Docs
Reference

Environment variables

Settings for the 3AM container.

The installer, the Compose file and the Helm chart set these for you. Change them only when you run the container yourself, or to override a default.

VariableDefaultMeaning
THREEAM_DATA/var/lib/3amData directory: the audit log, incidents, the estate model, indexes. Back this up
THREEAM_LICENCE/etc/3am/licence.jsonLicence file. If absent, upload the licence in the console
THREEAM_PACKS/etc/3am/packsSealed check packs, shipped with the licence
THREEAM_CONNECTORS/etc/3am/connectors.jsonConnectors defined in a file. Connectors added in the console are kept in the data directory
THREEAM_POLICY/etc/3am/policy.jsonThe policy: autonomy, approval chain, rules, budgets
THREEAM_PORT8700Port the server listens on inside the container
THREEAM_BIND0.0.0.0Address the server listens on inside the container (publish the port to the host carefully)
THREEAM_ADMIN_TOKENGeneratedThe console's admin token. If unset, one is generated at first start, printed once in the logs and kept in admin-token in the data directory (readable only by 3AM)
THREEAM_INGEST_TOKENNoneBearer token for POST /v1/events. Event ingestion is off without it
THREEAM_POLL_S15How often, in seconds, 3AM polls alert sources and approval channels
THREEAM_ORCHESTRATE10 turns incident handling off (the console, API and audit log still work)
THREEAM_MODEL_URLNoneAn OpenAI-compatible endpoint for incident notes (Models)
THREEAM_MODELqwen2.5:1.5b-instructThe model name at that endpoint
THREEAM_MODEL_KEYNoneBearer token for the model endpoint
THREEAM_MODEL_TIMEOUT_S60After this, the incident note falls back to the template
THREEAM_CLUSTER_UIDNoneSet by the Helm chart: the install fingerprint follows the cluster rather than a node
THREEAM_MACHINE_ID_FILE/etc/machine-idWhere the fingerprint is read from on a single host

The fingerprint is derived from THREEAM_CLUSTER_UID or the machine id. Changing either (for example moving 3AM to another host) needs a new licence: see Licensing.

Secrets in connector settings

A connector's secret settings never hold the secret itself. They point to it:

{"token": {"file": "/etc/3am/secrets/pagerduty-token"}}
{"token": {"env": "PD_API_TOKEN"}}

The value is read only when the connector is built, and never written to the logs or the audit log.

On this page