Configuration
The app reads configuration from environment variables and from Epinio configurations that mount as files under /configurations/<name>/<key>.
| Setting | Source | Notes |
|---|---|---|
BETTER_AUTH_URL |
env | Base URL of the deployment. |
BETTER_AUTH_SECRET / _FILE |
env or mounted file | Auth signing secret; the *_FILE variant points at a mounted path. |
GOOGLE_CLIENT_ID |
env | Google Workspace SSO client. |
GOOGLE_CLIENT_SECRET / _FILE |
env or mounted file | SSO client secret. |
| Postgres connection | bound configuration | Provided by the bound postgres service. |
Secrets are never committed — they come from Epinio configurations mounted at runtime.