Environment variables
OpenAEON pulls environment variables from multiple sources. The rule is never override existing values.Precedence (highest → lowest)
- Process environment (what the Gateway process already has from the parent shell/daemon).
.envin the current working directory (dotenv default; does not override).- Global
.envat~/.openaeon/.env(aka$OPENAEON_STATE_DIR/.env; does not override). - Config
envblock in~/.openaeon/openaeon.json(applied only if missing). - Optional login-shell import (
env.shellEnv.enabledorOPENAEON_LOAD_SHELL_ENV=1), applied only for missing expected keys.
Config env block
Two equivalent ways to set inline env vars (both are non-overriding):
Shell env import
env.shellEnv runs your login shell and imports only missing expected keys:
OPENAEON_LOAD_SHELL_ENV=1OPENAEON_SHELL_ENV_TIMEOUT_MS=15000
Env var substitution in config
You can reference env vars directly in config string values using${VAR_NAME} syntax:
Secret refs vs ${ENV} strings
OpenAEON supports two env-driven patterns:
${VAR}string substitution in config values.- SecretRef objects (
{ source: "env", provider: "default", id: "VAR" }) for fields that support secrets references.
Path-related env vars
Logging
OPENAEON_HOME
When set, OPENAEON_HOME replaces the system home directory ($HOME / os.homedir()) for all internal path resolution. This enables full filesystem isolation for headless service accounts.
Precedence: OPENAEON_HOME > $HOME > USERPROFILE > os.homedir()
Example (macOS LaunchDaemon):
OPENAEON_HOME can also be set to a tilde path (e.g. ~/svc), which gets expanded using $HOME before use.