Skip to content

Environment variables ​

All settings are prefixed PALENA_PSEUDONYMIZER_. The service validates them on startup and exits on invalid values.

Runtime ​

VariableDefaultNotes
HTTP_ADDR:8080Bind address.
LOG_LEVELinfodebug | info | warn | error.
LOG_FORMATjsonjson | text.
MAX_REQUEST_BYTES33554432Request body cap (32 MiB).
API_KEY(empty)Required x-api-key value; empty = accept all.
SHUTDOWN_TIMEOUT30sGraceful drain period.

Presidio ​

VariableDefaultNotes
PRESIDIO_ANALYZER_URLhttp://presidio-analyzer:5001Text detection service.
PRESIDIO_IMAGE_REDACTOR_URLhttp://presidio-image-redactor:5003Image detection service.
PRESIDIO_TIMEOUT_SECONDS10Per-request timeout.
PRESIDIO_SCORE_THRESHOLD0.7Minimum detection confidence, [0,1].
PRESIDIO_ENTITIESPERSON,ORGANIZATIONEntity types to detect. Add structured PII (CREDIT_CARD, US_SSN, EMAIL_ADDRESS, …) to opt in. LOCATION excluded by default.
PRESIDIO_LANGUAGEenLanguage forwarded to Presidio.
ENTITY_STRATEGY_DEFAULTtokenStrategy for enabled non-nominal types: pool (fictional value) or token (<TYPE_N> placeholder).
ENTITY_STRATEGY(empty)Per-type overrides, e.g. PHONE_NUMBER:pool,CREDIT_CARD:token. Nominal types (PERSON/ORGANIZATION/LOCATION) default to pool. See Substitution strategy.

Redis ​

VariableDefaultNotes
REDIS_URLredis://redis:6379/0Connection URL.
REDIS_SESSION_TTL_SECONDS3600Mapping lifetime, refreshed on access.
REDIS_KEY_PREFIXpalena:pseudonymizerKey namespace.
REDIS_TIMEOUT_SECONDS2Per-command timeout.
REDIS_POOL_SIZE10Connection pool size.

Text & session ​

VariableDefaultNotes
SESSION_METADATA_KEYsession_idMetadata field read for the session id.
DECOMPOSE_PERSON_NAMEStrueRegister first/last-name sub-mappings.
ALLOW_LIST(empty)Comma-separated terms never pseudonymized even when detected — brand/product names, public figures, words Presidio over-tags. Case-insensitive. See Configuration → Allow-list.
DETERMINISTIC_SECRET(empty)When set, pool assignment uses a keyed HMAC of the real value so the same name maps to the same pseudonym across sessions. Token entities unaffected. Treat as a secret. See Configuration → Deterministic pseudonyms.
POOL_PERSON(unisex names)Comma-separated person pseudonyms.
POOL_ORGANIZATION(neutral orgs)Comma-separated org pseudonyms.
POOL_LOCATION(neutral places)Used only if LOCATION is enabled.

Non-text content (images) ​

VariableDefaultNotes
NON_TEXT_PII_ACTIONredactredact | block | passthrough.
MAX_IMAGE_BYTES20971520Per-image cap (20 MiB).
MAX_IMAGES_PER_REQUEST20Request-level image limit.

Deploying with Helm?

The chart maps these to friendly values.yaml keys — you rarely set the raw env vars by hand. See Deploy with Helm.

Released under the Apache 2.0 License.