PurrOSDocs
Getting started

Configuration

Every environment variable, and the config and state directories.

Server-level configuration lives in environment variables, usually in config/purros.env. Everything that belongs to the business (features, roles, locations, sign-in methods, labor rules and so on) is stored in the database and managed through the API and the purros CLI (and under Settings once the web app ships), not here.

Restart the api container (and any worker containers) after changing config/purros.env:

docker compose up -d

Core

VariableRequiredDefaultDescription
PURROS_URLYesPublic URL, e.g. https://erp.example.com. Used in links, emails and the API spec.
PURROS_SECRETYesAt least 32 random bytes (openssl rand -base64 32). Encrypts stored secrets and signs sessions. PurrOS refuses to start with a missing or example value.
DATABASE_URLYesPostgreSQL connection string.
REDIS_URLNoOptional Redis, used to share rate limits across several API containers.
PURROS_LISTENNo:8080Address the API listens on.
PURROS_RUN_WORKERNotrueRun the background worker inside purros serve. Set to false when you run separate purros worker containers.
LOG_LEVELNoinfodebug, info, warn or error.
PURROS_TRUST_PROXYNotrueTrust X-Forwarded-* headers from the reverse proxy.
PURROS_ENV_FILENoEnv file for the purros command to load instead of $PURROS_CONFIG_DIR/purros.env (same as --env-file).

Directories

PurrOS keeps configuration and runtime state apart:

VariableDefaultDocker imageWhat's in it
PURROS_CONFIG_DIR./config(unused: Compose passes config/purros.env as the environment)purros.env (PurrOS settings) and postgres.env (database container). The purros command loads purros.env from here when it exists.
PURROS_STATE_DIR./state/var/lib/purros, on the state volumefiles/ (uploaded files with local storage) and backups/

Back up both: config/ holds PURROS_SECRET, and state/ holds uploaded files. See Backups & upgrades.

Email

PurrOS sends email through any SMTP server. Today that's invitations, sign-in links and password resets; notifications, scheduled reports, purchase orders and invoices by email are planned.

VariableDefaultDescription
SMTP_HOST, SMTP_PORT587SMTP server and port
SMTP_SECUREfalsetrue for implicit TLS (port 465)
SMTP_USER, SMTP_PASSWORDCredentials
SMTP_FROM, SMTP_REPLY_TOSender and reply-to address
SMTP_REQUIRE_TLS, SMTP_TLS_REJECT_UNAUTHORIZEDtrueTLS requirements
SMTP_RATE_PER_SECOND10Sending rate

See Email & file storage for what's sent, deliverability (SPF, DKIM, DMARC), testing and the delivery log.

File storage

Uploaded files (documents, photos, receipts…) are stored on local disk or in any S3-compatible object storage.

VariableDefaultDescription
STORAGE_DRIVERlocallocal (Docker volume) or s3
STORAGE_LOCAL_PATH$PURROS_STATE_DIR/filesWhere local storage keeps files
STORAGE_S3_BUCKET, STORAGE_S3_REGIONBucket and region
STORAGE_S3_ENDPOINTFor non-AWS services (MinIO, R2, Backblaze, Wasabi…)
STORAGE_S3_ACCESS_KEY_ID, STORAGE_S3_SECRET_ACCESS_KEYCredentials (or an IAM role on AWS)
STORAGE_S3_FORCE_PATH_STYLE, STORAGE_S3_PREFIXfalse,Path-style addressing, and a folder prefix inside the bucket
STORAGE_S3_SSE, STORAGE_S3_KMS_KEY_IDServer-side encryption
STORAGE_SIGNED_URL_TTL300Seconds a download link stays valid
STORAGE_MAX_UPLOAD_MB25Largest single upload

See Email & file storage for bucket setup, IAM policy, CORS, a MinIO example and migrating from local disk to S3.

Backups

VariableDefaultDescription
PURROS_BACKUP_DIR(off); /var/lib/purros/backups in the config written by purros initTurn on daily backups into this directory
PURROS_BACKUP_HOUR2Hour of the day (UTC) after which the daily backup runs
PURROS_BACKUP_KEEP14How many backups to keep
PURROS_BACKUP_PASSPHRASEEncrypt backups with this passphrase
PURROS_BACKUP_FILESautoInclude uploaded files: auto (only with local storage), true or false
PURROS_BACKUP_S3_ENABLEDfalseAlso upload backups to an S3 bucket
PURROS_BACKUP_S3_BUCKET, _REGION, _ENDPOINT, _ACCESS_KEY_ID, _SECRET_ACCESS_KEY, _FORCE_PATH_STYLE, _SSE, _KMS_KEY_IDThe backup bucket, with the same meaning as the STORAGE_S3_* settings. See Database backups to S3.
PURROS_BACKUP_S3_PREFIXpurros-backups/Folder inside the bucket
PURROS_BACKUP_S3_KEEPPURROS_BACKUP_KEEPBackups to keep in the bucket

See Backups & upgrades.

API and ingestion limits

VariableDefaultDescription
API_RATE_LIMIT_PER_MIN600Default requests per minute per API key.
API_INGEST_RATE_LIMIT_PER_MIN3000Limit for keys that send data feeds (POS, online store).
API_MAX_BATCH_SIZE1000Maximum records per batch request.

Planned settings

These aren't read by PurrOS yet. They're listed so you know what's coming; setting them today has no effect.

VariableFor
PURROS_DEFAULT_TIMEZONE, PURROS_DEFAULT_LOCALETimezone before the first location exists; default language and formats
OIDC_ISSUER, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET, OIDC_DISPLAY_NAMEPre-configuring a single sign-on provider (redirect URL PURROS_URL/api/auth/callback/oidc). See Authentication.
WEB_PUSH_VAPID_PUBLIC_KEY, WEB_PUSH_VAPID_PRIVATE_KEYBrowser push notifications (purros generate-vapid)
AI_PROVIDER_BASE_URL, AI_PROVIDER_API_KEY, AI_MODELThe optional AI assistant. No data will be sent anywhere unless these are set and the feature is on.
OTEL_EXPORTER_OTLP_ENDPOINTTraces and metrics to an OpenTelemetry collector
METRICS_ENABLEDPrometheus metrics at /api/metrics
PURROS_TELEMETRYOpt-in anonymous usage statistics (off by default)

SMS and chat notifications will be sent through an integration rather than configured here.

On this page