Configuration
Redrive reads each setting in this order: CLI flag, then environment variable, then built-in default.
| Setting | CLI | Env | Default |
|---|---|---|---|
| Port | --port | REDRIVE_PORT | 5100 (falls back to an OS-assigned port if taken, and prints it) |
| Bind host | --host | REDRIVE_HOST | localhost |
| Auth password | — | REDRIVE_PASSWORD | unset |
| Data directory | --data-dir | REDRIVE_DATA_DIR | per platform, listed below |
| Open browser | --no-browser to disable | REDRIVE_NO_BROWSER=1 | opens on start |
| Batch limit | — | REDRIVE_REDRIVE_BATCH_LIMIT | 100 |
| Scan depth | — | REDRIVE_REDRIVE_SCAN_DEPTH | 1000 |
| Update check | — | REDRIVE_NO_UPDATE_CHECK=1 to disable | on |
| Update check URL | — | REDRIVE_UPDATE_CHECK_URL | https://get.redrive.dev/latest.json |
| License key | — | REDRIVE_LICENSE_KEY | unset |
| Licensing server | — | REDRIVE_LICENSING_URL | https://licensing.redrive.dev |
The batch limit caps messages moved per run, and the scan depth caps messages read while matching; both apply to redrives and discards alike. Redriving describes how each limit plays out during a run.
REDRIVE_PASSWORDis deliberately the only way to set the password. A--passwordflag would end up in your shell history and in the process list, where anything runningps auxcan read it.
Data directory
| Platform | Location |
|---|---|
| Windows | %LOCALAPPDATA%\redrive |
| Linux | ~/.local/share/redrive (honors $XDG_DATA_HOME) |
| macOS | ~/Library/Application Support/redrive |
| Docker | /data |
What's in it:
redrive.db, the SQLite database: connections, saved filters, everything except message content.dataprotection-keys/, the keys that encrypt broker credentials at rest.logs/, daily log files.
The update check
On startup, and every 24 hours after that, Redrive makes an HTTP request to https://get.redrive.dev/latest.json to see whether a newer version is out. That request is all Redrive sends; it carries no identifiers and no details about your setup. The privacy policy has the full picture.
Set REDRIVE_NO_UPDATE_CHECK=1 to turn the check off, or set REDRIVE_UPDATE_CHECK_URL to point it at a different URL.
License activation
A paid license activates in the app, or hands-free for Docker and IaC: set
REDRIVE_LICENSE_KEY and Redrive activates itself on boot if it isn't
activated already. Changing the variable to a different key re-enrolls the
install with it — on the next restart, or within a day on a running
install; the current license keeps working until the new key is accepted.
Clearing the variable changes nothing: the install stays activated. Like
the password, the key is env-only by design.
Activation and the daily license heartbeat make outbound HTTPS requests to
one hostname: licensing.redrive.dev. That is the only egress a licensed
install needs. An install that can't reach the licensing server keeps its
paid features for 14 days and falls back to the free tier after that;
everything free keeps working regardless. The
privacy policy lists exactly what an activated install
transmits — and broker data is never on the list.
REDRIVE_LICENSING_URL exists for networks that route egress through their
own gateway. It must point at a host root (https://host, no path): Redrive
addresses /v1/... on it directly, so a sub-path reverse proxy would
misroute every request.
Next
Continue to Deployment to run Redrive in Docker or as a shared team instance.