# Configuration

tide reads only these environment variables. All are optional. With none, tide runs without sign-in on `http://localhost:8080`. tide does not start if a required variable is missing or too short.

## Server

| Variable | Default | Meaning |
| --- | --- | --- |
| `TIDE_ADDR` | `:8080` | Listen address. |
| `TIDE_BASE_URL` | `http://localhost:8080` | The address people open, with `https://`. No trailing slash. |
| `TIDE_SESSION_SECRET` | random at each start, without sign-in | **Required with sign-in**, 32+ characters. Signs session cookies. Use random data. |
| `TIDE_DB_PATH` | `./data/tide.db` | The SQLite database, with sign-in. The image uses `/data/tide.db`. Put a durable volume at `/data`. |
| `TIDE_DEV_MODE` | `false` | For local development only. Do not use it in production. |

## Sign-in

| Variable | Default | Meaning |
| --- | --- | --- |
| `TIDE_OIDC_ISSUER` | none: no sign-in | Turns sign-in on. Use the issuer URL exactly as the provider shows it. Without it, anyone can make a room. |
| `TIDE_OIDC_CLIENT_ID` | `tide` | The client ID. |
| `TIDE_OIDC_CLIENT_SECRET` | — | **Required with sign-in**, 16+ characters. The client secret. |
| `TIDE_USER_GROUPS` | empty | Groups that can sign in, with commas between them. Empty lets all users sign in. |
| `TIDE_ADMIN_GROUPS` | empty | Groups that can manage all rooms, with commas between them. |

## Media

| Variable | Default | Meaning |
| --- | --- | --- |
| `TIDE_MEDIA_NODE_IP` | 127.0.0.1 on localhost, else found | The IPv4 address that browsers send media to. Set it only behind a load balancer or NAT. With recording, the recorder must also reach it. |
| `TIDE_MEDIA_UDP_PORT` | `7882` | Media over UDP. Open it to the internet. |
| `TIDE_MEDIA_TCP_PORT` | `7881` | Media when UDP is blocked. Open it to the internet. |
| `TIDE_MEDIA_API_PORT` | `7880` | The media server's API, on 127.0.0.1 only. Change it to run two tides on one host. |
| `TIDE_MEDIA_API_KEY` | random at each start | **Required with recording**. The media key. tide and the recorder use the same one. Letters, digits, `-` and `_`. |
| `TIDE_MEDIA_API_SECRET` | random at each start | **Required with recording**, 32+ characters. The secret for the media key. |
| `TIDE_MEDIA_URL` | none: built in | An external media server. Only for old installations. It needs the key, the secret and `TIDE_MEDIA_PUBLIC_URL`. |
| `TIDE_MEDIA_PUBLIC_URL` | the base URL, as `ws` or `wss` | The external media server, as browsers reach it. Only with `TIDE_MEDIA_URL`. |

## Recording

| Variable | Default | Meaning |
| --- | --- | --- |
| `TIDE_S3_ENDPOINT` | none: no recording | Turns recording on. Needs sign-in. The bucket address, as tide reaches it. |
| `TIDE_S3_PUBLIC_ENDPOINT` | `TIDE_S3_ENDPOINT` | The bucket address, as browsers reach it. Use HTTPS. |
| `TIDE_S3_RECORDER_ENDPOINT` | `TIDE_S3_ENDPOINT` | The bucket address, as the recorder reaches it. |
| `TIDE_S3_BUCKET` | `tide-recordings` | The bucket. tide puts recordings in `recordings/`. |
| `TIDE_S3_REGION` | `us-east-1` | The bucket region. |
| `TIDE_S3_ACCESS_KEY` | — | **Required with recording**. The access key. |
| `TIDE_S3_SECRET_KEY` | — | **Required with recording**, 16+ characters. The secret key. |
| `TIDE_RECORDER_REDIS_PASSWORD` | — | **Required with recording**, 32+ characters. The Redis password. tide and the recorder use the same one. Use hex. |
| `TIDE_RECORDER_REDIS_ADDR` | `127.0.0.1:6379` | The Redis that tide and the recorder use, as host:port. Keep it private: jobs contain the bucket keys. Use one Redis for each tide. |
| `TIDE_RECORDER_TEMPLATE_URL` | `TIDE_BASE_URL` + `/egress-template` | The page that the recorder opens to draw a meeting. Beside tide, use `http://127.0.0.1:8080/egress-template`. |

## Rate limits

| Variable | Default | Meaning |
| --- | --- | --- |
| `TIDE_TRUSTED_PROXIES` | empty | The addresses of your proxy, as IPs or CIDRs with commas between them. tide then trusts their `X-Forwarded-For`. |
| `TIDE_JOIN_RATE_LIMIT` | `10` | Joins for each client in a minute. Also limits new rooms without sign-in. |
| `TIDE_WAIT_RATE_LIMIT` | `20` | Lobby waits for each client in a minute. |
| `TIDE_LOGIN_RATE_LIMIT` | `10` | Sign-ins for each client in a minute. |
| `TIDE_PAIR_RATE_LIMIT` | `10` | Machine pairings for each client in a minute. |

## Transcripts

| Variable | Default | Meaning |
| --- | --- | --- |
| `TIDE_TRANSCRIPTS` | `false` | Turns [transcripts](/docs#transcripts) on. Needs recording. |
