camelAI Documentation

Self-hosting

Configuration

Environment variables for a self-hosted camelRun runtime

Everything in the Compose deployment's .env reaches the runtime. These are the settings a self-hosted runtime uses.

Required

Variable
AGENT_TENANT, AGENT_OPERATOR_TOKENThe one tenant the runtime serves, and that tenant's operator token (at least 24 characters). Your application sends the token as Authorization: Bearer
AGENT_SESSION_SECRET32 random bytes, hex. Keep it: changing it invalidates agents' tokens and signed links
AGENT_SECRETS_KEY32 random bytes, hex. Encrypts stored provider keys; changing it makes them unreadable
AGENT_PUBLIC_URLThe URL your application and tool servers reach the runtime at. Signed links and identity tokens name it
AGENT_DATABASE_URLPostgres. The Compose file sets it for its own database, with POSTGRES_PASSWORD

Generate the secrets with openssl rand -hex 32.

Models

Variable
AGENT_TENANT_API_KEYSThe tenant's provider keys as JSON, such as {"anthropic": "sk-ant-...", "openrouter": "sk-or-..."}. Optional: keys can also be stored later with PUT /v1/providers/{provider}/key, or per key scope
AGENT_PROVIDER, AGENT_MODELThe default model for agents that name none, such as anthropic and claude-sonnet-5-5
AGENT_MODEL_FALLBACKSDefaults after it, as comma-separated provider/model references. An agent that names no model gets the first its tenant has a key for

Storage

Variable
AGENT_STORAGEfile (default, one node only), shared-file (several processes on one filesystem), or s3
AGENT_S3_BUCKET, AGENT_S3_PREFIXThe bucket, with s3 storage
AGENT_S3_ENDPOINT, AGENT_S3_FORCE_PATH_STYLEAn S3-compatible service instead of AWS S3, and true for path-style requests
AGENT_GC_ENABLED, AGENT_GC_DRY_RUNStorage garbage collection (off by default), and true to only log what it would delete

Networking

Variable
AGENT_BROWSER_URLWhere browsers reach the runtime, as browser tokens say. Defaults to AGENT_PUBLIC_URL; empty for a private runtime browsers read through your application
AGENT_OUTBOUND_ALLOW_ORIGINSExact origins (scheme://host:port, comma-separated) of your own services the runtime may call despite the private-address guard, over http too. Never used by web_fetch or web_search
AGENT_OUTBOUND_BLOCK_CIDRSExtra ranges no tool source may reach, such as your VPC's CIDR
AGENT_NODE_URLThis node's address for forwarding between nodes, when running several
HOST, PORTWhere the runtime listens. Default 127.0.0.1:8790 outside the container

Operations

Variable
AGENT_DRAIN_TIMEOUT_MSHow long a stop waits for running turns before handing them off. Default 100,000
AGENT_DATABASE_POOL_SIZEDatabase connections per node. Default 10
AGENT_SANDBOX_PROCESSESHow many sandbox processes run model-written code. Default 2, at most 16
AGENT_TOOL_SEARCHRanking for tools.search: keyword (default), or embeddings with an embeddings API key

Several tenants

Instead of AGENT_TENANT and AGENT_OPERATOR_TOKEN, give a tenants file as AGENT_TENANTS_FILE (a mounted path) or AGENT_TENANTS_JSON (inline). It is re-read on SIGHUP:

json
{"tenants": {
  "acme": {"tokenSha256": "<sha256 of the operator token>", "apiKeys": {"anthropic": "sk-ant-..."}},
  "globex": {"tokenSha256": "...", "maxAgents": 50, "maxMonthlyCost": 500}
}}

Each tenant's tokenSha256 is the SHA-256 hex digest of its operator token. Optional fields include maxAgents (agents awake at once), maxWatchers and maxMonthlyCost.