Configuration and variables
Reference expressions, credentials, ports, and retention.
Railway variable inventory
Source: variables.json in the template repository. secret(...) expressions are Railway template generators, not literal passwords. During manual setup, generate independent values with the lengths in the inventory and enter them directly in Railway. Never commit resolved values.
{
"Elasticsearch": {
"RAILWAY_RUN_UID": "0",
"ELASTIC_PASSWORD": "${{secret(48)}}",
"KIBANA_PASSWORD": "${{secret(48)}}",
"LOGSTASH_PASSWORD": "${{secret(48)}}",
"PORT": "8081"
},
"Logstash": {
"INPUT_PASSWORD": "${{secret(48)}}",
"RAILWAY_RUN_UID": "0",
"ELASTICSEARCH_URL": "http://${{Elasticsearch.RAILWAY_PRIVATE_DOMAIN}}:9200",
"ELASTICSEARCH_READY_URL": "http://${{Elasticsearch.RAILWAY_PRIVATE_DOMAIN}}:8081/ready",
"LOGSTASH_PASSWORD": "${{Elasticsearch.LOGSTASH_PASSWORD}}",
"PORT": "9600"
},
"Kibana": {
"ELASTICSEARCH_URL": "http://${{Elasticsearch.RAILWAY_PRIVATE_DOMAIN}}:9200",
"KIBANA_PASSWORD": "${{Elasticsearch.KIBANA_PASSWORD}}",
"SECURITY_KEY": "${{secret(64)}}",
"SAVED_OBJECTS_KEY": "${{secret(64)}}",
"REPORTING_KEY": "${{secret(64)}}",
"PORT": "8082"
}
}RAILWAY_RUN_UID=0 supports startup provisioning. The service startup scripts drop to the runtime user. Preserve the configured volume paths and permissions.
Credentials and encryption keys
| Variable | Purpose |
|---|---|
ELASTIC_PASSWORD | Elasticsearch administrator and initial Kibana login |
Elasticsearch KIBANA_PASSWORD | Dedicated Kibana system identity |
Elasticsearch LOGSTASH_PASSWORD | Restricted Elasticsearch writer |
Logstash INPUT_PASSWORD | Producer Basic auth password for shipper |
SECURITY_KEY | Kibana security encryption |
SAVED_OBJECTS_KEY | Kibana saved object encryption |
REPORTING_KEY | Kibana reporting encryption |
Changing a Railway password variable does not rotate a persisted Elasticsearch user. Use the rotation procedure in OPERATIONS.md. Retain original secrets and encryption keys with protected recovery records.
Optional lifecycle variables
Set these on Elasticsearch before provisioning a new volume:
| Variable | Default | Accepted form |
|---|---|---|
LOG_RETENTION | 7d | Positive integer with d, h, m, or s; or forever |
LOG_ROLLOVER_SIZE | 1gb | Positive integer with mb or gb |
Source: elasticsearch/lifecycle.py. Rollover also occurs at configured maximum age 1d. Deletion age is measured after rollover, not per event. ILM polling can delay deletion. Retention limits age, not total disk occupancy.
Variables do not silently rewrite the policy on existing installations. Update /_ilm/policy/elk_logs deliberately with a backup and recovery plan. Existing fixed indices are preserved.
Ports and capacity
See Architecture for service ports and Quickstart for healthchecks. PORT identifies readiness or management, not always the user-facing interface.
Queue and DLQ ceilings are configured in logstash/logstash.yml. JVM heap values are in the Dockerfiles. These are configuration choices, not measured capacity guarantees. Measure your workload before changing resource settings.