Skip to content
This documentation covers the kagent 1.0 alpha. For the latest 0.x release, see the 0.x docs.

For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.

Environment variables

Page as Markdown

Look up the environment variables that each kagent component reads, including their types and defaults.

Review the environment variables that a kagent installation reads, grouped by the component that reads them.

Most of the following variables have a Helm chart setting that writes them for you, and the chart setting is the supported way to set them. Use a variable directly only whenever you run a component outside the cluster, such as kagent db against a database from your own machine, or when a variable has no chart setting.

Default values describe the component on its own. Helm, or an agent’s HarnessHarnessA Kubernetes custom resource defining how an agent is allowed to run: its runtime, workload image, and WorkerPool and snapshot storage. An Agent pairs it with the AgentTemplate it runs.Learn more spec.env, might supply a different value, so the default listed here is not the guaranteed value that a running installation might use. (none) means the variable has no fixed default, so read the description for what happens when it is unset. A variable that more than one component reads appears under each of them.

Credentials, controller-generated runtime payloads, and internal process wiring are not configurable settings and are not listed.

Controller

The kagent controller reads these variables at startup. Helm writes most of them into the controller ConfigMap, so prefer the matching chart value where one exists. Set the variable directly only for a setting the chart does not expose. For the chart values, see the Helm reference.

VariableTypeDefaultDescription
KAGENT_AUTH_MODEStringinsecureController authentication mode: insecure or trusted-proxy. trusted-proxy requires an upstream credential-validating proxy and network isolation preventing bypass.
KAGENT_AUTH_USER_ID_CLAIMString(none)JWT claim used for the caller identity in trusted-proxy mode. Empty uses sub; a missing or empty custom claim falls back to sub.
KAGENT_CONTROLLER_NAMEStringkagent-controllerName of the kagent controller service.
KAGENT_DATABASE_VECTOR_ENABLEDBooleanfalseEnable vector database migrations and vector-backed database functionality. The controller defaults to false. When unset in the CLI, migrations read the controller ConfigMap and fall back to true if it is unavailable.
KAGENT_GATEWAY_URLString(none)Base URL for A2A and MCP traffic. The controller falls back to http://127.0.0.1:8083; Python runtimes require a value.
KAGENT_GRPC_REFLECTIONBooleanfalseEnable gRPC server reflection on the controller.
KAGENT_HTTP_BIND_ADDRESSString:8083Listen address for the controller HTTP, gRPC, A2A, and MCP server.
KAGENT_LEADER_ELECTBooleantrueEnable controller leader election, including during single-replica rolling updates. Required for sandbox lifecycle coordination.
KAGENT_LOG_LEVELStringinfoLogging level for the controller, CLI, and Go/Python runtimes, including the Python ADK HTTP server: debug, info, warn, or error. Python also accepts standard Python logging levels.
KAGENT_METRICS_BIND_ADDRESSString0Address the controller-runtime metrics server binds to, e.g. :8080. “0” (the default) serves no metrics, so an installation that does not set this is unchanged. The Helm chart renders this variable, and its ServiceMonitor, from controller.metrics.
KAGENT_METRICS_SECUREBooleanfalseServe the metrics endpoint over HTTPS with authentication and authorization. A scraper then needs a token bound to the metrics-reader ClusterRole.
KAGENT_NAMESPACEStringkagentKubernetes namespace where kagent resources are deployed. The controller injects the agent namespace into runtimes; Python runtimes require it.
KAGENT_OTEL_CAPTURE_RAW_API_BODIESBooleanfalseSet to true, t, or 1 (case-insensitive) to enable native Claude raw API body logging when log export is enabled. Independent of span content capture; bodies may contain sensitive data.
KAGENT_OTEL_MAX_CAPTURE_BYTESInteger16384Per-input/output content capture budget in bytes when capture is enabled. Valid values are 1 through 65536; absent or invalid values use 16384.
KAGENT_OTEL_RESOURCE_ATTRIBUTESString(none)Resource attributes, as key=value pairs, added to every agent runtime.
KAGENT_POSTGRES_DATABASE_MAX_CONNSIntegerGreater of 4 and number of CPUsMaximum size of the PostgreSQL connection pool
KAGENT_POSTGRES_DATABASE_MAX_CONN_IDLE_TIMEDuration30m0sDuration after which an idle connection will be automatically closed
KAGENT_POSTGRES_DATABASE_MAX_CONN_LIFETIMEDuration1h0m0sDuration since creation after which a connection will be automatically closed
KAGENT_POSTGRES_DATABASE_MIN_CONNSInteger0Minimum size of the PostgreSQL connection pool
KAGENT_POSTGRES_DATABASE_URLStringpostgres://postgres:kagent@kagent-postgresql.kagent.svc.cluster.local:5432/postgresPostgreSQL connection URL. The default applies only to the controller; kagent db requires this variable or –db-url. Helm supplies its configured connection URL.
KAGENT_POSTGRES_DATABASE_URL_FILEString(none)File containing the PostgreSQL connection URL; takes precedence over KAGENT_POSTGRES_DATABASE_URL in the controller.
KAGENT_RUNTIME_REVISION_GC_INTERVALDuration1m0sInterval between unreferenced runtime revision cleanup sweeps. Must be positive.
KAGENT_SANDBOX_CPUString1CPU limit for standalone sandbox runtimes.
KAGENT_SANDBOX_DEFAULT_TTLDuration1h0m0sDefault standalone sandbox lifetime.
KAGENT_SANDBOX_EXPIRATION_POLL_INTERVALDuration1sInterval between expired sandbox cleanup batches. Must be positive; longer intervals delay deletion after TTL expiry.
KAGENT_SANDBOX_GUEST_IMAGEString(none)Guest package image pinned by sha256 digest. Required for sandbox preparation and passed unchanged to Substrate.
KAGENT_SANDBOX_MAX_TTLDuration24h0m0sMaximum standalone sandbox lifetime, at most 24h.
KAGENT_SANDBOX_MEMORYString1GiMemory limit for standalone sandbox runtimes.
KAGENT_SCHEDULED_RUN_EXECUTION_POLL_INTERVALDuration1sInterval between scheduled execution reconciliation attempts. Must be positive; longer intervals delay dispatch, status updates, deadline enforcement, and cleanup.
KAGENT_SCHEDULED_RUN_POLL_INTERVALDuration1sInterval between reserving due scheduled runs. Must be positive; occurrences more than 30 seconds late are skipped.
KAGENT_SESSION_EXPIRATION_POLL_INTERVALDuration1m0sInterval between idle session expiration sweeps. Must be positive.
KAGENT_SESSION_IDLE_TTLDuration168h0m0sDelete sessions after this idle duration. Zero disables expiration; running and waiting tasks are retained.
KAGENT_SESSION_SHARE_MAX_TTLDuration0sLongest lifetime a session share may request. Shares created without a ttl receive it. Zero leaves shares unbounded.
KAGENT_SKIP_MIGRATIONSBooleanfalseVerify required database migrations at startup without applying them.
KAGENT_SUBSTRATE_ATENET_ROUTER_URLStringhttp://atenet-router.ate-system.svc:80Substrate router endpoint for agent and sandbox guest traffic.
KAGENT_SUBSTRATE_ATE_API_CA_FILEString(none)PEM CA bundle used to verify the Substrate API server. Empty uses system trust roots.
KAGENT_SUBSTRATE_ATE_API_CLIENT_CERT_FILEString(none)PEM bundle containing both the client certificate and private key for Substrate API mTLS. Reloaded for each TLS handshake.
KAGENT_SUBSTRATE_ATE_API_ENDPOINTStringdns:///api.ate-system.svc:443Substrate control-plane gRPC endpoint.
KAGENT_WATCH_NAMESPACESString(none)Comma-separated namespaces to watch. Empty watches all namespaces.
KUBECONFIGString(none)Kubernetes client configuration file list for the controller, CLI Kubernetes operations, and tests. When unset, client-go uses its normal in-cluster or user kubeconfig discovery.
OTEL_EXPORTER_OTLP_COMPRESSIONStringgzipOTLP compression default applied by kagent. The native Codex process has this variable removed because its exporter does not support gzip.
OTEL_EXPORTER_OTLP_ENDPOINTString(none)OTLP endpoint for every signal. OTEL_EXPORTER_OTLP_<SIGNAL>_ENDPOINT overrides it for one signal.
OTEL_EXPORTER_OTLP_LOGS_ENDPOINTString(none)Log endpoint override. Falls back to OTEL_EXPORTER_OTLP_ENDPOINT; an HTTP override must include its signal path.
OTEL_EXPORTER_OTLP_LOGS_PROTOCOLString(none)Log protocol override: grpc or http/protobuf. Falls back to OTEL_EXPORTER_OTLP_PROTOCOL.
OTEL_EXPORTER_OTLP_LOGS_TIMEOUTString(none)Log SDK timeout in milliseconds, overriding OTEL_EXPORTER_OTLP_TIMEOUT. Not forwarded by the controller.
OTEL_EXPORTER_OTLP_METRICS_DEFAULT_HISTOGRAM_AGGREGATIONStringbase2_exponential_bucket_histogramDefault SDK histogram aggregation applied by kagent and supplied to managed runtimes.
OTEL_EXPORTER_OTLP_METRICS_ENDPOINTString(none)Metric endpoint override. Falls back to OTEL_EXPORTER_OTLP_ENDPOINT; an HTTP override must include its signal path.
OTEL_EXPORTER_OTLP_METRICS_PROTOCOLString(none)Metric protocol override: grpc or http/protobuf. Falls back to OTEL_EXPORTER_OTLP_PROTOCOL.
OTEL_EXPORTER_OTLP_METRICS_TIMEOUTString(none)Metric SDK timeout in milliseconds, overriding OTEL_EXPORTER_OTLP_TIMEOUT. Not forwarded by the controller.
OTEL_EXPORTER_OTLP_PROTOCOLStringgrpcOTLP protocol, grpc or http/protobuf. OTEL_EXPORTER_OTLP_<SIGNAL>_PROTOCOL overrides it for one signal.
OTEL_EXPORTER_OTLP_TIMEOUTString(none)OTLP export timeout in milliseconds. The controller forwards positive integers; absent values use each SDK’s default (normally 10000 ms).
OTEL_EXPORTER_OTLP_TRACES_ENDPOINTString(none)Trace endpoint override. Falls back to OTEL_EXPORTER_OTLP_ENDPOINT; an HTTP override must include its signal path.
OTEL_EXPORTER_OTLP_TRACES_PROTOCOLString(none)Trace protocol override: grpc or http/protobuf. Falls back to OTEL_EXPORTER_OTLP_PROTOCOL.
OTEL_EXPORTER_OTLP_TRACES_TIMEOUTString(none)Trace SDK timeout in milliseconds, overriding OTEL_EXPORTER_OTLP_TIMEOUT. Not forwarded by the controller.
OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENTStringNO_CONTENTSPAN_ONLY records prompts and responses on agent spans. NO_CONTENT disables capture. Managed runtimes support these two modes; standalone Python ADK also recognizes SPAN_AND_EVENT. Captured content may be sensitive.
OTEL_LOGS_EXPORTERString(none)Log exporter, otlp or none. Managed runtime export requires explicit otlp and an endpoint; unset disables forwarding. Standalone SDKs may default to otlp.
OTEL_METRICS_EXPORTERString(none)Metric exporter, otlp or none. Managed runtime export requires explicit otlp and an endpoint; unset disables forwarding. Standalone SDKs may default to otlp.
OTEL_PROPAGATORSStringtracecontextSDK trace propagators. Kagent defaults to W3C tracecontext without baggage and supplies that default to managed runtimes.
OTEL_RESOURCE_ATTRIBUTESString(none)Comma-separated SDK resource attributes for the current process. Helm injects controller identity; kagent constructs runtime identity separately. Use KAGENT_OTEL_RESOURCE_ATTRIBUTES for attributes shared with managed agents.
OTEL_SDK_DISABLEDStringfalseDisable SDK telemetry and forwarding to managed runtimes when true (case-insensitive). Other values are treated as false.
OTEL_SERVICE_NAMEString(none)SDK service name for the current process. Defaults to kagent-controller in the controller; the controller supplies the agent name to managed runtimes.
OTEL_TRACES_EXPORTERString(none)Trace exporter, otlp or none. Managed runtime export requires explicit otlp and an endpoint; unset disables forwarding. Standalone SDKs may default to otlp.

Agent runtime

The kagent controller supplies these variables to each agent runtime that it schedules. Setting one of them in a Harness spec.env does not override the controller on a managed runtime, because the controller writes its own value into every revision it compiles. The byo runtime is the exception because the controller sends it no configuration, so it reads whatever spec.env holds. For more information, see Agent harness.

VariableTypeDefaultDescription
ADK_CAPTURE_MESSAGE_CONTENT_IN_SPANSString(none)Python Google ADK span content capture. When absent, derived from OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT (true for SPAN_ONLY or SPAN_AND_EVENT, false otherwise).
ADK_TELEMETRY_SCHEMA_VERSION_OPT_INString2Python Google ADK telemetry schema version; set by kagent when absent.
ANTHROPIC_API_KEYString(none)API key for Anthropic.
AWS_ACCESS_KEY_IDString(none)AWS access key ID for IAM authentication with Bedrock.
AWS_BEARER_TOKEN_BEDROCKString(none)Bearer token for authentication with AWS Bedrock.
AWS_DEFAULT_REGIONString(none)Preferred region for Python Bedrock models and Go/Python Bedrock embeddings, before AWS_REGION and the us-east-1 fallback.
AWS_REGIONString(none)AWS region for Bedrock. Python Bedrock and Go Bedrock embeddings prefer AWS_DEFAULT_REGION, then AWS_REGION, then us-east-1.
AWS_SECRET_ACCESS_KEYString(none)AWS secret access key for IAM authentication with Bedrock.
AWS_SESSION_TOKENString(none)AWS session token for temporary/SSO credentials with Bedrock.
AZURE_AD_TOKENString(none)Azure Active Directory authentication token for Azure OpenAI.
AZURE_OPENAI_API_KEYString(none)API key for Azure OpenAI.
AZURE_OPENAI_ENDPOINTString(none)Endpoint URL for Azure OpenAI service.
FOUNDRY_API_KEYString(none)API key for Azure AI Foundry.
FOUNDRY_API_VERSIONString2024-10-21Azure AI Foundry OpenAI-compatible data-plane API version.
FOUNDRY_DEPLOYMENTString(none)Azure AI Foundry model deployment name.
FOUNDRY_ENDPOINTString(none)Endpoint URL for Azure AI Foundry or an Azure AI Services account.
GEMINI_API_KEYString(none)Fallback Gemini API key when GOOGLE_API_KEY is unset; supported by the CLI and Go/Python ADKs.
GOOGLE_API_KEYString(none)API key for Google Gemini.
GOOGLE_APPLICATION_CREDENTIALSString(none)Path to Google Cloud service account JSON key file.
GOOGLE_CLOUD_LOCATIONString(none)Google Cloud region/location for Vertex AI.
GOOGLE_CLOUD_PROJECTString(none)Google Cloud project ID for Vertex AI.
GOOGLE_CLOUD_REGIONString(none)Go ADK Vertex AI region fallback when GOOGLE_CLOUD_LOCATION is unset.
GOOGLE_GENAI_USE_VERTEXAIString(none)When set to ’true’, use Vertex AI for Gemini models.
KAGENT_A2A_MAX_CONTENT_LENGTHString10485760Maximum A2A request size in bytes for Go/Python servers. 0, none, or unlimited disables the limit; invalid values use the default.
KAGENT_API_URLString(none)Base URL for kagent control-plane API calls. Required by Python runtimes and supplied by the controller in managed runtimes; also used as the E2E test URL when KAGENT_E2E_API_URL is unset.
KAGENT_BASH_VENV_PATHString(none)Virtual environment used for Python skills shell commands; its bin directory is prepended to PATH and VIRTUAL_ENV is set.
KAGENT_CONFIG_DIRString/configGo ADK configuration directory; –filepath takes precedence.
KAGENT_ENABLE_FILE_SEARCH_TOOLSBooleanfalseWhen true, t, or 1 (case-insensitive), enables the list_files and grep_file skills tools, which let an agent enumerate and search the filesystem under its session/skills roots without a shell. Disabled by default; set in Harness env to opt in.
KAGENT_GATEWAY_URLString(none)Base URL for A2A and MCP traffic. The controller falls back to http://127.0.0.1:8083; Python runtimes require a value.
KAGENT_LOG_LEVELStringinfoLogging level for the controller, CLI, and Go/Python runtimes, including the Python ADK HTTP server: debug, info, warn, or error. Python also accepts standard Python logging levels.
KAGENT_NAMEString(none)Agent name for standalone runtimes. Required by Python runtimes; supplied by the controller in managed runtimes.
KAGENT_NAMESPACEStringkagentKubernetes namespace where kagent resources are deployed. The controller injects the agent namespace into runtimes; Python runtimes require it.
KAGENT_OPENAI_AGENTS_NATIVE_TRACINGBooleanfalseKeep the OpenAI Agents SDK native tracing processor alongside kagent OpenTelemetry export in the Python OpenAI runtime.
KAGENT_PORTString(none)ADK A2A listen port: the Go HTTP/gRPC listener defaults to 8080; the Python gRPC listener defaults to 80. Explicit Go –port/AppConfig.Port or Python a2a_grpc_address takes precedence. The controller sets 80 for managed kagent runtimes. Python’s HTTP –port is separate.
KAGENT_PROPAGATE_TOKENString(none)Set to true to propagate authentication tokens to downstream services. Unset or any other value disables propagation.
KAGENT_SKILLS_FOLDERString/skillsSkills directory for standalone Python skills tools. The Python ADK adds skills tools when set; managed Go ADK runtimes use their compiled skill configuration.
KAGENT_STS_AUDIENCEString(none)Comma-separated RFC 8693 audiences sent on STS token-exchange requests. Alternate to KAGENT_STS_RESOURCE for servers that key on audience.
KAGENT_STS_RESOURCEString(none)Comma-separated RFC 8707 resource indicators sent on STS token-exchange requests to scope issued tokens to target backends.
KAGENT_STS_WELL_KNOWN_URIString(none)Well-known endpoint for the Security Token Service (STS) used for token exchange.
MISTRAL_API_BASEString(none)Custom base URL for the Mistral AI API (defaults to https://api.mistral.ai/v1).
MISTRAL_API_KEYString(none)API key for Mistral AI.
OLLAMA_API_BASEString(none)Base URL for the Ollama API endpoint; falls back to http://localhost:11434 when model configuration and this variable are unset.
OLLAMA_API_KEYString(none)API key for Ollama Cloud. When set, a cloud-tagged model reaches api.ollama.com directly.
OPENAI_AGENTS_DISABLE_TRACINGBooleanfalseDisable OpenAI Agents SDK tracing, including the kagent bridge. The Python OpenAI runtime accepts true or 1.
OPENAI_API_BASEString(none)Custom base URL for the OpenAI API.
OPENAI_API_KEYString(none)API key for OpenAI. Upgrade tests fall back to a placeholder when unset or empty.
OPENAI_API_VERSIONString(none)Azure OpenAI API version. The Go and Python ADKs fall back to 2024-02-15-preview when model configuration and this variable are unset.
OPENAI_ORGANIZATIONString(none)OpenAI organization identifier.
OTEL_EXPORTER_OTLP_COMPRESSIONStringgzipOTLP compression default applied by kagent. The native Codex process has this variable removed because its exporter does not support gzip.
OTEL_EXPORTER_OTLP_ENDPOINTString(none)OTLP endpoint for every signal. OTEL_EXPORTER_OTLP_<SIGNAL>_ENDPOINT overrides it for one signal.
OTEL_EXPORTER_OTLP_LOGS_ENDPOINTString(none)Log endpoint override. Falls back to OTEL_EXPORTER_OTLP_ENDPOINT; an HTTP override must include its signal path.
OTEL_EXPORTER_OTLP_LOGS_PROTOCOLString(none)Log protocol override: grpc or http/protobuf. Falls back to OTEL_EXPORTER_OTLP_PROTOCOL.
OTEL_EXPORTER_OTLP_LOGS_TIMEOUTString(none)Log SDK timeout in milliseconds, overriding OTEL_EXPORTER_OTLP_TIMEOUT. Not forwarded by the controller.
OTEL_EXPORTER_OTLP_METRICS_DEFAULT_HISTOGRAM_AGGREGATIONStringbase2_exponential_bucket_histogramDefault SDK histogram aggregation applied by kagent and supplied to managed runtimes.
OTEL_EXPORTER_OTLP_METRICS_ENDPOINTString(none)Metric endpoint override. Falls back to OTEL_EXPORTER_OTLP_ENDPOINT; an HTTP override must include its signal path.
OTEL_EXPORTER_OTLP_METRICS_PROTOCOLString(none)Metric protocol override: grpc or http/protobuf. Falls back to OTEL_EXPORTER_OTLP_PROTOCOL.
OTEL_EXPORTER_OTLP_METRICS_TIMEOUTString(none)Metric SDK timeout in milliseconds, overriding OTEL_EXPORTER_OTLP_TIMEOUT. Not forwarded by the controller.
OTEL_EXPORTER_OTLP_PROTOCOLStringgrpcOTLP protocol, grpc or http/protobuf. OTEL_EXPORTER_OTLP_<SIGNAL>_PROTOCOL overrides it for one signal.
OTEL_EXPORTER_OTLP_TIMEOUTString(none)OTLP export timeout in milliseconds. The controller forwards positive integers; absent values use each SDK’s default (normally 10000 ms).
OTEL_EXPORTER_OTLP_TRACES_ENDPOINTString(none)Trace endpoint override. Falls back to OTEL_EXPORTER_OTLP_ENDPOINT; an HTTP override must include its signal path.
OTEL_EXPORTER_OTLP_TRACES_PROTOCOLString(none)Trace protocol override: grpc or http/protobuf. Falls back to OTEL_EXPORTER_OTLP_PROTOCOL.
OTEL_EXPORTER_OTLP_TRACES_TIMEOUTString(none)Trace SDK timeout in milliseconds, overriding OTEL_EXPORTER_OTLP_TIMEOUT. Not forwarded by the controller.
OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENTStringNO_CONTENTSPAN_ONLY records prompts and responses on agent spans. NO_CONTENT disables capture. Managed runtimes support these two modes; standalone Python ADK also recognizes SPAN_AND_EVENT. Captured content may be sensitive.
OTEL_LOGS_EXPORTERString(none)Log exporter, otlp or none. Managed runtime export requires explicit otlp and an endpoint; unset disables forwarding. Standalone SDKs may default to otlp.
OTEL_METRICS_EXPORTERString(none)Metric exporter, otlp or none. Managed runtime export requires explicit otlp and an endpoint; unset disables forwarding. Standalone SDKs may default to otlp.
OTEL_PROPAGATORSStringtracecontextSDK trace propagators. Kagent defaults to W3C tracecontext without baggage and supplies that default to managed runtimes.
OTEL_RESOURCE_ATTRIBUTESString(none)Comma-separated SDK resource attributes for the current process. Helm injects controller identity; kagent constructs runtime identity separately. Use KAGENT_OTEL_RESOURCE_ATTRIBUTES for attributes shared with managed agents.
OTEL_SDK_DISABLEDStringfalseDisable SDK telemetry and forwarding to managed runtimes when true (case-insensitive). Other values are treated as false.
OTEL_SEMCONV_STABILITY_OPT_INStringgen_ai_latest_experimentalPython Google ADK semantic-convention opt-in; set by kagent when absent.
OTEL_SERVICE_NAMEString(none)SDK service name for the current process. Defaults to kagent-controller in the controller; the controller supplies the agent name to managed runtimes.
OTEL_TRACES_EXPORTERString(none)Trace exporter, otlp or none. Managed runtime export requires explicit otlp and an endpoint; unset disables forwarding. Standalone SDKs may default to otlp.
SAP_AI_CORE_CLIENT_IDString(none)OAuth2 client ID for SAP AI Core authentication.
SAP_AI_CORE_CLIENT_SECRETString(none)OAuth2 client secret for SAP AI Core authentication.

Database

Both the kagent controller and kagent db read these variables. The controller takes its connection settings from Helm, so set these directly only when you run a database command outside of the cluster.

VariableTypeDefaultDescription
KAGENT_DATABASE_VECTOR_ENABLEDBooleanfalseEnable vector database migrations and vector-backed database functionality. The controller defaults to false. When unset in the CLI, migrations read the controller ConfigMap and fall back to true if it is unavailable.
KAGENT_POSTGRES_DATABASE_MAX_CONNSIntegerGreater of 4 and number of CPUsMaximum size of the PostgreSQL connection pool
KAGENT_POSTGRES_DATABASE_MAX_CONN_IDLE_TIMEDuration30m0sDuration after which an idle connection will be automatically closed
KAGENT_POSTGRES_DATABASE_MAX_CONN_LIFETIMEDuration1h0m0sDuration since creation after which a connection will be automatically closed
KAGENT_POSTGRES_DATABASE_MIN_CONNSInteger0Minimum size of the PostgreSQL connection pool
KAGENT_POSTGRES_DATABASE_URLStringpostgres://postgres:kagent@kagent-postgresql.kagent.svc.cluster.local:5432/postgresPostgreSQL connection URL. The default applies only to the controller; kagent db requires this variable or –db-url. Helm supplies its configured connection URL.
KAGENT_POSTGRES_DATABASE_URL_FILEString(none)File containing the PostgreSQL connection URL; takes precedence over KAGENT_POSTGRES_DATABASE_URL in the controller.
KAGENT_SKIP_MIGRATIONSBooleanfalseVerify required database migrations at startup without applying them.

CLI

The kagent command line tool reads these variables from the environment that it runs in. Each one has an equivalent flag where the command takes a flag, and the flag wins when both are set.

VariableTypeDefaultDescription
ANTHROPIC_API_KEYString(none)API key for Anthropic.
AZURE_OPENAI_API_KEYString(none)API key for Azure OpenAI.
GEMINI_API_KEYString(none)Fallback Gemini API key when GOOGLE_API_KEY is unset; supported by the CLI and Go/Python ADKs.
GOOGLE_API_KEYString(none)API key for Google Gemini.
KAGENT_DATABASE_VECTOR_ENABLEDBooleanfalseEnable vector database migrations and vector-backed database functionality. The controller defaults to false. When unset in the CLI, migrations read the controller ConfigMap and fall back to true if it is unavailable.
KAGENT_DEFAULT_MODEL_PROVIDERStringopenAIDefault LLM provider for agents (e.g. openAI, anthropic, ollama, azureOpenAI).
KAGENT_HELM_EXTRA_ARGSString(none)Additional arguments to pass to Helm commands.
KAGENT_HELM_REPOStringoci://ghcr.io/kagent-dev/kagent/helm/Helm repository URL for kagent charts.
KAGENT_HELM_VERSIONString(none)Helm chart version to deploy. When unset, the CLI uses its own version.
KAGENT_LOG_LEVELStringinfoLogging level for the controller, CLI, and Go/Python runtimes, including the Python ADK HTTP server: debug, info, warn, or error. Python also accepts standard Python logging levels.
KAGENT_POSTGRES_DATABASE_URLStringpostgres://postgres:kagent@kagent-postgresql.kagent.svc.cluster.local:5432/postgresPostgreSQL connection URL. The default applies only to the controller; kagent db requires this variable or –db-url. Helm supplies its configured connection URL.
KUBECONFIGString(none)Kubernetes client configuration file list for the controller, CLI Kubernetes operations, and tests. When unset, client-go uses its normal in-cluster or user kubeconfig discovery.
OLLAMA_API_KEYString(none)API key for Ollama Cloud. When set, a cloud-tagged model reaches api.ollama.com directly.
OPENAI_API_KEYString(none)API key for OpenAI. Upgrade tests fall back to a placeholder when unset or empty.

UI

The UI container and the Vite development server read these variables. Values prefixed KAGENT_UI_ that reach the browser are public, so none of them can carry a secret.

VariableTypeDefaultDescription
KAGENT_UI_API_BASE_URLString/apiBrowser API base URL for UI containers and Vite development.
KAGENT_UI_BASE_PATHString(none)UI public path prefix, such as /ui; empty serves at the root. Applies in containers and Vite development; the container falls back to the root for invalid or reserved prefixes.
KAGENT_UI_DEV_CONTROLLER_URLStringhttp://127.0.0.1:8083Vite development proxy target for /api and /a2a; not sent to the browser.
KAGENT_UI_ENABLE_MOCKBooleanfalseServe the development UI from in-browser fixtures when true. Overrides backend settings; no user is signed in. Release bundles do not include the mock backend.
KAGENT_UI_EXTENSION_<NAME>String(none)UI extension settings forwarded to the browser at runtime. Each installed extension owns its keys and defaults; these values are public.
KAGENT_UI_SSO_REDIRECT_PATHString/oauth2/startUI path used by Sign in with SSO.
KAGENT_UI_STREAM_TIMEOUT_MSString1800000UI chat stream inactivity timeout in milliseconds. 0 disables the timeout. Applies in containers and Vite development.
KAGENT_UI_VITE_API_MODEString(none)Build-time API mode override, mock or live, used by UI tests. Overrides KAGENT_UI_ENABLE_MOCK; leave unset for normal development.
KAGENT_UI_VITE_EXAMPLE_EXTENSIONBooleanfalseBuild-time switch enabling the bundled example UI extension.