REMOTE_CACHE_MAX_REGIONSnumber100Maximum byte-range regions to cache per remote source
CDB64_REMOTE_CACHE_TTL_MSnumber300000TTL for cached byte-range regions (5 minutes)
CDB64_REMOTE_REQUEST_TIMEOUT_MSnumber30000Request timeout for remote CDB64 sources
CDB64_REMOTE_MAX_CONCURRENT_REQUESTSnumber4One limit on concurrent HTTP requests, shared by all remote CDB64 sources
CDB64_REMOTE_SEMAPHORE_TIMEOUT_MSnumber5000Maximum wait for a request slot before failing

Index Sharing

Settings for the index-swarm sidecar, which subscribes to other gateways' indexes and publishes your own. Available from Release 84. See Index Sharing for how each one is used.

VariableTypeDefaultDescription
INDEX_SWARM_SUBSCRIBEJSONunsetPublishers to subscribe to, by gateway wallet: [{"publisher":"<wallet>","name":"root-tx-index"}]. name may be one index or a list. Without name, you take every index the publisher offers except opt-in kinds; from Release 85, parquet-l1 is opt-in and must be named. An optional url fetches from another address, such as a fleet's signing node; the signature is still checked against the registered key. See Take L1 Bands
INDEX_SWARM_PUBLISHJSONunsetIndexes this gateway publishes: [{"name":"root-tx-index","kind":"cdb64-root-tx"}]
INDEX_SWARM_MAX_DISK_BYTESnumberunset (no ceiling; the setup script writes 50 GiB)Ceiling on the disk the sidecar takes for bands. A band that would go over it is skipped. See Disk
INDEX_SWARM_OBSERVER_KEYPAIR_FILEstringunsetPublishers only: host path of the observer keypair file. Set this or OBSERVER_PRIVATE_KEY, not both
INDEX_SWARM_TRUSTED_PUBLISHERSstringunsetComma-separated wallets. When set, only these publishers are accepted
INDEX_SWARM_ALLOWED_FILE_ORIGINSstringunsetOther servers (http(s)://host[:port]) a publisher may send band files from, such as its CDN. Anything else is refused
INDEX_SWARM_POLL_INTERVAL_SECONDSnumber300How often each publisher is checked for new bands
INDEX_SWARM_DOWNLOAD_RATE_LIMIT_BYTES_PER_SECnumberunsetCap on download speed, shared across all files of a band
INDEX_SWARM_DOWNLOAD_STALL_TIMEOUT_SECONDSnumber60Give up on a download that receives nothing for this long; it resumes next poll
INDEX_SWARM_DOWNLOAD_CONCURRENCYnumber4Parallel file downloads within one band
INDEX_SWARM_DATA_PATHstring./data/indexesHost directory for published, downloading and installed bands. The gateway mounts the same directory
INDEXES_PUBLISHED_DIRstringdata/indexes/publishedWhere the gateway's /ar-io/indexes routes serve from, inside the core container
INDEX_SWARM_PUBLISH_TTL_SECONDSnumber86400How long a publication is valid. See Index Sharing
INDEX_SWARM_PUBLISH_SCAN_INTERVAL_SECONDSnumber60How often the publisher looks for new or changed bands
INDEX_SWARM_SUPERSEDE_GRACE_SECONDSnumber300How long a retired band's files stay on disk after it stops being served
INDEX_SWARM_MANIFEST_FETCH_TIMEOUT_MSnumber30000Give up on a publisher that has not answered in this long
INDEX_SWARM_REGISTRY_CACHE_TTL_SECONDSnumber300How long one read of the gateway's /ar-io/peers, where the sidecar gets registry records, is reused
INDEX_SWARM_DATA_DIRstringdata/indexesThe index directory inside the sidecar's container. To move the directory on the host, set INDEX_SWARM_DATA_PATH instead
INDEX_SWARM_CORE_URLstringhttp://core:4000Where the sidecar reaches the gateway for its release check
INDEX_SWARM_MIN_CORE_RELEASEnumber84Gateway release needed to load installed bands. Below it, the subscriber installs nothing until the gateway is upgraded
INDEX_SWARM_METRICS_PORTnumber9101Port for the sidecar's /metrics and /healthz, inside its container
INDEX_SWARM_METRICS_HOSTstring0.0.0.0Bind address for metrics, inside the container. Nothing reaches the host unless the port is mapped
INDEX_SWARM_SHUTDOWN_TIMEOUT_MSnumber10000How long to let work finish on shutdown before exiting anyway
INDEX_SWARM_LOG_LEVELstringinfoSidecar log level
INDEX_SWARM_LOG_FORMATstringsimpleSidecar log format (simple or json)
INDEX_SWARM_LOG_MAX_SIZEstring50mDocker log rotation size for the sidecar, the torrent engine and its init container, and, from Release 85, index-export
INDEX_SWARM_LOG_MAX_FILEnumber3Docker log rotation file count for the same containers

BitTorrent

Settings for the optional torrent engine (compose profile index-swarm-torrent). Setting INDEX_SWARM_ENGINE_AUTH turns it on; ./tools/index-swarm-setup --torrent generates it. See Tuning the Torrent Engine.

VariableTypeDefaultDescription
INDEX_SWARM_ENGINE_AUTHstringunsetuser:password for the engine's Web API, for example swarm:<generated>. The password must be at least 16 characters. Setting it turns the engine on
INDEX_SWARM_ENGINE_URLstringhttp://index-swarm-engine:8080 with INDEX_SWARM_ENGINE_AUTH, else unsetThe engine's Web API. Set it only for an engine run outside the compose profile
INDEX_SWARM_ENGINE_PORTnumber6881Peer port, published on the host over TCP and UDP. Keep it below Linux's ephemeral range (32768–60999)
INDEX_SWARM_ENGINE_PUBLIC_HOSTstringhost of the first INDEX_SWARM_TRACKERS URLThe host or IP peers reach this node's engine on. Set it when the tracker is behind a load balancer that does not forward the peer port
INDEX_SWARM_UPLOAD_LIMIT_BYTES_PER_SECnumber10000000Cap on upload to peers (10 MB/s). 0 is unlimited. See Bounding Upload
INDEX_SWARM_UPLOAD_DAILY_LIMIT_BYTESnumber100000000000Most the engine may upload in a UTC day (100 GB). 0 is no budget. See Bounding Upload
INDEX_SWARM_TORRENT_TIMEOUT_SECONDSnumber3600How long a torrent may go without progress before the band is fetched over HTTP instead
INDEX_SWARM_WEBSEED_AFTER_SECONDSnumber120How long a torrent may stall before the publisher's WebSeed is added
INDEX_SWARM_TRACKERSstringunsetComma-separated announce URLs written into every torrent this node publishes; normally its own tracker, http://<public host>:6969/announce
INDEX_SWARM_TRACKER_PORTnumber6969Port the tracker listens on, published on the host by the sidecar. Only a node that publishes torrents listens on it
INDEX_SWARM_TRACKER_TRUSTED_PROXIESstringunsetComma-separated IPs or CIDRs of proxies in front of the tracker whose X-Forwarded-For it believes. See Publishing from a Fleet
INDEX_SWARM_ALLOWED_TRACKERSstringunsetTracker URLs, exactly as written, that a subscriber hands its engine even though their host is private. Only useful with INDEX_SWARM_ENGINE_BLOCK_PRIVATE=false
INDEX_SWARM_ENGINE_BLOCK_PRIVATEbooleantrueHave the engine refuse peers, trackers and WebSeeds on private, loopback, link-local and carrier-grade NAT addresses. See Sharing Between Your Own Gateways
INDEX_SWARM_ENGINE_NETWORK_NAMEstringar-io-index-swarm-engineDocker network the engine runs on, shared only with the sidecar
INDEX_SWARM_ENGINE_UID / INDEX_SWARM_ENGINE_GIDnumber1000User and group the engine runs as. Set the same values for the sidecar and the engine
INDEX_SWARM_ENGINE_CONFIG_PATHstring./data/index-swarm-engineHost directory for the engine's configuration and resume data
INDEX_SWARM_ENGINE_CONFIG_DIRstring/configWhere index-swarm-engine-init writes the engine's configuration, inside its container. Set it only when running the init outside compose

Building Bands (Release 85)

Release Requirement: The index-export service and these settings are part of gateway Release 85, which is not released yet.

Settings for the index-export service (compose profile index-export), which builds your gateway's bands for the sidecar to publish. It logs by LOG_LEVEL and LOG_FORMAT. See What the Daily Run Does.

VariableTypeDefaultDescription
INDEX_EXPORT_KINDSstringroot-tx-indexComma-separated indexes to build: root-tx-index, parquet-l1. See Publish L1 Bands
INDEX_EXPORT_START_HEIGHTnumberunsetThe lowest height to build. Root-TX bands need it before the first run; ./tools/index-swarm-setup --publish --start-height <n> sets it
INDEX_EXPORT_HEADER_CHECK_URLstringunsetRequired for root-TX bands: the gateway a sample of each band's entries is checked against before publishing. ./tools/index-swarm-setup --publish writes https://turbo-gateway.com
INDEX_EXPORT_HEADER_CHECK_TIMEOUT_MSnumber30000Timeout for each read of that check
INDEX_EXPORT_SOURCESJSONunset (this gateway's ClickHouse when CLICKHOUSE_URL is set, else its SQLite)Where root-TX records come from
INDEX_EXPORT_SECRETS_DIRstringunsetHost directory of password files for the ClickHouse sources INDEX_EXPORT_SOURCES names
INDEX_EXPORT_CORE_DBstringdata/sqlite/core.dbThe core.db L1 bands are built from, opened read-only
INDEX_EXPORT_RUN_AT_UTCstring04:00Time of the daily run, HH:MM UTC
INDEX_EXPORT_RECENT_MAX_BLOCKSnumber100000Span at which a recent root-TX band is frozen and a new one starts
INDEX_EXPORT_L1_RUN_BUDGET_MINUTESnumber240How long a run keeps starting whole L1 bands. Raise it for a bootstrap
INDEX_EXPORT_METRICS_PORTnumber9102Port for index-export's /metrics and /healthz, inside its container
INDEX_EXPORT_IMAGE_TAGstringthe value of CORE_IMAGE_TAGCore image tag for index-export, when it should run a newer image than the gateway
LOG_LEVELstringinfoindex-export log level
LOG_FORMATstringsimpleindex-export log format (simple or json)
INDEXES_ADVERTISE_FROM_URLstringunsetOn a fleet node that serves your indexes but does not sign them: the signing node's base URL (for example http://10.0.0.1:4000), so /ar-io/info advertises the same publication on every node. Leave it unset on the signing node. See Giving the Other Nodes the Index

Indexing & Synchronization

VariableTypeDefaultDescription
START_WRITERSbooleantrueEnable indexing processes
START_HEIGHTnumber0Starting block height for indexing
STOP_HEIGHTnumberInfinityStopping block height for indexing
SKIP_CACHEbooleanfalseBypass header cache
SIMULATED_REQUEST_FAILURE_RATEnumber0Rate of simulated request failures

ANS-104 Bundle Processing

VariableTypeDefaultDescription
ANS104_UNBUNDLE_FILTERJSON{"never": true}Filter for bundles to unbundle
ANS104_INDEX_FILTERJSON{"always": true} while background verification is on, else {"never": true}Filter for data items to index
ANS104_UNBUNDLE_WORKERSnumber1, or 0 when background verification is off and ANS104_UNBUNDLE_FILTER matches nothingNumber of unbundling workers
ANS104_DOWNLOAD_WORKERSnumber5, or 0 in the same caseNumber of download workers
FILTER_CHANGE_REPROCESSbooleanfalseReprocess old bundles with new filter
BACKFILL_BUNDLE_RECORDSbooleanfalseBackfill bundle records

Data Management

VariableTypeDefaultDescription
WRITE_ANS104_DATA_ITEM_DB_SIGNATURESbooleanfalseWrite data item signatures to DB
WRITE_TRANSACTION_DB_SIGNATURESbooleanfalseWrite transaction signatures to DB
ENABLE_DATA_DB_WAL_CLEANUPbooleanfalseEnable data DB WAL cleanup
MAX_DATA_ITEM_QUEUE_SIZEnumber100000Max data items in queue
BUNDLE_DATA_IMPORTER_QUEUE_SIZEnumber1000Max bundles in import queue
VERIFICATION_DATA_IMPORTER_QUEUE_SIZEnumber1000Max verification items in queue
DATA_ITEM_FLUSH_COUNT_THRESHOLDnumber1000Data items threshold for flushing
MAX_FLUSH_INTERVAL_SECONDSnumber600Max interval between flushes

File System Cleanup

VariableTypeDefaultDescription
FS_CLEANUP_WORKER_BATCH_SIZEnumber2000Files per cleanup batch
FS_CLEANUP_WORKER_BATCH_PAUSE_DURATIONnumber5000Pause between cleanup batches (ms)
FS_CLEANUP_WORKER_RESTART_PAUSE_DURATIONnumber14400000Pause before restarting cleanup (ms)

Background Verification

VariableTypeDefaultDescription
ENABLE_BACKGROUND_DATA_VERIFICATIONbooleantrueEnable background data verification
BACKGROUND_DATA_VERIFICATION_INTERVAL_SECONDSnumber600Verification interval
BACKGROUND_DATA_VERIFICATION_WORKER_COUNTnumber1Number of verification workers
BACKGROUND_DATA_VERIFICATION_STREAM_TIMEOUT_MSnumber30000Stream timeout for verification

Bundle Repair

VariableTypeDefaultDescription
BUNDLE_REPAIR_RETRY_INTERVAL_SECONDSnumber300Bundle repair retry interval
BUNDLE_REPAIR_UPDATE_TIMESTAMPS_INTERVAL_SECONDSnumber300Timestamp update interval
BUNDLE_REPAIR_BACKFILL_INTERVAL_SECONDSnumber900Backfill interval
BUNDLE_REPAIR_FILTER_REPROCESS_INTERVAL_SECONDSnumber300Filter reprocess interval
BUNDLE_REPAIR_RETRY_BATCH_SIZEnumber5000Batch size for repair retries

ArNS Configuration

VariableTypeDefaultDescription
ARNS_ROOT_HOSTstring-Root hostname for ArNS. Envoy and the ClickHouse auto-import service read it too
SANDBOX_PROTOCOLstring-Protocol for sandboxing redirects (http or https)
AR_IO_SDK_LOG_LEVELstringnonear.io SDK log level
ARNS_CACHE_TYPEstringredis; node outside DockerArNS cache type
ARNS_CACHE_TTL_SECONDSnumber86400ArNS cache TTL
ARNS_CACHE_MAX_KEYSnumber10000Max ArNS cache keys
ARNS_RESOLVER_PRIORITY_ORDERstringon-demand,gatewayArNS resolver priority
ARNS_COMPOSITE_RESOLVER_TIMEOUT_MSnumber3000Composite resolver timeout
ARNS_NAMES_CACHE_TTL_SECONDSnumber3600Names cache TTL
ARNS_MAX_CONCURRENT_RESOLUTIONSnumber1Max concurrent resolutions

ar.io

The ar.io protocol runs on five Solana programs (see protocol architecture), and the gateway talks to four of them: ario-core, ario-gar, ario-arns, and ario-ant. The fifth, ario-ant-escrow, has no gateway-side program ID below because a gateway never calls it; it is a wallet-to-wallet escrow, not something a gateway needs to resolve. Each program ID below is configured independently, so the same image can run against mainnet, staging-devnet, or a local devnet. The defaults are the mainnet IDs, listed in the Token docs. To confirm which set a running gateway is using, GET /ar-io/info returns the resolved programIds object.

VariableTypeDefaultDescription
AR_IO_WALLETstring-Operator Solana public key (base58). Display label surfaced on /ar-io/info
SOLANA_RPC_URLstringhttps://api.mainnet-beta.solana.comSolana JSON-RPC endpoint, for the gateway and the observer
SOLANA_KEYPAIR_PATHstring-Path to the operator's 64-byte Solana keypair JSON file. Signs join_network, update_gateway_settings, and cranker instructions. Inside the container the path must start with /app/wallets/
SOLANA_PRIVATE_KEYstring-Alternative to SOLANA_KEYPAIR_PATH: base58-encoded 64-byte secret (Phantom export format). Mutually exclusive with the file form
ENABLE_EPOCH_CRANKINGbooleanfalseWhen true, the observer runs permissionless epoch instructions (close_observation, tick_epoch, etc.)
ARIO_CORE_PROGRAM_IDstring73YoECm6NKXpVRoe5f1Q9BcP5DJGPFUjnFy6AxBE5Nvhario-core program ID (token, staking, epoch state)
ARIO_GAR_PROGRAM_IDstring89fNiiwgpFSPHKuqfNUkgYTYjtAJAhyqHjXmgXeppGpfario-gar program ID (Gateway Registry; joins, observations, distributions)
ARIO_ARNS_PROGRAM_IDstring2yCUx5edFvUrkibYaUa2ZXWyx9kuJkS8CwyzsgHPWdZZario-arns program ID (ArNS name registry)
ARIO_ANT_PROGRAM_IDstring2MWexMHfMhGJwMHv9Qm9YAVCqjUFUJwDJAysW4oCUGk5ario-ant program ID (ANT records — Metaplex Core NFTs that route names to data)
AR_IO_NODE_RELEASEstringthe release of the imageThe release the gateway and observer report. Leave it unset
APEX_TX_IDstring-Transaction served at the apex domain. See Setting an Apex Domain
APEX_ARNS_NAMEstring-ArNS name served at the apex domain
ARNS_NOT_FOUND_TX_IDstring-Not found transaction ID
ARNS_NOT_FOUND_ARNS_NAMEstringunregistered_arnsNot found ArNS name

The default public Solana RPC is rate-limited and may block getProgramAccounts queries needed for full registry enumeration. For production gateways, use a dedicated RPC provider such as Helius, Triton, or QuickNode.

Caching

VariableTypeDefaultDescription
CHAIN_CACHE_TYPEstringredis; lmdb outside DockerChain cache type (lmdb, fs, redis)
REDIS_CACHE_URLstringredis://redis:6379; redis://localhost:6379 outside DockerRedis cache URL
REDIS_USE_TLSbooleanfalseUse TLS for Redis
REDIS_CACHE_TTL_SECONDSnumber28800Redis cache TTL
ENABLE_FS_HEADER_CACHE_CLEANUPbooleanfalseEnable FS header cache cleanup
CONTIGUOUS_DATA_CACHE_CLEANUP_THRESHOLDstring-Contiguous data cache cleanup threshold

Webhooks

VariableTypeDefaultDescription
WEBHOOK_TARGET_SERVERSstring-Comma-separated webhook target servers
WEBHOOK_INDEX_FILTERJSON{"never": true}Webhook index filter
WEBHOOK_BLOCK_FILTERJSON{"never": true}Webhook block filter

Mempool Watcher

VariableTypeDefaultDescription
ENABLE_MEMPOOL_WATCHERbooleanfalseEnable mempool watcher
MEMPOOL_POLLING_INTERVAL_MSnumber30000Mempool polling interval

AWS S3

VariableTypeDefaultDescription
AWS_ACCESS_KEY_IDstring-AWS access key ID
AWS_SECRET_ACCESS_KEYstring-AWS secret access key
AWS_SESSION_TOKENstring-AWS session token
AWS_REGIONstring-AWS region
AWS_ENDPOINTstring-AWS endpoint
AWS_S3_CONTIGUOUS_DATA_BUCKETstring-S3 bucket for contiguous data
AWS_S3_CONTIGUOUS_DATA_PREFIXstring-S3 prefix for contiguous data

ClickHouse

VariableTypeDefaultDescription
CLICKHOUSE_URLstring-ClickHouse URL
CLICKHOUSE_USERstring-ClickHouse username, for the gateway, the ClickHouse server and the auto-import service. Set it explicitly (usually default) when you set a password
CLICKHOUSE_PASSWORDstring-ClickHouse password, for the same three services. Required by the auto-import service

PostgreSQL (Legacy)

VariableTypeDefaultDescription
LEGACY_PSQL_CONNECTION_STRINGstring-PostgreSQL connection string
LEGACY_PSQL_PASSWORD_FILEstring-Path to PostgreSQL password file
LEGACY_PSQL_SSL_REJECT_UNAUTHORIZEDbooleantrueReject unauthorized SSL connections

Circuit Breaker

VariableTypeDefaultDescription
ARIO_PROCESS_DEFAULT_CIRCUIT_BREAKER_TIMEOUT_MSnumber60000Circuit breaker timeout
ARIO_PROCESS_DEFAULT_CIRCUIT_BREAKER_ERROR_THRESHOLD_PERCENTAGEnumber30Error threshold percentage
ARIO_PROCESS_DEFAULT_CIRCUIT_BREAKER_ROLLING_COUNT_TIMEOUT_MSnumber600000Rolling count timeout
ARIO_PROCESS_DEFAULT_CIRCUIT_BREAKER_RESET_TIMEOUT_MSnumber1200000Reset timeout

Performance Tuning

VariableTypeDefaultDescription
NODE_MAX_OLD_SPACE_SIZEnumber2048, or 8192 when ANS104_UNBUNDLE_WORKERS is above 1Node.js heap limit for the core service, in MB
WEIGHTED_PEERS_TEMPERATURE_DELTAnumber2Weighted peers temperature delta
GATEWAY_PEERS_WEIGHTS_CACHE_DURATION_MSnumber5000Gateway peers weights cache duration
GATEWAY_PEERS_REQUEST_WINDOW_COUNTnumber20Gateway peers request window count
TAG_SELECTIVITYJSON{"Parent-Folder-Id": 20, "Message": 20, "Drive-Id": 10, "Process": 10, "Recipient": 10, "App-Name": -10, "Content-Type": -10, "Data-Protocol": -10}Tag selectivity configuration

Data Paths

Host directories mounted into the core service. Other services that share a directory mount the same path.

VariableTypeDefaultDescription
CHUNKS_DATA_PATHstring./data/chunksPath to chunks data
CONTIGUOUS_DATA_PATHstring./data/contiguousPath to contiguous data
HEADERS_DATA_PATHstring./data/headersPath to headers data
SQLITE_DATA_PATHstring./data/sqlitePath to SQLite data (also backed up by Litestream)
DUCKDB_DATA_PATHstring./data/duckdbPath to DuckDB data
TEMP_DATA_PATHstring./data/tmpPath to temporary data (also used by the observer)
LMDB_DATA_PATHstring./data/lmdbPath to LMDB data
PARQUET_DATA_PATHstring./data/parquetPath to Parquet data (also used by ClickHouse auto-import)

Rate Limiter

VariableTypeDefaultDescription
ENABLE_RATE_LIMITERbooleanfalseEnable rate limiting system
RATE_LIMITER_TYPEstringredis; memory outside DockerRate limiter type (memory or redis)
RATE_LIMITER_REDIS_ENDPOINTstringredis://redis:6379; localhost:6379 outside DockerRedis endpoint for rate limiter
RATE_LIMITER_IP_TOKENS_PER_BUCKETnumber100000IP bucket token capacity
RATE_LIMITER_IP_REFILL_PER_SECnumber20IP bucket refill rate per second
RATE_LIMITER_RESOURCE_TOKENS_PER_BUCKETnumber1000000Resource bucket token capacity
RATE_LIMITER_RESOURCE_REFILL_PER_SECnumber100Resource bucket refill rate
RATE_LIMITER_IPS_AND_CIDRS_ALLOWLISTstring-Comma-separated IP/CIDR allowlist, exempt from rate limits and x402. Matched against the client address only
TRUSTED_PROXIESstringloopback, private, CGNAT and link-local rangesProxies (IPs/CIDRs) whose X-Forwarded-For and X-Real-IP are believed when working out the client address. Add a CDN's or public load balancer's ranges when one is in front; none trusts no proxy, only for a core that clients reach directly, with no Envoy in front. See x402 setup
RATE_LIMITER_ARNS_ALLOWLISTstring-Comma-separated ArNS allowlist

x402 Payment Protocol

VariableTypeDefaultDescription
ENABLE_X_402_USDC_DATA_EGRESSbooleanfalseEnable x402 USDC payments
X_402_USDC_NETWORKstringbase-sepoliaBase network (base-sepolia or base)
X_402_USDC_WALLET_ADDRESSstring-USDC wallet address for receiving payments
X_402_USDC_FACILITATOR_URLstringhttps://x402.org/facilitatorPayment facilitator URL
X_402_USDC_PER_BYTE_PRICEnumber0.0000000001Price per byte in USDC
X_402_USDC_DATA_EGRESS_MIN_PRICEnumber0.001Minimum payment amount
X_402_USDC_DATA_EGRESS_MAX_PRICEnumber1.00Maximum payment amount
X_402_RATE_LIMIT_CAPACITY_MULTIPLIERnumber10Paid token capacity multiplier
X_402_APP_NAMEstringAR.IO GatewayApplication name for paywall
X_402_APP_LOGOstring-Application logo URL for paywall
X_402_CDP_CLIENT_KEYstring-PUBLIC: CDP client key for Onramp (optional testnet, required mainnet)
CDP_API_KEY_IDstring-SECRET: CDP API key ID for Onramp (optional testnet, required mainnet)
CDP_API_KEY_SECRETstring-SECRET: CDP API secret for Onramp (use CDP_API_KEY_SECRET_FILE instead)
CDP_API_KEY_SECRET_FILEstring-SECRET: Path to CDP secret file for Onramp (takes precedence, recommended)
CHUNK_GET_BASE64_SIZE_BYTESnumber368640Fixed size for chunk pricing

Autoheal

VariableTypeDefaultDescription
RUN_AUTOHEALbooleanfalseLabel the gateway's containers so the autoheal service restarts them when unhealthy

OpenTelemetry Tracing

Basic Configuration

VariableTypeDefaultDescription
OTEL_SERVICE_NAMEstringar-io-nodeOpenTelemetry service name
OTEL_EXPORTER_OTLP_ENDPOINTstring-OTLP exporter endpoint
OTEL_EXPORTER_OTLP_HEADERSstring-OTLP exporter headers
OTEL_EXPORTER_OTLP_HEADERS_FILEstring-Path to OTLP exporter headers file

Tracing Performance

VariableTypeDefaultDescription
OTEL_BATCH_LOG_PROCESSOR_SCHEDULED_DELAY_MSnumber2000Batch log processor scheduled delay
OTEL_BATCH_LOG_PROCESSOR_MAX_EXPORT_BATCH_SIZEnumber10000Max export batch size
OTEL_TRACING_SAMPLING_RATE_DENOMINATORnumber1Tracing sampling rate denominator (1 keeps every trace)

Observer Service

Basic Configuration

VariableTypeDefaultDescription
OBSERVER_PORTnumber5050Host port for the observer, and the port Envoy forwards to
OBSERVER_LOG_LEVELstringverboseObserver log level
OBSERVER_WALLETstring-Observer wallet

Observer Operation

VariableTypeDefaultDescription
RUN_OBSERVERbooleantrueRun observer service
SUBMIT_CONTRACT_INTERACTIONSbooleantrue; false outside DockerSubmit observations to Solana programs. Pre-flight no-ops unless your pubkey is in epoch.prescribed_observers, so it is harmless before join_network
NUM_ARNS_NAMES_TO_OBSERVE_PER_GROUPnumber8Number of ArNS names per observation group
REPORT_GENERATION_INTERVAL_MSnumber3600000Report generation interval (one hour)
REPORT_DATA_SINKstringturboWhere reports are saved
TURBO_UPLOAD_SERVICE_URLstring-Turbo upload service URL
MIN_RELEASE_NUMBERnumber0Minimum release number

Upload Wallet Identities

The observer uploads report bundles to Turbo. The upload signer is resolved from the first matching env in the precedence chain. Setting envs from more than one chain group at once is rejected at startup.

If your observer logs warn that TurboReportSink is not configured, explicitly set a Solana upload signer. Most operators can use the same base58 secret for both OBSERVER_PRIVATE_KEY and SOLANA_UPLOAD_PRIVATE_KEY.

VariableTypeDefaultDescription
ARWEAVE_UPLOAD_KEY_FILEstring-Path to an Arweave JWK file. Highest priority for upload signing
ARWEAVE_UPLOAD_JWKstring-Inline Arweave JWK JSON. Lower priority than the file form
ETHEREUM_UPLOAD_PRIVATE_KEY_FILEstring-Path to a 32-byte hex private key (with or without 0x prefix)
ETHEREUM_UPLOAD_PRIVATE_KEYstring-Inline hex private key. Lower priority than the file form
SOLANA_UPLOAD_KEYPAIR_PATHstring-Path to a separate Solana keypair JSON for uploads. Ignored when any ARWEAVE_UPLOAD_* or ETHEREUM_UPLOAD_* is set
SOLANA_UPLOAD_PRIVATE_KEYstring-Alternative to above: base58 secret. Mutually exclusive with the file form

When none of the above are set, uploads fall back to the observer key, then the operator key. For production observers, prefer setting SOLANA_UPLOAD_KEYPAIR_PATH or SOLANA_UPLOAD_PRIVATE_KEY explicitly so report uploads do not depend on fallback behavior.

Observer Data Paths

VariableTypeDefaultDescription
REPORTS_DATA_PATHstring./data/reportsPath to reports data
WALLETS_PATHstring./walletsPath to wallets

Envoy Proxy

Docker Compose also passes Envoy CORE_PORT, OBSERVER_PORT and ARNS_ROOT_HOST, described above.

VariableTypeDefaultDescription
ENVOY_PORTnumber3000Host port Envoy listens on
ENVOY_LOG_LEVELstringinfoEnvoy log level
TRUSTED_NODE_HOSTstringarweave.netArweave node Envoy forwards node requests to
TRUSTED_NODE_PORTnumber443Port of that node
GRAPHQL_HOSTstringcoreWhere Envoy sends GraphQL requests
GRAPHQL_PORTnumber4000Port for GraphQL requests

Redis Cache

VariableTypeDefaultDescription
REDIS_MAX_MEMORYstring256mbRedis max memory
EXTRA_REDIS_FLAGSstring--save "" --appendonly noExtra Redis flags
REDIS_DATA_PATHstring./data/redisPath to Redis data

ClickHouse Server

CLICKHOUSE_USER and CLICKHOUSE_PASSWORD are under ClickHouse in the core section.

VariableTypeDefaultDescription
CLICKHOUSE_PORTnumber9000Host port for ClickHouse's native protocol
CLICKHOUSE_DATA_PATHstring./data/clickhousePath to ClickHouse data
CLICKHOUSE_LOGS_PATHstring./logs/clickhousePath to ClickHouse logs

ClickHouse Auto-Import

VariableTypeDefaultDescription
CLICKHOUSE_DEBUGstring-ClickHouse debug flag
CLICKHOUSE_HOSTstringclickhouseClickHouse host
CLICKHOUSE_AUTO_IMPORT_SLEEP_INTERVALstring-Auto-import sleep interval
CLICKHOUSE_AUTO_IMPORT_HEIGHT_INTERVALstring-Auto-import height interval
CLICKHOUSE_AUTO_IMPORT_MAX_ROWS_PER_FILEstring-Max rows per file for auto-import

Litestream Backup

VariableTypeDefaultDescription
AR_IO_SQLITE_BACKUP_S3_BUCKET_NAMEstring-S3 bucket name for SQLite backups
AR_IO_SQLITE_BACKUP_S3_BUCKET_REGIONstring-S3 bucket region for SQLite backups
AR_IO_SQLITE_BACKUP_S3_BUCKET_ACCESS_KEYstring-S3 access key for SQLite backups
AR_IO_SQLITE_BACKUP_S3_BUCKET_SECRET_KEYstring-S3 secret key for SQLite backups
AR_IO_SQLITE_BACKUP_S3_BUCKET_PREFIXstring-S3 prefix for SQLite backups

Image Tags

Each service's image tag can be overridden. The defaults change with each release, so they are not listed here: they are in docker-compose.yaml on main.

VariableTypeDefaultDescription
CORE_IMAGE_TAGstringsee docker-compose.yamlCore image tag, also used by the index-swarm sidecar
ENVOY_IMAGE_TAGstringsee docker-compose.yamlEnvoy image tag
OBSERVER_IMAGE_TAGstringsee docker-compose.yamlObserver image tag
REDIS_IMAGE_TAGstringsee docker-compose.yamlRedis image tag
CLICKHOUSE_IMAGE_TAGstringsee docker-compose.yamlClickHouse image tag
CLICKHOUSE_AUTO_IMPORT_IMAGE_TAGstringsee docker-compose.yamlClickHouse auto-import image tag
LITESTREAM_IMAGE_TAGstringsee docker-compose.yamlLitestream image tag

INDEX_EXPORT_IMAGE_TAG (Release 85) is under Building Bands.

Usage Notes

  • All environment variables are optional unless otherwise specified
  • Default values are shown in the "Default" column
  • Boolean values should be set to true or false
  • JSON values should be valid JSON strings
  • Path values should be absolute or relative to the project root
  • Some variables are only used in specific deployment scenarios (e.g., ClickHouse, Litestream)
  • Data paths can be customized based on your storage requirements

Configuration Examples

Basic Gateway Setup

# Core configuration
CORE_LOG_LEVEL=info
ADMIN_API_KEY=your-admin-key-here

# Network configuration
TRUSTED_GATEWAY_URL=https://turbo-gateway.com

# Data paths
CHUNKS_DATA_PATH=/data/chunks
CONTIGUOUS_DATA_PATH=/data/contiguous
SQLITE_DATA_PATH=/data/sqlite

Advanced Gateway with ClickHouse

# Core configuration
CORE_LOG_LEVEL=info
ADMIN_API_KEY=your-admin-key-here

# ClickHouse configuration
CLICKHOUSE_URL=http://clickhouse:8123
CLICKHOUSE_USER=default
CLICKHOUSE_PASSWORD=your-password

# Bundle processing
ANS104_UNBUNDLE_FILTER={"and": [{"equals": {"App-Name": "MyApp-v1.0"}}]}
ANS104_INDEX_FILTER={"and": [{"equals": {"App-Name": "MyApp-v1.0"}}]}
ANS104_UNBUNDLE_WORKERS=2
ANS104_DOWNLOAD_WORKERS=5

Gateway with Redis Caching

Under Docker Compose, the chain cache and the ArNS cache already use the bundled Redis. Outside Docker:

# Redis configuration
CHAIN_CACHE_TYPE=redis
REDIS_CACHE_URL=redis://localhost:6379
REDIS_USE_TLS=false
REDIS_CACHE_TTL_SECONDS=28800

# ArNS configuration
ARNS_ROOT_HOST=your-domain.com
ARNS_CACHE_TYPE=redis

How is this guide?