Skip to main content

Environment variables

If you are integrating against the API directly, you need one credential and one base URL: read the key from a secrets manager or an environment variable and send it as the x-api-key header. That is the whole developer-facing surface.

The variables below configure the fleet agent — the collector you run on a host to ship telemetry.

Fleet agent​

The installer writes these to /etc/constellation/agent.env (root-only) and /etc/constellation/socket.env; the collector reads them at start.

VariablePurpose
CONSTELLATION_API_TOKENThe account API token, sent as x-api-key
CONSTELLATION_API_URLPlatform API base URL for this host (for example https://api.constellation.space)
CONSTELLATION_ENTITY_IDNode identity for the agent's OWN health metrics. Optional: the installer falls back to /etc/machine-id, then the hostname, and only fails if neither exists. Set it explicitly on cloned images, where a shared machine-id would merge every node's health into one entity. It is not a global tag — it is scoped to inputs.internal on purpose, so a socket record missing its own entity_id surfaces as misconfigured instead of being silently attributed to the node. Every record you publish needs its own entity_id.
CONSTELLATION_ENDPOINTgRPC ingest host:port for gRPC egress. Empty on HTTP egress
CONSTELLATION_SOCKET_PATHIngest socket. Default /run/constellation-agent/telemetry.sock

Publishing applications read CONSTELLATION_SOCKET_PATH only. The credential stays in the root-only file and never reaches application code.

Installer​

The install script reads these. Set them before piping the script to sh.

VariablePurpose
CONSTELLATION_API_TOKENRequired. The data-plane key the collector authenticates with
CONSTELLATION_API_URLOverride the API base URL. Default https://api.constellation.space
CONSTELLATION_EGRESSgrpc or http. Selects native gRPC egress or REST egress. Any other value fails the install. See Choosing an egress mode
CONSTELLATION_BUFFER_STRATEGYdisk (default) or memory. Disk survives a restart and caps ingest near 290 metrics/s; memory is far faster and loses up to one flush interval on a hard stop. Any other value fails the install. See Throughput budget
CONSTELLATION_ENDPOINTgRPC ingest host:port. Derived from CONSTELLATION_API_URL for the production hostname; required for any other API URL
CONSTELLATION_TELEGRAF_VERSIONPin a Telegraf version instead of the default
CONSTELLATION_TELEGRAF_PACKAGEPath to a local .deb or .rpm for private or air-gapped hosts
CONSTELLATION_TELEGRAF_SIGNATUREDetached signature for that package. Required with a local package
CONSTELLATION_TELEGRAF_SHA256Override the expected package checksum

Install with a pinned collector version and an explicit egress mode:

curl -fsSL https://install.constellation.space/agent | \
sudo env CONSTELLATION_API_TOKEN="$CONSTELLATION_API_TOKEN" \
CONSTELLATION_EGRESS=http \
CONSTELLATION_TELEGRAF_VERSION=1.39.2 sh

gRPC egress child​

On gRPC egress the collector supervises telegraf-constellation-grpc, which translates line protocol to the native ingest contract. The installer passes it the endpoint and the credential through the collector's environment, so the child never reads a config file and application code still never holds a credential. The remaining variables are tuning knobs you set on the [[outputs.execd]] block if you need them.

VariablePurpose
CONSTELLATION_ENDPOINTRequired. gRPC host:port. The child exits without it
CONSTELLATION_API_TOKENRequired. Sent as x-api-key request metadata
CONSTELLATION_TIMEOUTPer-RPC timeout as a Go duration. Default 10s
CONSTELLATION_BATCH_SIZERecords per Write call, 1 to 1000. Default 500
CONSTELLATION_INSECUREtrue disables TLS. Test and private-tunnel use only; the default is TLS with a 1.2 minimum

Key handling guidance lives in Security overview; the install contract in Fleet agent.