🚀 Get to pre-production in weeks, not months, with private training direct from Jube’s developer — real sovereignty, zero vendor lock-in.

Environment Variables

In Jube, application settings can only be passed via operating system (or container) Environment Variables. The following hardcoded Environment Variables, this would be to say defaults, are available:

Variable Default Value Description  
ModelSynchronisationWait 10000 The duration in milliseconds between model synchronisation. Many of the entities in model synchronisation require explicit instruction to synchronise, with that instruction being checked for each interval. Model entities which do not require explicit synchronisation will be included for each interval.  
EnableNotification True A boolean value to indicate if Notifications are enabled in the instance, in which case background threads will be established to relay the notifications created by the model invocation, and that model invocation may be branched to dispatch notifications to the thread.  
EnableTtlCounter True A boolean value indicating if this instance should start a thread to manage the decrement of TTL Counters.  
ConnectionString null The connection string to the Postgres database.  
CacheConnectionString null The connection string to the optional Cache Postgres database. In the absence of value will fall back to ConnectionString.  
MigrationConnectionString null An optional, separate connection string used only for running Migration on startup (see Architecture), falling back to ConnectionString - with a warning logged - when unset. Useful to grant DDL permissions (CREATE TABLE, CREATE INDEX) only to the credential used for Migration, while ConnectionString itself stays scoped to a restricted, DDL-less runtime user - see the restricted Postgres users note on Deploying with Docker.  
ReportConnectionString null The connection string to the Reporting Postgres database. In the absence of value there is no fallback value. In practice the connection string might be the same as the main, but be a different account for the purpose of reporting. When set, reprocessing and backtests also read the archive through it, so a read replica can take that load.  
EnableSearchKeyCache True A boolean value indicating if this instance should start a thread to manage the computation of Abstraction Rules set to Cache, meaning the background computation of aggregation values. Only a single instance may exist.  
EnableCasesAutomation True A boolean value indicating if this instance should start a thread to manage changing of status in the case records. Only a single instance may exist.  
CasesAutomationWait 60000 Subject to EnableCasesAutomation being True, the duration in milliseconds between model case status change and automation.  
EnableEntityModel True A boolean value to indicate if the models should be synchronised to this instance thus being available for invocation.  
ArchiverPersistThreads 4 The number of threads preparing records for bulk insert to the Archive and ArchiveKey tables. In extremely high throughput implementations with thousands of records being inserted, balancing the number of threads inserting records with the amount of records batched to insert allows for write performance optimisation. Zero (0) has the effect of disabling.  
ModelInvokeAsynchronousThreads 1 The number of threads allocated to processing model invocation switched to be asynchronous. Zero (0) has the effect of disabling.  
BulkCopyThreshold 1000 For each Archiver Persist Thread the number of records to be buffered before a bulk copy is committed. A maximum of ten seconds is allowed from the last message else bulk insert is performed regardless.  
ActivationWatcherAllowPersist True A boolean value to indicate that the instance may persist activation records to the ActivationWatcher table and also allowing for the instantiation of threads to manage the asynchronous bulk insert.  
ActivationWatcherPersistThreads 1 The number of threads preparing records for bulk insert into the ActivationWatcher table. Zero (0) has the effect of disabling.  
ActivationWatcherBulkCopyThreshold 100 For each Activation Watcher Persist Thread the number of records to be buffered before a bulk copy is committed.  
EnableReprocessing True A boolean value to indicate that the reprocessing of model invocation given Archive data, be allowed to create threads.  
ReprocessingThreads 1 The number of threads allocated to reprocessing model invocation given Archive data. Zero (0) has the effect of disabling.  
ReprocessingBulkLimit 10000 Reprocessing reads the Postgres Archive a page at a time, oldest reference date first, invokes the model for each matched record and writes the page’s updated archive records together in one transaction. The value is the number of records in a page, which bounds the instance memory and sets how many archive updates share a transaction.  
ThreadPoolManualControl False A boolean value to override the .Net Thread Pool with MinThreadPoolThreads and MaxThreadPoolThreads values, else .Net self managed. Managing the thread pool manually can reduce apparent warm up time for the application and reduce risk of thread starvation through threads being closely sized to underlying compute resources. All requests to the Kestrel web server will place demand on the Thread Pool, with each IO demand being made ashncronously (and likely in a seperate thread allocated by the Thread Pool). Model invocation can be decoupled from the thread pool partially via the use of asynchronous model invocation, otherwise it forms part of the request handled by the Kestrel thread.  
MinThreadPoolThreads 30 Given ThreadPoolManualControl being True, the minimum threads in the Thread Pool.  
MaxThreadPoolThreads 1000 Given ThreadPoolManualControl being True, the maximum threads in the Thread Pool.  
MaximumModelInvokeAsyncQueue 10000 The maximum number of pending asynchronous HTTP Model invocations allowed in queue before further requests are returned with an error.  
SMTPHost null For notification functionality, the SMTP server host.  
SMTPPort 587 The SMTP server port.  
SMTPUser null Assuming authentication the SMTP server user name.  
SMTPPassword null The SMTP server password given user name.  
SMTPFrom null The email address to be sent from.  
ClickatellAPIKey null For notification functionality, the API key provided by Clickatell for the SMS dispatch service.  
HttpAdaptationUrl http://localhost:5001 As a security measure a prefix to the HTTP Endpoint value entered by the end user in HTTP Adaptation to recall scores.  
HttpAdaptationTimeout 1000 The timeout value for HTTP Adaptation endpoint recall.  
HttpAdaptationValidateSsl False A boolean value to ensure SSL validation for HTTP Adaptation endpoint recall.  
EnableSanction True A boolean value to indicate if sanctions should be loaded from the database, cached to the instance memory and made available for searching in model invocation or directly.  
EnableSanctionLoader False A boolean value to indicate that this instance should load the Sanctions tables from local or internet resources. Disabled by default for reasons of security and privacy given outbound request to external HTTP resources.  
EnableMockEndpoints True A boolean value to indicate if the unauthenticated mock endpoints are mapped: the HTTP Adaptation Protocol test doubles under /api/MockHttpAdaptation/* (see HTTP Adaptation Protocol) and the mock RSA MFA verifier at /api/Mfa. Enabled by default, because the seeded example model points its adaptation at one of them and the endpoints are the documented way to exercise the protocol without an R or Python sandbox. Set to False on any deployment that does not need them: they are anonymous by design and one of them, ServerError, returns a 500 deliberately, so a security scan of an instance that leaves them mapped will report that 500 as a server error and an application error disclosure. The nightly OWASP ZAP scan sets this to False for exactly that reason.  
EnableDynamicEval False A boolean value to indicate if named dynamic expressions (rows in the DictionaryEvalExpression table) are made available as rule extension methods - see Curated Dynamic Expressions. Disabled by default for reasons of security: when False, no curated names are registered as rule tokens and the runtime evaluation call refuses to run. The underlying mechanism is not directly reachable from rule text regardless of this switch - only the automatic per-name rewrite can reach it.  
EnableInlineScriptExecution False A boolean value to indicate if the EntityAnalysisModelInlineScriptExecute agent tool may run an inline script against an invocation context outside the engine. Disabled by default for reasons of security: inline scripts are whole VB.NET or C# classes that are not restricted by the rule token allow-list and receive the invocation context, so running one could call out or have side effects. When False the tool refuses without compiling anything. Rule execution tools are not affected.  
EnableBacktest True A boolean value to start the backtest threads, which run backtests submitted from the rule pages and the backtest tools (EntityAnalysisModelBacktestSubmit). When False submitted backtests stay Pending until a node with it True picks them up. The immediate backtest (EntityAnalysisModelBacktestRunRule) is not affected.  
BacktestThreads 1 The number of threads on this node that claim and run submitted backtests, one instance per thread at a time. Several nodes and threads share the queue safely. Zero (0) has the effect of disabling.  
BacktestMaxRows 1000000 The most archived transactions one submitted backtest may read. Backtests read the archive in pages and evaluate in memory, so millions of rows are practical; the cost is one indexed range read per page.  
BacktestOnlineMaxRows 10000 The most archived transactions the immediate backtest (EntityAnalysisModelBacktestRunRule) may read while the caller waits. Larger backtests must be submitted.  
BacktestPageSize 5000 How many archived transactions a backtest reads from the database at a time. Only one page is held in memory; progress and stop requests are checked between pages.  
BacktestMaxRunInterval s The unit for BacktestMaxRunIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
BacktestMaxRunIntervalValue 3600 The longest a submitted backtest may run, in the unit set by BacktestMaxRunInterval, before it is stopped and marked Failed.  
BacktestStaleInterval s The unit for BacktestStaleIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
BacktestStaleIntervalValue 120 A submitted backtest left Running whose heartbeat is older than this (in the unit set by BacktestStaleInterval) is marked Failed, for example after an engine stopped mid run. The heartbeat is sent on a timer, every quarter of this value and at most every 10 seconds, so a long page does not count as stalled. It is never run again automatically.  
BacktestMaxConcurrentRunsPerTenant 1 How many submitted backtests of one tenant may run at once across all nodes, so one tenant cannot hold every backtest thread; tenants waiting are served in turn.  
SanctionLoaderWait 3600000 The duration in milliseconds between polling the file system or internet location for sanctions files. Raised from an earlier 60000 (one minute) default after that interval hit rate limits against a real sanctions source - now polled hourly by default.  
EnableSanctionLoaderChangePoll True True (the default) checks the sanctions import audit at SanctionLoaderChangePoll intervals and refreshes the sanctions cache when a new import is seen. False restores a single wait of SanctionLoaderWait between refreshes. It does not affect EnableSanctionLoader, which only gates the loading of HTTP and directory sources.  
SanctionLoaderChangePoll 60000 The interval in milliseconds at which the engine checks the sanctions import audit table (SanctionEntryImport) for a new import, for example an upload from the UI, and when one is found refreshes the in-memory sanctions cache at once instead of waiting for SanctionLoaderWait. Entries removed by the import leave the cache too. A missing, non numeric, zero or negative value is read as 60000, and a value at or above SanctionLoaderWait means a single check at the end of the wait. Switch the check off with EnableSanctionLoaderChangePoll.  
NegotiateAuthentication False A boolean value to indicate that authentication should take place via Negotiated Authentication (commonly known as Active Directory in Windows networks) rather than JSON Web Token authentication. Very common in corporate environments.  
UseMockDataExhaustive True A boolean value to indicate that given an Exhaustive training instance having been instructed by the end user, whether the Mock data should be used for training. Mock data is only useful for Demonstration purposes and should routinely be set to False for production use.  
AMQP False A boolean value to indicate that connections should be established via the AMQPUri connection string to the RabbitMQ server or cluster.  
AMQPUri null The connection string to the RabbitMQ server or cluster.  
JWTValidAudience http://localhost:5001 The server domain that is allowed for the token.  
JWTValidIssuer http://localhost:5001 The server domain that issued the token.  
JWTKey null The encryption key for the JWT. This key is created randomly on first startup of the Jube instance, but can be changed. The key value is stored in the Jube.environment file, having being randomly created on application first use.  
PasswordHashingKey null Passwords are encrypted in an irreversible manner using the Argon2 hashing algorithm, alongside a salting value. The salt value is stored in the Jube.environment file, having being randomly created on application first use.  
EnablePublicInvokeController True Most HTTP Endpoint require authentication, although an exception is the api/Invoke endpoint which is intended for integration. A boolean value needs to be set to allow the invocation API to be recalled on an open basis, and will in the event of False, return Not Found HTTP Status.  
EnableEngine True A boolean value to indicate if the engine should be instantiated. The engine contains functionality such as Sanctions, Model Invocation, Archiving, Search Key Caching, Notifications, Case Automation, Counters, Tagging, Reprocessing and Exhaustive Training. In the absence of the engine, only functions required by the user interface are instantiated.  
EnableCallback True A boolean value to indicate that HTTP callbacks are available - see HTTP Asynchronous Model Invocation. Paired with CallbackTimeout.  
EnableMigration True A boolean value to indicate whether this instance should perform database Migration on startup - see Architecture. Disable and run the Fluent Migrator Command Line Runner separately where DDL permissions are unavailable at runtime.  
EnableExhaustiveTraining True A boolean value to indicate that a thread should be started for the purpose of Exhaustive training. Given the computation expense of Exhaustive training only a single thread is available per instance.  
ExhaustiveTrialsLimit 1000 For an Exhaustive training instance, the maximum number of trials to be performed (which is a random selection of input variables. This variable does not govern the evolution of a Neural Networks topology for each trial.  
ExhaustiveMinVariableCount 5 For an Exhaustive trial, the minimum number of variables to be trained and topology evolve.  
ExhaustiveMaxVariableCount 30 For an Exhaustive trial, the maximum number of variables to be trained and topology evolve.  
ExhaustiveTrainingDataSamplePercentage 0.6 To avoid over-fitting, data available is randomly split between training, cross validation and testing. The percentage of data to be allocated to training.  
ExhaustiveCrossValidationDataSamplePercentage 0.2 The percentage of data to be allocated to Cross Validation.  
ExhaustiveTestingDataSamplePercentage 0.2 The percentage of data to be allocated to Testing.  
ExhaustiveValidationTestingActivationThreshold 0.5 The threshold at which a recalled example will be allocated to the positive class.  
ExhaustiveTopologySinceImprovementLimit 10 During a trial the internal topology will have processing elements and hidden layers evolved. The evolution process will terminate at the point a number of additional evolutions have taken place without improvement. The value at which evolution should terminate upon no improvement. Lesser performance will always terminate and carry forward as best topology.  
ExhaustiveLayerDepthLimit 4 The maximum number of hidden layers in a topology exploration.  
ExhaustiveLayerWidthLimitInputLayerFactor 4 A value when multiplied by the number of inputs for the trial represents the maximum number of processing elements for a hidden layer.  
ExhaustiveTopologyComplexityLimit 10000 For topology evolution the maximum number of weights allowed before termination and carrying forward of that topology as best.  
ExhaustiveActivationFunctionExplorationEpochs 3 The number of epochs to be trained to evaluate then select an Activation Function.  
ExhaustiveTopologyExplorationEpochs 3 The number of epochs to be trained to evaluate then evolve further a topology.  
ExhaustiveTopologyFinalisationEpochs 20 With topology selected, the number of epochs to create a final model for testing.  
ExhaustiveSimulationsCount 100 The number of random simulations to be processed through the final model for the purpose of testing and creation of description statistics for the positive class. Often known as Monte Carlo Model Simulation.  
CallbackTimeout 1000 The time in milliseconds before callbacks ready for collection via HTTP are to be removed. Callbacks are only created if HTTP model invocation has been called using the async switch.  
StreamingActivationWatcher True The default behaviour for the Activation Watcher streaming, in the absence of AMQP having been enabled, is via database streaming notifications. When false indicates that the database ActivationWatcher table, given also ActivationWatcherAllowPersist, should be polled for Watcher messages rather than subscribing to database streaming notifications. Given streaming notifications the message is dispatched to the notification service in the database synchronously. A typical connection string is of the form: HOST_NAME:PORT_NUMBER,password=PASSWORD where HOST_NAME is the host name of your server (e.g. localhost), PORT_NUMBER is the port number Redis is listening on (e.g. 6379) and PASSWORD is your redis server’s password (e.g. secret_password).  
WatcherStreamHeartbeatIntervalSeconds 15 How often, in seconds, the Watcher Server-Sent Events stream writes a : keep-alive comment to an open connection while there is nothing to relay, so intermediate proxies do not time out an idle response.  
WaitPollFromActivationWatcherTable 5000 In the event that of StreamingActivationWatcher and ActivationWatcherAllowPersist the polling interval to relay messaged from the ActivationWatcher database table to the watcher user interface page.  
WaitTtlCounterDecrement 1000 In the event of TTLCounter being enabled to signify that the server should be responsible to decrementing TTL counter entries, the wait interval between decrement jobs in milliseconds  
RedisConnectionString localhost The server or IP address of he Redis cluster in the connection string format supported by the c# Redis client NRedisStack and StackExchange.Redis.  
RedisSentinelConnectTimeout 2000 Only used when RedisConnectionString sets serviceName= (Sentinel mode). The connect/response timeout in milliseconds for the Sentinel-discovery hop specifically - deliberately independent of RedisConnectionString’s own connectTimeout/syncTimeout, which govern the data connection to the resolved primary and are typically set more generously to tolerate ordinary command latency. Keeping this short means a slow or partially unreachable Sentinel quorum fails fast and hands back to the reconnect backoff quickly, rather than a stuck master re-resolution riding the same long timeout the data connection needs.  
RedisSentinelSyncTimeout 2000 Companion to RedisSentinelConnectTimeout above - the Sentinel-discovery hop’s response timeout in milliseconds.  
RedisSentinelConnectRetry 1 Only used when RedisConnectionString sets serviceName= (Sentinel mode). The number of connection attempts made against the Sentinel quorum before giving up for that cycle and handing back to ReconnectRetryPolicy’s backoff, rather than retrying the Sentinel hop itself repeatedly.  
PgPoolClearDebounceMilliseconds 5000 The minimum interval in milliseconds between successive Npgsql pool clears for a given connection string. A pool clear is the correct response to a Patroni failover, since pooled connections may still point at a node that has been demoted, but the pool is process-global and keyed on the connection string, so every concurrently failing operation would otherwise clear the same pool on every one of its retries. Clearing once has the full intended effect; clearing repeatedly destroys each connection warmed since the previous clear and prevents the pool re-establishing during exactly the window it is needed. This debounce collapses that stampede to a single clear per failover episode. The default is comfortably shorter than HAProxy’s own detection of a demoted primary (inter 3s fall 3, so roughly nine seconds) while being long enough to absorb a burst of simultaneous failures. Raise it if failover storms still show repeated clears in the logs; lower it if a second genuine failover shortly after the first is being missed.  
PgMaxConnectionRetries 10 How many times a failed Postgres connection or command is retried by the resilient Npgsql layer before the failure is allowed to surface. The wait between attempts is exponential and capped at thirty seconds, so the default spends roughly three and a half minutes (2+4+8+16 then 30 a time) before giving up. That is deliberate patience for a Patroni leader election, where the cluster genuinely may be unwritable for tens of seconds and an engine task has nowhere better to be. It is far less appropriate on a synchronous request path, where whoever asked has usually abandoned the request long before the retries are spent, and each waiting attempt holds its thread and its pool slot. Lower it for a deployment whose Postgres is local and whose callers are interactive; leave it alone where failover tolerance matters more than latency. Connection-pool exhaustion is deliberately excluded from retrying altogether, since the pool has already waited its own Timeout and retrying only re-queues behind the same starvation. Zero disables retrying entirely.  
RedisReconnectRetryBaseDelay 100 The initial delay in milliseconds of the ExponentialRetry policy governing how fast StackExchange.Redis retries re-establishing the physical connection after it drops. Governs recovery speed once the connection is down, not how long an in-flight command waits - see RedisBacklogFailFast below for that.  
RedisReconnectRetryMaxDelay 3000 The delay cap in milliseconds of the same ExponentialRetry reconnect policy, paired with RedisReconnectRetryBaseDelay above.  
RedisBacklogFailFast False When False (StackExchange.Redis’s own default), a Redis command issued while the connection is unhealthy is queued and left to ride out its own SyncTimeout before failing - the mechanism behind a transaction being held for a long period during a genuine network outage, since every Redis call in that window queues and waits rather than failing immediately. When True, such commands fail as soon as the connection is known unhealthy instead, letting the caller react (skip/degrade/retry at its own level) rather than block. Only change this if the calling code is prepared to handle the resulting exception being thrown immediately rather than after a delay.  
RedisCommandFlag 0 A command that controls the Redis client, pipeline and quorum. PreferMaster=0; 2=FireAndForget;4-DemandMaster; 8=PreferSlave; DemandSlave=12; NoRedirect=64; NoScriptCache=512.  
CachePruneServer True A flag indicating if this instance is responsible for processing the Time To Live (TTL) deletion in both the Redis or Postgres Database cache.  
WaitCachePrune 10000 The time in milliseconds between the cache being pruned for expired payload and latest entries.  
Landlord True A boolean flag to support multi tenancy administration in the user interface. Landord is configured for the default administrator user only on installation. Landlord permissions are allocated in the Tenant Registry, where a tenant is taken to be super user.  
Log4NetConfigFileLocationName null Will fall back to programmatic instantiation if unavailable. The XML configuration file allowing for advanced configuration and instantiation of the log4net logging library. This is helpful in the case of configuration of remote logging such as syslog. In the case of the RollingFileAppender all necessary settings are otherwise available via dedicated Environment Variables as follows.  
Log4NetLogPath null Will fall back to the binary directory as target for logs, which is far from ideal and may not work in containers. The file path to write and rotate log files to, given the absence of the Log4NetConfigFileLocationName environment variable  
Log4NetLogMaximumFileSize 500MB The maximum file size before the logs get rotated to new files, given the absence of the Log4NetConfigFileLocationName environment variable  
Log4NetLogMaxSizeRollBackups 100 The maximum number of files to write before they are purged, given the absence of the Log4NetConfigFileLocationName environment variable  
Log4NetLogLevel WARN The logging level to write log events out, given the absence of the Log4NetConfigFileLocationName environment variable  
PreservationSalt null For the import and export of definition an environment specific salting value in keeping with the downloaded file bytes encryption scheme  
LocalCache True To enable the local Least Recently Used (LRU) Cache for payload data in the Jube instance  
LocalCacheFill True To enable a fill of the local LRU cache from Redis on the startup of the Jube instance based on the most recently used LruJournal keys in Redis, returning at the point the LRU Cache is at capacity as specified in the LocalCacheBytes Environment Variable. Requires LocalCache environment variable to be True.  
LocalCacheBytes 1073741824 The maximum size of the local LRU cache before evictions.  
RedisMessagePackCompression True To enable LZ4BlockArray compression for message pack serialization of Payload data.  
RedisStorePayloadCountsAndBytes False To enable the informational storage of Payload data counts and bytes for visibility into model usage of Redis. Defaulted off this branch to reduce noise - only useful for multi-tenancy, and even then not always.  
RedisPublishSubscribeEvents False To enable to publish\subscribe events of updates to the local LRU cache for clustered instances of Jube.  
SearchKeyCacheServerIntervalType h The interval type for the launching of the search key cache calculation job. Accepted values: n (minutes), h (hours), d (days), m (months) - any other value is treated as d. Note n, not m, is minutes; m is reserved for months.  
SearchKeyCacheServerIntervalValue 1 The interval value for the launching of the search key cache calculations job.  
AMQPHeartbeatInterval s The unit for AMQPHeartbeatIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
AMQPHeartbeatIntervalValue 30 How often, in the unit set by AMQPHeartbeatInterval, the AMQP client sends heartbeats to the server to avoid the connection being closed.  
CaseCreationThreads 4 The number of background thread responsible for the expensive case creation and upward classification processing.  
MaxInvokeControllerRequestBytes 4000 The maximum number of bytes that can be JSON parsed for the invocation pipeline, beyond which an exception will be thrown.  
PartialResponseMessageSerialisation True When true, only return elements in the response payload on the basis of ResponsePayload switch being true in varius model entities, otherwise return the same comprehensive payload as stored in the Archive table. Disabling PartialResponseMessageSerialisation is useful when developing configurations where testing needs total visibility of invocation context payload.  
RedisBackplane True In a load balanced environment the preference is not to use server affinity for the user interface, but this cases breakage in the Activation Watcher page. In the absence of server affinity Redis can be used as a backplane such that the connection does not need to be stateful.  
DataProtectionRedisBackplane True In a load balanced environment ASP.NET Core Data Protection keys (e.g. cookie encryption) must be shared across nodes. When enabled, the Data Protection key ring is persisted to Redis using the RedisConnectionString rather than the local file system, so nodes share a consistent application name and key ring. Enabled by default: set to False on a single node that has no Redis.  
SecretsPath null The file system path to look up secrets, where the file name is the key and the trimmed contents of the file is the value. This has special compatibility with Docker Secrets. If not provided, defaults to the application’s working directory. Secrets are only tokenised where the [@Key@] pattern exists inside the Environment Variable string.  
JempFileLegacyEncryptionFallback True Preservation (.jemp) export files are AES encrypted with a random Initialisation Vector (IV) per file. Files exported before this hardening used a fixed IV, which is a weaker scheme. When True, import falls back to the legacy fixed-IV scheme if random-IV decryption fails, so older exports remain importable. Set to False once no legacy exports remain in use to remove the fallback attempt entirely.  
ApiHmacKey null The HMAC-SHA256 secret used to sign and verify UserRegistryApiKey API keys (Base62-encoded, versioned payload). Must be set to a strong, unique, per-environment value before issuing API keys. Changing this value invalidates every API key issued under the old value immediately and with no overlap window - there is no dual-key transition support, so rotating it is an all-keys-dead-at-once event, not a graceful rollover. Plan API key reissuance for every integration before rotating this in a live environment.  
RedisHsetOffloadToPostgres False When True, Redis HSET-shaped cache writes (see Cache Concepts) are instead served from a Postgres CacheSetHash table, using a covering index over Key, Field and each of the typed value columns to avoid heap access. This may outperform Redis for this access pattern on server-grade Postgres hardware, at the cost of moving load onto the primary database rather than Redis.  
SecureHttpCookie False A boolean value to mark the authentication cookie as Secure, meaning the browser will only transmit it over HTTPS. Should be True for any environment served over HTTPS, which should be all environments other than local development.  
SessionAbsoluteLifetimeInterval n The unit for SessionAbsoluteLifetimeIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
SessionAbsoluteLifetimeIntervalValue 720 The absolute maximum age of a login session, in the unit set by SessionAbsoluteLifetimeInterval, counted from the original login. A session is refreshed while it is used, but is never extended beyond this age: after it the user must log in again. The token carries the original login instant, so a refresh can never lengthen the session. Set to 0 to disable the absolute limit (not recommended).  
MaxConcurrentConnections 10000 The maximum number of concurrent connections the web server accepts, protecting against connection exhaustion when no reverse proxy fronts the application. Set to 0 for no limit. Previously unlimited.  
RevokedSessionCheckInterval s The unit for RevokedSessionCheckIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
RevokedSessionCheckIntervalValue 30 How often, in the unit set by RevokedSessionCheckInterval, open streaming connections (Watcher, Service Change) are re-checked against the database. A connection whose user has logged out, changed password, been locked, deactivated or deleted, or whose session has passed its absolute lifetime, is closed at the next check. Set to 0 to disable the check.  
CsrfOriginCheck True When True, a state-changing request (POST, PUT, PATCH, DELETE) that is authenticated only by the authentication cookie must be provably same-origin: the browser’s Sec-Fetch-Site must be same-origin, or its Origin (or Referer) must match the site host (or X-Forwarded-Host behind a proxy). Requests that carry an Authorization header or an X-API-KEY are unaffected. Set to False only if a proxy makes the host impossible to match.  
WafEnabled True Master switch for the content Web Application Firewall (see Web Application Firewall). When False the middleware passes every request straight through and the polling and flush background services do nothing. Enabled by default; review the seeded WafSignature rows and add any WafException rows the deployment needs, because a signature whose Drop flag is set will reject matching requests with 403.  
WafRefreshInterval s The unit for WafRefreshIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
WafRefreshIntervalValue 30 How often, in the unit set by WafRefreshInterval, the WafSignature and WafException tables are re-read from the database, recompiled and swapped in atomically. Adding, editing or disabling a signature or exception takes effect at the next poll with no restart.  
WafFlushInterval s The unit for WafFlushIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
WafFlushIntervalValue 10 How often, in the unit set by WafFlushInterval, captured matches queued in memory are bulk-inserted into the WafAttack table.  
WafMaxInspectBytes 262144 The maximum number of request-body bytes the WAF middleware buffers and inspects. A JSON body larger than this, or a request declaring a larger Content-Length, is passed through without body inspection (its path and query string are still inspected). Prevents the WAF becoming a memory-exhaustion surface on large or streamed bodies.  
WafMaxRegexTimeoutMilliseconds 100 The hard ceiling, in milliseconds, on each signature’s and exception’s regular-expression match timeout. A WafSignature.MatchTimeoutMilliseconds above this value is capped to it. A match that times out is treated as a non-match and never hangs a request, bounding the ReDoS risk of a table-driven pattern.  
WafMaxInspectionMilliseconds 200 The overall time budget, in milliseconds, for inspecting one request across every field and every signature. WafMaxRegexTimeoutMilliseconds only bounds a single regex match; without this, a request with several fields, or one that runs several signatures close to their own timeout, can add those costs up into a multi-second delay even though no single match ever hangs. Once the budget is exceeded, inspection of that request stops and every signature not yet evaluated is treated as a non-match (fail open), the same as an individual match timing out.  
ElementSymmetricEncryptionKey SuperSecretEncryptionKeyGoesHere The symmetric key used by the AES string encryption helper available to Inline Scripts, for encrypting individual payload elements at the point of use (for example, before writing a value to a Search Key). NOTE: this ships with a well-known placeholder default - it must be changed to a securely generated, per-environment value before any Inline Script relies on it, otherwise encrypted values are trivially reversible by anyone with a copy of this documentation.  
EnableMultifactorAuthentication False A boolean value to enable RSA SecurID-led Multi-Factor Authentication (MFA) as a second authentication step, enforced regardless of whether the first step was Negotiate or Username and Password authentication. Not applicable to OAuth sign-in, which is assumed to always offload MFA to the identity provider itself.  
MultifactorAuthenticationEndpoint http://localhost:5001/api/mfa The RSA Authentication Manager (SecurID) endpoint used to validate the one-time passcode. Points at the bundled mock endpoint by default (accepts only the OTP value 123456), for environments without access to a real RSA sandbox.  
MultifactorAuthenticationApplicationId MyApplicationGuidOrSomeSuch The application identifier RSA Authentication Manager was configured with for this integration. Replace with the real application identifier issued for your RSA Authentication Manager tenant.  
MultifactorAuthenticationClientKey SomethingSecretForTheClientKeyHeader A shared secret sent as a client-key header on every request to MultifactorAuthenticationEndpoint. Replace with a securely generated value shared with the RSA Authentication Manager deployment; the placeholder default must not reach production.  
PasswordAttempts 3 The number of consecutive incorrect password attempts allowed before the user account is locked out.  
EnablePasswordLockoutReset True A boolean value, the deliberate and explicit switch for whether a per-user database lockout (PasswordLocked) is ever allowed to auto-expire. When True (the default), PasswordLockoutInterval/PasswordLockoutIntervalValue below govern how long a lock lasts before the next login attempt clears it automatically. Set to False for a permanent, admin-only-unlock lockout regardless of those two settings - useful where an operator would rather investigate every lockout than have any of them clear themselves. Auto-expiry exists because an unauthenticated caller who only knows a victim’s username could otherwise lock that account forever with PasswordAttempts wrong guesses; see LoginIpRateLimitAttempts below for the complementary per-source-IP mitigation of the same attack from a single source.  
PasswordLockoutInterval n The unit for PasswordLockoutIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
PasswordLockoutIntervalValue 30 How long, in the unit set by PasswordLockoutInterval, a per-user database lockout (PasswordLocked) lasts before it auto-expires on the next login attempt, when EnablePasswordLockoutReset is True. A value of 0 or negative also disables auto-expiry as a defensive fallback, but EnablePasswordLockoutReset=False above is the explicit, intended way to choose a permanent lockout.  
LoginIpRateLimitAttempts 1000 The number of failed login attempts, across any username, permitted from a single source IP within the window set by LoginIpRateLimitInterval/LoginIpRateLimitIntervalValue before further attempts from that IP are rejected outright. Mitigates a distributed account-enumeration/lockout attempt from one source that PasswordLockoutIntervalValue’s per-user counter alone cannot see.  
LoginIpRateLimitInterval s The unit for LoginIpRateLimitIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
LoginIpRateLimitIntervalValue 60 The sliding time window that LoginIpRateLimitAttempts is measured over, in the unit set by LoginIpRateLimitInterval.  
EnableGlobalHttpRateLimit False A boolean value, the deliberate and explicit switch for a per-source-IP rate limit applied to every HTTP request except the high-throughput /api/Invoke transaction-submission path, which is always exempt. Off by default since it is a broad behavioural change affecting all traffic, not just authentication; enable it to add a DDoS/flood backstop in front of the rest of the API and UI. A request over the limit gets HTTP 429 (Too Many Requests) and never reaches the endpoint.  
GlobalHttpRateLimitAttempts 2000 The number of requests, from a single source IP, permitted within the window set by GlobalHttpRateLimitInterval/GlobalHttpRateLimitIntervalValue before further requests from that IP get HTTP 429. Every request counts, not just failed ones - unlike the per-user password lockout, there is no concept of a “failed” request at this layer.  
GlobalHttpRateLimitInterval s The unit for GlobalHttpRateLimitIntervalValue: s (seconds), n (minutes), h (hours) - any other value, including d, is treated as days.  
GlobalHttpRateLimitIntervalValue 60 The sliding time window that GlobalHttpRateLimitAttempts is measured over, in the unit set by GlobalHttpRateLimitInterval.  
RateLimitBackplane True A boolean value controlling how EnableGlobalHttpRateLimit’s counter is kept. False counts in memory, local to each node - fine for a single instance, but a client can get GlobalHttpRateLimitAttempts on every node in a cluster before HAProxy has spread enough load for any one of them to notice. True (the default) counts through Jube.Cache’s existing Redis connection instead (the same HINCRBY-plus-expiry pattern used by TTL Counters), so every node behind HAProxy shares one counter per source IP and the limit holds cluster-wide regardless of which node an attacker lands on. Requires Redis (RedisConnectionString) to be reachable; a Redis failure fails open (the request is allowed through) rather than blocking traffic.  
CacheTtlDeleteLimit 1000 The per-cycle deletion batch limit (a SQL/sorted-set range LIMIT, not a Redis HSCAN) for the general cache-prune background task that removes reference-date-expired entries from the Payload and Payload-Latest caches, so a large expired backlog drains over several bounded passes rather than being loaded into memory in one operation. Despite the name, this is not specific to TTL Counters - see TtlCounterEntryDeleteLimit below for that.  
TtlCounterEntryDeleteLimit 200 The maximum number of expired TTL Counter entries processed per administration cycle, so a large backlog drains over several cycles rather than flooding a single concurrent-task burst. This is the TTL-Counter-specific equivalent of CacheTtlDeleteLimit above, and is a separate setting.  
TtlCounterAdministrationMaxConcurrency 25 The maximum number of expired TTL Counter entries decremented/deleted concurrently within a single administration cycle (a semaphore, not a batch size - see TtlCounterEntryDeleteLimit above for that). Raising it increases Redis/Postgres concurrency during a large backlog drain; lowering it reduces peak load at the cost of a slower drain.  
PasswordAsymmetricEncryption False A boolean value to enable RSA asymmetric encryption of the password field in transit, on top of the existing SHA-256 wire hash (see WirePasswordHash below). When True, the browser encrypts the password with PasswordAsymmetricEncryptionPublicKey before sending it, and the server decrypts it with PasswordAsymmetricEncryptionPrivateKey. Jube refuses to start with this set to True unless both key Environment Variables below are also explicitly set - see PasswordAsymmetricEncryptionPrivateKey.  
PasswordAsymmetricEncryptionPrivateKey null The Base64-encoded PEM private key used to decrypt the password field when PasswordAsymmetricEncryption is True. Generate a fresh, per-environment RSA keypair for this - Jube validates at startup that this and PasswordAsymmetricEncryptionPublicKey are both set whenever PasswordAsymmetricEncryption is True, and refuses to start otherwise, so a shared or default keypair can no longer be used by omission.  
PasswordAsymmetricEncryptionPublicKey null The Base64-encoded PEM public key the browser encrypts the password with. See PasswordAsymmetricEncryptionPrivateKey - both must be set together, and Jube will not start with PasswordAsymmetricEncryption True and either one missing.  
SessionCookie True A boolean value to control whether the authentication cookie is a session cookie. When True, the cookie is not persisted and the user is signed out when the browser is closed; when False, the cookie persists per its normal expiry regardless of the browser closing.  
AssumeLocalDateInPayloadExtraction True A boolean value controlling how dates without explicit timezone information, extracted during payload extraction (Request XPath, Inline Functions, Inline Scripts), are interpreted. When True they are assumed to be in the server’s local time and converted to UTC accordingly; when False they are assumed to already be UTC. Set to match the timezone convention of the systems sending transactions to Jube.  
ActivationRuleIdempotency False A boolean value to enable idempotency guarantees on Activation Rules - TTL Counter increments, Case Creation and Notification dispatch are each applied at most once per transaction lifecycle, even under reprocessing or retry. Idempotency records are only written to Redis when this is True, so leave it False in memory-constrained deployments that do not use Reprocessing, to avoid the extra Redis writes. Idempotency Set keys in Redis have no TTL of their own and are only removed when the underlying transaction’s payload is deleted, so enabling this on a deployment that never deletes/expires payloads will accumulate idempotency keys for as long as the payload itself is retained.  
LruJournalMaxAgeInterval h The interval unit for how long an entry may remain in the LruJournal Redis sorted set - used only to prime the local LRU cache on startup (LocalCacheFill) - before a background task prunes it. Paired with LruJournalMaxAgeValue below. Accepted values: n (minutes), h (hours) - any other value, including d, is treated as days. Similar to, but not identical to, SearchKeyCacheServerIntervalType above - this one has no dedicated m (months) case.  
LruJournalMaxAgeValue 1 The interval value paired with LruJournalMaxAgeInterval, e.g. 1 and h together mean entries older than one hour are pruned.  
WaitLruJournalPrune 10000 The interval in milliseconds between background LruJournal pruning cycles, which evict entries older than LruJournalMaxAgeInterval/LruJournalMaxAgeValue. The same age check also runs a second time during cache warming itself, so a slow prune cycle cannot cause a stale entry to be used to prime the cache.  
WaitHashCacheAssemblyObservability 60000 The interval in milliseconds between snapshots of the compiled rule assembly cache (HashCacheAssembly) to the HashCacheAssemblyInstance/HashCacheAssemblyInstanceJournal/HashCacheAssemblyInstanceEntry tables - see Rule Compilation Algorithm.  
SMTPUseDefaultCredentials False A boolean value to indicate that the SMTP client should use the process’s default network credentials rather than SMTPUser/SMTPPassword. Useful where the SMTP relay trusts the sending host/network rather than requiring explicit credentials.  
SMTPEnableSsl True A boolean value to indicate that the SMTP client should negotiate SSL/TLS with the SMTP server.  
OutboundHttpRsaAmCertificateBypass False A boolean value to bypass all TLS certificate validation for outbound HTTP requests to the RSA Authentication Manager MFA endpoint. Intended for sandbox/UAT RSA deployments behind a self-signed or otherwise unverifiable certificate chain. Do not enable in production - prefer OutboundHttpRsaAmCertificateThumbprint below, which trusts one specific certificate rather than disabling validation entirely. Currently implemented for the RSA token endpoint only.  
OutboundHttpRsaAmCertificateThumbprint null A SHA1 certificate thumbprint to explicitly trust for outbound HTTP requests to the RSA Authentication Manager MFA endpoint, for chains that do not terminate at a verifiable root but where disabling validation entirely (OutboundHttpRsaAmCertificateBypass) is not acceptable. Scoped to the RSA MFA client only (Jube.Mfa/Mfa.cs) - not applied to HTTP Adaptation or any other outbound webhook, each of which has its own independent, unrelated TLS handling.  
OAuthAuthentication False A boolean value to enable OAuth 2.0 / OpenID Connect (authorization code flow with PKCE) as a third authentication scheme, alongside Username/Password and Negotiate. See Authentication Concepts. Mutually exclusive with NegotiateAuthentication - both cannot be True at once - and Username/Password authentication (including password changes) is disabled whenever either is True.  
OAuthAuthority null The OpenID Connect authority (issuer) URL of the identity provider, used for OIDC discovery.  
OAuthClientId null The OAuth client identifier registered with the identity provider for this Jube instance.  
OAuthClientSecret null The OAuth client secret registered with the identity provider for this Jube instance.  
OAuthForceRedirect null On conclusion of the full OAuth authentication the redirect url that will override anything passed for redirection.  
OAuthForceGet False A boolean value to force the OAuth/OIDC callback to use GET/query-string responses instead of the default form_post response mode, for identity providers that require it.  
SanctionsLevenshteinMaxDistanceRatio 0.3 The server-wide default for the maximum Levenshtein edit-distance-to-token-length ratio permitted for a sanctions token match, before per-model MaxDistanceRatio override. See Sanction Searching.  
SanctionsLevenshteinMaxCoverageRatio 2.0 The server-wide default for the maximum coverage ratio permitted for a sanctions token match, before per-model MaxCoverageRatio override. See Sanction Searching.  
UseForwardedHeaders True A boolean value to enable ASP.NET Core’s forwarded-headers middleware, transposing X-Forwarded-For/X-Forwarded-Proto headers from an upstream reverse proxy or load balancer onto the request context. Important for OAuth redirect URIs and remote-IP logging to be correct when Jube sits behind a proxy.  
EnableOpenTelemetry False A boolean value to enable OpenTelemetry tracing and metrics export for the service layer (Jube.Service). When enabled and OpenTelemetryBackendEndpoint is not set, an OTLP exporter is configured from the standard OTEL_EXPORTER_OTLP_* Environment Variables instead. The /api/invoke transaction ingress is excluded from request tracing. When disabled the instrumentation calls are still made but are no-ops.  
OpenTelemetryBackendEndpoint null The base URL of an OTLP/HTTP backend to export traces/metrics/logs to when EnableOpenTelemetry is True, e.g. http://localhost:4318 – explicit and owned by Jube’s own configuration rather than the OTel SDK’s own OTEL_EXPORTER_OTLP_ENDPOINT env var auto-detection (still used as a fallback when this is left unset). Exporting is bounded, not buffered – a full export queue drops the newest item rather than growing without limit, and a dead/unreachable backend fails fast (short fixed timeouts) rather than backing up; see OTLP Dispatch Counter for how every dispatch attempt, failure and drop is captured as both a live counter and a browsable per-minute table. See also Log-Derived OpenTelemetry Counters and Jube.OpenTelemetryListener for a disposable local test target.  
OpenTelemetryMetricCaptureSamplePercentage 100 The percentage, from 0 to 100 (values outside the range are clamped), of OpenTelemetry metric measurements from the Jube, .NET runtime, HTTP, ASP.NET Core and process meters that are captured into the OpenTelemetryMetric table used by the monitoring pages. 100 captures every measurement; lower values sample, which reduces database volume on busy instances at the cost of resolution. Read once at startup.  
EnableServiceChangeStream False A boolean value to enable publishing of service-layer change events (create/update/delete) so open Blazor/browser sessions can live-refresh. Requires RedisBackplane for cross-node delivery; single-node deployments fan the events out in-process. When disabled, the service layer still calls the publisher but it is a no-op.  
ServiceChangeStreamHeartbeatIntervalSeconds 15 How often, in seconds, the Service Change Server-Sent Events stream writes a : keep-alive comment to an open connection while there is nothing to relay, so intermediate proxies do not time out an idle response.  
ArchiverWarnThresholdMilliseconds 10000 The duration in milliseconds a single background Archiver stage (BuildArchiveJson, CaseCreationDispatch, RdbmsArchiveWrite, BulkCopyArchiveBuffer) may take before a row is captured to Archiver Warning and jube.engine.archiver.warn.count is incremented. Set much higher than an in-thread invoke trace threshold, since these stages are I/O-bound background work (RDBMS writes, buffered bulk copies) that is routinely slow by nature – this should only trip for genuinely abnormal slowness, not everyday operation.  
CaseCreationWarnThresholdMilliseconds 10000 The duration in milliseconds a single background case creation stage (ExistingCasePriorityLookup, WorkflowStatusLookupAndPersist, Notification, HttpEndpoint) may take before a row is captured to Case Creation Warning and jube.engine.casecreation.warn.count is incremented. Set much higher than an in-thread invoke trace threshold for the same reason as ArchiverWarnThresholdMilliseconds above – notification/webhook callbacks in particular are routinely slow by nature.  
EtcdEndpoints null A comma separated list of etcd client endpoints in the form host:port that the infrastructure health metrics poll for cluster orchestration state (members, leader, events). When empty, endpoints are discovered by DNS using EtcdDiscoveryPrefix, EtcdPatroniDiscoveryMaxNodes and EtcdClientPort.  
EtcdDiscoveryPrefix etcd The DNS host name prefix used when EtcdEndpoints is empty. The numbers 1 to EtcdPatroniDiscoveryMaxNodes are appended (etcd1, etcd2, and so on) and each name that resolves is used as an etcd endpoint on EtcdClientPort.  
EtcdClientPort 2379 The etcd client port appended to each host discovered through EtcdDiscoveryPrefix. It is not applied to endpoints given explicitly in EtcdEndpoints. An unparseable value falls back to 2379.  
EtcdClientUsername null The etcd username the infrastructure health metrics authenticate as when polling member/health status and Patroni’s DCS history key. etcd client auth is mandatory in the Jube Cluster deployment (see Deploying with Jube Cluster), so this and EtcdClientPassword must both be set there; left null, the samplers make unauthenticated calls, which only works against an etcd cluster with auth disabled.  
EtcdClientPassword null The password for EtcdClientUsername. Resolved from a Docker secret via the [@Key@] convention in the Jube Cluster deployment, the same as every other password-shaped Environment Variable.  
PatroniEndpoints null A comma separated list of Patroni REST API endpoints in the form host:port that the infrastructure health metrics poll for cluster role, lag and timeline. When empty, endpoints are discovered by DNS using PatroniDiscoveryPrefix, EtcdPatroniDiscoveryMaxNodes and PatroniApiPort.  
PatroniDiscoveryPrefix patroni The DNS host name prefix used when PatroniEndpoints is empty. The numbers 1 to EtcdPatroniDiscoveryMaxNodes are appended (patroni1, patroni2, and so on) and each name that resolves is used as a Patroni endpoint on PatroniApiPort.  
PatroniApiPort 8008 The Patroni REST API port appended to each host discovered through PatroniDiscoveryPrefix. It is not applied to endpoints given explicitly in PatroniEndpoints. An unparseable value falls back to 8008.  
EtcdPatroniDiscoveryMaxNodes 5 The highest number tried when discovering etcd and Patroni hosts by DNS: with the default, etcd1 to etcd5 and patroni1 to patroni5 are resolved. It applies to both discoveries and is ignored for endpoints given explicitly. An unparseable value falls back to 5.  
PatroniDcsNamespace /service/ The etcd key namespace under which Patroni keeps its cluster state (its dcs namespace setting). The Patroni scope name is appended to read the cluster history events that are recorded as Patroni cluster events, so it must match the namespace configured on the Patroni nodes.  
WaitInfrastructureHealthMetricsPurge 60000 The duration in milliseconds between purge cycles of the infrastructure health metric tables (application and container logs, Docker host, container and event metrics, .NET runtime metrics, etcd member status and events, OpenTelemetry metrics, OTLP dispatch counters and Patroni cluster events).  
InfrastructureHealthMetricsPurgeIntervalType d The unit of the retention period for the infrastructure health metric tables: d days, h hours, n minutes, s seconds, m months or y years. Any other value is treated as days.  
InfrastructureHealthMetricsPurgeIntervalValue 7 The number of InfrastructureHealthMetricsPurgeIntervalType units of infrastructure health metric data to keep. Rows older than that are deleted, so 7 with a type of d keeps seven days.  
InfrastructureHealthMetricsPurgeDeleteLimit 1000 The maximum number of rows deleted in one chunk, per table, in a purge cycle. A purge loops in chunks of this size until nothing older than the retention period remains, which keeps individual delete transactions short.  

Environment Variables passed to Jube at startup will override the hardcoded defaults above. Environment Variables are not written to disk in any form, and their contents are available only in the Jube application’s memory and operating system session.

The Environment Variable string can be tokenised, and secrets can be swapped in from a file topology at a given path, where the file name is the key and the contents of the file is the value. This approach provides full compatibility with Docker Secrets, which mounts secrets as files using tmpfs (memory-mounted file system). For example, given the token [@RedisPassword@], a file called RedisPassword and the contents of that file being localhost, the Environment Variable may be passed as RedisConnectionString=[@RedisPassword@]. At startup the token is detected, extracted and replaced with the contents of the file RedisPassword mounted by Docker Secrets. Tokens that resolve are replaced in place; those that do not are left unchanged and an error is written to STDOUT. This approach ensures that only genuinely secret information is stored in Docker Secrets, with more verbose Environment Variable strings being safe to live outside declared secrets, allowing for clearer intent and greater maintainability. Secrets are processed at startup and before logging, with any errors written to STDOUT rather than the logging library.

This mechanism is entirely free-form: there is no fixed or hardcoded list of recognised token names anywhere in Jube. Any Environment Variable’s string value is scanned for the [@...@] pattern, and whatever name appears between the brackets is looked up directly as a file name under SecretsPath - the token name and the Environment Variable it appears in are otherwise unrelated to each other and to any specific secret Jube ships with. Naming a new secret file and referencing it as [@ThatFileName@] from any Environment Variable is enough to wire it in; no code change is needed to add support for a new token.


Jube™. © Jube Holdings Limited 2022 to present.

This site uses Just the Docs, a documentation theme for Jekyll.