Coder powers secure, scalable development across key industries — automotive, finance, government, and technology — enabling faster builds, tighter compliance, and seamless AI adoption in enterprise-grade cloud environments.
HTTP bind address of the server. Unset to disable the HTTP endpoint.
--tls-address
Type
host:port
Environment
$CODER_TLS_ADDRESS
YAML
networking.tls.address
Default
127.0.0.1:3443
HTTPS bind address of the server.
--tls-enable
Type
bool
Environment
$CODER_TLS_ENABLE
YAML
networking.tls.enable
Whether TLS will be enabled.
--tls-cert-file
Type
string-array
Environment
$CODER_TLS_CERT_FILE
YAML
networking.tls.certFiles
Path to each certificate for TLS. It requires a PEM-encoded file. To configure the listener to use a CA certificate, concatenate the primary certificate and the CA certificate together. The primary certificate should appear first in the combined file.
--tls-client-ca-file
Type
string
Environment
$CODER_TLS_CLIENT_CA_FILE
YAML
networking.tls.clientCAFile
PEM-encoded Certificate Authority file used for checking the authenticity of client.
--tls-client-auth
Type
string
Environment
$CODER_TLS_CLIENT_AUTH
YAML
networking.tls.clientAuth
Default
none
Policy the server will follow for TLS Client Authentication. Accepted values are "none", "request", "require-any", "verify-if-given", or "require-and-verify".
--tls-key-file
Type
string-array
Environment
$CODER_TLS_KEY_FILE
YAML
networking.tls.keyFiles
Paths to the private keys for each of the certificates. It requires a PEM-encoded file.
--tls-min-version
Type
string
Environment
$CODER_TLS_MIN_VERSION
YAML
networking.tls.minVersion
Default
tls12
Minimum supported version of TLS. Accepted values are "tls10", "tls11", "tls12" or "tls13".
--tls-client-cert-file
Type
string
Environment
$CODER_TLS_CLIENT_CERT_FILE
YAML
networking.tls.clientCertFile
Path to certificate for client TLS authentication. It requires a PEM-encoded file.
--tls-client-key-file
Type
string
Environment
$CODER_TLS_CLIENT_KEY_FILE
YAML
networking.tls.clientKeyFile
Path to key for client TLS authentication. It requires a PEM-encoded file.
Whether to enable or disable the embedded DERP relay server.
--derp-server-relay-url
Type
url
Environment
$CODER_DERP_SERVER_RELAY_URL
YAML
networking.derp.relayURL
An HTTP URL that is accessible by other replicas to relay DERP traffic. Required for high availability.
--block-direct-connections
Type
bool
Environment
$CODER_BLOCK_DIRECT
YAML
networking.derp.blockDirect
Block peer-to-peer (aka. direct) workspace connections. All workspace connections from the CLI will be proxied through Coder (or custom configured DERP servers) and will never be peer-to-peer when enabled. Workspaces may still reach out to STUN servers to get their address until they are restarted after this change has been made, but new connections will still be proxied regardless.
--prometheus-enable
Type
bool
Environment
$CODER_PROMETHEUS_ENABLE
YAML
introspection.prometheus.enable
Serve prometheus metrics on the address defined by prometheus address.
--prometheus-address
Type
host:port
Environment
$CODER_PROMETHEUS_ADDRESS
YAML
introspection.prometheus.address
Default
127.0.0.1:2112
The bind address to serve prometheus metrics.
--pprof-enable
Type
bool
Environment
$CODER_PPROF_ENABLE
YAML
introspection.pprof.enable
Serve pprof metrics on the address defined by pprof address.
Enables trace exporting to Honeycomb.io using the provided API Key.
--trace-logs
Type
bool
Environment
$CODER_TRACE_LOGS
YAML
introspection.tracing.captureLogs
Enables capturing of logs as events in traces. This is useful for debugging, but may result in a very large amount of events being sent to the tracing backend which may incur significant costs.
--log-human
Type
string
Environment
$CODER_LOGGING_HUMAN
YAML
introspection.logging.humanPath
Default
/dev/stderr
Output human-readable logs to a given file.
--log-json
Type
string
Environment
$CODER_LOGGING_JSON
YAML
introspection.logging.jsonPath
Output JSON logs to a given file.
--log-stackdriver
Type
string
Environment
$CODER_LOGGING_STACKDRIVER
YAML
introspection.logging.stackdriverPath
Output Stackdriver compatible logs to a given file.
--experiments
Type
string-array
Environment
$CODER_EXPERIMENTS
YAML
experiments
Enable one or more experiments. These are not ready for production. Separate multiple experiments with commas, or enter '*' to opt-in to all available experiments.
--proxy-trusted-headers
Type
string-array
Environment
$CODER_PROXY_TRUSTED_HEADERS
YAML
networking.proxyTrustedHeaders
Headers to trust for forwarding IP addresses. e.g. Cf-Connecting-Ip, True-Client-Ip, X-Forwarded-For.
--proxy-trusted-origins
Type
string-array
Environment
$CODER_PROXY_TRUSTED_ORIGINS
YAML
networking.proxyTrustedOrigins
Origin addresses to respect "proxy-trusted-headers" and X-Forwarded-Host for subdomain app routing. e.g. 192.168.1.0/24.
--secure-auth-cookie
Type
bool
Environment
$CODER_SECURE_AUTH_COOKIE
YAML
networking.secureAuthCookie
Controls if the 'Secure' property is set on browser session cookies.
--samesite-auth-cookie
Type
lax|none
Environment
$CODER_SAMESITE_AUTH_COOKIE
YAML
networking.sameSiteAuthCookie
Default
lax
Controls the 'SameSite' property is set on browser session cookies.
--host-prefix-cookie
Type
bool
Environment
$CODER_HOST_PREFIX_COOKIE
YAML
networking.hostPrefixCookie
Default
false
Recommended to be enabled. Enables __Host- prefix for cookies to guarantee they are only set by the right domain. This change is disruptive to any workspaces built before release 2.31, requiring a workspace restart.
--strict-transport-security
Type
int
Environment
$CODER_STRICT_TRANSPORT_SECURITY
YAML
networking.tls.strictTransportSecurity
Default
0
Controls if the 'Strict-Transport-Security' header is set on all static file responses. This header should only be set if the server is accessed via HTTPS. This value is the MaxAge in seconds of the header.
--strict-transport-security-options
Type
string-array
Environment
$CODER_STRICT_TRANSPORT_SECURITY_OPTIONS
YAML
networking.tls.strictTransportSecurityOptions
Two optional fields can be set in the Strict-Transport-Security header; 'includeSubDomains' and 'preload'. The 'strict-transport-security' flag must be set to a non-zero value for these options to be used.
--disable-path-apps
Type
bool
Environment
$CODER_DISABLE_PATH_APPS
YAML
disablePathApps
Disable workspace apps that are not served from subdomains. Path-based apps can make requests to the Coder API and pose a security risk when the workspace serves malicious JavaScript. This is recommended for security purposes if a --wildcard-access-url is configured.
--disable-owner-workspace-access
Type
bool
Environment
$CODER_DISABLE_OWNER_WORKSPACE_ACCESS
YAML
disableOwnerWorkspaceAccess
Remove the permission for the 'owner' role to have workspace execution on all workspaces. This prevents the 'owner' from ssh, apps, and terminal access based on the 'owner' role. They still have their user permissions to access their own workspaces.
--write-config
Type
bool
Write out the current server config as YAML to stdout.
--proxy-session-token
Type
string
Environment
$CODER_PROXY_SESSION_TOKEN
YAML
externalWorkspaceProxy.proxySessionToken
Authentication token for the workspace proxy to communicate with coderd.
--primary-access-url
Type
url
Environment
$CODER_PRIMARY_ACCESS_URL
YAML
externalWorkspaceProxy.primaryAccessURL
URL to communicate with coderd. This should match the access URL of the Coder deployment.
--derp-only
Type
bool
Environment
$CODER_PROXY_DERP_ONLY
YAML
externalWorkspaceProxy.derpOnly
Run a proxy server that only supports DERP connections and does not proxy workspace app/terminal traffic.