Environment Variables & Configuration
Configuration• 2 min read• Updated 2026-09-10
Reference guide for dewDrive environment variables across local development and production. Details YugabyteDB, PostgREST 12/16, Zitadel IAM, and NATS JetStream.
dewDrive requires environment variables for local development and cloud integration. Create a .env or .env.local file at the root of the project (or see .env.example).
1. Required Variables Matrix
Database & REST API (YugabyteDB & PostgREST 12/16)
NEXT_PUBLIC_POSTGREST_URL(orNEXT_PUBLIC_SUPABASE_URL): The URL to the PostgREST API endpoint (http://localhost:3004for local dev, orhttps://rest.v1.dewdrive.comin production).NEXT_PUBLIC_POSTGREST_ANON_KEY(orNEXT_PUBLIC_SUPABASE_ANON_KEY): Anon JWT key for public client queries.POSTGREST_SERVICE_ROLE_KEY(orSUPABASE_SERVICE_ROLE_KEY): High-privilege service role JWT (role: "postgres") used strictly in backend Next.js API routes for JIT tenant and user provisioning.PGRST_JWT_SECRET(orSUPABASE_JWT_SECRET): HS256 secret key (minimum 32 characters) for signing and verifying PostgREST JWTs.DATABASE_URL/YUGABYTE_DATABASE_URL: YugabyteDB 2.20 distributed SQL connection string (postgres://yugabyte@localhost:5433/dewdrive_macos_local_devlocally, orpostgres://postgres@localhost:5433/dewdrive).
Identity & Access Management (Zitadel IAM)
NEXT_PUBLIC_ZITADEL_ISSUER: The OIDC issuer URL (https://auth.v1.dewdrive.comin production orhttp://localhost:8080locally).NEXT_PUBLIC_ZITADEL_CLIENT_ID: Zitadel OIDC Client ID for web consoles.ZITADEL_CLIENT_SECRET: Optional confidential client secret for server-side token validation.
Realtime Messaging & Backup Engines
NATS_URL: The URL for the embedded or local NATS JetStream broker (nats://localhost:34222).RESTIC_BIN: Path override to the OS-partitioned restic binary (e.g.resources/engines/restic/macos/dewdrive-macos-aarch64-0.19.1).
2. Example .env.local
# Database & REST API
DATABASE_URL="postgres://yugabyte@localhost:5433/dewdrive_macos_local_dev"
NEXT_PUBLIC_POSTGREST_URL="http://localhost:3004"
NEXT_PUBLIC_SUPABASE_URL="http://localhost:3004"
NEXT_PUBLIC_SUPABASE_ANON_KEY="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
SUPABASE_SERVICE_ROLE_KEY="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
PGRST_JWT_SECRET="dewdrive-super-secret-jwt-token-key-with-at-least-32-chars"
# Zitadel IAM OIDC PKCE
NEXT_PUBLIC_ZITADEL_ISSUER="https://auth.v1.dewdrive.com"
NEXT_PUBLIC_ZITADEL_CLIENT_ID="[client-id-from-zitadel]"
# Realtime & Engines
NATS_URL="nats://localhost:34222"
RESTIC_BIN="resources/engines/restic/macos/dewdrive-macos-aarch64-0.19.1"
WARNING
Never commit .env or production credentials to version control. They are strictly ignored in .gitignore.
Tags:#environment#secrets#database#zitadel#postgrest#nats