Environment Configuration¶
Trustpoint can be configured through environment variables using a .env file.
Create the file from the provided example:
cp .env.example .env
Unless stated otherwise, all variables are optional.
Startup¶
Variable |
Values / Default |
Description |
|---|---|---|
|
|
Controls whether Trustpoint determines the startup phase automatically, starts the setup wizard, or starts directly in operational mode. |
Database¶
Variable |
Default |
Description |
|---|---|---|
|
|
PostgreSQL database name. |
|
|
PostgreSQL user. |
|
|
PostgreSQL password. Change for production deployments. |
|
|
PostgreSQL hostname. |
|
|
PostgreSQL port. |
|
|
Django database backend. |
TLS and Network Configuration¶
Variable |
Default |
Description |
|---|---|---|
|
|
Comma-separated IPv4 addresses used for TLS SANs, Django |
|
|
Comma-separated IPv6 addresses. |
|
|
Comma-separated DNS names. |
|
|
HTTP port. |
|
|
HTTPS port. |
Outgoing Mail¶
If EMAIL_HOST is not configured, Trustpoint uses Django’s console email backend.
Variable |
Default |
Description |
|---|---|---|
|
|
Sender address used for outgoing email. |
|
unset |
SMTP server. Setting this enables SMTP delivery. |
|
|
SMTP server port. |
|
automatic |
Enable STARTTLS. |
|
automatic |
Enable implicit TLS. |
|
unset |
SMTP username. |
|
unset |
SMTP password. |
|
|
SMTP connection timeout in seconds. |
Security Configuration¶
TP_SECURITY_MODE defines the security baseline. Additional security variables may only make the selected preset more restrictive.
Variable |
Values |
Description |
|---|---|---|
|
|
Selects the security preset. |
|
Integer / |
Minimum allowed RSA key size. |
|
Integer / |
Maximum certificate validity period. |
|
Integer / |
Maximum CRL validity period. |
|
Boolean |
Allow issuance of CA certificates. |
|
Boolean |
Allow use of the automatically generated PKI. |
|
Boolean |
Allow importing self-signed CAs. |
|
Boolean |
Allow importing existing private-key credentials. |
|
Boolean |
Enable the local automatically generated PKI. |
|
Comma-separated list |
Allowed PKI protocols without onboarding. |
|
Comma-separated list |
Allowed onboarding protocols. |
Supported no-onboarding protocols:
CMP_SHARED_SECRET
EST_USERNAME_PASSWORD
MANUAL
REST_USERNAME_PASSWORD
Supported onboarding protocols:
MANUAL
CMP_IDEVID
CMP_SHARED_SECRET
EST_IDEVID
EST_USERNAME_PASSWORD
AOKI
BRSKI
OPC_GDS_PUSH
REST_USERNAME_PASSWORD
AGENT
Boolean values accept true, false, 1, 0, yes, no, on, and off.
Unset security restriction variables inherit the selected preset. Environment restrictions cannot enable functionality that is prohibited by the preset.
If a new security configuration conflicts with existing devices or CAs, the requested change is rejected, the previous valid configuration remains active, and the conflict is logged.
Automatic Setup¶
Automatic setup can be used for automated testing and repeatable deployments.
Variable |
Default |
Description |
|---|---|---|
|
|
Skip the interactive setup wizard and configure Trustpoint from environment variables. |
|
unset |
Superuser username. Required when auto-setup is enabled. |
|
unset |
Superuser password. Required when auto-setup is enabled. |
|
unset |
Optional superuser email address. |
|
|
Inject example devices and certificates for development and demonstration environments. |
When automatic setup is enabled, the TLS certificate is generated using the configured TP_TLS_* values.