Reference
Environment variables
Every variable the binary reads. There is no configuration file — these and the UI are the whole surface.
Server
| Variable | What it does |
|---|---|
| MANGODOCK_PORT | The port inside the container. Not the published port — the left side of your -p mapping is what matters from outside. |
| MANGODOCK_DATA_DIR | Where the database, the encryption key and the dial-in listener's identity live. Defaults to /app/data. |
| MANGODOCK_DATABASE_URL | A postgres:// URL, to use Postgres instead of the bundled SQLite. |
| MANGODOCK_SECRET_KEY | Supplies the credential-encryption key instead of reading secret.key from the data directory. If it changes between starts, MangoDock will not start. |
| MANGODOCK_WEB_DIR | Serve the frontend from a directory instead of the one baked into the image. |
Backups
| Variable | What it does |
|---|---|
| MANGODOCK_BACKUP_IMAGE | Use your own mirror of the backup helper image rather than the one on ghcr.io. |
| MANGODOCK_BACKUP_TIMEOUT_HOURS | How long a single backup run may take before it is abandoned. |
Dial-in listener
| Variable | What it does |
|---|---|
| MANGODOCK_EDGE_ADDR | The address the dial-in listener binds. |
| MANGODOCK_EDGE_PORT | The port the dial-in listener binds. |
| MANGODOCK_EDGE_FINGERPRINT | The identity dial-in agents pin to. Preserved across a restore, so agents reconnect unchanged. |
Escape hatches
| Variable | What it does |
|---|---|
| MANGODOCK_ALLOW_PUBLIC_PLAINTEXT | Permit an unencrypted tcp:// endpoint on a public address. A server setting rather than a checkbox, deliberately. |
| MANGODOCK_DAEMON_SHARES_FILESYSTEM | Tell MangoDock the Docker host genuinely sees its data directory at the same path — for instance because you bind-mounted it identically — so relative stack paths are allowed. |
Air-gapped
- None of these reach a network by themselves. MANGODOCK_BACKUP_IMAGE is the one that matters offline: point it at your internal mirror.