Reference
Environment variables
Settings for the 3AM container.
The installer, the Compose file and the Helm chart set these for you. Change them only when you run the container yourself, or to override a default.
| Variable | Default | Meaning |
|---|---|---|
THREEAM_DATA | /var/lib/3am | Data directory: the audit log, incidents, the estate model, indexes. Back this up |
THREEAM_LICENCE | /etc/3am/licence.json | Licence file. If absent, upload the licence in the console |
THREEAM_PACKS | /etc/3am/packs | Sealed check packs, shipped with the licence |
THREEAM_CONNECTORS | /etc/3am/connectors.json | Connectors defined in a file. Connectors added in the console are kept in the data directory |
THREEAM_POLICY | /etc/3am/policy.json | The policy: autonomy, approval chain, rules, budgets |
THREEAM_PORT | 8700 | Port the server listens on inside the container |
THREEAM_BIND | 0.0.0.0 | Address the server listens on inside the container (publish the port to the host carefully) |
THREEAM_ADMIN_TOKEN | Generated | The console's admin token. If unset, one is generated at first start, printed once in the logs and kept in admin-token in the data directory (readable only by 3AM) |
THREEAM_INGEST_TOKEN | None | Bearer token for POST /v1/events. Event ingestion is off without it |
THREEAM_POLL_S | 15 | How often, in seconds, 3AM polls alert sources and approval channels |
THREEAM_ORCHESTRATE | 1 | 0 turns incident handling off (the console, API and audit log still work) |
THREEAM_MODEL_URL | None | An OpenAI-compatible endpoint for incident notes (Models) |
THREEAM_MODEL | qwen2.5:1.5b-instruct | The model name at that endpoint |
THREEAM_MODEL_KEY | None | Bearer token for the model endpoint |
THREEAM_MODEL_TIMEOUT_S | 60 | After this, the incident note falls back to the template |
THREEAM_CLUSTER_UID | None | Set by the Helm chart: the install fingerprint follows the cluster rather than a node |
THREEAM_MACHINE_ID_FILE | /etc/machine-id | Where the fingerprint is read from on a single host |
The fingerprint is derived from THREEAM_CLUSTER_UID or the machine id. Changing either (for example moving 3AM to
another host) needs a new licence: see Licensing.
Secrets in connector settings
A connector's secret settings never hold the secret itself. They point to it:
{"token": {"file": "/etc/3am/secrets/pagerduty-token"}}
{"token": {"env": "PD_API_TOKEN"}}The value is read only when the connector is built, and never written to the logs or the audit log.