Tunploy

Configuration

Environment variables the panel container reads.

The panel container reads these environment variables. With the install script, set them through its install options instead; with Docker Compose, put them under environment.

VariableDefaultMeaning
TUNPLOY_LISTEN:3000Address inside the container.
TUNPLOY_DATA_DIR/var/lib/tunployDatabase and WireGuard configs. Mount it at the same path on the host.
TUNPLOY_PUBLIC_HOSTemptyDefault endpoint for new servers, used while Settings → General is empty.
TUNPLOY_SESSION_TTL168hHow long a sign-in lasts.
TUNPLOY_HTTPStruefalse stops the panel from listening on 80 and 443; Settings then can't set a domain.
TUNPLOY_HTTPS_LISTEN, TUNPLOY_HTTP_LISTEN:443, :80Where HTTPS and its redirect listen inside the container.
TUNPLOY_ACME_DIRECTORYLet's EncryptACME directory URL, for example the Let's Encrypt staging server while testing.
TUNPLOY_TRUSTED_PROXIESemptyReverse proxies whose X-Forwarded-For and X-Forwarded-Proto are believed.
TUNPLOY_CONTAINER_PREFIXtunploy-wg-Name prefix of the VPN containers, which are named prefix plus server ID. Give each panel sharing one Docker daemon its own, ending in -; a panel only ever touches containers with its prefix. Changing it on a running panel leaves the old containers behind.
TUNPLOY_SECURE_COOKIESfalseForce Secure cookies. Not needed with a panel domain or a trusted proxy that sends X-Forwarded-Proto.
TUNPLOY_UPDATE_CHECKtrueCheck GitHub for new releases twice a day. false checks only when you press Check now.
TUNPLOY_GEOIPtrueShow device countries. Downloads the free DB-IP Lite database (about 8 MB) into the data dir and refreshes it monthly. Set to false to never contact db-ip.com.
TUNPLOY_LOG_LEVELinfodebug, info, warn or error.
TZUTCTime zone for daily and monthly data usage, so monthly limits reset at your midnight, for example Europe/Istanbul.