Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Appendix C: Container Environment Variables

Prev Next

This section lists the runtime environment variables that you can set before deploying the Nok Nok S3 Servers in Step 2. Modifying these variables is optional, since the CDT provides default values that work out of the box. Edit the hidden ${NN_CDT_HOME}/nns3/.env file to make change.

Log4J2

Name

Description

NN_LOGS_DIR

Path within the container. Use when the log target NN_LOG4J2_TARGET is set to file.

If this is not defined, the Authentication Server, API Server, Admin Server, and Tutorial App Server containers use ${CATALINA_HOME}/logs directory as the logs directory.

The default location in the CLI container is ${NNL_INSTALL_DIR}/logs.

By default, the docker-compose file bind-mounts the logs directory to NN_CDT_HOME/nns3/logs directory on the Docker host system.

Make sure that the NN_UID and NN_GID have write permissions on the host bind-mounted directory. Use the 'chmod -R a+w' on the bind-mounted host directory for this.

NN_API_SERVER_LOG_LEVEL

NN_ADMIN_SERVER_LOG_LEVEL

NN_AUTH_SERVER_LOG_LEVEL

NN_CLI_LOG_LEVEL

Choices: OFF, FATAL, ERROR, WARN, INFO, DEBUG, TRACE

Default: ERROR

Refer to Log4j2 documentation

NN_LOG4J2_DATETIME_FORMAT

Refer to Log4j2 documentation

Default: {ISO8601}{UTC}

NN_LOG4J2_LAYOUT

Choices: json, text

Default: text

NN_LOG4J2_TARGET

Choices: file, stdout

Default: file

NN_ENABLE_ACCESS_LOG

Choices: true, false

Default: false

NN_ACCESS_LOG_REQUEST_HEADER_FILTER

Choices: postman-token,host,accept-encoding,path

Default: blank

JRE and Tomcat

Name

Description

JAVA_OPTS

Optional. No default.

CATALINA_OPTS

Optional. No default.

CATALINA_JMX_PORT

Used when JMX monitoring agent is enabled

Default: 8081

Authentication Server

Name

Description

NN_AUTH_SERVER_LOG_LEVEL

See Log4J2

NN_AUTH_SERVER_HTTP_SERVICE_URL

The docker-compose service name should be used as the hostname for auth server

Default: http://auth-server:8080

NN_AUTH_SERVER_HTTP_LISTENER_URL

Default: http://localhost:8080

NN_POLICY_CACHE_EXPIRY_TIME_SECONDS

Policy cache expiry time in seconds. A value of -1 disables eviction based on time.

NN_POLICY_CACHE_MAX_SIZE

The maximum number of policy entries allowed in the cache.

NN_POLICY_UPDATE_POLL_INTERVAL_SECONDS

Poll interval for policy updates.

NN_OOB_LIST_AUTH_ENABLED

Enables the LIST_OOB_AUTH operation that allows the user to manage pending authentications.

NN_SMTP_HOST_ALLOWLIST

SMTP host allowlist of allowed email servers that the administrator can use to authenticate a user with email OTP.

API Server

Name

Description

NN_API_SERVER_LOG_LEVEL

See Log4J2

NN_API_SERVER_HTTP_EXTERNAL_URL

This URL is accessible from a browser or a mobile

device. Set this to where the TLS is terminated.

Default: https://nns3-api.noknokeval.com:9443

If you changed the CDT Deployment Profile, the URL

will be https://<subdomain-prefix>-api.<wildcarddomain>:9443

NN_API_SERVER_HTTP_SERVICE_URL

Docker Compose service name is used as the hostname

Default: https://api-server:8443

NN_AUTH_SERVER_HTTP_LISTENER_URL

Default: https://localhost:8443

Admin Server

Name

Description

NN_ADMIN_SERVER_LOG_LEVEL

See Log4J2

NN_ADMIN_SERVER_HTTP_EXTERNAL_URL

This URL is accessible from a browser or a mobile device. Set this to where the TLS is terminated.

Default: https://nns3-admin.noknokeval.com:8443

If you changed the CDT Deployment Profile, the URL will be https://<subdomain-prefix>-admin.<wildcarddomain>:8443

NN_ADMIN_SERVER_HTTP_SERVICE_URL

Docker Compose service name is used as the hostname.

Default: https://admin-server:8443

NN_ADMIN_SERVER_HTTP_LISTENER_URL

Default: https://localhost:8443

Optional Webapps

Name

Description

NN_OPTIONAL_WEBAPPS_HTTP_EXTERNAL_URL

This URL is accessible from a browser or a mobile device. Set this to where the TLS is terminated.

Default: https://nns3-optional-webapps.noknokeval.com:8443

If you changed the CDT Deployment Profile, the URL will be https://<subdomain-prefix>-optional-webapss.<wildcarddomain>:8443

NN_OPTIONAL_WEBAPPS_HTTP_SERVICE_URL

Docker Compose service name is used as the hostname.

Default: https://optional-webapps:8443

NN_OPTIONAL_WEBAPPS_HTTP_LISTENER_URL

Default: https://localhost:8443

Operational Database Configuration

Name

Description

NN_AUTHDB_TYPE

Choices: mysql, postgres, oracle, or cockroachdb

Default: postgres

NN_AUTHDB_JDBC_DRIVER_CLASS

Java JDBC driver class name

Defaults

PostgreSQL: org.postgresql.Driver

MySQL: com.mysql.cj.jdbc.Driver

Oracle: oracle.jdbc.driver.OracleDriver

CockroachDB: org.postgresql.Driver

NN_AUTHDB_JNDI_JDBC_URL

Java JDBC JNDI URL to connect to the database

NN_AUTHDB_HOST

This should be the service name used in the docker compose file if the database instance is provisioned using CDT. For the BYODb instance, set this to the hostname of the database instance.

Default: nnauthdb

NN_AUTHDB_PORT

Port where the database instance is listening for connections.

Defaults:

PostgreSQL: 5432

MySQL: 3306

Oracle: 1521

CockroachDB: 26257

NN_AUTHDB_NAME

Database name

Default: nnauthdb

NN_AUTHDB_USER_NAME

Database user name

Default: nnauthdbuser

NN_AUTHDB_USER_PASSWORD

Database user password

DB_ADDITIONAL_PROPS_ENV

Additional JDBC connection properties, if required for the operational database.