Environment variables
Set most options in the web UI. Use these variables for deployment settings.
Mounts and permissions
Section titled “Mounts and permissions”| Variable | Purpose |
|---|---|
PUID, PGID |
The user and group that run Aurral in the container. Set them to the owner of the mounted folders. |
AURRAL_DATA_DIR |
The app data folder. Default /config. |
DOWNLOAD_FOLDER |
The first Downloads Folder path. Use an absolute path under your media mount. After setup, change it in Settings > Download clients > Downloads Folder > Path. |
FILE_BROWSE_ROOTS |
Comma-separated folders that Browse folders can open, and where Aurral can create a Downloads Folder. By default these are /data, the app data folder, and the Downloads Folder. Set this variable when your media mount is not under /data, for example /music. |
PORT |
The port that Aurral listens on inside the container. Default 3001. |
Path mappings
Section titled “Path mappings”| Variable | Purpose |
|---|---|
PATH_MAPPINGS |
Path translations for mixed Windows and Docker setups. Use the format remote|local. Separate mappings with ;. To limit a mapping to one application, use source|remote|local. You can also edit mappings in Settings > Download clients > Remote path mappings. |
Authentication
Section titled “Authentication”| Variable | Purpose |
|---|---|
TRUST_PROXY |
Set this variable when Aurral runs behind a reverse proxy. |
AURRAL_PUBLIC_URL |
The public address of Aurral, used for OAuth callbacks. Example: https://aurral.example.com. |
SESSION_EXPIRY_HOURS |
Session length in hours for all sign-in methods. Default 720, which is 30 days. |
AUTH_PROXY_ENABLED |
Turns on reverse-proxy authentication. The default header is x-forwarded-user. |
AUTH_PROXY_HEADER |
The header that holds the authenticated username. |
AUTH_PROXY_TRUSTED_IPS |
Comma-separated addresses of your reverse proxy. Aurral accepts the identity header only from these addresses. Set it whenever you turn on proxy authentication. Without it, any client can send the header and act as any user. |
AUTH_PROXY_DOMAIN |
The address of your forward-auth sign-in page, for example https://auth.example.com. Aurral adds it to the connect-src content security policy, so that pages can reach it. |
AUTH_PROXY_LOGOUT_URL |
The logout address of your proxy or identity provider. Log out in Aurral then ends the proxy session. For Authentik single-application forward auth, use https://aurral.example.com/outpost.goauthentik.io/sign_out. While proxy authentication is on and this variable is not set, Aurral hides Log out. |
AUTH_PROXY_DEFAULT_ROLE |
The role for proxy users who do not get the admin role another way: user or admin. Aurral checks the role on every request. |
AUTH_PROXY_ADMIN_USERS |
Comma-separated usernames that get the admin role. Aurral checks the list on every request. When you remove a name, the user loses the admin role at the next request. |
AUTH_PROXY_ROLE_HEADER |
Optional header with the user’s groups, such as Authelia’s Remote-Groups. The value is usually a comma-separated list. |
AUTH_PROXY_ADMIN_GROUPS |
Comma-separated groups that give the admin role. Aurral compares them with AUTH_PROXY_ROLE_HEADER. A group named admin has no special effect unless you list it here. |
OIDC_ENABLED |
Set to true to turn on native OpenID Connect sign-in. |
OIDC_ISSUER |
The issuer URL of your identity provider, used for discovery. |
OIDC_CLIENT_ID |
The OIDC client ID. |
OIDC_CLIENT_SECRET |
The OIDC client secret. Not required when OIDC_TOKEN_ENDPOINT_AUTH_METHOD is none. |
OIDC_TOKEN_ENDPOINT_AUTH_METHOD |
How Aurral authenticates to the token endpoint: client_secret_basic, the default, client_secret_post, or none. It must match the method registered with your identity provider. |
OIDC_REDIRECT_URI |
The callback URL registered with your identity provider. It must be https://<your-aurral-host>/sso/callback. |
OIDC_SCOPES |
Space-separated scopes. Default openid profile email. |
OIDC_USERNAME_CLAIM |
The claim that becomes the Aurral username. Default preferred_username. If the claim is missing, Aurral uses email. |
OIDC_DEFAULT_ROLE |
The role for OIDC users who do not get the admin role another way: user or admin. |
OIDC_ADMIN_USERS |
Comma-separated usernames that get the admin role at OIDC sign-in. |
OIDC_GROUPS_CLAIM |
Optional ID-token claim that holds group membership. |
OIDC_ADMIN_GROUPS |
Comma-separated groups in OIDC_GROUPS_CLAIM that give the admin role. |
OIDC_LOGOUT_URL |
Optional logout address of the identity provider. After Aurral ends its own session, it sends the browser there. |
OIDC_DOMAIN |
Optional address of the identity provider, added to the connect-src content security policy. |
Google and Plex sign-in use settings in the web UI, not environment variables. See Sign in with Google or Plex.
Cross-origin clients
Section titled “Cross-origin clients”| Variable | Purpose |
|---|---|
CORS_ORIGIN |
Comma-separated browser origins that can call Aurral’s JSON API. Browser Subsonic clients do not need this variable. |
Metadata
Section titled “Metadata”| Variable | Purpose |
|---|---|
BRAINZMASH_BASE_URL |
The address of your own BrainzMash metadata server. A Base URL set in /settings/metadata takes precedence. See Metadata and search. |
Logging
Section titled “Logging”| Variable | Purpose |
|---|---|
AURRAL_VERBOSE_LOGS |
Set to true to add routine and debug messages to the server log. The normal log shows startup messages, warnings, and errors. |
Image cache
Section titled “Image cache”| Variable | Purpose |
|---|---|
AURRAL_IMAGE_PROXY_MAX_BYTES |
The largest size of the disk cache for library artwork, in bytes. Default 268435456, which is 256 MB. When the cache is full, Aurral removes the images that it served least recently. |
Resource tuning
Section titled “Resource tuning”The Docker image uses low defaults for artwork processing. Use these variables to trade memory for faster artwork generation.
| Variable | Purpose |
|---|---|
AURRAL_DISCOVERY_ARTWORK_CONCURRENCY |
How many discover playlist covers Aurral renders at the same time. Default 1. Range 1 to 3. |
AURRAL_SHARP_CONCURRENCY |
How many image worker threads Sharp uses. Default 2. Range 1 to 4. |
AURRAL_WORKER_IDLE_STOP_MS |
How long a background task stays loaded after its last job, in milliseconds. Aurral then stops its process to free memory and starts it again when new work arrives. Default 60000. Minimum 5000. Set 0 to keep background processes running once they start. |
MALLOC_CONF |
jemalloc memory settings. The Docker image sets background_thread:true,dirty_decay_ms:1000,muzzy_decay_ms:1000, so memory from image processing returns to the operating system sooner, also while Aurral is idle. |
Last.fm
Section titled “Last.fm”| Variable | Purpose |
|---|---|
AURRAL_LASTFM_TIMEOUT_MS |
Last.fm API timeout in milliseconds. Default 15000. Increase it if Focus playlists have no tracks and the logs show ECONNABORTED. |
Spotify playlist import
Section titled “Spotify playlist import”These variables change the shared Spotify OAuth proxy that Lidarr also uses. The defaults work for most installations.
| Variable | Purpose |
|---|---|
SPOTIFY_CLIENT_ID |
The OAuth client ID. |
SPOTIFY_OAUTH_REDIRECT_URI |
The authorization redirect. Default https://spotify.lidarr.audio/auth. |
SPOTIFY_OAUTH_RENEW_URI |
The token refresh endpoint. Default https://spotify.lidarr.audio/renew. |
Example
Section titled “Example”environment: - PUID=1000 - PGID=1000 - TRUST_PROXY=trueFor mounts and path mappings, see Filesystem and mounts.