Skip to main content

Server configuration

Datagrok supports several deployment schemas which can be configured using GROK_MODE and GROK_PARAMETERS environment variables.

Datlas Configuration​

GROK_PARAMETERS is a JSON-formatted environment variable with the Datlas configuration options:

OptionRequiredDefaultDescription
dbServerRequiredPostgres database server
dbPortOptional5432Postgres database server port
dbRequiredDatagrok database name
dbLoginRequiredDatabase user Datagrok uses for everything: runtime, schema migrations, and bootstrap. The user must own the database and have CREATEROLE (plus CREATEDB for a fresh install)
dbPasswordRequiredPassword of dbLogin
dbSslOptionalfalseIf set to true, TLS connection will be used to connect to database
dbAdminLoginOptionalDeprecated. If set to a different user, Datagrok uses this user instead of dbLogin as its only database credential
dbAdminPasswordOptionalDeprecated. Password of dbAdminLogin
recreateDbOptionalfalseDrops and recreates the database on a full deployment. Destructive. Without it, Datagrok creates a missing database and never drops an existing one
googleStorageCertOptionalAccess certificate to Google Cloud Storage. If set, GCS will be used for persistent data storage
amazonStorageRegionOptionalS3 region
amazonStorageBucketOptionalS3 bucket name
amazonStorageIdOptionalS3 credential ID, Datagrok will resolve EC2 role if empty
amazonStorageKeyOptionalS3 credential secret key, Datagrok will resolve EC2 role if empty
amazonStorageEndpointOptionalCustom S3-compatible endpoint host (e.g. eu2.contabostorage.com); uses path-style addressing when set
googleStorageBucketOptionalGoogle Cloud Storage bucket name
googleStorageCredentialsOptionalGoogle Cloud Storage credentials
googleStorageProjectOptionalGoogle Cloud Storage project ID
adminPasswordOptionalDatagrok admin user password which will be created on first start
debugOptionalfalseExtended logging and saving stack traces
useSSLOptionalfalseIf set to true, Datlas serves TLS connections
certPathOptionalPath to the TLS certificate
certKeyPathOptionalPath to the TLS certificate key
certKeyPwdOptionalPassword to the TLS certificate key
queueSettingsOptionalSee Queue SettingsConfiguration for Scripting and Computations
dockerSettingsOptionalSee Docker SettingsConfiguration for Plugins Docker Management
connectorsSettingsOptionalSee Connectors SettingsList of Grok Connect endpoints for External Database Connectivity

Datagrok also creates a read-only <db>_reader database role and gives it a new random password on every start. You don't configure it. The former dbReaderLogin and useAdminForMigrations options are no longer used.

Queue Settings​

queueSettings object:

OptionDefaultDescription
useQueuetrueEnables usage of queue for calls execution (required for scripting)
amqpHostrabbitmqHost of the AMQP message queue
amqpPort5672Port of the AMQP message queue
amqpAuthModepasswordAMQP authentication: password (static user) or jwt (Datagrok-issued tokens)
mqAudiencedatagrok-mqAudience of broker tokens. Must match the RabbitMQ resource_server_id
amqpUserguestAMQP username in password mode
amqpPasswordguestAMQP password in password mode
tlsfalseEnables TLS for AMQP connection
taskPickupTimeout60000Timeout in ms for task pickup by worker
queueReconnectWaitTime1500Time in ms to wait before retrying connection
pipeHostgrok_pipeHost of the grok_pipe service
pipePort3000Port of the grok_pipe service
pipeAuthModepasswordgrok_pipe authentication: password (static pipeKey) or jwt
pipeAudiencedatagrok-pipeAudience of grok_pipe tokens. Must match the grok_pipe token audience
pipeKeydatagrok-keyLegacy static key for grok_pipe, used in password mode

In jwt mode, Datagrok signs short-lived tokens with its server keys, and RabbitMQ, grok_pipe, and Grok Spawner verify them against the Datagrok JWKS endpoint (/api/.well-known/jwks.json). No shared password or key is stored. Static keys still work but are legacy. The Helm chart enables jwt for grok_pipe and Grok Spawner by default, and for RabbitMQ when ingress.host is set.

Docker Settings​

dockerSettings object:

OptionDefaultDescription
useGrokSpawnertrueEnables Grok Spawner for managing containers
spawnerAuthModejwtGrok Spawner authentication: jwt (Datagrok-issued tokens, see Queue Settings) or password (static grokSpawnerApiKey)
spawnerAudiencedatagrok-spawnerAudience of Grok Spawner tokens. Must match the spawner token audience
grokSpawnerApiKeytest-x-api-keyLegacy static API key for Grok Spawner, used in password mode
grokSpawnerHostgrok_spawnerHost for Grok Spawner
grokSpawnerPort8000Port for Grok Spawner
imageBuildTimeoutMinutes30Max wait time in minutes for Docker image build
proxyRequestTimeout60000Max wait time in ms for proxy request to a Docker container

Connectors Settings​

connectorsSettings is a list of Grok Connect endpoints. The first entry is the default endpoint. Add the ADBC connector and the optional extended connectors as extra entries. If the list is empty or missing, Datagrok runs without Grok Connect. A single object, the form used before 1.28, is still accepted and becomes a one-element list.

"connectorsSettings": [
{"grokConnectHost": "grok_connect", "grokConnectPort": 1234},
{"grokConnectHost": "grok_connect_adbc", "grokConnectPort": 1235, "externalDataFrameCompress": false},
{"grokConnectHost": "grok_connect_extended", "grokConnectPort": 1234}
]

Each entry accepts these options:

OptionDefaultDescription
grokConnectHostgrok_connectHost of the endpoint
grokConnectPort1234Port of the endpoint
useGrokConnecttruePolls this endpoint. Set to false to skip it
externalDataFrameCompresstrueCompresses data frames sent to the client for queries served by this endpoint
gzipLevel1Compression level (1–9) for these data frames
dataFrameBatchSize8000000Maximum WebSocket frame size, in bytes, for query results

File storage and parsing options apply to the whole server and go to the root of GROK_PARAMETERS, not into a connectorsSettings entry:

OptionDefaultDescription
sambaVersion3.0Samba version
sambaSpaceEscapenoneSpecifies how spaces are escaped in Samba (none, space, quotes)
dataframeParsingModeNew ProcessDataFrame parsing mode (Main Thread, New Thread, New Process)
localFileSystemAccessfalseEnables local file system access
windowsSharesProxyProxy for Windows shares

Overriding Datlas Configuration with Environment Variables​

In addition to supplying the full JSON, you can override individual values using environment variables. This is useful when deploying in containerized or cloud environments where injecting single parameters is easier than rebuilding the entire configuration object.

Naming Convention​

The environment variable name is derived from the configuration key by applying the following rules:

  1. Prefix every variable with GROK_PARAMETERS_
  2. Flatten nested objects by joining keys with a double underscore __. Example:
    • queueSettings.queueReconnectWaitTime → QUEUE_SETTINGS__QUEUE_RECONNECT_WAIT_TIME
  3. Convert key names to uppercase.
  • dbLogin → DB_LOGIN
  • grokConnectHost → GROK_CONNECT_HOST

Examples​

Config OptionEnvironment Variable Name
dbLoginGROK_PARAMETERS_DB_LOGIN
dbPasswordGROK_PARAMETERS_DB_PASSWORD
queueSettings.queueReconnectWaitTimeGROK_PARAMETERS_QUEUE_SETTINGS__QUEUE_RECONNECT_WAIT_TIME
connectorsSettings[0].grokConnectHostGROK_PARAMETERS_CONNECTORS_SETTINGS__GROK_CONNECT_HOST
connectorsSettings[1].grokConnectPortGROK_PARAMETERS_CONNECTORS_SETTINGS__1__GROK_CONNECT_PORT
dockerSettings.proxyRequestTimeoutGROK_PARAMETERS_DOCKER_SETTINGS__PROXY_REQUEST_TIMEOUT
sambaSpaceEscapeGROK_PARAMETERS_SAMBA_SPACE_ESCAPE

To address a connectorsSettings entry other than the first, add its zero-based index after CONNECTORS_SETTINGS__. Without an index, the override applies to the first entry. The legacy GROK_PARAMETERS_CONNECTORS_SETTINGS__<option> form of these server-wide options, such as CONNECTORS_SETTINGS__SAMBA_SPACE_ESCAPE, still works.

Datlas Startup Mode​

GROK_MODE possible values:

  • start - Starts the application without database and storage deployment.
  • deploy - Datlas will perform the full deployment.
  • auto - Datlas will check the existing database and storage and perform deployment only if needed.

Settings​

You can set Datargok server settings as a part of GROK_PARAMETERS. Get the template JSON in /settings view using {} button near the server settings section. Put any parameter to settings map of GROK_PARAMETERS respecting the hierarchy.