Every flag can also be set as CURRAL_<FLAG>, for example
CURRAL_MAX_CONCURRENCY=16. Repeatable flags take a comma-separated list:
CURRAL_POLICY=policy.rego,roles.json. Run curral serve -h for the full
list from your version.
| Flag |
Default |
|
--catalog |
|
extensions, secrets and databases |
--users |
|
users, API keys and identities |
--policy |
|
.rego or JSON/YAML data, repeatable |
--policy-query |
data.curral.allow |
decision that must be true |
--policy-limits-query |
off |
per-request limits, e.g. data.curral.limits |
--policy-masks-query |
off |
column masks, e.g. data.curral.masks |
--row-filters |
off |
row-level security file |
| Flag |
Default |
|
--max-concurrency |
8 |
queries executing at once |
--queue-timeout |
5s |
wait for a slot, then 503 |
--max-concurrency-per-user |
0 |
per-user quota when the policy sets none |
--query-timeout |
60s |
maximum duration, then 504 |
--max-rows |
0 |
rows per response (0 = no limit) |
| Flag |
Default |
|
--threads |
|
DuckDB threads |
--memory-limit |
|
e.g. 8GB |
--temp-dir, --max-temp-size |
|
spill to disk |
--extension-dir |
|
pre-installed extensions (offline) |
--external-access |
false |
keep enable_external_access on |
--allowed-path |
|
path or s3://bucket/ allowed while external access is off, repeatable |
| Flag |
Default |
|
--auth-cache-ttl |
5m |
cache of verified passwords |
--oidc-issuer, --oidc-audience |
off |
accept JWTs; audience is required |
--oidc-user-claim, --oidc-roles-claim |
sub, roles |
dotted paths work |
--oidc-skew |
30s |
clock tolerance |
--oidc-require-email-verified |
true |
with email as user claim |
--oidc-hosted-domain |
any |
accepted hd claims, repeatable |
--auth-ip-max-failures |
10 |
per IP, before lockout (0 = off) |
--auth-user-max-failures |
30 |
per user name, before lockout (0 = off) |
--auth-failure-window, --auth-lockout |
5m, 15m |
window and lockout duration |
| Flag |
Default |
|
--tls-cert, --tls-key |
plain HTTP |
native HTTPS, reloads on SIGHUP |
--trusted-proxy |
none |
IP/CIDR allowed to set X-Forwarded-For, repeatable |
--metrics-listen |
off |
address for Prometheus /metrics |
| Flag |
Default |
|
--audit-log |
off |
JSONL file; - = stdout |
--audit-sql |
redacted |
redacted, full or hash |
--audit-queue |
4096 |
events waiting to be written |
--schema-cache-ttl |
10m |
/v1/schema snapshot lifetime (0 = no cache) |