DocumentationConfiguration

Rust · 0.1.0

Runtime flags and environment

Understand the Rust command's settings and its packaging defaults.

Choose explicit values

The command supports flags and their MEMOS_ environment counterparts. Command-line values take precedence through the CLI parser. Run --help on the binary you deploy. The table describes source defaults; the Dockerfile additionally sets MEMOS_PORT=5230 and its working data directory is /var/opt/memos.

Flag / environmentMeaning / default
--addr / MEMOS_ADDRTCP address; empty means 0.0.0.0
--port / MEMOS_PORTTCP port; native default 8081
--data / MEMOS_DATAData directory; choose an explicit persistent path
--driver / MEMOS_DRIVERsqlite (default), postgres or mysql
--dsn / MEMOS_DSNDatabase connection string; SQLite defaults to memos_prod.db in the data directory
--unix-sock / MEMOS_UNIX_SOCKUnix socket path, instead of TCP; Unix only
--instance-url / MEMOS_INSTANCE_URLExternal instance URL; empty by default
--log-level / MEMOS_LOG_LEVELinfo by default; debug, warn and error also supported
--demo / MEMOS_DEMOfalse; demo requires SQLite and is not for private data
--rate-limit / MEMOS_RATE_LIMITtrue
--trusted-proxies / MEMOS_TRUSTED_PROXIESComma-separated trusted proxies; default private
--allow-private-webhooks / MEMOS_ALLOW_PRIVATE_WEBHOOKSfalse; avoid broadly enabling private-network destinations
--webhook-private-network-allowlist / MEMOS_WEBHOOK_PRIVATE_NETWORK_ALLOWLISTComma-separated, narrowly scoped outbound exceptions

Packaging-only variables

MEMOS_DSN_FILE is handled by the container entrypoint, not the native Rust argument parser. MEMOS_BUILD_VERSION and MEMOS_BUILD_COMMIT are build-time metadata. They are not substitutes for runtime configuration or a database schema version. Keep credentials out of shell history and source control.

Proxy trust and container-only controls

MEMOS_TRUSTED_PROXIES accepts comma-separated IP addresses/CIDRs, private for the built-in private ranges, or none to trust no forwarded peers. Hostnames are not accepted here. Use the address as observed by the backend, not the external client address. The container also recognizes MEMOS_UID and MEMOS_GID (both default 10001) and MEMOS_DSN_FILE. Those three are entrypoint controls and should not be passed as invented Rust CLI flags. Changing variables in an already-running process does not reconfigure it; restart using the new deployment definition. The local SQLite example below explicitly clears an inherited DSN so it cannot accidentally select a previously configured database. Run it from a clean development shell on a host/container without production resources mounted at /etc/secrets; --data does not isolate those deployment overrides.

env -u MEMOS_UNIX_SOCK -u MEMOS_DEMO -u MEMOS_INSTANCE_URL \
  MEMOS_ADDR=127.0.0.1 MEMOS_PORT=5230 \
  MEMOS_DATA=./memos-data MEMOS_TRUSTED_PROXIES=none \
  ./build/memos --driver sqlite --dsn '' --demo=false --instance-url ''