Environment Variables
This page is the source-of-truth reference for OpenReader environment variables.
Use Settings → Admin as the primary source of truth for shared providers and runtime site features.
API_BASE / API_KEY / API_MODEL_NAME are optional one-time provider bootstrap seeds.
Runtime site features are seeded with RUNTIME_SEED_JSON / RUNTIME_SEED_JSON_PATH.
Quick Reference Table
All OpenReader configuration variables are server-only; none are exposed through a NEXT_PUBLIC_ browser variable. "App" includes the bootstrap process and embedded worker it starts. Standalone-worker rows must be set on the worker service itself.
| Variable | Owner / runtime | Default and validation | When to set |
|---|---|---|---|
LOG_FORMAT | Runtime logging | pretty | Set json for structured logs |
LOG_LEVEL | Runtime logging | info | Set app server log level |
API_BASE | TTS provider bootstrap seed | unset | Optional first-boot base URL for default-openai |
API_KEY | TTS provider bootstrap seed | unset | Optional first-boot API key for default-openai |
API_MODEL_NAME | TTS provider bootstrap seed | kokoro | Optional first-boot default model for default-openai |
BASE_URL | Auth | unset | Required at startup |
AUTH_SECRET | App auth + provider encryption | unset | Required on the app; never configure it on a standalone worker |
AUTH_TRUSTED_ORIGINS | Auth | empty | Add extra allowed origins |
USE_ANONYMOUS_AUTH_SESSIONS | Auth | false | Set true to allow anonymous auth sessions |
GITHUB_CLIENT_ID | Auth/OAuth | unset | Set with GITHUB_CLIENT_SECRET to enable GitHub sign-in |
GITHUB_CLIENT_SECRET | Auth/OAuth | unset | Set with GITHUB_CLIENT_ID to enable GitHub sign-in |
BOOTSTRAP_ADMIN_EMAIL | First-admin seed (app only) | unset | Initial credential account email on a fresh instance |
BOOTSTRAP_ADMIN_PASSWORD | First-admin seed (app only) | unset | Initial password (16+ characters); remove after rotation |
BOOTSTRAP_ADMIN_PASSWORD_FILE | First-admin seed (app only) | unset | Read initial password from a mounted file instead of inline env |
CRON_SECRET | Scheduled tasks | unset | Required for Vercel cron invocations |
RICHARDRDEV_PRODUCTION | Official hosted instance | false; enabled only by exact true | Enables the official-instance label, privacy notice, and US region gate |
POSTGRES_URL | Database | unset (SQLite mode) | Set to switch metadata/auth DB to Postgres |
SQLITE_DB_PATH | Database | docstore/sqlite3.db | Override the SQLite file path; relative values resolve from the app workspace |
USE_EMBEDDED_WEED_MINI | Storage | true when unset | Set false to use external S3-compatible storage only |
WEED_MINI_DIR | Storage | docstore/seaweedfs | Override embedded SeaweedFS data directory |
WEED_MINI_WAIT_SEC | Storage | 20 | Tune SeaweedFS startup wait timeout |
WEED_MINI_BIND_HOST | Storage | 127.0.0.1 | Override embedded SeaweedFS bind interface |
WEED_MINI_ADVERTISE_HOST | Storage | bind host or detected private host | Override the host embedded SeaweedFS advertises |
WEED_MINI_PORT | Storage | 8333 | Override embedded SeaweedFS S3 port |
S3_ACCESS_KEY_ID | Storage | auto-generated in embedded mode | Set explicitly for stable/external credentials |
S3_SECRET_ACCESS_KEY | Storage | auto-generated in embedded mode | Set explicitly for stable/external credentials |
S3_BUCKET | Storage | openreader-documents in embedded mode | Required for external S3-compatible storage |
S3_REGION | Storage | us-east-1 in embedded mode | Required for external S3-compatible storage |
S3_INTERNAL_ENDPOINT | Storage | http://127.0.0.1:8333 embedded | Private S3 endpoint for app and worker traffic |
S3_PUBLIC_ENDPOINT | Storage | — | Public HTTPS S3 endpoint for browser presigned transfers |
S3_BROWSER_TRANSPORT | Storage | auto | Browser transfer mode: auto, proxy, or presigned |
S3_FORCE_PATH_STYLE | Storage | true in embedded mode | Set per provider requirement |
S3_AUTO_CREATE_BUCKET | Storage | false | Create a missing external bucket during startup; intended for self-contained deployments |
S3_PREFIX | Storage | openreader | Customize object key prefix |
IMPORT_LIBRARY_DIRS | App library import | docstore/library fallback | Set one or more roots (comma/colon/semicolon separated) |
EMBEDDED_COMPUTE_WORKER_PORT | Compute | 8081 | Override embedded worker bind port |
EMBEDDED_NATS_PORT | Compute | 4222 | Override embedded NATS client port |
EMBEDDED_NATS_MONITOR_PORT | Compute | 8222 | Override embedded NATS monitor port |
EMBEDDED_NATS_STORE_DIR | Compute | docstore/nats/jetstream | Override embedded JetStream storage directory |
NATS_URL | Compute | nats://127.0.0.1:4222 in embedded startup | Override embedded startup or set standalone worker URL |
NATS_CREDS | Standalone worker | unset | Raw NATS credentials; mutually exclusive in practice with NATS_CREDS_FILE |
NATS_CREDS_FILE | Standalone worker | unset | Path to a NATS credentials file |
COMPUTE_LOG_LEVEL | Compute | info | Compute worker log level |
COMPUTE_WORKER_HOST | Compute worker HTTP | 127.0.0.1 embedded; 0.0.0.0 standalone | Override worker bind host |
PORT | Standalone worker / container | 8081 in worker; 3003 in app image | Usually injected by the hosting platform |
COMPUTE_WHISPER_TIMEOUT_MS | Compute | 30000 | Whisper alignment timeout budget |
COMPUTE_PDF_TIMEOUT_MS | Compute | 300000 | PDF parse timeout budget |
COMPUTE_TTS_PLAYBACK_SEGMENT_TIMEOUT_MS | Compute | Whisper timeout | Per-segment TTS generation timeout budget |
COMPUTE_PDF_JOB_ATTEMPTS | Compute | 1 | Max JetStream deliveries for PDF layout jobs |
COMPUTE_PREWARM_MODELS | Compute | false | Set true to pre-download worker models at startup |
COMPUTE_JOBS_STREAM_MAX_BYTES | Compute / JetStream | 268435456 | Override jobs stream retention bytes with a positive integer |
COMPUTE_EVENTS_STREAM_MAX_BYTES | Compute / JetStream | 134217728 | Override events stream retention bytes with a positive integer |
COMPUTE_JOB_STATES_MAX_BYTES | Compute / JetStream | 67108864 | Override job-state KV storage bytes with a positive integer |
COMPUTE_NATS_REPLICAS | Compute / JetStream | 1; only 1, 3, or 5 survive normalization | Use 3 or 5 for a clustered NATS deployment |
COMPUTE_OP_STALE_MS | Compute | max(30m, 4x max compute timeout) | Shared stale window for compute op replacement |
WHISPER_MODEL_BASE_URL | Compute model source | onnx-community default | Override Whisper ONNX model base URL |
PDF_LAYOUT_MODEL_BASE_URL | Compute model source | PP-DocLayoutV3 default | Override PDF layout ONNX model base URL |
COMPUTE_WORKER_URL | External compute mode | unset | Set only for standalone external worker mode |
COMPUTE_WORKER_PUBLIC_URL | TTS playback | COMPUTE_WORKER_URL | Set when browsers need a different worker URL for audio |
COMPUTE_WORKER_TOKEN | External compute mode | unset | Required for standalone external worker auth |
COMPUTE_CREDENTIAL_BROKER_URL | Standalone worker | unset | HTTPS app endpoint used to resolve TTS provider execution credentials |
COMPUTE_CREDENTIAL_BROKER_TOKEN | App + worker | generated for embedded startup | Authenticates worker-to-app credential resolution |
COMPUTE_CREDENTIAL_BROKER_TIMEOUT_MS | Standalone worker | 5000 | Credential-broker request timeout |
TTS_PLAYBACK_TOKEN_SECRET | TTS playback | unset | Required for signed worker-owned playback audio URLs |
FFMPEG_BIN | Audio runtime | auto-detected (ffmpeg-static) | Override ffmpeg binary path |
DISABLE_AUTH_RATE_LIMIT | Auth request throttling | false | Set true to disable Better Auth request rate limiting |
RUN_DRIZZLE_MIGRATIONS | DB migrations | true | Set false to skip startup Drizzle migrations |
RUN_V4_DECOMMISSION | Storage decommission | true | Set false to skip startup v4 legacy object-prefix purge |
RUNTIME_SEED_JSON_PATH | Runtime JSON seed | unset | Absolute path to first-boot JSON seed document |
RUNTIME_SEED_JSON | Runtime JSON seed | unset | Inline first-boot JSON seed document |
Runtime Logging
LOG_FORMAT
Controls log output format for server-side Pino loggers.
- Default:
pretty - Allowed values:
pretty,json - Applies to app server and compute worker
LOG_LEVEL
App server log level.
- Default:
info
TTS Provider and Request Behavior
API_BASE
Optional first-boot bootstrap base URL for the auto-created default-openai shared provider.
- Example:
http://host.docker.internal:8880/v1 - Read only for provider bootstrap when shared providers are empty. Setting
API_BASEis sufficient;API_KEYmay be blank. - After bootstrap, provider configuration is DB-backed and managed in Settings → Admin → Shared providers.
API_KEY
Optional first-boot bootstrap API key for the auto-created default-openai shared provider.
- Read only for provider bootstrap when shared providers are empty.
- Stored encrypted at rest after bootstrap.
- After bootstrap, provider configuration is DB-backed and managed in Settings → Admin → Shared providers.
API_MODEL_NAME
Optional first-boot default model for the auto-created default-openai shared provider.
- Default:
kokoro - Examples:
kokoro,supertonic-3, or another model name accepted by the configured OpenAI-compatible endpoint. - Read only when
API_BASEorAPI_KEYtriggers provider bootstrap and shared providers are empty. It does not trigger provider creation by itself. - After bootstrap, provider configuration is DB-backed and managed in Settings → Admin → Shared providers.
Auth and Identity
BASE_URL
Required external base URL for this OpenReader instance.
- Required at startup
- Example:
http://localhost:3003orhttps://reader.example.com
AUTH_SECRET
Required secret key used by auth/session handling.
- Required at startup
- App-only: standalone workers resolve provider credentials through the authenticated credential broker and must not receive this secret
- Generate with
openssl rand -base64 32
AUTH_TRUSTED_ORIGINS
Additional allowed origins for auth requests.
- Comma-separated list
BASE_URLorigin is trusted automatically
USE_ANONYMOUS_AUTH_SESSIONS
Controls whether auth-enabled deployments can create/use anonymous sessions.
- Default:
false
GITHUB_CLIENT_ID
GitHub OAuth client ID.
- Set with
GITHUB_CLIENT_SECRET
GITHUB_CLIENT_SECRET
GitHub OAuth client secret.
- Set with
GITHUB_CLIENT_ID
BOOTSTRAP_ADMIN_EMAIL, BOOTSTRAP_ADMIN_PASSWORD, BOOTSTRAP_ADMIN_PASSWORD_FILE
One-time first-administrator credential for a fresh database. Set the email and
exactly one password source before first boot. The password must have at least
16 characters; the file form reads a mounted secret file and removes one
trailing newline. Do not put these values in RUNTIME_SEED_JSON.
The account starts without active admin privileges. Sign in, change its
password under Settings → Account, and then use Settings → Admin → Users
to grant subsequent admin roles. If account email delivery is enabled, verify
the address before sign-in. After rotation, no .env edit or restart is
required; removing the now-inert seed values later is optional secret hygiene.
The seed is consumed once in the database; restarting or deleting the account does not
recreate it. An existing admin prevents new seeding. ADMIN_EMAILS is no
longer used for authorization.
CRON_SECRET
Bearer-token secret for GET /api/admin/tasks/tick.
- Required on Vercel so scheduled maintenance tasks can run from the configured Vercel Cron.
- Vercel automatically sends
Authorization: Bearer <CRON_SECRET>on cron invocations. - Generate a strong random value, for example with
openssl rand -base64 32. - Self-hosted Node.js deployments run the scheduler in-process and do not require this variable.
RICHARDRDEV_PRODUCTION
Official-host deployment flag for openreader.richardr.dev.
- Default:
false - Exact
trueenables the official-instance badge, official privacy notice, and US-only request gate - Self-hosted deployments should leave it unset
Database and Object Blob Storage
POSTGRES_URL
Switches metadata/auth storage from SQLite to Postgres.
- Unset: SQLite at
docstore/sqlite3.db - Set: Postgres mode
USE_EMBEDDED_WEED_MINI
Controls embedded SeaweedFS startup.
- Default behavior: treated as enabled when unset
- Set
falseto rely on external S3-compatible storage
WEED_MINI_DIR
Data directory for embedded SeaweedFS (weed mini).
- Default:
docstore/seaweedfs
WEED_MINI_WAIT_SEC
Max wait time for embedded SeaweedFS startup.
- Default:
20
WEED_MINI_BIND_HOST
Bind interface for embedded SeaweedFS.
- Default:
127.0.0.1
WEED_MINI_ADVERTISE_HOST
Host embedded SeaweedFS advertises in generated S3 URLs.
- Default: the bind host, or a detected reachable private address when binding all interfaces
WEED_MINI_PORT
S3-compatible port for embedded SeaweedFS.
- Default:
8333
S3_ACCESS_KEY_ID
S3 access key.
- Optional in embedded mode (auto-generated when unset)
- Required for external S3 mode
S3_SECRET_ACCESS_KEY
S3 secret key.
- Optional in embedded mode (auto-generated when unset)
- Required for external S3 mode
S3_BUCKET
S3 bucket name.
- Embedded default:
openreader-documents - Required for external S3 mode
S3_REGION
S3 region.
- Embedded default:
us-east-1 - Required for external S3 mode
S3_INTERNAL_ENDPOINT
Private endpoint used by the app and compute worker for S3-compatible storage.
S3_PUBLIC_ENDPOINT
Browser-reachable HTTPS endpoint used only to generate direct presigned URLs.
S3_BROWSER_TRANSPORT
auto (default), proxy, or presigned. Proxy is not allowed on Vercel/cloud request-duration hosting.
S3_FORCE_PATH_STYLE
Force path-style S3 URLs.
- Embedded default:
true
S3_AUTO_CREATE_BUCKET
Create S3_BUCKET during startup when it does not exist. This is disabled by default for externally
managed storage; enable it only when the configured credentials may create buckets. The full Docker
Compose examples enable it so a new SeaweedFS volume can boot without a separate initialization step.
S3_PREFIX
Object key prefix.
- Default:
openreader
Library Import
IMPORT_LIBRARY_DIRS
One or more library roots.
- Supports comma, colon, or semicolon-separated values
- Defaults to
docstore/librarywhen unset
Compute Worker and Model Configuration
EMBEDDED_COMPUTE_WORKER_PORT
Embedded compute worker port.
- Default:
8081
EMBEDDED_NATS_PORT
Embedded NATS client port.
- Default:
4222
EMBEDDED_NATS_MONITOR_PORT
Embedded NATS monitor port.
- Default:
8222
EMBEDDED_NATS_STORE_DIR
Embedded NATS JetStream data directory.
- Default:
docstore/nats/jetstream
NATS_URL
NATS URL used by compute services.
- Embedded startup default:
nats://127.0.0.1:4222
NATS_CREDS
Raw NATS credentials content for a standalone worker. Prefer this form on platforms that inject multiline secrets.
NATS_CREDS_FILE
Path to a NATS credentials file for a standalone worker. NATS_CREDS takes precedence when both are set.
COMPUTE_LOG_LEVEL
Compute worker log level.
- Default:
info
COMPUTE_WORKER_HOST
Compute worker HTTP bind host.
- Embedded default:
127.0.0.1 - Standalone default:
0.0.0.0
PORT
Compute worker HTTP port.
- Worker default:
8081 - Hosting platforms commonly inject this value
- The published app container separately sets
PORT=3003for the Next standalone server
COMPUTE_WHISPER_TIMEOUT_MS
Whisper alignment timeout budget.
- Default:
30000
COMPUTE_PDF_TIMEOUT_MS
PDF parse timeout budget.
- Default:
300000
COMPUTE_TTS_PLAYBACK_SEGMENT_TIMEOUT_MS
Per-segment TTS generation timeout budget.
- Default: the resolved
COMPUTE_WHISPER_TIMEOUT_MSvalue
COMPUTE_PDF_JOB_ATTEMPTS
Max JetStream deliveries for PDF layout jobs.
- Default:
1 - In embedded worker mode, set this in the root
.env
COMPUTE_PREWARM_MODELS
Controls whether the worker downloads model artifacts during startup.
- Default:
false
COMPUTE_JOBS_STREAM_MAX_BYTES
Maximum retained bytes in the JetStream jobs stream.
- Default:
268435456
COMPUTE_EVENTS_STREAM_MAX_BYTES
Maximum retained bytes in the JetStream operation-events stream.
- Default:
134217728
COMPUTE_JOB_STATES_MAX_BYTES
Maximum bytes used by the job-state key-value bucket.
- Default:
67108864
COMPUTE_NATS_REPLICAS
JetStream replica count requested by the worker.
- Default:
1 - Accepted effective values:
1,3, or5; other values normalize to1
COMPUTE_OP_STALE_MS
Stale operation window before worker/app cleanup logic can replace an op.
- Default:
max(30m, 4x max compute timeout)
WHISPER_MODEL_BASE_URL
Base URL for Whisper ONNX model downloads.
PDF_LAYOUT_MODEL_BASE_URL
Base URL for PDF layout model downloads.
COMPUTE_WORKER_URL
External compute worker URL.
- Leave unset for embedded worker mode
- Used by the app server for internal worker API calls.
- In embedded mode, bootstrap sets this to the local embedded worker URL for the app process.
COMPUTE_WORKER_PUBLIC_URL
Browser-reachable compute worker URL for worker-owned TTS playback audio.
- Default:
COMPUTE_WORKER_URL - Set this when
COMPUTE_WORKER_URLpoints at an internal hostname that browsers cannot reach. - The browser loads signed progressive MP3 playback directly from
${COMPUTE_WORKER_PUBLIC_URL}/v1/tts-playback/sessions/:sessionId/audio. - Do not include
COMPUTE_WORKER_TOKENin this URL. Browser playback usesTTS_PLAYBACK_TOKEN_SECRET-signed short-lived URLs instead.
COMPUTE_WORKER_TOKEN
Shared token for app-to-external-worker requests.
- Required when
COMPUTE_WORKER_URLpoints at a standalone worker. - Never expose this token to browsers.
COMPUTE_CREDENTIAL_BROKER_URL
App-owned credential endpoint used by a standalone worker when TTS generation begins.
- Required on standalone workers
- Use
https://<app-origin>/api/internal/compute/tts-credentialsfor remote deployments - Full Compose uses the private
http://openreader:3003/api/internal/compute/tts-credentialsservice URL - Never point this at
COMPUTE_WORKER_PUBLIC_URL
COMPUTE_CREDENTIAL_BROKER_TOKEN
Dedicated bearer token for worker-to-app TTS credential resolution.
- Required on the app and every standalone worker, with the same value
- Generated automatically for an embedded worker when unset
- Separate from
COMPUTE_WORKER_TOKENbecause the request direction and permitted route differ - Never sent to browsers, NATS, operation state, or storage
- Generate with
openssl rand -base64 32
COMPUTE_CREDENTIAL_BROKER_TIMEOUT_MS
Timeout for a worker credential-broker request.
- Default:
5000 - Positive integer milliseconds
- Transient broker failures use a bounded worker-side retry
TTS_PLAYBACK_TOKEN_SECRET
Secret used to sign short-lived browser-facing TTS playback URLs.
- Required for worker-owned TTS playback.
- Must be set to the same value on the app server and standalone compute worker.
- Generate with
openssl rand -base64 32. - This is separate from
COMPUTE_WORKER_TOKEN; it signs public audio URLs and must not be used as the internal worker bearer token.
Audio Runtime
FFMPEG_BIN
Override ffmpeg binary path used for audio processing.
- Used by TTS audio normalization/probing and compute worker Whisper audio decode.
Testing and CI
DISABLE_AUTH_RATE_LIMIT
Disables Better Auth request rate limiting.
- Default:
false
Migration Controls
RUN_DRIZZLE_MIGRATIONS
Controls startup Drizzle schema migrations.
- Default:
true - Set
falseto skip startup migration run
RUN_V4_DECOMMISSION
Controls startup v4 legacy object-prefix purge.
- Default:
true - Set
falseto skip deleting retiredtts_segments_v1/,tts_segments_v2/, andaudiobooks_v1/object prefixes
Runtime JSON Seed
RUNTIME_SEED_JSON_PATH
Path-based first-boot seed document.
- If both
RUNTIME_SEED_JSON_PATHandRUNTIME_SEED_JSONare set, path wins. - Value must point to a JSON file readable by the app process.
RUNTIME_SEED_JSON
Inline first-boot seed document.
- Used only when
RUNTIME_SEED_JSON_PATHis unset. - Must be a JSON object with
version: 1.
Supported top-level keys:
version(required, must be1)runtimeConfig(optional object, strict-validated against runtime schema)providers(optional array of shared provider seed entries)accountEmail(optional complete Resend account-email delivery seed)
Example:
{
"version": 1,
"runtimeConfig": {
"signupPolicy": "open",
"defaultTtsProvider": "custom-openai",
"enableTtsProvidersTab": true,
"enableAudiobookExport": true,
"enableDocxConversion": true,
"showAllProviderModels": true,
"ttsCacheMaxSizeBytes": 268435456,
"ttsCacheTtlMs": 1800000,
"ttsUpstreamMaxRetries": 2,
"ttsUpstreamTimeoutMs": 285000,
"ttsPlaybackBackgroundExtent": "section",
"maxUploadMb": 200,
"changelogFeedUrl": "https://docs.openreader.richardr.dev/changelog/manifest.json"
},
"providers": [
{
"slug": "default-openai",
"displayName": "Default (seeded)",
"providerType": "custom-openai",
"baseUrl": "http://localhost:8880/v1",
"defaultModel": "kokoro",
"enabled": true
}
],
"accountEmail": {
"enabled": true,
"senderName": "OpenReader",
"senderEmail": "mail@example.com",
"replyTo": "support@example.com",
"apiKey": "REPLACE_WITH_RESEND_API_KEY"
}
}
This minimal seed uses the built-in compute policy. To seed every compute limit explicitly, use the complete maintained examples/openreader-seed.json file with RUNTIME_SEED_JSON_PATH; computeLimitPolicies is strict-validated as one complete document.
Provider fallback behavior:
- If the JSON seed includes
providers(including an empty array), theAPI_BASE/API_KEY/API_MODEL_NAMEfallback is skipped. - If the JSON seed does not include a
providerskey, the legacyAPI_BASE/API_KEYbootstrap fallback can still createdefault-openaiwhen provider rows are empty.API_MODEL_NAMEsets that row's default model and defaults tokokoro; it does not trigger the fallback by itself.API_BASEalone is sufficient for an upstream that does not require authentication.
Account email seed behavior:
accountEmailrequiresenabled,senderName,senderEmail, andapiKey;replyTois optional and may benull.- The Resend API key is encrypted with
AUTH_SECRETbefore it is stored. Keep the seed file orRUNTIME_SEED_JSONsecret; do not commit the key. - The seed only creates the account-email record when it is missing. Later Email-panel changes are never overwritten.
- The shipped
examples/openreader-seed.jsonincludes a disabled account-email block with a placeholder key. Replace the placeholder and sender address, then setenabledtotruewhen configuring Resend.
Precedence summary:
- Runtime reads: admin DB runtime rows override built-in defaults.
- Seed input (
RUNTIME_SEED_JSON*) only populates missing runtime rows on first boot; it does not overwrite existing/admin-edited rows. - Provider bootstrap order: JSON
providerssection >API_BASE/API_KEY/API_MODEL_NAMEfallback > no provider bootstrap. - Account email bootstrap: JSON
accountEmailsection > no account-email bootstrap.
Platform-Supplied Signals
These values are read by OpenReader but owned by Node.js, Next.js, the hosting platform, or the test runner. They are not deployment configuration knobs and should normally be left to the owning platform.
| Variable | Owner | OpenReader use |
|---|---|---|
NODE_ENV | Node.js / Next.js | Production cookie security and runtime behavior |
NEXT_RUNTIME | Next.js | Loads Node-only instrumentation in the Node runtime |
VERCEL | Vercel | Selects scheduled-task behavior, request IP handling, and rejects proxy browser storage on request-duration hosting |
CI | CI runner | Test retries, server reuse, and reporter selection |
PWD | Process launcher | Worker fallback for locating the bundled docstore directory |
Documentation Build Variables
These variables belong only to scripts/build-changelog-feed.mjs and the documentation deployment workflow; they are not read by the OpenReader app or worker.
| Variable | Default / owner | Purpose |
|---|---|---|
CHANGELOG_REPO | GITHUB_REPOSITORY, then richardr1126/openreader | Release repository queried for changelog data |
CHANGELOG_PUBLIC_BASE_URL | https://docs.openreader.richardr.dev | Public base used in generated changelog URLs |
CHANGELOG_MUTABLE_COUNT | 3; positive numeric input expected | Number of recent releases refreshed during incremental builds |
CHANGELOG_FORCE_FULL | unset; exact 1 enables | Forces a full changelog reconciliation |
GITHUB_TOKEN | GitHub Actions secret | Authenticates release API requests |
GITHUB_REPOSITORY | GitHub Actions | Default changelog repository |
GITHUB_EVENT_PATH | GitHub Actions | Event payload used to identify a release change |
GITHUB_EVENT_NAME | GitHub Actions | Selects incremental event handling |