Skip to content

Environment variables

These are the production settings an operator may need to change in /etc/labpod/labpod.env. CLI flags (--port, --db, --dev) override the corresponding server variables when set.

Boolean variables accept true / 1 (on) or false / 0 (off) only - other values cause a startup error.

Duration variables (LABPOD_API_TIMEOUT, LABPOD_SESSION_TTL, LABPOD_WORKSPACE_START_TIMEOUT, LABPOD_LAUNCHER_READINESS_TIMEOUT) use Go’s time.ParseDuration format: a number followed by a unit, ns, us/µs, ms, s, m, or h (units can be combined, e.g. 24h30m). There is no d (days) unit and a bare number without a unit is rejected - to set a 7-day TTL, write 168h. An invalid or non-positive value is logged and LabPod falls back to the default.

This page lists supported operator settings. Use the shipped /etc/labpod/labpod.env comments as the host-local source for rarely changed advanced defaults.

A fresh install’s /etc/labpod/labpod.env stays deliberately short: only the active database path and the generated JWT secret are uncommented. LabPod derives its other paths from the database directory, uses the production Podman/GPU implementations directly, and detects NVIDIA/MIG capability automatically - a CPU-only host and a GPU host both boot from the same minimal file. Two CLI commands complement this reference page against what a specific host is actually running:

Terminal window
sudo labpod env # this host's explicit overrides, plus what auto-detection resolved to
sudo labpod env --all # every setting, including unset ones at their default and legacy compatibility keys
Terminal window
# Run these as root
labpod env # this host's explicit overrides, plus what auto-detection resolved to
labpod env --all # every setting, including unset ones at their default and legacy compatibility keys

Reach for labpod env first when you’re troubleshooting a specific host - it shows only what’s different from the shipped defaults. Reach for labpod env --all when you need the complete picture, including rarely changed settings this page doesn’t mention. Legacy compatibility keys remain recognized on an upgraded host for upgrade compatibility, but do not add them to new configuration.

VariableDefaultNotes
LABPOD_PORT24680Platform HTTP/HTTPS port. The workspace gateway uses the next port (24681 by default); keep both outside the workspace port range.
LABPOD_DBlabpod.dbSQLite database path, resolved from the service working directory when relative
LABPOD_JWT_SECRET(required)Session signing secret; 32+ bytes. Server refuses to start without it in production
LABPOD_LICENSE_PATH/var/lib/labpod/license.licInstalled signed license path. If absent, LabPod resolves to the built-in 90-day trial
LABPOD_API_TIMEOUT15mPer-request handler timeout (e.g. 15m, 30m)
LABPOD_SESSION_TTL168hLogin lifetime for JWTs and browser cookies. Sessions remain revocable when a user logs out, changes password, or is disabled. The host-local CLI has no session of its own - it authenticates from the Linux peer on every call
LABPOD_WORKSPACE_START_TIMEOUT15mDeadline for the podman run -d workspace start call
VariableDefaultNotes
LABPOD_TLS_SELF_SIGNEDfalseAuto-generate and cache a self-signed cert
LABPOD_TLS_CERT(unset)Path to operator-supplied TLS certificate
LABPOD_TLS_KEY(unset)Path to operator-supplied TLS private key
LABPOD_TLS_DIR/var/lib/labpod/tlsCache directory for self-signed cert and key
LABPOD_TLS_HOSTS(unset)Comma-separated extra SANs for self-signed cert (e.g. 192.168.1.10,labpod.lan)
VariableDefaultNotes
LABPOD_GPU_SHARING_LIB_PATH(unset)Host path to the software GPU sharing runtime library. When set, enables fractional GPU mode. Server fails at startup if the file doesn’t exist

GPU inventory, MIG discovery, and GPU process inspection automatically follow whether nvidia-smi is installed. New configurations need no settings for them.

VariableDefaultNotes
LABPOD_SHARED_MOUNT_ROOTS(unset)Comma-separated allowed roots for admin-defined shared mounts. Empty = any non-blocked path
LABPOD_DISK_ROOT/homeAbsolute path selecting the primary filesystem shown for host-wide capacity. LabPod also discovers distinct filesystems that hold enabled users’ rootless Podman graphroots.
LABPOD_WORK_BASE(unset)Optional base for each user’s shared /work tree. Unset means <passwd-home>/work; when set, the path is <LABPOD_WORK_BASE>/<user>/work. Per-user disk totals include it when relocated.
LABPOD_BACKUP_DIR/var/lib/labpod/backupsScheduled backup and installer rollback directory

Linux account HOME comes from the host account database and has no LabPod environment variable. Rootless Podman storage is configured independently through Podman’s storage.conf; see Rootless Podman storage.

The retired LABPOD_SHARED_IMAGE_STORE_MODE and LABPOD_SHARED_IMAGE_STORE settings from the old root-managed shared image store are gone; each user’s images live only in that user’s own rootless Podman store. LabPod does not configure a root image cache. An old cache directory is not deleted automatically; inspect and remove it manually when you no longer need it.

VariableDefaultNotes
LABPOD_PORT_GUARDnftOwner-aware loopback isolation for workspace ports. Set none only to explicitly disable it
LABPOD_WORKSPACE_PORT_MIN10000First loopback port reserved for workspace services
LABPOD_WORKSPACE_PORT_MAX19999Last loopback port reserved for workspace services
LABPOD_TRUST_PROXY_HEADERSfalseHonor forwarded metadata only from the declared trusted proxy peers. Enable only behind a trusted reverse proxy
LABPOD_TRUSTED_PROXY_PEERSloopback,unixDirect proxy peers allowed to supply forwarded metadata: loopback, unix, exact IP addresses, or CIDRs
LABPOD_UPDATE_RELEASES_APIhttps://api.github.com/repos/LabPod/labpod/releases/latestRelease endpoint for the opt-in update check
LABPOD_WS_ALLOWED_ORIGINS(unset)Comma-separated extra WebSocket Origin values for the terminal endpoint
LABPOD_NOTIFY_ALLOW_PRIVATEfalseAllow crash-notification webhooks to dial private/loopback/link-local destinations (only for a self-hosted LAN messenger)
LABPOD_LAUNCHER_READINESS_TIMEOUT60sHow long launcher Start waits for the app port to become ready

See also Runtime settings for the DB-backed settings that can be changed without a restart.