kraken is configured with environment variables, which are substituted into its sys.config when the release starts. The defaults below are the ones baked into kraken's Docker image. A few settings exist only in sys.config; they are listed at the end of this page.
The repository's docker-compose.yml passes only AUTH_ALLOW_ALL through from your shell. To set anything else, add it under environment: in a compose file, or pass -e NAME=value to docker run.
This page describes v0.9.0. Where kraken's own docs/CONFIG.md says otherwise, this page reflects what the code does.
HTTP port: the WebSocket endpoint /ws and the health check /health
MQTT_PORT
1883
Port for kraken's MQTT 3.1.1 listener. No MQTT client can connect in v0.9.0: the connection handler fails to start for every connection. Do not expose this port.
syn (built in, no dependencies) or mqtt (an external MQTT broker), or a module name. syn ignores QoS; mqtt passes it to the external broker. See Scaling and MQTT.
STORE_BACKEND
ets
ets (in memory) or noop, or a module name. Where recorded messages go.
CONTROL_BACKEND
noop
noop or http, or a module name. Usage, subscription and webhook-failure reports. See Plugins.
When on, kraken gives every publish a message id and writes it to the store backend. Deliveries then carry msgId and requiresAck: true, and the SDKs acknowledge them. Nothing in v0.9.0 lets a client read recorded messages back, so for most deployments this only costs memory. The nolag-core quickstart turns it off.
STORE_TTL_SECONDS
3600
ets store: how long a recorded message is kept
STORE_MAX_MESSAGES
10000
ets store: above this many messages, the oldest tenth is dropped
Not enforced in v0.9.0. Every publish is held to a fixed 921,600 byte ceiling whatever this says, and the same goes for per-token sizes from an auth backend.
Guards an internal HTTP endpoint on the WebSocket port. It is internal and unsupported: do not build on it. Change the default anyway, and do not route /internal/ through your reverse proxy.
These have no environment variable. Change them by editing config/sys.config.src and rebuilding the image, or in the sys.config of an application that embeds kraken.
Key
Default
Meaning
cache_miss_fallback_enabled
true
Ask the auth backend's /check-room-access when a subscribe misses the cached grants
cache_miss_fallback_timeout_ms
2000
Timeout for that check
acl_deny_cache_ttl_ms
5000
How long a refused check is remembered per actor and address
release_shared_subs_on_close
true
Release a closing connection's load-balanced subscriptions. Applies only to persistent sessions with durable delivery on.
fallback_compat
true
Wildcard-resolved subscriptions also listen on the topic names used by brokers older than protocol version 2, for rolling upgrades