Environment Variables & Configuration

Configuration• 2 min read• Updated 2026-09-10

Reference guide for dewDrive environment variables across local development and production. Details YugabyteDB, PostgREST 12/16, Zitadel IAM, and NATS JetStream.

dewDrive requires environment variables for local development and cloud integration. Create a .env or .env.local file at the root of the project (or see .env.example).


1. Required Variables Matrix

Database & REST API (YugabyteDB & PostgREST 12/16)

  • NEXT_PUBLIC_POSTGREST_URL (or NEXT_PUBLIC_SUPABASE_URL): The URL to the PostgREST API endpoint (http://localhost:3004 for local dev, or https://rest.v1.dewdrive.com in production).
  • NEXT_PUBLIC_POSTGREST_ANON_KEY (or NEXT_PUBLIC_SUPABASE_ANON_KEY): Anon JWT key for public client queries.
  • POSTGREST_SERVICE_ROLE_KEY (or SUPABASE_SERVICE_ROLE_KEY): High-privilege service role JWT (role: "postgres") used strictly in backend Next.js API routes for JIT tenant and user provisioning.
  • PGRST_JWT_SECRET (or SUPABASE_JWT_SECRET): HS256 secret key (minimum 32 characters) for signing and verifying PostgREST JWTs.
  • DATABASE_URL / YUGABYTE_DATABASE_URL: YugabyteDB 2.20 distributed SQL connection string (postgres://yugabyte@localhost:5433/dewdrive_macos_local_dev locally, or postgres://postgres@localhost:5433/dewdrive).

Identity & Access Management (Zitadel IAM)

  • NEXT_PUBLIC_ZITADEL_ISSUER: The OIDC issuer URL (https://auth.v1.dewdrive.com in production or http://localhost:8080 locally).
  • NEXT_PUBLIC_ZITADEL_CLIENT_ID: Zitadel OIDC Client ID for web consoles.
  • ZITADEL_CLIENT_SECRET: Optional confidential client secret for server-side token validation.

Realtime Messaging & Backup Engines

  • NATS_URL: The URL for the embedded or local NATS JetStream broker (nats://localhost:34222).
  • RESTIC_BIN: Path override to the OS-partitioned restic binary (e.g. resources/engines/restic/macos/dewdrive-macos-aarch64-0.19.1).

2. Example .env.local

# Database & REST API
DATABASE_URL="postgres://yugabyte@localhost:5433/dewdrive_macos_local_dev"
NEXT_PUBLIC_POSTGREST_URL="http://localhost:3004"
NEXT_PUBLIC_SUPABASE_URL="http://localhost:3004"
NEXT_PUBLIC_SUPABASE_ANON_KEY="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
SUPABASE_SERVICE_ROLE_KEY="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
PGRST_JWT_SECRET="dewdrive-super-secret-jwt-token-key-with-at-least-32-chars"

# Zitadel IAM OIDC PKCE
NEXT_PUBLIC_ZITADEL_ISSUER="https://auth.v1.dewdrive.com"
NEXT_PUBLIC_ZITADEL_CLIENT_ID="[client-id-from-zitadel]"

# Realtime & Engines
NATS_URL="nats://localhost:34222"
RESTIC_BIN="resources/engines/restic/macos/dewdrive-macos-aarch64-0.19.1"
WARNING

Never commit .env or production credentials to version control. They are strictly ignored in .gitignore.

Tags:#environment#secrets#database#zitadel#postgrest#nats