Skip to content

Environment Variables

Tina4 Ruby is configured through environment variables, read from .env at the project root. Every variable has a sensible default — most projects set three or four values and leave the rest alone.

This chapter lists every variable the Ruby framework reads, grouped by subsystem. Start with the minimum-config examples at the end, then come back here when you need to tune something specific.


Core Server

VariableDefaultDescription
HOST0.0.0.0Bind address. 0.0.0.0 listens on every interface. 127.0.0.1 restricts to localhost.
TINA4_HOST(inherits HOST)Tina4-specific alias for HOST.
PORT7147HTTP server port. The Rust CLI prefers TINA4_PORT but falls back to PORT.
TINA4_PORT(inherits PORT)Explicit Tina4-specific port override. Takes precedence over PORT when both are set.
HOST_NAMElocalhost:7147Fully-qualified host used in generated absolute URLs (Swagger, OAuth redirects, emails).
TINA4_DEBUGfalseMaster debug toggle. Enables Swagger UI, dev dashboard, live reload, template dump filter, error overlay. Never set to true in production.
TINA4_ENVdevelopmentRuntime environment label. Values like development, staging, production control dev-only features. Falls back to RACK_ENV then RUBY_ENV.
RACK_ENV(none)Rack-standard environment label. Used if TINA4_ENV is unset.
RUBY_ENV(none)Ruby-ecosystem environment label. Used if TINA4_ENV and RACK_ENV are unset.
TINA4_NO_BROWSERfalseStops tina4 serve from opening your browser on every restart. Recommended during active development.
TINA4_NO_RELOADfalseDisables the dev hot-reload signal from the Rust CLI. Use when you want a stable server for debugging.

Secrets and Authentication

VariableDefaultDescription
SECRETtina4-default-secretJWT signing secret. Must be long, random, and unique per environment. Never commit.
TINA4_TOKEN_LIMIT60JWT token lifetime in minutes.
TINA4_API_KEY(empty)Static API key used by Tina4::Auth.validate_api_key as a fallback to JWT.
API_KEY(empty)Legacy alias for TINA4_API_KEY.

Database

VariableDefaultDescription
DATABASE_URL(required for non-SQLite)Connection URL. Scheme selects the driver: sqlite, postgres, mysql, firebird.
DATABASE_USERNAME(empty)Overrides the username embedded in DATABASE_URL.
DATABASE_PASSWORD(empty)Overrides the password embedded in DATABASE_URL.
DB_URL(empty)Legacy alias for DATABASE_URL.
TINA4_AUTOCOMMITfalseAuto-commit after every write. Default is off — call commit explicitly.
TINA4_DB_CACHEfalseEnables in-memory query-result caching for read queries.
TINA4_DB_CACHE_TTL30Query cache TTL in seconds when TINA4_DB_CACHE=true.
ORM_PLURAL_TABLE_NAMEStrueWhen true, the ORM pluralises class names into table names (Userusers). Set false to keep them singular.

CORS

VariableDefaultDescription
TINA4_CORS_ORIGINS*Comma-separated allowed origins. Lock down to real domains in production.
TINA4_CORS_METHODSGET, POST, PUT, PATCH, DELETE, OPTIONSAllowed request methods.
TINA4_CORS_HEADERSContent-Type,Authorization,X-Request-IDAllowed request headers.
TINA4_CORS_CREDENTIALSfalseSend Access-Control-Allow-Credentials: true.
TINA4_CORS_MAX_AGE86400Preflight cache lifetime in seconds.

Security Headers

VariableDefaultDescription
TINA4_CSPdefault-src 'self'Content-Security-Policy header.
TINA4_CSRFfalseCSRF token validation on POST/PUT/PATCH/DELETE. Off by default in Ruby; enable with true.
TINA4_HSTS(empty/off)Strict-Transport-Security max-age in seconds. Set 31536000 in production with HTTPS.
TINA4_FRAME_OPTIONSSAMEORIGINX-Frame-Options header.

Rate Limiting

VariableDefaultDescription
TINA4_RATE_LIMIT100Maximum requests per window per IP. Set 0 to disable.
TINA4_RATE_WINDOW60Rate-limit window in seconds.

Sessions

VariableDefaultDescription
TINA4_SESSION_BACKENDfileStorage backend. Options: file, redis, valkey, mongo, database.
TINA4_SESSION_TTL1800Session expiry in seconds (30 minutes).
TINA4_SESSION_SAMESITELaxSameSite cookie attribute. Options: Strict, Lax, None.
TINA4_SESSION_PATHdata/sessionsFilesystem path for the file backend.

Email

VariableDefaultDescription
TINA4_MAIL_HOSTlocalhostSMTP server hostname.
TINA4_MAIL_PORT587SMTP server port.
TINA4_MAIL_USERNAME(none)SMTP authentication username.
TINA4_MAIL_PASSWORD(none)SMTP authentication password.
TINA4_MAIL_FROMdev@localhostDefault sender email address.
TINA4_MAIL_FROM_NAME(empty)Default sender display name.
TINA4_MAIL_ENCRYPTIONtlsConnection encryption. Options: tls, ssl, none.
TINA4_MAIL_IMAP_HOST(inherits mail host)IMAP server for inbound mail.
TINA4_MAIL_IMAP_PORT993IMAP server port.
TINA4_MAILBOX_DIRdata/mailboxDev mailbox directory. All outbound mail lands here when TINA4_DEBUG=true.

SMTP_HOST, SMTP_PORT, SMTP_USERNAME, SMTP_PASSWORD, SMTP_FROM, SMTP_FROM_NAME, IMAP_HOST, IMAP_PORT are accepted as legacy aliases. New projects should use the TINA4_MAIL_* names.


Logging

VariableDefaultDescription
TINA4_LOG_LEVEL[TINA4_LOG_ALL]Console log level. Options: [TINA4_LOG_ALL], [TINA4_LOG_DEBUG], [TINA4_LOG_INFO], [TINA4_LOG_WARNING], [TINA4_LOG_ERROR], [TINA4_LOG_NONE]. Also accepts plain DEBUG, INFO, ERROR, etc.
TINA4_LOG_MAX_SIZE10Per-file log size limit in megabytes. Rotated when exceeded.
TINA4_LOG_KEEP5Number of rotated log files to retain.

Localisation

VariableDefaultDescription
TINA4_LOCALEenDefault locale for Tina4::Localization.
TINA4_LOCALE_DIRsrc/localeDirectory containing locale JSON files.

AI and MCP Tooling

The dashboard AI chat and the framework's RAG-based code search both default to a local qwen2.5-coder model served via Ollama. Nothing leaves your machine unless you point TINA4_AI_URL at a remote endpoint.

VariableDefaultDescription
TINA4_AI_URLhttp://localhost:11434OpenAI-compatible HTTP endpoint for the chat/completion model (Ollama by default).
TINA4_AI_MODELqwen2.5-coderModel identifier the endpoint should serve.
TINA4_RAG_URL(inherits TINA4_AI_URL)Embedding endpoint for the framework RAG index.
TINA4_RAG_MODELnomic-embed-textEmbedding model used to index the framework and src/.
TINA4_MCP_REMOTEfalseAllow the MCP server to bind on non-localhost interfaces. Never enable in production.
TINA4_NO_AI_PORTfalseDisables the MCP port listener in dev mode.
TINA4_OVERRIDE_CLIENTfalseAllow the framework to start without the Rust CLI (tina4 serve). Used in Docker images and CI runners; bypasses SCSS compilation, the file watcher, and live reload.

Swagger / OpenAPI

VariableDefaultDescription
SWAGGER_TITLETina4 APIOpenAPI spec title. Falls back to PROJECT_NAME.
PROJECT_NAME(none)Alternative OpenAPI title source.
VERSION(Gem version)Overrides the spec version.

Minimal .env for Development

bash
TINA4_DEBUG=true
TINA4_LOG_LEVEL=ALL
TINA4_NO_BROWSER=true

Debug mode lights up the Swagger UI, the dev dashboard, detailed error pages, and live reload. Keeping the browser flag on stops a new tab opening every time you save a file.


Minimal .env for Production

bash
SECRET=your-long-random-secret-here
DATABASE_URL=postgresql://user:password@db-host:5432/myapp
TINA4_CORS_ORIGINS=https://myapp.com,https://www.myapp.com
TINA4_HSTS=31536000
TINA4_MAIL_HOST=smtp.example.com
TINA4_MAIL_PORT=587
TINA4_MAIL_USERNAME=noreply@myapp.com
TINA4_MAIL_PASSWORD=your-smtp-password
TINA4_MAIL_FROM=noreply@myapp.com

No TINA4_DEBUG. It defaults to false, which is what you want in production. Set a real secret, a real database, locked-down CORS origins, HSTS, and SMTP credentials if you send email. Everything else has a production-appropriate default.

Sponsored with 🩵 by Code InfinityCode Infinity