Skip to content

Environment Variables

Environment variables must be specified before running the POS Docker container. The variables control how several options are configured, and how POS server components are run.

Environment variables are typically passed to a Docker container as a .env.docker file.

This topic describes the purpose of each environment variable.

Annotated Example

The following is a sample .env.docker file.

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
# ---------------------------------------------------------------------
#  Site Installation
#
#  NOTE: These values are used during initial configuration. They
#  should not be changed after the first container start.
# ---------------------------------------------------------------------

# The unique site key for this installation. Each installation within
# an organization MUST have a unique site key. This value is used to
# seed database identifiers. Values must be between 1 and 1000. The
# Corporate site key is typically 999, but this is a convention only.

POS_SITE_KEY=1 

# The site role applied automatically on first container start. This
# should be one of:
#  - Store - operate as a Store site.
#  - Corp (Corporate) - operate as a Corporate site.
#  - Both (Combined) - operate as a combined Corporate and Store site.

POS_SITE_MODE=Both

# The credentials to admin (super-user) account used to manage the
# RMS tenant that is created on first run. The password must meet
# Identity complexity rules (upper, lower, digit, symbol, >= 8 chars).

POS_RMS_ADMIN_USER=admin
POS_RMS_ADMIN_PASSWORD=Change_Me_Adm1n!
POS_RMS_ADMIN_EMAIL=admin@yourco.com

# The default title to display within the RMS web application. Once
# installed, this value can be changed within the RMS admin settings.

POS_RMS_SITE_TITLE=Kensium RMS

# The organization's primary time zone of operation. This value is
# REQUIRED and must be set to a valid IANA time zone name (e.g.
# "America/New_York"). Note that RMS will fail to start if this value
# is empty or invalid.
# IMPORTANT - the same time zone MUST be used across all sites within
# an organization. This requirement is a limitation of the current
# POS database design and reliance on local date/times.

POS_TIME_ZONE=


# ---------------------------------------------------------------------
#  Database
# ---------------------------------------------------------------------

# Specify "host,port", e.g. "sqlhost,1433", to indicate the external
# host *if* hosting the SQL Server on an external database server
# instead of the default SQL Server container. This is optional and
# can be left empty to indicate the default SQL Server container
# should be used.

# An external server is typically set when upgrading an existing
# POS installation that already has a SQL Server database, or when
# the client has a policy of hosting databases on a separate server.
# If you do specify an external host, the target database and the
# admin/app logins below must ALREADY EXIST on that host (nothing
# provisions them for you).
# IMPORTANT: to actually skip the built-in container you must
# also layer the external override file:
#  docker compose -f docker-compose.yml -f docker-compose.external-db.yml up --build -d

POS_DB_EXTERNAL_HOST=

# Admin user for the database host, used for database creation
# and migration. For the built-in container, this value should
# always be 'sa'. For an external database, this can be 'sa' but
# can also be a different user with sufficient privileges to create
# databases and users.

POS_DB_ADMIN_USER=sa

# Admin password for the database host, used for database creation
# and migration. Note that password may need to match SQL Server
# complexity rules (particularly for the 'sa' user). Complexity
# rules typically require at least 8 characters, including upper-case,
# lower-case, a digit and a symbol.

POS_DB_ADMIN_PASSWORD=Change_Me_Str0ng!

# Credentials for the database user that accesses the POS and RMS
# databases. This user should not have administrative privileges,
# with only the necessary privileges to operate the application.
# By convention we use the 'kensium_app' user for new installations,
# but this might be different if upgrading an existing installation.

POS_DB_USER=kensium_app
POS_DB_PASSWORD=Change_Me_Str0ng!

# Name of the POS database - the database that contains all POS
# inventory, transactional and other data. Unlike previous POS
# versions, this database no longer stores tables related to RMS
# (see next). If upgrading an existing POS installation that
# already has a single combined database, set this to the existing
# database name so that POS data is retained.

POS_DB_APP_DATABASE=kensium_pos

# Name of the RMS database - the database that contains the RMS
# configuration and preferences. This data is no longer stored in
# the POS database, and the database can be dropped to re-create the
# RMS shell without affecting POS data. If upgrading an existing
# POS installation that already has a single combined database,
# set this to a **new** database name.

POS_DB_RMS_DATABASE=kensium_rms


# ---------------------------------------------------------------------
#  HTTPS Certificate
# ---------------------------------------------------------------------

# Folder ON YOUR machine that holds "kensium-rms.pfx" (created via
# the command in README.Docker.md). Use forward slashes. Replace
# <YOUR_USER> with your Windows user name,
# e.g. C:/Users/jdoe/.aspnet/https
DOMAIN=client1.kensiumpos.com 
WILDCARD_DOMAIN=*.client1.kensiumpos.com
CLOUDFLARE_ZONE_ID=<cloudflare-zone-id>
LETSENCRYPT_EMAIL=<email-address>

POS_SSL_CERT_DIR=C:/Users/<YOUR_USER>/.aspnet/https

# Must match the -p password you used when creating the .pfx.

POS_SSL_CERT_PASSWORD=Change_Me_Cert_Pw


# ---------------------------------------------------------------------
#  Open Telemetry (OTEL) and logging
# ---------------------------------------------------------------------

# OTEL collector endpoint. This can be specified if the client is
# running their own OTEL infrastructure. Otherwise (if empty), a
# container will be started to run a default OTEL collector and
# dashboard environment.

POS_OTEL_EXTERNAL_OTLP_ENDPOINT=

# OTEL HTTP header, used for for authenticating with the OTEL
# collector endpoint. This should be specified if
# POS_OTEL_EXTERNAL_OTLP_ENDPOINT is specified. Otherwise
# (if empty), a security header appropriate to the default
# container collector will be used.

POS_OTEL_EXTERNAL_OTLP_HEADER=

# OTEL dashboard endpoint. This should be specified if
# POS_OTEL_EXTERNAL_OTLP_ENDPOINT is specified, and should
# indicate the URL to the Open Telemetry dashboard.
# Otherwise (if empty), the default container dashboard will
# be used.

POS_OTEL_EXTERNAL_DASHBOARD=

# Redact personal-identifying-information (PII) in log and
# telemetry data. This redaction may be enabled depending on
# client IT policies and/or privacy regulations of the
# jurisdiction(s) where clients are operating. This is
# usually disabled in test, demo and staging environments to
# allow for easier diagnostics. Set to '0' to disable.
# Other values (e.g. '1') are treated as 'enabled'.

POS_LOG_REDACT_PERSONAL_DATA=0

# Redact sensitive data (e.g. passwords, API keys) in log and
# telemetry data. This should **always** be enabled in client
# environments. It can be **temporarily** disabled for debugging
# and extended diagnostics of staging and test environments during
# initial configuration. Set to '0' to disable.
# Other values (e.g. '1') are treated as 'enabled'.

POS_LOG_REDACT_SENSITIVE_DATA=1


# ---------------------------------------------------------------------
#  Other
# ---------------------------------------------------------------------

# Optional. Base URL of the Register (WASM POS) app. Leave EMPTY for
# normal deployments: the Register app is served by the RMS server
# itself under /app/ (same-origin), so the URL is derived and CORS
# needs no extra origin. Set it only for split-origin setups
# (Register on a different host).

POS_APP_REGISTER_URL=

# The API keys to the **Kensium** Stripe Platform. These keys belong
# to Kensium, and are used to associate merchant accounts to the
# Kensium Stripe platform. These keys are not changed across our
# clients or their installations (and they are not included in
# this example file, which is committed to source control).

POS_STRIPE_PUBLISHABLE_KEY=
POS_STRIPE_SECRET_KEY=

Additional Reference

TODO add clarifications as needed