# MySQL Configuration MYSQL_ROOT_PASSWORD=change_this_root_password MYSQL_DATABASE=fleet MYSQL_USER=fleet MYSQL_PASSWORD=change_this_fleet_password # Fleet Server Configuration # Generate a random key with: openssl rand -base64 32 FLEET_SERVER_PRIVATE_KEY=change_this_private_key # Fleet HTTP Listener Configuration FLEET_SERVER_ADDRESS=0.0.0.0 FLEET_SERVER_PORT=1337 # TLS Configuration # Set to 'true' if Fleet handles TLS directly (requires certificates in ./certs/) # Set to 'false' if using a reverse proxy or load balancer for TLS termination FLEET_SERVER_TLS=false # TLS Certificate paths (only needed if FLEET_SERVER_TLS=true) FLEET_SERVER_CERT=/fleet/fleet.crt FLEET_SERVER_KEY=/fleet/fleet.key # Fleet License (optional - leave empty for free tier) FLEET_LICENSE_KEY= # Fleet Session & Logging FLEET_SESSION_DURATION=24h FLEET_LOGGING_JSON=true # Fleet Osquery Configuration FLEET_OSQUERY_STATUS_LOG_PLUGIN=filesystem FLEET_FILESYSTEM_STATUS_LOG_FILE=/logs/osqueryd.status.log FLEET_FILESYSTEM_RESULT_LOG_FILE=/logs/osqueryd.results.log FLEET_OSQUERY_LABEL_UPDATE_INTERVAL=1h # Fleet Vulnerabilities FLEET_VULNERABILITIES_CURRENT_INSTANCE_CHECKS=yes FLEET_VULNERABILITIES_DATABASES_PATH=/vulndb FLEET_VULNERABILITIES_PERIODICITY=1h # S3 Configuration (optional - leave empty if not using S3) FLEET_S3_SOFTWARE_INSTALLERS_BUCKET= FLEET_S3_SOFTWARE_INSTALLERS_ACCESS_KEY_ID= FLEET_S3_SOFTWARE_INSTALLERS_SECRET_ACCESS_KEY= FLEET_S3_SOFTWARE_INSTALLERS_FORCE_S3_PATH_STYLE= FLEET_S3_SOFTWARE_INSTALLERS_ENDPOINT_URL= FLEET_S3_SOFTWARE_INSTALLERS_REGION=