Skip to main content

References

GoFr Configuration Options

This document lists all the configuration options supported by the GoFr framework. The configurations are grouped by category for better organization.

App

NameDescriptionDefault Value
APP_NAMEName of the applicationgofr-app
APP_ENVName of the environment file to use (e.g., stage.env, prod.env, or local.env).
APP_VERSIONApplication versiondev
LOG_LEVELLevel of verbosity for application logs. Supported values are DEBUG, INFO, NOTICE, WARN, ERROR, FATALINFO
REMOTE_LOG_URLURL to remotely change the log level
REMOTE_LOG_FETCH_INTERVALTime interval (in seconds) to check for remote log level updates15
METRICS_PORTPort on which the application exposes the Prometheus pull endpoint. Set to 0 to disable it (e.g. push-only serverless).2121
METRICS_EXPORTEREnables push-based metrics export alongside the pull endpoint. Supported values: otlp, gcp. Unset (or prometheus) keeps pull-only behavior.
METRICS_URLEndpoint of the OTLP metrics collector/backend. host:port for gRPC, full URL for HTTP. Required when METRICS_EXPORTER is otlp (gcp defaults to telemetry.googleapis.com:443).
METRICS_PROTOCOLOTLP transport for pushed metrics. Supported values: grpc, http.grpc
METRICS_EXPORT_INTERVALInterval (in seconds) at which metrics are pushed to the collector/backend.30
METRICS_TEMPORALITYOTLP temporality preference. Supported values: cumulative, delta, lowmemory. Use delta for Datadog; cumulative for Prometheus/GMP/Grafana.cumulative
METRICS_HEADERSCustom headers for metric export requests in comma-separated key=value format (e.g., "dd-api-key=secret"). Takes priority over METRICS_AUTH_KEY.
METRICS_AUTH_KEYAuthorization header value for metric export requests. Used when METRICS_HEADERS is unset.
METRICS_INSECUREDisables transport security for the OTLP metrics connection. Set to false for managed backends over TLS. Ignored by the gcp exporter (always TLS).true
METRICS_CARDINALITY_LIMITPer-instrument attribute-set limit, inclusive of the overflow slot: an instrument keeps up to one fewer than this many distinct label sets per collection cycle, and the remaining series collapse into a single otel.metric.overflow series (so a value of n keeps n-1 real label sets). Set 0 or negative for unlimited. When unset, the OpenTelemetry SDK default applies (2000, or OTEL_GO_X_CARDINALITY_LIMIT if set); a set value takes precedence over OTEL_GO_X_CARDINALITY_LIMIT. HTTP metrics give requests that match no route (and unknown methods) at most a quarter of this limit, capped at 500 distinct (path, method, status) label sets; past that they are recorded as __unmatched__ / __other__, so scanner traffic cannot push real routes into the overflow series.2000
OTEL_RESOURCE_ATTRIBUTESStandard OpenTelemetry resource attributes, comma-separated key=value. Merged into the resource attached to every exported metric. Required for the gcp exporter outside Google Cloud: its ingest rejects any point whose prometheus_target has no location (e.g. "location=us-central1").
HTTP_PORTPort on which the HTTP server listens8000
GRPC_PORTPort on which the gRPC server listens9000
MCP_PORTPort on which the MCP server listens, bound to loopback. Only used when app.EnableMCP() is called; a port that cannot be claimed fails startup. Set to 0 to keep tools available in-process while serving no MCP transport. A non-numeric or out-of-range value refuses startup. Note the default collides with Vault's — see MCP.8200
TRACE_EXPORTERTracing exporter to use. Supported values: gofr, zipkin, jaeger, otlp, gcp. gcp exports directly to Google Cloud's Telemetry (OTLP) API using Application Default Credentials, and requires the blank import _ "gofr.dev/pkg/gofr/traces/exporters/gcp".
TRACER_HOSTHostname of the tracing collector. Required if TRACE_EXPORTER is set to zipkin or jaeger.DEPRECATED
TRACER_PORTPort of the tracing collector. Required if TRACE_EXPORTER is set to zipkin or jaeger.9411DEPRECATED
TRACER_URLURL of the trace collector. Required if TRACE_EXPORTER is set to zipkin, jaeger or otlp; optional for gcp, which defaults to telemetry.googleapis.com:443. For zipkin, jaeger and otlp an http:// or https:// scheme selects the transport, and a schemeless host:port is governed by TRACER_INSECURE. For gcp the value must be a schemeless host:port — that destination is always TLS on 443, so a scheme is rejected at startup rather than interpreted.
TRACER_INSECUREWhether a schemeless TRACER_URL (host:port) is exported over plaintext. Set to false to use TLS with the system root CAs. Ignored when TRACER_URL carries an http:// or https:// scheme, which selects the transport itself. Takes precedence over the OTel standard OTEL_EXPORTER_OTLP_INSECURE / OTEL_EXPORTER_OTLP_TRACES_INSECURE. Supported for otlp, jaeger.true
TRACER_RATIORefers to the proportion of traces that are exported through sampling. It is optional configuration. By default, this ratio is set to 1. A value that is not a valid number is rejected with an error log and also resolves to 1, so a typo over-samples rather than silently disabling tracing.
TRACER_AUTH_KEYAuthorization header for trace exporter requests. Supported for zipkin, jaeger, otlp.
TRACER_HEADERSCustom authentication headers for trace exporter requests in comma-separated key=value format (e.g., "X-Api-Key=secret,Authorization=Bearer token"). Supported for zipkin, jaeger, otlp. Takes priority over TRACER_AUTH_KEY.
CMD_LOGS_FILEFile to save the logs in case of a CMD application
SHUTDOWN_GRACE_PERIODTimeout duration for server shutdown process30s
GOFR_TELEMETRYEnable telemetry for GoFr framework usagetrue
GOFR_ROUTERRoute matcher for the HTTP server. Set to trie to opt into the O(path length) trie index instead of the default linear scan — see Routing Performance. Any other value falls back to mux.mux
LOG_DISABLE_PROBESDisable log probes for health checksfalse
GRPC_ENABLE_REFLECTIONEnable gRPC server reflectionfalse
HEALTH_CACHE_TTLHow long a health result may be served without re-checking the backends, as a duration (5s, 10s, 1m). Unset, 0 or disabled turns caching off, which is the default: within a TTL a recovered backend still reports DOWN and a failed one still reports UP, so it is a trade to opt into rather than inherit.disabled
HEALTH_CHECK_TIMEOUTUpper bound on one round of health checks, as a duration (2s). Backends that have not answered by then are left out of the response and the aggregate status is DEGRADED. A check that is still running when the round is abandoned keeps running, so a probe arriving before it finishes reports DEGRADED with no per-dependency detail rather than starting a second round against the same unresponsive backend. Unset or 0 means the round is bounded only by each backend client's own timeout.disabled

HTTP

NameDescription
REQUEST_TIMEOUTSet the request timeouts (in seconds) for HTTP server.
CERT_FILESet the path to your PEM certificate file for the HTTPS server to establish a secure connection.
KEY_FILESet the path to your PEM key file for the HTTPS server to establish a secure connection.

CORS

NameDescriptionDefault Value
ACCESS_CONTROL_ALLOW_ORIGINAllowed origin(s) for cross-origin requests. Supports comma-separated values for multiple origins (e.g., https://app.example.com,https://admin.example.com).*
ACCESS_CONTROL_ALLOW_HEADERSAllowed request headers for cross-origin requests.Authorization, Content-Type, x-requested-with, origin, true-client-ip, X-Correlation-ID
ACCESS_CONTROL_ALLOW_METHODSAllowed HTTP methods. Automatically set from registered routes if not provided.
ACCESS_CONTROL_ALLOW_CREDENTIALSAllow credentials (cookies, HTTP authentication) in cross-origin requests.
ACCESS_CONTROL_EXPOSE_HEADERSAdditional headers exposed to the client in cross-origin responses.
ACCESS_CONTROL_MAX_AGEMaximum time (in seconds) browsers can cache preflight responses.

Datasource

SQL

NameDescriptionDefault Value
DB_DIALECTDatabase dialect. Supported values: mysql, postgres, supabase
DB_HOSTHostname of the database server.
DB_PORTPort of the database server.3306
DB_USERUsername for the database.
DB_PASSWORDPassword for the database.
DB_NAMEName of the database to use.
DB_MAX_IDLE_CONNECTIONNumber of maximum idle connection.2
DB_MAX_OPEN_CONNECTIONNumber of maximum connections which can be used with database.0 (unlimited)
DB_SSL_MODETLS/SSL mode for database connections. Supported modes: disable (no TLS), preferred (attempts TLS, falls back to plain), require (enforces TLS, skips validation), skip-verify (enforces TLS, no certificate validation), verify-ca (enforces TLS, validates certificate against CA), verify-full (enforces TLS with full validation including hostname). Currently supported for MySQL/MariaDB and PostgreSQL.disable
DB_TLS_CA_CERTPath to CA certificate file for TLS connections. Required for verify-ca and verify-full SSL modes.None
DB_TLS_CLIENT_CERTPath to client certificate file for mutual TLS authentication.None
DB_TLS_CLIENT_KEYPath to client private key file for mutual TLS authentication.None
DB_REPLICA_HOSTSComma-separated list of replica database hosts. Used for read replicas.None
DB_REPLICA_PORTSComma-separated list of replica database ports. Used for read replicas.None
DB_REPLICA_USERSComma-separated list of replica database users. Used for read replicas.None
DB_REPLICA_PASSWORDSComma-separated list of replica database passwords. Used for read replicas.None
DB_REPLICA_MAX_IDLE_CONNECTIONSMaximum idle connections allowed for a replica50
DB_REPLICA_MIN_IDLE_CONNECTIONSMinimum idle connections for a replica10
DB_REPLICA_DEFAULT_IDLE_CONNECTIONSIdle connections used if no primary setting is provided10
DB_REPLICA_MAX_OPEN_CONNECTIONSMaximum open connections allowed for a replica200
DB_REPLICA_MIN_OPEN_CONNECTIONSMinimum open connections for a replica50
DB_REPLICA_DEFAULT_OPEN_CONNECTIONSOpen connections used if no primary setting is provided100
DB_CHARSETThe character set for database connectionutf8
SUPABASE_CONNECTION_TYPEConnection type to Supabase. Supported values: direct, session, transactiondirect
SUPABASE_PROJECT_REFSupabase project reference ID
SUPABASE_REGIONSupabase region for pooled connections
DB_URLFull PostgreSQL connection string for Supabase (alternative to separate config parameters)

Redis

NameDescriptionDefault Value
REDIS_HOSTHostname of the Redis server.localhost
REDIS_PORTPort of the Redis server.6379
REDIS_USERUsername for the Redis server (optional).""
REDIS_PASSWORDPassword for the Redis server (optional).""
REDIS_DBDatabase number to use for the Redis server.0
REDIS_TLS_ENABLEDEnable TLS for Redis connections.false
REDIS_TLS_CA_CERTPath to the TLS CA certificate file for Redis (or PEM-encoded string).""
REDIS_TLS_CERTPath to the TLS certificate file for Redis (or PEM-encoded string).""
REDIS_TLS_KEYPath to the TLS key file for Redis (or PEM-encoded string).""

Redis PubSub Configuration:

NameDescriptionDefault Value
REDIS_PUBSUB_DBRedis database number to use only for Redis Pub/Sub (when PUBSUB_BACKEND=REDIS). Use a different DB than REDIS_DB when running GoFr migrations with Redis Streams mode to avoid gofr_migrations key-type collisions.Default: 15 (highest default Redis database, 0-15)
REDIS_PUBSUB_MODEOperation mode: pubsub or streams.streams
REDIS_STREAMS_CONSUMER_GROUPConsumer group name (required for streams mode).""
REDIS_STREAMS_CONSUMER_NAMEUnique consumer name (optional, auto-generated if empty).""
REDIS_STREAMS_BLOCK_TIMEOUTBlocking duration for reading new messages using Redis XREADGROUP. Lower values (1s-2s) provide faster detection but increase CPU usage. Higher values (10s-30s) reduce CPU usage, ideal for batch processing.5s
REDIS_STREAMS_PEL_RATIORatio of PEL (pending) messages to read vs new messages (0.0-1.0). Controls balance between retry and fresh messages. 0.7 = 70% PEL, 30% new.0.7
REDIS_STREAMS_MAXLENMaximum length of the stream (approximate). Prevents streams from growing indefinitely. Set to 0 for unlimited.0 (unlimited)

Note: When using GoFr migrations with Streams mode, keep REDIS_DB and REDIS_PUBSUB_DB separate (defaults: 0 and 15). For REDIS_STREAMS_BLOCK_TIMEOUT: use 1s-2s for real-time or 10s-30s for batch processing.

Pub/Sub

NameDescriptionDefault Value
PUBSUB_BACKENDPub/Sub message broker backend wired automatically by gofr.New(). Accepted values: kafka, google, mqtt, redis (case-insensitive). Other backends (NATS JetStream, AWS SQS, Azure Event Hub) are wired explicitly via app.AddPubSub(...).

Kafka

NameDescriptionDefault Value
PUBSUB_BROKERComma-separated list of broker addresseslocalhost:9092
PARTITION_SIZESize of each message partition (in bytes)0
PUBSUB_OFFSETOffset to start consuming messages from. -1 for earliest, 0 for latest.-1
KAFKA_BATCH_SIZENumber of messages to batch before sending to Kafka1
KAFKA_BATCH_BYTESNumber of bytes to batch before sending to Kafka1048576
KAFKA_BATCH_TIMEOUTTime to wait before sending a batch to Kafka100ms
CONSUMER_IDUnique identifier for this consumergofr-consumer
KAFKA_SECURITY_PROTOCOLSecurity protocol used to communicate with Kafka (e.g., PLAINTEXT, SSL, SASL_PLAINTEXT, SASL_SSL)PLAINTEXT
KAFKA_SASL_MECHANISMSASL mechanism for authentication (e.g. PLAIN, SCRAM-SHA-256, SCRAM-SHA-512)None
KAFKA_SASL_USERNAMEUsername for SASL authenticationNone
KAFKA_SASL_PASSWORDPassword for SASL authenticationNone
KAFKA_TLS_CERT_FILEPath to the TLS certificate fileNone
KAFKA_TLS_KEY_FILEPath to the TLS key fileNone
KAFKA_TLS_CA_CERT_FILEPath to the TLS CA certificate fileNone
KAFKA_TLS_INSECURE_SKIP_VERIFYSkip TLS certificate verificationfalse

Google

NameDescriptionDefault Value
GOOGLE_PROJECT_IDID of the Google Cloud project. Required for Google Pub/Sub.None
GOOGLE_SUBSCRIPTION_NAMEName of the Google Pub/Sub subscription. Required for Google Pub/Sub.None
GOOGLE_MAX_OUTSTANDING_MESSAGESMax messages the client holds waiting for delivery to the handler, per subscribed topic (the memory/goroutine bound, not the handler concurrency). 0 uses the default; a negative value means no limit.1000
GOOGLE_MAX_OUTSTANDING_BYTESMax total size (bytes) of messages held waiting for delivery, per subscribed topic. 0 uses the default; a negative value means no limit.1000000000
GOOGLE_NUM_GOROUTINESNumber of StreamingPull streams opened by the subscriber, per subscribed topic. It is the stream count, not handler concurrency, and does not raise throughput under GoFr's one-message-at-a-time delivery. 0 or a negative value uses the default.10

MQTT

NameDescriptionDefault Value
MQTT_PORTPort of the MQTT broker1883
MQTT_MESSAGE_ORDEREnable guaranteed message orderfalse
MQTT_PROTOCOLCommunication protocol. Supported values: tcp, ssl.tcp
MQTT_HOSTHostname of the MQTT brokerlocalhost
MQTT_USERUsername for the MQTT broker
MQTT_PASSWORDPassword for the MQTT broker
MQTT_CLIENT_ID_SUFFIXSuffix appended to the client ID
MQTT_QOSQuality of Service Level

MQTT_KEEP_ALIVE

Sends regular messages to check the link is active. May not work as expected if handling func is blocking execution

MQTT_RETRIEVE_RETAINED

Retrieve retained messages on subscription

NATS JetStream

NameDescriptionDefault Value
NATS_SERVERURL of the NATS server. The NATS driver is wired explicitly via app.AddPubSub(...); this row is a convention only — the actual env-var name is whatever you read from app.Config.Get(...) and pass into nats.Config.Server.nats://localhost:4222
NATS_CREDS_FILEFile containing the NATS credentialscreds.json
Previous
Context