Environment Variables
Every environment variable the EEM agent reads to configure itself. A command-line flag wins, then the primary environment name, then its legacy EEM_* spelling, then the YAML file at /etc/erebine/eem.yaml, then the built-in default. This page documents the environment layer.
Overview
See Config Files for the YAML companion to this reference.
Prefix Split: EREBINE_* vs EEM_*
Every variable on this page is listed under its
primary name, and the agent reads that name first.
Most primary names start with
EREBINE_EEM_; the join key's is
EREBINE_AGENT_JOIN_KEY, the name the
EIM agent also reads.
Most settings also answer to a legacy
EEM_* name, read only when the primary
name is unset or empty. Each row names its legacy
spelling, if it has one. Set the primary name: when
both are set the primary wins, whichever file set
it, so a legacy name in an override file loses to a
primary name set anywhere else.
Rows also name the command-line flag and the
eem.yaml key for the same setting,
where one exists. A setting with no flag or no key
is read from the environment only. The EIM
inference agent uses the
EREBINE_AGENT_* prefix; see
EIM Agent Variables below.
Connection
Where the agent enrolls.
| Name | Default | Purpose |
|---|---|---|
EREBINE_EEM_ROUTER_URL
required
#
|
unset | HTTPS URL of the router the agent
enrolls with. Flag:
--router-url. YAML:
router_url. Legacy:
EEM_ROUTER_URL. |
EREBINE_AGENT_JOIN_KEY
first enrollment
#
|
unset | Enrollment token issued by the router.
Required only until the first enrollment
succeeds: the agent writes
agent-enrollment.json beside
its keys and restores that identity on
every later start, so the key is redeemed
once and can be revoked and the variable
dropped. Remove that file to enroll again,
which needs a fresh key. Flag:
--join-key, which shows the key
to every account on the host in
ps. YAML:
join_key. Legacy:
EEM_JOIN_KEY. |
Identity
How the agent advertises itself to the router.
| Name | Default | Purpose |
|---|---|---|
EREBINE_EEM_REGISTRATION_NAME
required
#
|
unset | Stable display name the router uses
to track this agent across restarts.
Flag: --registration-name.
YAML: registration_name.
Legacy:
EEM_REGISTRATION_NAME. |
Runtime
Concurrency, lease, and lifecycle tuning. A numeric value that is not a whole number is skipped as if unset.
| Name | Default | Purpose |
|---|---|---|
EREBINE_EEM_LEASE_RENEWAL_INTERVAL_MS
#
|
10000 |
Cadence (milliseconds) for lease
renewal messages to the router. No
flag. YAML:
lease_renewal_interval_ms.
Legacy:
EEM_LEASE_RENEWAL_INTERVAL_MS. |
EREBINE_EEM_SHUTDOWN_GRACE_SECONDS
#
|
30 |
Time the agent waits for in-flight
executions to finish on SIGTERM or
SIGINT before forcing exit. No flag.
YAML:
shutdown_grace_seconds.
Legacy:
EEM_SHUTDOWN_GRACE_SECONDS. |
EREBINE_EEM_MAX_CONCURRENT_EXECUTIONS
#
|
20 |
Ceiling on simultaneous tool
executions handled by the agent. No
flag. YAML:
max_concurrent_executions.
Legacy:
EEM_MAX_CONCURRENT_EXECUTIONS. |
EREBINE_EEM_LOG_LEVEL
#
|
info |
Log verbosity. One of
trace, debug,
info, notice,
warning, error,
critical; any other value
logs at info. Flag:
--log-level. YAML:
log_level. Legacy:
EEM_LOG_LEVEL. |
Filesystem Paths
Where the agent reads credentials and declared
workspaces, and stores keys and queue state. Defaults are the Linux paths; on macOS
/var/lib/erebine is
~/.local/state/erebine (the queue file
sits directly in it) and /etc/erebine is
~/.config/erebine.
| Name | Default | Purpose |
|---|---|---|
EREBINE_EEM_CREDENTIALS_DIR
#
|
/var/lib/erebine/credentials |
Directory of per-workspace credential
files referenced by
credentials_ref in tool
manifests. Flag:
--credentials-dir. YAML:
credentials_dir. Legacy:
EEM_CREDENTIALS_DIR. |
EREBINE_EEM_SIGNING_KEY_PATH
#
|
/var/lib/erebine/agent-signing-key.hex |
Persisted Ed25519 signing-key file
used to sign messages to the router.
Flag: --signing-key-path.
YAML: signing_key_path.
Legacy:
EEM_SIGNING_KEY_PATH. |
EREBINE_EEM_CURVE_KEY_PATH
#
|
/var/lib/erebine/agent-curve-key.hex |
Persisted CURVE key-agreement
private-key file. Flag:
--curve-key-path. YAML:
curve_key_path. Legacy:
EEM_CURVE_KEY_PATH. |
EREBINE_EEM_QUEUE_DB_PATH
#
|
/var/lib/erebine/state/queue.sqlite |
SQLite file backing the outbound
dispatch queue; :memory:
keeps the queue for the life of the
process only. No flag. YAML:
queue_db_path. Legacy:
EEM_QUEUE_DB_PATH. |
EREBINE_EEM_WORKSPACES_FILE
#
|
/etc/erebine/workspaces.yaml |
The operator-declared workspaces
document. No flag and no YAML key.
Legacy:
EEM_WORKSPACES_FILE. |
Tool Domains
Which tool domains the agent registers. Both take a comma-separated list and are read from the environment only: no flag and no YAML key.
| Name | Default | Purpose |
|---|---|---|
EREBINE_EEM_DOMAINS
#
|
unset | Tool domains to enable, for example
kubernetes,openstack. When
set, only these domains are registered;
unset registers every domain. Legacy:
EEM_DOMAINS. |
EREBINE_EEM_DISABLE_DOMAINS
#
|
unset | Tool domains to leave out, for
example shell,database,
applied after
EREBINE_EEM_DOMAINS.
Legacy:
EEM_DISABLE_DOMAINS. |
Discovery
Advisory host probes that report candidate workspaces after startup. They configure nothing. Read from the environment only: no flag and no YAML key.
| Name | Default | Purpose |
|---|---|---|
EREBINE_EEM_DISCOVERY_MODE
#
|
off |
off skips the probes;
any other value runs them. Legacy:
EEM_DISCOVERY_MODE. |
EREBINE_EEM_DISCOVERY_ROOTS
#
|
home directory | Colon-separated directories the
git-repository probe searches. Legacy:
EEM_DISCOVERY_ROOTS. |
KUBECONFIG
#
|
~/.kube/config |
Colon-separated kubeconfig files the Kubernetes probe reads. |
Router Callback
Settings that let callback-dependent tools
(for example, deep_think) dial
back into the router. Callbacks present the token
the agent receives at enrollment and refreshes on
its own; there is no token to configure. Until the
agent holds one, or when no project external id is
set, affected tools surface
router_callback_missing rather than
dispatching unauthenticated.
| Name | Default | Purpose |
|---|---|---|
EREBINE_EEM_PROJECT_EXTERNAL_ID
optional
#
|
unset | External project id
(ws_<hex>) attached
to callbacks for project-scoped
routing. No flag. YAML:
project_external_id.
Legacy:
EEM_PROJECT_EXTERNAL_ID. |
Observability
| Name | Default | Purpose |
|---|---|---|
EREBINE_EEM_METRICS_HOST
#
|
127.0.0.1 |
Bind address for the metrics, health and readiness HTTP server. An empty value keeps the default. |
EREBINE_EEM_METRICS_PORT
#
|
9095 |
TCP port for the metrics, health and readiness HTTP server. A value that is not a whole number keeps the default. |
EREBINE_AGENT_LOG_BUFFER_BYTES
#
|
65536 |
Bytes of recent log output the agent
keeps for live log streaming, clamped
to 8192 through
1048576. The EIM agent
reads the same name. |
EIM Agent Variables (Cross-Reference)
The EIM inference agent
(erebine-eim-agent) is a separate
binary that hosts vLLM and uses the
EREBINE_AGENT_* prefix. Subset
listed here; the EIM deployment page linked under
Further Reading
covers the rest.
| Name | Default | Purpose |
|---|---|---|
EREBINE_AGENT_ALLOW_INSECURE
#
|
unset | Set to 1 or
true to allow non-HTTPS
enrollment URLs (development only). |
EREBINE_AGENT_LOG_LEVEL
#
|
info |
Log verbosity for the EIM agent process. |
EREBINE_AGENT_MAX_CONCURRENT
#
|
auto | Optional ceiling on concurrent inference requests. |
EREBINE_AGENT_METRICS_PORT
#
|
9094 |
Prometheus metrics port for the EIM agent. |
EREBINE_AGENT_VLLM_PATH
#
|
PATH lookup | Absolute path to the vLLM binary. |
EREBINE_AGENT_VLLM_SOCKET_PATH
#
|
/tmp/erebine-engine.sock |
Unix socket path used to dial vLLM. |
EREBINE_AGENT_VLLM_SALT_SECRET
#
|
unset | Server secret for tenant-isolated cache keys. |
Precedence
Configuration layers for the EEM agent resolve in this order (later wins):
-
// 1
defaultsBuilt-in constants compiled into the agent. -
// 2
eem.yamlFile values from/etc/erebine/eem.yaml, or the file--confignames. -
// 3
legacy
EEM_*env The legacy spelling, read only when the primary name is unset or empty. -
// 4
primary env
The names this page lists, mostly
EREBINE_EEM_*. -
// 5
CLI flagserebine-eem-agentcommand-line flags.
An empty environment value counts as unset and falls
through to the next layer down. Secrets such as
EREBINE_AGENT_JOIN_KEY should flow
through environment variables or a secrets manager,
not committed YAML.
Further Reading
- EEM Config Files - YAML keys that mirror the variables above.
- EIM Environment Variables - the EIM inference agent's own variables.
No variables match. Press Esc to clear the filter.