config.yaml, in the environment
variables that set those settings, and in provider environment variables:
.env
files need no quoting. Docker
Compose interpolates ${...} in its own files, so write $${file:...} there;
Compose passes ${file:...} on to GoModel.
Syntax
A reference is${<scheme>:<reference>}. It may sit inside a larger value, and
one value may hold several:
Schemes
file reads Docker and Kubernetes secret mounts directly, so no entrypoint
script is needed to copy them into environment variables.
env differs from the plain ${NAME} form in two ways: it is strict, and it
works in environment variables, not only in config.yaml. The plain form is
unchanged: ${NAME} and ${NAME:-default} are expanded in config.yaml, and
an unset ${NAME} is left in place, which drops a provider whose key it is.
External secret managers (HashiCorp Vault, AWS Secrets Manager, GCP Secret
Manager, Azure Key Vault) plug in as further schemes with
GoModel Pro.
Failures stop startup
A reference that cannot be resolved stops the gateway with an error naming the setting and the scheme, never the value:OPENAI_API_KEY_2: secret reference ${file:...}.
A failed reload keeps the running
configuration. GoModel never starts with, or sends upstream, an unresolved
reference.
Only values in use are resolved: a provider value in config.yaml that an
environment variable overrides, a provider environment variable that GoModel
ignores (for example OPENAI_MODELS when several openai providers exist and
none is named openai), or a provider skipped for missing credentials, is not
looked up.
Literal ${
Write $${ for a literal ${. pa$${x} becomes pa${x}.
Limits
- References are resolved once, when the configuration is loaded or reloaded.
Rotating a secret takes a reload (
gomodel --reloadorSIGHUP). - They apply to string settings. A boolean or number setting cannot be a
reference, and an environment variable that GoModel parses as a number,
boolean, duration, or list (
LOGGING_ENABLED,HTTP_TIMEOUT,ENABLED_PASSTHROUGH_PROVIDERS, …) stops startup if it holds one. JSON variables accept references inside their string values. - Provider environment variables are the exception:
OPENAI_MODELS,OPENAI_MODEL_FILTER_*, andOPENAI_SESSION_STICKY_KEYSare resolved before they are parsed. - Values saved from the dashboard (provider credentials, MCP servers, guardrails) do not accept references yet.