Environment variables
These are the production settings an operator may need to change in /etc/labpod/labpod.env.
CLI flags (--port, --db, --dev) override the corresponding server variables when set.
Boolean variables accept true / 1 (on) or false / 0 (off) only - other values cause a
startup error.
Duration variables (LABPOD_API_TIMEOUT, LABPOD_SESSION_TTL, LABPOD_WORKSPACE_START_TIMEOUT,
LABPOD_LAUNCHER_READINESS_TIMEOUT) use Go’s time.ParseDuration format: a number followed by a
unit, ns, us/µs, ms, s, m, or h (units can be combined, e.g. 24h30m). There is no
d (days) unit and a bare number without a unit is rejected - to set a 7-day TTL, write 168h.
An invalid or non-positive value is logged and LabPod falls back to the default.
This page lists supported operator settings. Use the shipped /etc/labpod/labpod.env comments as
the host-local source for rarely changed advanced defaults.
A fresh install’s /etc/labpod/labpod.env stays deliberately short: only the active database
path and the generated JWT secret are uncommented. LabPod derives its other paths from the
database directory, uses the production Podman/GPU implementations directly, and detects
NVIDIA/MIG capability automatically - a CPU-only host and a GPU host both boot from the same
minimal file. Two CLI commands complement this reference page against what a specific host is
actually running:
sudo labpod env # this host's explicit overrides, plus what auto-detection resolved tosudo labpod env --all # every setting, including unset ones at their default and legacy compatibility keys# Run these as rootlabpod env # this host's explicit overrides, plus what auto-detection resolved tolabpod env --all # every setting, including unset ones at their default and legacy compatibility keysReach for labpod env first when you’re troubleshooting a specific host - it shows only what’s
different from the shipped defaults. Reach for labpod env --all when you need the complete
picture, including rarely changed settings this page doesn’t mention. Legacy compatibility keys
remain recognized on an upgraded host for upgrade compatibility, but do not add them to new
configuration.
| Variable | Default | Notes |
|---|---|---|
LABPOD_PORT | 24680 | Platform HTTP/HTTPS port. The workspace gateway uses the next port (24681 by default); keep both outside the workspace port range. |
LABPOD_DB | labpod.db | SQLite database path, resolved from the service working directory when relative |
LABPOD_JWT_SECRET | (required) | Session signing secret; 32+ bytes. Server refuses to start without it in production |
LABPOD_LICENSE_PATH | /var/lib/labpod/license.lic | Installed signed license path. If absent, LabPod resolves to the built-in 90-day trial |
LABPOD_API_TIMEOUT | 15m | Per-request handler timeout (e.g. 15m, 30m) |
LABPOD_SESSION_TTL | 168h | Login lifetime for JWTs and browser cookies. Sessions remain revocable when a user logs out, changes password, or is disabled. The host-local CLI has no session of its own - it authenticates from the Linux peer on every call |
LABPOD_WORKSPACE_START_TIMEOUT | 15m | Deadline for the podman run -d workspace start call |
| Variable | Default | Notes |
|---|---|---|
LABPOD_TLS_SELF_SIGNED | false | Auto-generate and cache a self-signed cert |
LABPOD_TLS_CERT | (unset) | Path to operator-supplied TLS certificate |
LABPOD_TLS_KEY | (unset) | Path to operator-supplied TLS private key |
LABPOD_TLS_DIR | /var/lib/labpod/tls | Cache directory for self-signed cert and key |
LABPOD_TLS_HOSTS | (unset) | Comma-separated extra SANs for self-signed cert (e.g. 192.168.1.10,labpod.lan) |
| Variable | Default | Notes |
|---|---|---|
LABPOD_GPU_SHARING_LIB_PATH | (unset) | Host path to the software GPU sharing runtime library. When set, enables fractional GPU mode. Server fails at startup if the file doesn’t exist |
GPU inventory, MIG discovery, and GPU process inspection automatically follow whether
nvidia-smi is installed. New configurations need no settings for them.
Storage
Section titled “Storage”| Variable | Default | Notes |
|---|---|---|
LABPOD_SHARED_MOUNT_ROOTS | (unset) | Comma-separated allowed roots for admin-defined shared mounts. Empty = any non-blocked path |
LABPOD_DISK_ROOT | /home | Absolute path selecting the primary filesystem shown for host-wide capacity. LabPod also discovers distinct filesystems that hold enabled users’ rootless Podman graphroots. |
LABPOD_WORK_BASE | (unset) | Optional base for each user’s shared /work tree. Unset means <passwd-home>/work; when set, the path is <LABPOD_WORK_BASE>/<user>/work. Per-user disk totals include it when relocated. |
LABPOD_BACKUP_DIR | /var/lib/labpod/backups | Scheduled backup and installer rollback directory |
Linux account HOME comes from the host account database and has no LabPod environment variable.
Rootless Podman storage is configured independently through Podman’s storage.conf; see
Rootless Podman storage.
The retired LABPOD_SHARED_IMAGE_STORE_MODE and LABPOD_SHARED_IMAGE_STORE settings from the old
root-managed shared image store are gone; each user’s images live only in that user’s own
rootless Podman store. LabPod does not configure a root image cache. An old cache directory is not
deleted automatically; inspect and remove it manually when you no longer need it.
Security and network
Section titled “Security and network”| Variable | Default | Notes |
|---|---|---|
LABPOD_PORT_GUARD | nft | Owner-aware loopback isolation for workspace ports. Set none only to explicitly disable it |
LABPOD_WORKSPACE_PORT_MIN | 10000 | First loopback port reserved for workspace services |
LABPOD_WORKSPACE_PORT_MAX | 19999 | Last loopback port reserved for workspace services |
LABPOD_TRUST_PROXY_HEADERS | false | Honor forwarded metadata only from the declared trusted proxy peers. Enable only behind a trusted reverse proxy |
LABPOD_TRUSTED_PROXY_PEERS | loopback,unix | Direct proxy peers allowed to supply forwarded metadata: loopback, unix, exact IP addresses, or CIDRs |
LABPOD_UPDATE_RELEASES_API | https://api.github.com/repos/LabPod/labpod/releases/latest | Release endpoint for the opt-in update check |
LABPOD_WS_ALLOWED_ORIGINS | (unset) | Comma-separated extra WebSocket Origin values for the terminal endpoint |
LABPOD_NOTIFY_ALLOW_PRIVATE | false | Allow crash-notification webhooks to dial private/loopback/link-local destinations (only for a self-hosted LAN messenger) |
LABPOD_LAUNCHER_READINESS_TIMEOUT | 60s | How long launcher Start waits for the app port to become ready |
See also Runtime settings for the DB-backed settings that can be changed without a restart.