Configuration and variables
Understand generated credentials, shared references, retention and optional email.
Keep template references intact
The template's runtime/*/variables.json files define the Railway wiring. Generated credentials are per-install values. Shared service references should resolve to the same values across Web, consumers and tasks. Do not replace references with secrets in source files.
| Variable | Source or default | Purpose |
|---|---|---|
ADMIN_EMAIL | Web default admin@sentry.local | Initial administrator account |
ADMIN_PASSWORD | Generated by Railway | Initial account password; not a password-reset mechanism |
SENTRY_SYSTEM_SECRET_KEY | Generated by Railway, shared from Web | Stable application secret |
RELAY_KEY_SEED | Generated on Relay | Stable private ingestion identity |
SENTRY_EVENT_RETENTION_DAYS | Web default 7, shared to workers | Indexed event retention and raw object expiry fallback |
PUBLIC_URL | Gateway public domain reference | Canonical interface URL |
INGESTION_URL | Private Gateway URL, port 8081 | Private SDK ingestion address |
WEB_WORKERS | Web default 1 | Web worker count |
TASKWORKER_CONCURRENCY | Tasks default 1 | Taskworker concurrency |
KAFKA_LOG_RETENTION_HOURS | Kafka default 3 | Queue age policy |
These are configuration defaults, not performance targets. Sources: Web variables, Relay variables, Tasks variables, Kafka variables.
Database and storage wiring
POSTGRES_HOST and POSTGRES_PASSWORD reference PostgreSQL. REDIS_HOST and REDIS_PASSWORD reference Valkey. KAFKA_BROKERS, SNUBA, SYMBOLICATOR_HOST, TASKBROKER_HOST and MEMCACHED_HOST connect private backend services.
NODE_* variables reference the Nodestore bucket. FILE_* variables reference Filestore. Their endpoint, bucket, region, access key and secret key references come from Railway. Keep the buckets separate and private. Protect actual generated values and backup copies.
Retention
Keep SENTRY_EVENT_RETENTION_DAYS consistent across the services that reference Web. Invalid retention aborts startup. Raw nodestore writes preserve expiry metadata. Legacy objects without authoritative age metadata remain retained until an operator can establish their age.
Raw expiry, relational cleanup and ClickHouse TTL are independent. Monitor cleanup status and consumer lag. Kafka's queue retention cannot recreate records already deleted. See operations.
Optional SMTP
Email remains disabled while SMTP_HOST is empty. Add these optional variables on Web:
| Variable | Meaning |
|---|---|
SMTP_HOST | Your SMTP provider host |
SMTP_PORT | Provider port; configuration fallback 587 |
SMTP_USER | Provider username |
SMTP_PASSWORD | Provider credential, stored only in Railway variables |
SMTP_TLS | Whether to use TLS; configuration fallback true |
SMTP_FROM | Provider-authorized sender; fallback to ADMIN_EMAIL |
Add matching ${{web.SMTP_*}} references on sentry-consumers and sentry-tasks. Verify invitation and password-reset delivery with your provider. A fallback port does not prove provider compatibility.
Sources: runtime Sentry configuration, operations.
Reset an existing administrator password
Changing ADMIN_PASSWORD does not overwrite an existing user's password. An authenticated Railway operator can run:
railway ssh --service web -- /docker-entrypoint.sh django changepassword EMAILReplace EMAIL with the account email. Enter the new password interactively. Do not pass it as a command-line argument. Keep generated application secrets and Relay identity stable across redeploys.