New Ory Agent Security is now live! Claim your complimentary test drive. Get Started!

Skip to main content

Configure and secure Ory Console Lite

Ory Console Lite is a single stateless container. It owns no database and holds no configuration file — everything it knows comes from environment variables you pass at startup: the URLs of your Ory Kratos Identities, Ory Hydra Authorization, and Ory Keto Permissions APIs, plus a few optional settings.

Environment variables​

VariableEnables
ORY_KRATOS_URLOry Kratos admin API. User management, sessions, and message delivery.
ORY_KRATOS_PUBLIC_URLOry Kratos public API. Creating an identity, which reads the schema.
ORY_HYDRA_URLOry Hydra admin API. OAuth2 client management.
ORY_KETO_READ_URLOry Keto read API. Viewing relationships. Set it together with ORY_KETO_WRITE_URL, or set neither.
ORY_KETO_WRITE_URLOry Keto write API. Creating, editing, and deleting relationships. Set it together with ORY_KETO_READ_URL, or set neither. Without it, Permissions reports itself as enabled but every write fails.
CSRF_TOKEN_SECRETOptional. At least 32 characters. If you do not set it, or set it to fewer than 32 characters, Ory Console Lite generates an ephemeral secret at startup, and tokens issued before a restart stop being accepted after the restart.
NODE_EXTRA_CA_CERTSOptional. Path to a CA bundle, for admin APIs served with a certificate from a private authority.
PORTOptional. Port the Ory Console Lite listens on. Defaults to 3000.

At least one of ORY_KRATOS_URL, ORY_HYDRA_URL, ORY_KETO_READ_URL, or ORY_KETO_WRITE_URL must be set, or Ory Console Lite will not serve. Each value must be an http or https URL including the scheme; the port is optional and defaults to the one implied by the scheme: 80 for http and 443 for https.

warning

ORY_KRATOS_PUBLIC_URL is not one of the URLs that satisfies that requirement. If you set ORY_KRATOS_PUBLIC_URL alone, Ory Console Lite will not serve. If you don't set it, Ory Console Lite starts cleanly but cannot create identities.

How Ory Console Lite reaches your services​

Ory Console Lite resolves the services' URLs from inside its own network. They never reach the browser: every request the browser makes goes to Ory Console Lite's own origin under /api/oss/, and Ory Console Lite forwards it. That means your admin APIs need no CORS configuration and never have to be reachable from your users' browsers.

It also means the URLs are resolved from inside the container. http://localhost:4434 points Ory Console Lite at itself. Use a hostname that resolves on Ory Console Lite's own network — a Docker service name, a Kubernetes service, or an internal DNS name.

Configure only the services you run​

Ory Console Lite adapts to the Ory services you configure. Leave a service out and its features are switched off. Nothing breaks, and there is nothing to turn on or off.

The Ory Console Lite sidebar with the OAuth 2 and Permissions entries greyed out

With only ORY_KRATOS_URL and ORY_KRATOS_PUBLIC_URL set, Get started, Activity, User management, and Settings work as usual, while OAuth 2 and Permissions are greyed out. Hovering over one shows why — for example, Ory Hydra is not configured. Opening the URL directly shows a not found page.

The feature table lists which service drives which feature.

Next steps​

  • Security — Ory Console Lite has no authentication of its own, so run it behind something that does
  • Troubleshooting — fixes for startup failures, unreachable services, and disabled features
  • Quickstart — run Ory Console Lite against your Ory deployment
  • Ory Console Lite overview — what Ory Console Lite manages, and what stays in your configuration files
Professional support?

Ory offers support for self-hosted Ory software through the Ory Enterprise License (OEL). Read more about the OEL here.