Skip to main content

Environment Variables

IaC Code reads configuration from CLI arguments, environment variables, and configuration files. The precedence is:

CLI arguments > environment variables > configuration files

Environment variables are useful for CI/CD pipelines, containers, and one-off overrides without editing configuration files.

LLM Configuration

VariableDescription
IAC_CODE_PROVIDERModel provider name (case-insensitive). Valid values: DashScope, DashScope Token Plan, OpenAI, Anthropic, DeepSeek, Gemini, Azure OpenAI, ModelScope, Kimi CN, Kimi Intl, MiniMax CN, MiniMax Intl, ZhiPu CN, ZhiPu Intl, Volcengine CN, SiliconFlow CN, SiliconFlow Intl, Aliyun CodingPlan, Aliyun CodingPlan Intl, ZhiPu CN CodingPlan, ZhiPu Intl CodingPlan, Volcengine CodingPlan, OpenAI Compatible, Anthropic Compatible, OpenRouter, Ollama, LM Studio
IAC_CODE_MODELModel name
IAC_CODE_BASE_URLAPI endpoint for OpenAI Compatible only; ignored (with a warning) for other providers
IAC_CODE_API_KEYProvider API key; overrides the active provider's key in .credentials.yml

See LLM Providers for provider details.

Alibaba Cloud Credentials

VariableDescription
ALIBABA_CLOUD_ACCESS_KEY_IDAccessKey ID
ALIBABA_CLOUD_ACCESS_KEY_SECRETAccessKey Secret
ALIBABA_CLOUD_SECURITY_TOKENSTS token; switches the credential mode to STS when set
ALIBABA_CLOUD_REGION_IDDefault region

See Alibaba Cloud Credentials for more details.

Telemetry

VariableDescription
IAC_CODE_DISABLE_NONESSENTIAL_TRAFFICSet to 1 / true / yes / on to disable non-essential telemetry traffic
DISABLE_TELEMETRYSet to 1 / true / yes / on to disable all telemetry
IAC_CODE_TELEMETRY_ENDPOINTBase OTLP endpoint; individual signal endpoints default to this value
IAC_CODE_TELEMETRY_TRACES_ENDPOINTOverride endpoint for traces
IAC_CODE_TELEMETRY_METRICS_ENDPOINTOverride endpoint for metrics
IAC_CODE_TELEMETRY_LOGS_ENDPOINTOverride endpoint for logs
IAC_CODE_TELEMETRY_HEADERSCustom OTLP headers (JSON or key=value format)

Other

VariableDescription
IAC_CODE_CONFIG_DIROverride the runtime configuration directory (default ~/.iac-code/); supports ~ and $VAR expansion. All persisted artifacts (credentials, settings, history, projects, image cache, skills, telemetry, etc.) follow it
IAC_CODE_LOG_DIROverride the local startup/debug log directory (default <config-dir>/logs/); supports ~ and $VAR expansion. Permission audit records follow the session layout and are not moved by this variable
IAC_CODE_PERMISSION_AUDIT_INCLUDE_TOOL_INPUTOverride permissions.audit.include_tool_input; set to 1 / true / yes / on to include shape-only tool input in permission audit records, using type/length/fingerprint instead of raw business payload strings and fingerprinting non-whitelisted field names
IAC_CODE_ENVDeployment environment label (default: production)
IAC_CODE_TENANT_IDTenant identifier for telemetry; auto-prefixed with iac_tenant_ if not already
IAC_CODE_GIT_BASH_PATHPath to Git Bash bash.exe on Windows when it is not on PATH
IAC_CODE_A2A_PUSH_KEYRINGEnvironment-managed encrypted push secret keyring for A2A (JSON format)
OTEL_EXPORTER_OTLP_ENDPOINTStandard OpenTelemetry endpoint; when set, enables OTLP export
OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENTCapture GenAI message/tool content on spans: SPAN_ONLY, EVENT_ONLY, SPAN_AND_EVENT

Session Backup

VariableDescription
IAC_CODE_CONFIG_BACKUP_DIROptional session backup directory; supports ~ and $VAR expansion, and %VAR% expansion on Windows. In PowerShell, pass a concrete path or let the shell expand $env:VAR before starting iac-code. In sandbox deployments this is commonly an OSS-mounted path, but it must be independent from and not overlap IAC_CODE_CONFIG_DIR or any session source, and should be low latency enough for critical checkpoints. UNC paths, mapped drives, and mounted OSS paths must preserve .backup-lock file locking, atomic replace semantics, and file metadata well enough for incremental mirroring; avoid symlink, junction, or reparse-point ancestry for the active session source, backup root, and mirrored sessions. When enabled, checkpoints mirror each v2 session to <backup>/projects/<project>/<session_id>/ with the same directory shape as the active session; .backup-state.json and .backup-lock stay local and are not copied. Normal chat turn-end backups use normal_turn_end and do not block the response; only critical=true checkpoint failures block publication. Shared A2A task/context indexes can be mounted separately.