Skip to content

Environment Variables Reference ​

Environment variables configure your Frappe Docker setup. They can be set directly in the container or defined in a .env file referenced by Docker Compose.

Getting Started:

bash
cp example.env .env

Then edit .env and set variables according to your needs.


Required Variables ​

VariablePurposeExampleNotes
FRAPPE_PATHFrappe framework pathhttps://github.com/frappe/frappe
FRAPPE_BRANCHFrappe Branchversion-15See Frappe releases
ERPNEXT_VERSIONERPNext release versionv15.67.0Required although its never used
DB_PASSWORDPassword for database root (MariaDB or Postgres)secure_password_123Not needed if using DB_PASSWORD_SECRETS_FILE

Database Configuration ​

VariablePurposeDefaultWhen to Set
DB_PASSWORDDatabase root user password123Always (unless using secrets file)
DB_PASSWORD_SECRETS_FILEPath to file containing database password—Setup mariadb-secrets overrider
DB_HOSTDatabase hostname or IPdb (service name)Only if using external database
DB_PORTDatabase port3306 (MariaDB) / 5432 (Postgres)Only if using external database

Redis Configuration ​

VariablePurposeDefaultWhen to Set
REDIS_CACHERedis hostname for cachingredis-cache (service name)Only if using external Redis instance
REDIS_QUEUERedis hostname for job queues and real-time updatesredis-queue (service name)Only if using external Redis instance

Volume Bind Mounts ​

VariablePurposeDefaultWhen to Set
SITES_DATA_LOCATIONHost directory for the sites volume; must be an absolute path and already exist-Required for compose.bind-mount-sites.yaml
DB_DATA_LOCATIONHost directory for the db-data volume; must be an absolute path and already exist-Required for compose.bind-mount-db-data.yaml
REDIS_QUEUE_DATA_LOCATIONHost directory for the redis-queue-data volume; must be an absolute path and already exist-Required for compose.bind-mount-redis-queue.yaml

The host directory must exist before docker compose up -d and must be writable by the user the container runs as:

DirectoryOwner
sitesuid/gid 1000 (the frappe user of the image)
db-datauid/gid 999 (the mariadb or postgres image)
redis-queue-datauid/gid 999 (the redis image)

Warning: with a bind mount, the data lives on the host, not inside the Docker volume. Removing the volume (for example with docker compose down -v) will not delete the data. To actually erase the data, delete the host directory manually with rm -r <data path>.

Example:

bash
mkdir -p /srv/frappe/{sites,db-data,redis-queue-data}
chown 1000:1000 /srv/frappe/sites
chown 999:999 /srv/frappe/db-data /srv/frappe/redis-queue-data
bash
SITES_DATA_LOCATION=/srv/frappe/sites
DB_DATA_LOCATION=/srv/frappe/db-data
REDIS_QUEUE_DATA_LOCATION=/srv/frappe/redis-queue-data

Reverse Proxy and SSL (HTTPS) Configuration ​

Traefik (compose.proxy.yaml / compose.https.yaml) ​

VariablePurposeDefaultWhen to Set
LETSENCRYPT_EMAILEmail for Let's Encrypt certificate registration-Required for compose.https.yaml
SITES_RULEDomains for routing (Traefik rule expression)-Required for Traefik routing/HTTPS overrides

Format for SITES_RULE:

bash
# Single site
SITES_RULE=Host(`mysite.example.com`)

# Multiple sites
SITES_RULE=Host(`a.example.com`) || Host(`b.example.com`)

Note: The Traefik v3 migration is complete. Use SITES_RULE as a full v3 rule expression; SITES is deprecated. Rule syntax now defaults to v3, so no core.defaultRuleSyntax or per-router ruleSyntax settings are required.

nginx-proxy + acme-companion (compose.nginxproxy*.yaml) ​

VariablePurposeDefaultWhen to Set
LETSENCRYPT_EMAILEmail for Let's Encrypt certificate-Required for compose.nginxproxy-ssl.yaml
NGINX_PROXY_HOSTSComma-separated hostnames for nginx-proxy-Required for compose.nginxproxy*.yaml

Example:

bash
NGINX_PROXY_HOSTS=example.com,www.example.com

Note: Automatic certificates require port 80 to be reachable (HTTP-01).

Published Ports (Traefik and nginx-proxy) ​

VariablePurposeDefaultWhen to Set
HTTP_PUBLISH_PORTPublished HTTP port80 (proxy) / 8080 (noproxy)Change if port is in use
HTTPS_PUBLISH_PORTPublished HTTPS port443Change if port 443 is in use

Site Configuration ​

VariablePurposeDefaultWhen to Set
FRAPPE_SITE_NAME_HEADERSite name for multi-tenant setup$host (resolved from request hostname)When accessing by IP or need explicit site name

Examples:

If your site is named mysite but you want to access it via 127.0.0.1:

bash
FRAPPE_SITE_NAME_HEADER=mysite

If your site is named example.com and you access it via that domain, no need to set this (defaults to hostname).


Image Configuration ​

VariablePurposeDefaultNotes
CUSTOM_IMAGECustom Docker image repositoryFrappe official imageLeave empty to use default
CUSTOM_TAGCustom Docker image tagLatest stableCorresponds to FRAPPE_VERSION
PULL_POLICYImage pull behavioralwaysOptions: always, never, if-not-present
RESTART_POLICYContainer restart behaviorunless-stoppedOptions: no, always, unless-stopped, on-failure

Backend (Gunicorn) Configuration ​

VariablePurposeDefaultWhen to Set / Allowed Values
GUNICORN_WORKERSNumber of worker processes handling web requests2Scale up for multi-core CPUs. Formula: (2 x Cores) + 1
GUNICORN_THREADSNumber of concurrent threads per worker process4Increase to handle more simultaneous I/O-bound requests without high memory cost
GUNICORN_TIMEOUTMax time a worker can spend on a single request before restart120Increase if long-running reports or data imports time out

Frontend Nginx Configuration (inside the frontend container) ​

VariablePurposeDefaultAllowed Values
NGINX_LISTEN_PORTSets the listen directive8080{port}
BACKENDBackend service address and port0.0.0.0:8000{host}:{port}
SOCKETIOSocket.IO service address and port0.0.0.0:9000{host}:{port}
PROXY_READ_TIMEOUTUpstream request timeout120sAny nginx timeout value (e.g., 300s, 5m)
CLIENT_MAX_BODY_SIZEMaximum upload file size50mAny nginx size value (e.g., 100m, 1g)

Real IP Configuration (Behind Proxy) ​

Use these variables when running behind a reverse proxy or load balancer:

VariablePurposeDefault
UPSTREAM_REAL_IP_ADDRESSTrusted upstream IP address for real IP detection127.0.0.1
UPSTREAM_REAL_IP_HEADERRequest header containing client IPX-Forwarded-For
UPSTREAM_REAL_IP_RECURSIVEEnable recursive IP searchoff

Migration Service ​

VariablePurposeDefaultAllowed Values
MIGRATE_SITESSwitch auto migration on or offtrue - auto migration ontrue , false