Environment Variables
Local orchestration composes reviewed environment layers; hosted services still own and validate their exact production variables independently.
Common Variables
| Variable | Services | Notes |
|---|---|---|
| NODE_ENV | Web, API, Gateway, Worker | production on Railway. |
| PORT | Web, API, Gateway, Worker | Injected by Railway for the running container. |
| SERVICE_NAME | Web, API, Gateway, Worker | Must match the package literal. |
| PUBLIC_WEB_ORIGIN | Web, API, Gateway, Worker | Browser-facing web origin. |
| API_PUBLIC_URL | Web, API, Gateway, Worker | Browser-facing API URL. The hosted Windows WSL Downloads command supplies it as both -ApiUrl and -ArtifactUrl. |
| GATEWAY_PUBLIC_URL | Web, API, Gateway, Worker | Browser-facing gateway URL. The hosted Windows WSL Downloads command supplies it as -GatewayUrl. |
Production Guards
- API production receipt and launch signing require immutable GCP KMS/HSM key versions through workload identity; private signing PEMs are rejected.
- Gateway production session signing requires an immutable GCP KMS/HSM key version; TLS key material is certificate-scoped and never reused as a signing key.
- Worker production process-mode scans run from the pinned worker image; container-mode scans require PACKAGE_SECURITY_SCANNER_IMAGE_DIGEST.
- Metrics bearer tokens are required whenever production metrics are enabled.
Protected Local Windows WSL Profile
- The onboarding wizard owns .local/wsl-hacp-onboarding/sigroom-wsl.env. Local start and health commands load the base environment, generated TLS/signing environment, then that mode-600 marker-owned profile.
- The profile explicitly configures protected Linux temporary storage, localhost origins and CA trust, self-service enrollment, the exact Windows workspace allowlist, the local GeneSYS kill switch, L4/L5 mode, manual or autonomy admission, canonical signed launch-rootfs measurement, stable launch/Gateway verification descriptors, release trust, PACKAGE_SECURITY_RELEASE_BLOCKING_ENABLED=true, and optional bounded model access. Disabled TPM/model/inference/rotation values are cleared rather than inherited; hosted harness admission comes from versioned database policies.
- Direct local processes receive only service-owned private material; Compose maps reviewed variables per container. Direct processes use REDIS_URL on localhost while containers use REDIS_INTERNAL_URL.
- Do not source, edit, commit, or copy the protected profile. Rerun onboarding when its release or path changes. SIGROOM_LOCAL_ENV_OVERRIDE_FILE remains an advanced explicit CI/recovery override.
- Only the default local-process stack is qualified. Docker/hybrid application-service WSL L5, the separate PROJECT_TEST_* Linux Worker role, and all hosted values are outside this local contract.
Source Material
- ops/railway/env-matrix.md
- .env.local.example
- docs/deployment/runtimes/windows-wsl2/local-development-walkthrough.md
- ops/hacp-control/onboard-wsl-hacp.sh
- scripts/local/run-full-stack.sh
- scripts/local/start-services.sh
- scripts/local/check-health.sh
- scripts/local/ensure-gateway-tls-env.sh
- apps/api/src/env.ts
- apps/gateway/src/env.ts
- apps/worker/src/env.ts
- apps/web/src/env.ts