Skip to content

Environment Variables ​

Cloud Harness MCP is configured via environment variables supplied to the stateless API, the Runner, and the Cloudflare Worker Gateway.

Copy .env.example to .env and replace all change-me placeholder secrets before starting services.

Configuration Table ​

VariableDefault / ExampleRequired / ModeDescription & Purpose
MCP_BEARER_TOKENchange-me-at-least-32-random-charactersRequiredCopy to .env and replace every change-me value. Never commit real secrets.
RUNNER_TOKENchange-me-independent-runner-tokenRequiredRequired configuration.
OWNER_IDownerRequiredRequired configuration.
AUTH_MODEowner-bearerRequiredowner-bearer (default) or cloudflare-access. In Access mode, remove MCP_BEARER_TOKEN.
CLOUDFLARE_ACCESS_ISSUERhttps://your-team.cloudflareaccess.comOptionalOptional configuration.
CLOUDFLARE_ACCESS_AUDIENCE—OptionalOptional configuration.
CLOUDFLARE_ACCESS_JWKS_URLhttps://your-team.cloudflareaccess.com/cdn-cgi/access/certsOptionalOptional configuration.
API_KEY_AUTH_ENABLEDfalseOptionalOptional managed API-key lane. Enable all four together only in cloudflare-access mode. The gateway audience belongs to a separate Access application scoped exactly to /mcp-api-key.
API_KEY_GATEWAY_ACCESS_AUDIENCE—OptionalOptional configuration.
API_KEY_GATEWAY_SERVICE_SUBJECTcf-service:base64url-cloudflare-service-token-client-idOptionalOptional configuration.
API_KEY_GATEWAY_PUBLIC_URLhttps://api.harness.zuey.me/mcpOptionalOptional configuration.
ACCESS_LEGACY_OWNER_IDownerOptionalWorker-only secrets CF_ACCESS_CLIENT_ID and CF_ACCESS_CLIENT_SECRET are configured with Wrangler, never here. Exact one-time legacy owner binding for the first Access rollout:
ACCESS_LEGACY_ISSUERhttps://your-team.cloudflareaccess.comOptionalOptional configuration.
ACCESS_LEGACY_SUBJECT—OptionalOptional configuration.
ACCESS_PRINCIPAL_RELINKS[]OptionalOptional audited subject-rotation mappings, supplied as strict JSON:
API_PUBLIC_HOSTSlocalhost,127.0.0.1,cloud-harness-mcp.46-250-239-227.sslip.ioRequiredRequired configuration.
API_ALLOWED_ORIGINShttps://cloud-harness-mcp.46-250-239-227.sslip.ioRequiredRequired configuration.
API_PORT3000RequiredRequired configuration.
RUNNER_PORT3001RequiredRequired configuration.
RUNNER_URLhttp://runner:3001RequiredRequired configuration.
MCP_GATEWAY_TIMEOUT_MS30000OptionalMCP gateway (/mcp-gateway) downstream connection bounds and safe defaults.
MCP_GATEWAY_MAX_RESPONSE_BYTES262144OptionalOptional configuration.
MCP_GATEWAY_MAX_TOOLS_PER_SERVER500OptionalOptional configuration.
MCP_GATEWAY_MAX_SCHEMA_BYTES65536OptionalOptional configuration.
MCP_GATEWAY_MAX_CATALOG_BYTES2097152OptionalOptional configuration.
MCP_GATEWAY_MAX_TRACE_ROWS20000OptionalOptional configuration.
MCP_GATEWAY_MAX_CONNECTIONS32OptionalOptional configuration.
MCP_GATEWAY_ALLOW_PRIVATE_ENDPOINTSfalseOptionalLocalhost, loopback, link-local, metadata, and private MCP endpoints are rejected unless the private-endpoint opt-in is enabled. Cleartext http endpoints additionally require both the insecure-http and private-endpoint opt-ins. Both opt-ins are refused in cloudflare-access mode; use https public endpoints there.
MCP_GATEWAY_ALLOW_INSECURE_HTTPfalseOptionalOptional configuration.
MODEL_GATEWAY_SESSION_HEADERx-opencode-sessionOptionalModel gateway provider override. When set, the gateway sends this one upstream header, filled with the calling agent id, to OpenAI-compatible providers that require a conversation identifier (for example x-opencode-session for OpenCode Go). Unset sends no such header. The value must be a lowercase header name the gateway does not set itself.
JOBS_ROOT/var/lib/cloud-harness/jobsRequiredRequired configuration.
STATE_DB/var/lib/cloud-harness/state/cloud-harness.dbRequiredRequired configuration.
ARTIFACT_ROOT/var/lib/cloud-harness/artifactsRequiredRequired configuration.
MAX_ARTIFACT_BYTES16777216RequiredRequired configuration.
MAX_PRINCIPAL_ARTIFACT_BYTES134217728RequiredRequired configuration.
ARTIFACT_RETENTION_SECONDS86400RequiredRequired configuration.
REPO_CACHE_ROOT/var/lib/cloud-harness/cache/reposRequiredRequired configuration.
ENABLE_REPO_CACHEfalseOptionalOptional configuration.
TOOLKIT_CACHE_ROOT/var/lib/cloud-harness/cache/toolkitsRequiredRequired configuration.
ENABLE_TOOLKIT_CACHEtrueOptionalOptional configuration.
TOOLKIT_NETWORK_POLICYcache-onlyOptionalOptional configuration.
BUILTIN_SKILLS_ROOT/var/lib/cloud-harness/skillsOptionalOperator-provided agent skills: the single source for the built-in skills tier. Set to a host directory (absolute) and it is mounted read-only into every executor at /opt/cloud-harness/skills, the worker's highest-precedence tier, and rescanned by the runner from this same directory to attribute that partition. Content is operator-owned: the harness never writes to it and records its provenance as built-in. The mount target stays authoritative on the executor side. This name is reserved, so a workspace environment can never shadow it. Replaces the former CH_BUILTIN_SKILLS_ROOT override: rename that variable to this one, or move the catalog to the mount target. Leave unset to keep the tier empty.
AGENTKIT_REGISTRY_URLhttps://agentkit.bestOptionalLicensed AgentKit kits (toolkits: [{ kind: "agentkit", kitId: "engineer" }]).
AGENTKIT_REGISTRY_CREDENTIAL_SECRETAGENTKIT_REGISTRY_TOKENOptionalThe secret name that holds this principal's AgentKit licence token. The token must start with ak_dev_ or ak_cli_ and MUST be created with purpose=provisioning, never runtime: runtime secrets are injected into executor environments. It is resolved from the dashboard secret store; without it the agentkit toolkit kind fails closed.
AGENTKIT_REGISTRY_KEY_IDagentkit-registry-2026OptionalEd25519 registry signing key id. Required before the agentkit toolkit kind is available.
AGENTKIT_REGISTRY_PUBLIC_KEY<PEM or base64 SPKI DER>OptionalEd25519 registry signing public key (PEM or base64 SPKI DER). Required before the agentkit toolkit kind is available; an unverified manifest is refused.
EXECUTOR_IMAGEcloud-harness-executor:localRequiredRequired configuration.
NETWORK_GUARD_IMAGEcloud-harness-network-guard:localRequiredRequired configuration.
ALLOWED_GIT_HOSTSgithub.comRequiredRequired configuration.
WORKSPACE_NETWORK_PROFILEdependency-accessRequiredExecutor egress for newly opened workspaces. dependency-access (default) permits public DNS and TCP 80/443 so the GitHub API and the bundled gh CLI work; network-none blocks all egress. dependency-access requires a Linux host firewall provisioned via deploy/scripts/setup-dependency-firewall.sh and is refused, never silently downgraded, when that firewall is not attested. The dashboard Settings page overrides this value for future workspaces without a redeploy.
DEPENDENCY_DNS_RESOLVERS8.8.8.8,1.1.1.1OptionalOptional configuration.
DEPENDENCY_BRIDGE_SUBNET172.30.240.0/24OptionalOptional configuration.
DEPENDENCY_BRIDGE_INTERFACEchm-egress0OptionalOptional configuration.
DEPENDENCY_NETWORK_NAMEcloud-harness-dependency-accessOptionalOptional configuration.
WORKSPACE_WALL_TTL_SECONDS900RequiredRequired configuration.
WORKSPACE_IDLE_TTL_SECONDS300RequiredRequired configuration.
MAX_ACTIVE_WORKSPACES_PER_OWNER3RequiredConcurrent active workspaces allowed per principal. Defaults to 3 when unset; set 1 to restore single-workspace behaviour. Each counted workspace can use up to 1 GiB of container memory, one CPU, and 256 pids, so size host memory for this limit times the expected simultaneous builds.
GITHUB_APP_ID—OptionalOptional GitHub App repository access; required fields depend on AUTH_MODE:
GITHUB_APP_INSTALLATION_ID—OptionalRequired in owner-bearer mode; omit in Access mode, where each principal binds an installation:
GITHUB_APP_SLUG—OptionalRequired in Access mode for the installation redirect:
GH_TOKEN—OptionalOptional operator-wide GitHub fallback credential, read from GH_TOKEN (preferred) then GITHUB_TOKEN, each also accepting a _FILE form. Used only by the runner, only when no GitHub App repository token can be minted, and only in owner-bearer mode: an operator-wide credential must never authorize a different principal. In cloudflare-access mode, create a per-principal global runtime secret named GH_TOKEN or GITHUB_TOKEN in the dashboard instead. This credential authenticates harness-side GitHub operations only and is never placed in executor environments. To authenticate the bundled gh CLI inside a workspace, create a global runtime secret named GH_TOKEN or GITHUB_TOKEN.
GITHUB_TOKEN—OptionalOptional configuration.
GITHUB_APP_PRIVATE_KEY_FILE/run/cloud-harness-secrets/github-app-private-key.pemOptionalProduction host file: /etc/cloud-harness-mcp/github-app-private-key.pem
SECRET_KEYRING_FILE/run/cloud-harness-secrets/secret-keyring.jsonOptionalVersioned AES-256-GCM keyring JSON. Prefer the runner-only file form.

Security Guidelines ​

  1. Never commit .env files or tokens into version control.
  2. Runner secrets isolation: RUNNER_TOKEN and SECRET_KEYRING_FILE are passed only to the Runner container, never to the API or workspace executors.
  3. Managed OAuth vs Bearer: When AUTH_MODE=cloudflare-access, remove MCP_BEARER_TOKEN and configure CLOUDFLARE_ACCESS_* variables instead.
  4. Executor Isolation: Executors never inherit host environment variables or control plane tokens.

Released under the MIT License. Single-owner private remote coding harness.