Redrive

Configuration

Redrive reads each setting in this order: CLI flag, then environment variable, then built-in default.

SettingCLIEnvDefault
Port--portREDRIVE_PORT5100 (falls back to an OS-assigned port if taken, and prints it)
Bind host--hostREDRIVE_HOSTlocalhost
Auth password—REDRIVE_PASSWORDunset
Data directory--data-dirREDRIVE_DATA_DIRper platform, listed below
Open browser--no-browser to disableREDRIVE_NO_BROWSER=1opens on start
Batch limit—REDRIVE_REDRIVE_BATCH_LIMIT100
Scan depth—REDRIVE_REDRIVE_SCAN_DEPTH1000
Update check—REDRIVE_NO_UPDATE_CHECK=1 to disableon
Update check URL—REDRIVE_UPDATE_CHECK_URLhttps://get.redrive.dev/latest.json
License key—REDRIVE_LICENSE_KEYunset
Licensing server—REDRIVE_LICENSING_URLhttps://licensing.redrive.dev

The batch limit caps messages moved per run, and the scan depth caps messages read while matching; both apply to redrives and discards alike. Redriving describes how each limit plays out during a run.

REDRIVE_PASSWORD is deliberately the only way to set the password. A --password flag would end up in your shell history and in the process list, where anything running ps aux can read it.

Data directory

PlatformLocation
Windows%LOCALAPPDATA%\redrive
Linux~/.local/share/redrive (honors $XDG_DATA_HOME)
macOS~/Library/Application Support/redrive
Docker/data

What's in it:

  • redrive.db, the SQLite database: connections, saved filters, everything except message content.
  • dataprotection-keys/, the keys that encrypt broker credentials at rest.
  • logs/, daily log files.

The update check

On startup, and every 24 hours after that, Redrive makes an HTTP request to https://get.redrive.dev/latest.json to see whether a newer version is out. That request is all Redrive sends; it carries no identifiers and no details about your setup. The privacy policy has the full picture.

Set REDRIVE_NO_UPDATE_CHECK=1 to turn the check off, or set REDRIVE_UPDATE_CHECK_URL to point it at a different URL.

License activation

A paid license activates in the app, or hands-free for Docker and IaC: set REDRIVE_LICENSE_KEY and Redrive activates itself on boot if it isn't activated already. Changing the variable to a different key re-enrolls the install with it — on the next restart, or within a day on a running install; the current license keeps working until the new key is accepted. Clearing the variable changes nothing: the install stays activated. Like the password, the key is env-only by design.

Activation and the daily license heartbeat make outbound HTTPS requests to one hostname: licensing.redrive.dev. That is the only egress a licensed install needs. An install that can't reach the licensing server keeps its paid features for 14 days and falls back to the free tier after that; everything free keeps working regardless. The privacy policy lists exactly what an activated install transmits — and broker data is never on the list.

REDRIVE_LICENSING_URL exists for networks that route egress through their own gateway. It must point at a host root (https://host, no path): Redrive addresses /v1/... on it directly, so a sub-path reverse proxy would misroute every request.

Next

Continue to Deployment to run Redrive in Docker or as a shared team instance.