Skip to content

Environment Variables ​

The following environment variables can be configured in your .env file.

General ​

VariableDescriptionDefault
TZContainer timezoneUTC
VERSIONDocker image version taglatest

Paths ​

VariableDescriptionDefault
DATA_DIRDirectory for application data./data
CONFIG_DIRDirectory for platform configuration files./config
OUTPUT_DIRInitial recording folder when the standalone backend creates a fresh database; also watched by startup and disk-space health probes. Under Docker Compose this is the host bind-mount directory, while the container receives OUTPUT_DIR=/app/output. Existing database settings are preserved../output
LOG_DIRDirectory for log files. A relative value resolves against the process working directory; the bundled system service sets it to /var/log/rust-srec instead, so log files are stored outside the state directory. See Installation../logs
LOG_MAX_FILE_BYTESMaximum bytes per managed log segment, read at startup; integer from 1024 to 1073741824. Oversized records are truncated with a marker.16777216 (16 MiB)
LOG_MAX_FILESMaximum managed log segments including the current file, read at startup; integer from 2 to 1024. Use consistent settings for shared LOG_DIR; see retention limits.16

Initial and saved recording directories

The standalone backend initializes a fresh database's output_folder from OUTPUT_DIR, using ./output when unset or blank. It resolves relative paths against the startup working directory and saves an absolute path. Docker Compose and the systemd unit provide /app/output and /var/lib/rust-srec/output, respectively.

If initial migrations or saving the output folder fail, the next start resumes initialization with the absolute path selected on the first attempt, even if OUTPUT_DIR or the working directory changes.

Later starts preserve the saved setting. Change it under Settings → Global → Output Folder, with optional overrides per platform, template, and streamer. The resolved path shown by the application is authoritative. An existing binary or system-service installation that still has /app/output needs this setting changed to a writable directory.

Keep RUST_SREC_OUTPUT_ROOTS aligned with the saved folder when explicit boundaries are configured. Discovery uses saved output settings and overrides; a stale OUTPUT_DIR value does not add a second probe location after initialization.

Shutdown ​

VariableDescriptionDefault
RUST_SREC_SHUTDOWN_TIMEOUT_SECSStrict standalone-server shutdown deadline30
RUST_SREC_SHUTDOWN_FORCE_RESERVE_SECSTime reserved inside the deadline for forced process-tree containment; must be greater than zero and less than the total timeout2
RUST_SREC_CONTAINER_STOP_GRACE_PERIODDocker Compose wait before external SIGKILL; keep longer than the backend deadline35s
RUST_SREC_RUNTIME_MARKER_PATHDirty-generation marker retained after a forced or crashed runtimeBeside the SQLite database

The standalone backend allows 30 seconds for shutdown by default and reserves the final two seconds for forced process cleanup. Set the total with RUST_SREC_SHUTDOWN_TIMEOUT_SECS and keep the force reserve positive and below that total. Docker's stop grace period must be longer than the backend deadline.

A forced or crashed run leaves a recovery marker beside the database. Later clean exits do not clear earlier unresolved recovery. Remove the marker only while the backend is stopped and after checking interrupted files. Exit status 124 means the hard deadline expired; 125 means process-tree termination could not be requested. See runtime shutdown for signal and process-containment details.

Network ​

VariableDescriptionDefault
API_BIND_ADDRESSIP address the backend API binds to0.0.0.0
API_PORTExternal port for the backend API12555
FRONTEND_PORTExternal port for the web interface15275
BACKEND_URLInternal URL for the frontend to reach the backendhttp://rust-srec:8080
HTTP_PROXYHTTP proxy server URL-
HTTPS_PROXYHTTPS proxy server URL-
NO_PROXYComma-separated list of hosts to bypass proxy-

Security & Auth ​

VariableDescriptionDefault
JWT_SECRETSecret key for JWT signing (Required unless using the local-only opt-out below)-
AUTH_DISABLEDDisable backend authentication for loopback-only local developmentfalse
API_CORS_ORIGINSComma-separated exact browser origins (scheme://host[:port]) allowed to call the API cross-origin while authentication is disabledLocal dev server and desktop webview origins
API_LOGIN_MAX_FAILURESFailed logins tolerated per account inside the window5
API_LOGIN_IP_MAX_FAILURESFailed logins tolerated per source address inside the window100
API_LOGIN_WINDOW_SECSLength of the failed-login window, in seconds900 (15m)
JWT_ISSUERJWT issuer identifierrust-srec
JWT_AUDIENCEJWT audience identifierrust-srec-api
SESSION_SECRETFrontend session encryption secret (Required, min 32 chars)-
COOKIE_SECURESet to true to force HTTPS-only cookies(auto)
MIN_PASSWORD_LENGTHMinimum length for user passwords8

The backend refuses to start without a non-empty JWT_SECRET. For local development only, authentication can be disabled by setting both AUTH_DISABLED=true and API_BIND_ADDRESS=127.0.0.1 (or ::1). The backend rejects this opt-out for wildcard, hostname, and non-loopback bind addresses.

While authentication is disabled, only the origins in API_CORS_ORIGINS may call the API from a browser; the default list covers http://localhost:15275, http://127.0.0.1:15275, http://[::1]:15275, tauri://localhost, and http://tauri.localhost. Set the variable to override it — entries must be exact origins with no trailing path, and malformed entries are skipped with a warning at startup. Requests from any other origin are refused with 403, as are requests whose Host header is neither a loopback name nor the configured bind address. With authentication enabled the variable is ignored and any origin may send requests, because every protected route still requires a bearer token.

Login throttling ​

POST /api/auth/login counts failed attempts in a sliding window and answers 429 with a Retry-After delay once a budget is spent. Two budgets apply to every attempt:

  • Per account (API_LOGIN_MAX_FAILURES, default 5). A successful login clears it immediately.
  • Per source address (API_LOGIN_IP_MAX_FAILURES, default 100). This limit is higher to allow for shared proxies. The source address is the peer of the TCP connection, and X-Forwarded-For is not trusted, so behind the bundled frontend container, nginx, or any other reverse proxy every login arrives from the proxy's address. Treat this budget as a cap on password-hashing work, not as a per-user lockout — while it is exhausted, everyone behind that proxy is throttled. Raise it if that matters more to you than the hashing cap; lower it only if browsers reach the backend directly.

Both share the window length set by API_LOGIN_WINDOW_SECS.

Token Expiration ​

VariableDescriptionDefault
ACCESS_TOKEN_EXPIRATION_SECSJWT access token lifetime3600 (1h)
REFRESH_TOKEN_EXPIRATION_SECSJWT refresh token lifetime604800 (7d)

Browser Notifications (Web Push / VAPID) ​

VariableDescriptionDefault
WEB_PUSH_VAPID_PUBLIC_KEYVAPID public key (base64url, unpadded). Leave empty/unset to disable.-
WEB_PUSH_VAPID_PRIVATE_KEYVAPID private key (base64url, unpadded). Leave empty/unset to disable.-
WEB_PUSH_VAPID_SUBJECTVAPID subject (e.g. mailto:admin@localhost)mailto:admin@localhost

Backend Service ​

VariableDescriptionDefault
RUST_LOGLogging level (trace, debug, info, warn, error)info
DATABASE_URLSQL database connection string. The value shown is the one the Docker .env sets. Left unset the backend falls back to sqlite:srec.db?mode=rwc, relative to the working directory; the bundled system service sets sqlite:///var/lib/rust-srec/rust-srec.db. The runtime generation marker is derived from this URL and is stored beside the database file.sqlite:///app/data/rust-srec.db (Docker)
RUST_SREC_LOCALELocale for backend-emitted notification strings. Affects every notification event — stream online/offline, download lifecycle, segments, pipeline jobs, system alerts, credential events. Supported: en, zh-CN.en
RUST_SREC_OUTPUT_ROOTSComma-separated list of absolute paths to treat as output-root boundaries for the write gate. If unset, the gate uses a heuristic that takes the first two named components of each resolved output path (e.g. /rec/huya for /rec/huya/X/20260415, /home/user for /home/user/recordings/X/20260415). Two named components is the smallest safe default — it avoids accidentally sharing a gate key across unrelated users in /home/... layouts. For a single-mount /rec-style layout where you want one gate key per mount (and therefore one aggregated notification on failure instead of one per platform), set this explicitly: RUST_SREC_OUTPUT_ROOTS=/rec.-

The heuristic groups deep paths under broader keys: /var/lib/rust-srec/output uses /var/lib. Startup discovery tests a concrete recording directory that resolves to that same key, so it does not require write access to a read-only ancestor. Setting RUST_SREC_OUTPUT_ROOTS=/var/lib/rust-srec/output gives the directory its own boundary; the longest matching configured prefix wins. Explicit boundaries are themselves probed and should name writable recording locations. See output-root probes for discovery limits.

Resource Limits (Docker) ​

VariableDescriptionDefault
CPU_LIMITMaximum CPUs the container can use4
MEMORY_LIMITMaximum memory the container can use4G
CPU_RESERVATIONReserved CPUs for the container1
MEMORY_RESERVATIONReserved memory for the container512M

Released under the MIT License.