galena
Reference

Configuration

The stage config, SSM parameters, and every environment variable each app reads.

Stage config

infra/config/stages.ts defines each stage (dev, prod) and is validated with Zod when CDK synthesises.

FieldTypeMeaning
stagedev or prodNames every stack and resource
homeRegionregionThe API, database, queue, detection and the workers' AWS access
probeRegionsat least 3 regionsWhere checks run
pageRegions.primary, .replicaregionsThe status page's buckets; all three of these and homeRegion must differ
pageDomainhostname, optionalThe page's own domain; adds a certificate stack in us-east-1
webDomainhostname, optionalThe dashboard's own domain; adds a certificate stack in us-east-1 and becomes the public URL
email.domain, email.fromoptionalThe SES identity, and the sender, which must be an address at that domain
github.repositoryowner/nameYour fork
github.oidcSubjectrepo:owner@id/name@idThe sub prefix of GitHub's OIDC tokens for your fork
github.deployRefrefs/…The only ref whose workflows may assume the deploy role
telemetryCapacity.read, .writeintegersDynamoDB units; stages in one region may not add up to more than 25 each
auroraMaxAcu1 to 16Aurora's capacity ceiling; the floor is 0, so it pauses

prod has no domain or email by default. A prod stage also keeps 14 days of database backups instead of 1, turns on deletion protection for the database, and keeps the key, database, table and config bucket if their stack is ever deleted.

SSM parameters

See Data stores. The three you create by hand are /galena/<stage>/auth-secret, /galena/<stage>/app-key and /galena/<stage>/trigger-secret-key.

API

In AWS, CDK sets these on the Lambda. Locally, pnpm dev uses the defaults.

VariableDefaultMeaning
GLN_STAGElocallocal, dev or prod
GLN_API_PORT8787The local server's port
GLN_PUBLIC_URLhttp://localhost:3000The dashboard's address, where the API also answers
GLN_PUBLIC_URL_PARAMIn AWS: the SSM parameter holding it
GLN_DATABASE_URLthe Docker databaseLocal Postgres
GLN_DB_CLUSTER_ARN, GLN_DB_SECRET_ARN, GLN_DB_NAMEIn AWS: the Data API
GLN_AUTH_SECRET / GLN_AUTH_SECRET_PARAMThe session secret, or its SSM parameter
GLN_APP_KEY / GLN_APP_KEY_PARAMa fixed local keyThe app key, or its SSM parameter
TRIGGER_SECRET_KEY / GLN_TRIGGER_SECRET_PARAMtrigger.dev's secret key, or its SSM parameter
GLN_ORIGIN_SECRET_PARAMIn AWS: the secret header CloudFront adds
GLN_TELEMETRY_TABLEtelemetryThe DynamoDB table
GLN_DYNAMODB_ENDPOINTLocally, DynamoDB Local
GLN_PROBE_REGIONSThe probe regions, comma-separated
GLN_ALLOW_LOOPBACKfalseLets monitors reach loopback addresses; only honoured when the stage is local
GLN_GITHUB_CLIENT_ID, GLN_GITHUB_CLIENT_SECRETGitHub sign-in, off when unset

Dashboard build

VariableDefaultMeaning
GLN_SITEproject builds the project's landing page at /; otherwise / opens the dashboard. The Deploy workflow reads it from the repository variable of the same name.

Probe

VariableDefaultMeaning
GLN_HOME_REGIONWhere the config bucket and queue are
GLN_CONFIG_BUCKET, GLN_CONFIG_KEYkey monitors.jsonThe monitors file
GLN_QUEUE_URLThe check results queue
GLN_CANARY_URLhttps://checkip.amazonaws.com/The canary check

Evaluator

VariableDefaultMeaning
GLN_TELEMETRY_TABLEThe DynamoDB table
GLN_CONFIG_BUCKET, GLN_CONFIG_KEYkey monitors.jsonFor each monitor's detection settings and maintenance windows
GLN_PROBE_REGIONSThe probe regions, comma-separated
GLN_TRIGGER_SECRET_PARAMtrigger.dev's secret key in SSM

Workers

Set in the trigger.dev project's environment; see Self-hosting. Locally, from apps/workers/.env.

VariableDefaultMeaning
GLN_TRIGGER_PROJECT_REFThe trigger.dev project (proj_…)
GLN_DATABASE_URLthe Docker databaseLocal Postgres
GLN_DB_CLUSTER_ARN, GLN_DB_SECRET_ARN, GLN_DB_NAMEname galenaIn AWS: the Data API; both ARNs or neither
GLN_HOME_REGIONeu-central-1The Data API's and config bucket's region
GLN_CONFIG_BUCKET, GLN_CONFIG_KEYWhere monitors.json goes; unset, to GLN_CONFIG_DIR
GLN_CONFIG_DIR.local/configLocal monitors.json
GLN_PAGE_BUCKET, GLN_PAGE_REGIONregion eu-west-1The primary page bucket; unset, files go to GLN_PAGE_DIR
GLN_PAGE_DIR.local/pagesLocal page files
GLN_PAGE_URLhttp://localhost:4321The page's address, for links in feeds and email
GLN_APP_KEYa fixed local keyRequired with the Data API; the same value as the API's
GLN_EMAIL_FROMSends through SES as this address; unset, to GLN_MAIL_DIR
GLN_SES_CONFIGURATION_SETgalena-devThe SES configuration set
GLN_MAIL_DIR.local/mailLocal email
AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEYThe worker access user's key

On this page