Configuration parameters

WEM and the host agent are each configured through a dedicated configuration file on their respective hosts. These parameters cover all supported options, their defaults, and their descriptions.

WEM parameters

Configure these parameters in /etc/wem/wem.conf on the WEM host.

Target cluster

ParameterDefaultRequiredDescription
WHPG_HOSTlocalhostYesHostname of the WarehousePG coordinator.
WHPG_PORT5432YesPort for the WarehousePG coordinator.
WHPG_DATABASEwemYesDatabase on the WHPG cluster to connect to. Any database is valid, but WHPG_USER must be a superuser.
WHPG_USERgpadminYesWarehousePG superuser. Used for setup tasks and as the runtime connection when WHPG_WEM_USER isn't configured.
WHPG_PASSWORD—YesPassword for WHPG_USER.
WHPG_SSLMODEpreferNoSSL mode for the WHPG connection. Valid values are disable, allow, prefer, require, verify-ca, and verify-full.
WHPG_WEM_USER—NoDedicated WarehousePG role that WEM creates automatically during wem setup and uses for its runtime connection instead of reusing WHPG_USER for every query. WEM falls back to WHPG_USER/WHPG_PASSWORD if this parameter or WHPG_WEM_USER_PASSWORD is unset.
WHPG_WEM_USER_PASSWORD—NoPassword for WHPG_WEM_USER.
WHPG_MONITORING_DBWHPG_DATABASENoDatabase WEM uses for monitoring queries, if different from WHPG_DATABASE.

ClickHouse

WEM queries ClickHouse for all historical metrics and log data. See Installing ClickHouse.

ParameterDefaultRequiredDescription
CLICKHOUSE_URL—YesClickHouse connection URL. For example, clickhouse://username:password@localhost:9000.
CLICKHOUSE_DBacp_observabilityNoClickHouse database that stores the OTel-collected metrics and logs.

OTel Collector

ParameterDefaultRequiredDescription
OTEL_GATEWAY_ENDPOINT—NoExternal gateway collector endpoint. When set, every node's OTel Collector exports to this gateway. When empty, WEM manages the gateway internally on the standby coordinator, with the coordinator as failover. See Installing the gateway collector.
OTEL_COLLECTION_INTERVAL30sNoFrequency at which each node's OTel Collector gathers host metrics.
OTEL_PROMETHEUS_SCRAPE_ENDPOINT127.0.0.1:8889NoHost and port where the OTel Collector exposes WHPG cluster and host metrics in Prometheus scrape format, for an external Prometheus instance. WEM's own pipeline for these metrics is ClickHouse-only, so set this parameter only if you also need Prometheus access alongside it. See Metrics reference.

Application state

WEM stores its internal state in its own dedicated wem database rather than reusing WHPG_DATABASE. Host this database on a Postgres instance separate from the WHPG cluster you're monitoring, so a problem with that cluster doesn't take WEM down with it too. Use these parameters to point WEM at the host and role that own this database. See Application state for the role to create and the trade-offs of reusing the WHPG cluster's own server instead.

ParameterDefaultRequiredDescription
WEM_HOSTlocalhostNoHostname of the WEM application state database. Doesn't fall back to WHPG_HOST, even when WHPG_HOST is set explicitly.
WEM_PORT5432NoPort for the WEM application state database. This is a fixed default, independent of WHPG_PORT — it isn't derived from it even when WHPG_PORT is set explicitly.
WEM_DATABASEwemNoDatabase name for WEM application state. WEM creates this database itself on first start if it doesn't already exist.
WEM_USERgpadminNoUser for the WEM application state database. Must already exist. This is a fixed default, independent of WHPG_USER — it isn't derived from it even when WHPG_USER is set explicitly. If this database is hosted on the WHPG cluster's own Postgres server, set this to the same value as WHPG_USER. Otherwise, precreate a role with LOGIN and CREATEDB privileges. WEM doesn't create this role.
WEM_PASSWORD—NoPassword for WEM_USER.
WEM_SSLMODEpreferNoSSL mode for the WEM application state database connection. Valid values are the same as WHPG_SSLMODE.

Web server

ParameterDefaultRequiredDescription
PORT8080NoHTTP port on which the WEM web portal listens.

Performance

ParameterDefaultRequiredDescription
HIGH_LOAD_MODEfalseNoExtends WEM's internal timeouts for large clusters. Equivalent to passing the --high-load flag.
LONG_RUNNING_THRESHOLD10NoDuration, in minutes, after which a query is flagged as long-running in the Connection & Query Metrics section on the System Metrics page. Accepts a plain integer, not a duration string. Can also be set from the WEM interface.
LOG_MIN_DURATION_STATEMENT—NoSets WHPG's log_min_duration_statement configuration parameter, in milliseconds. Use -1 to disable statement logging or 0 to log every statement. Leave unset to leave WHPG's own setting unchanged.

Connection pooling

WEM maintains separate connection pools for the WHPG cluster, its own application state database, and the Query Editor. These parameters share the same suffixes across all three prefixes (WHPG_POOL_, WEM_POOL_, and QUERY_EDITOR_POOL_).

ParameterDefaultRequiredDescription
WHPG_POOL_MAX_CONNS5NoMaximum number of pooled connections to the WHPG cluster.
WHPG_POOL_MIN_CONNS—NoMinimum number of pooled connections to the WHPG cluster.
WHPG_POOL_MAX_LIFETIME30mNoMaximum lifetime of a pooled WHPG connection before it's recycled.
WHPG_POOL_MAX_IDLE_TIME5mNoMaximum time a pooled WHPG connection can sit idle before it's closed.
WHPG_POOL_HEALTH_CHECK30sNoInterval at which idle WHPG pool connections are health-checked.
WEM_POOL_MAX_CONNS4NoMaximum number of pooled connections to the WEM application state database.
WEM_POOL_MIN_CONNS1NoMinimum number of pooled connections to the WEM application state database.
WEM_POOL_MAX_LIFETIME30mNoMaximum lifetime of a pooled WEM application state connection before it's recycled.
WEM_POOL_MAX_IDLE_TIME5mNoMaximum time a pooled WEM application state connection can sit idle before it's closed.
WEM_POOL_HEALTH_CHECK30sNoInterval at which idle WEM application state pool connections are health-checked.
QUERY_EDITOR_POOL_MAX_CONNS4NoMaximum number of pooled connections used by the Query Editor.
QUERY_EDITOR_POOL_MIN_CONNS0NoMinimum number of pooled connections used by the Query Editor.
QUERY_EDITOR_POOL_MAX_LIFETIME30mNoMaximum lifetime of a pooled Query Editor connection before it's recycled.
QUERY_EDITOR_POOL_MAX_IDLE_TIME5mNoMaximum time a pooled Query Editor connection can sit idle before it's closed.
QUERY_EDITOR_POOL_HEALTH_CHECK30sNoInterval at which idle Query Editor pool connections are health-checked.
LOG_POOL_STATSfalseNoLogs periodic connection pool statistics for all three pools.
LOG_POOL_STATS_INTERVAL60sNoFrequency at which pool statistics are logged, when LOG_POOL_STATS is enabled.

Pool utilization is also exposed as Prometheus metrics at /prom/metrics.

Session security

ParameterDefaultRequiredDescription
WEM_COOKIE_SECRET—Yes32-byte secret key for session cookies. Generate with openssl rand -base64 32. WEM returns an error at startup if this is unset.
WEM_INSECURE_COOKIES—NoSet to 1 to allow cookies over HTTP. Required when WEM is not served over HTTPS.

Admin credentials

ParameterDefaultRequiredDescription
WEM_ADMIN_PASSWORDAuto-generated at installNoInitial admin password. Only used during first-time setup, if the dashboard_users table doesn't yet exist. The wem service runs wem setup --non-interactive on every start as a consistency check, and if that check finds first-time setup still incomplete, for example after restoring or repointing the app-state database, it fails with admin password pre-flight failed unless this or WEM_ADMIN_PASSWORD_FILE is already set, rather than auto-generating one at that point.
WEM_ADMIN_PASSWORD_FILE—NoPath to a file containing the admin password. Use instead of WEM_ADMIN_PASSWORD for automated deployments.

Access control

ParameterDefaultRequiredDescription
WEM_ACTION_PERMISSIONS_ENABLEDtrueNoEnables per-action permission grants, defined in the Permissions tab. Set to false to fall back to admin-only access for every gated action, regardless of what's granted there, as an emergency rollback. Requires a restart of the WEM service to take effect. See Defining role-based access control.

TLS for database connections

These parameters configure client-certificate TLS for WEM's two Postgres connections. They're unrelated to the mutual TLS (mTLS) system WEM uses to authenticate host agents, which is managed automatically through WEM's internal certificate authority. See Host agent.

ParameterDefaultRequiredDescription
PGSSLCERT—NoClient certificate for the WHPG connection.
PGSSLKEY—NoClient private key for the WHPG connection.
PGSSLROOTCERT—NoRoot certificate authority (CA) bundle used to verify the WHPG server, for verify-ca or verify-full values of WHPG_SSLMODE.
WEM_SSLCERT—NoClient certificate for the WEM application state database connection, configured independently from the WHPG connection.
WEM_SSLKEY—NoClient private key for the WEM application state database connection.
WEM_SSLROOTCERT—NoRoot CA bundle used to verify the WEM application state database server.

Cluster identity

ParameterDefaultRequiredDescription
WEM_CLUSTER_NAME—NoDisplay name for this cluster, shown in the WEM interface. Also included as a resource tag on the metrics and logs WEM exports through the OTel pipeline, so it's useful for telling clusters apart when several send data to the same ClickHouse instance.
WEM_CLUSTER_ENVIRONMENT—NoEnvironment label shown in the WEM interface and used to gate confirmation prompts for cluster management actions. Valid values are dev, uat, and prod.

Job retention

ParameterDefaultRequiredDescription
WEM_JOB_RETENTION_HOURS168NoHow long WEM keeps completed or failed Cluster Management and Safeguard job records before deleting them. A background cleanup task sweeps expired records every 24 hours.
WEM_BACKUP_JOB_RETENTION_HOURS168NoHow long WEM keeps completed backup and restore job records before deleting them. A background cleanup task sweeps expired records every 24 hours.

Safeguard

Safeguard backup and disaster-recovery settings (repositories, schedules, DR targets, and so on) are configured through the WEM interface and stored in the WEM application state database, not in wem.conf. These parameters only control the background sync of that configuration out to host agents.

ParameterDefaultRequiredDescription
CONFIG_DRIFT_ENABLEDtrueNoEnables periodic sync of Safeguard configuration from host agents, to detect and reconcile drift.
CONFIG_DRIFT_INTERVAL60sNoFrequency at which WEM syncs Safeguard configuration from host agents.

Alert evaluator

WEM evaluates alert rules itself and pushes firing alerts to its bundled Alertmanager. Rules are managed from the Alert Rules tab in the WEM interface rather than from static files.

ParameterDefaultRequiredDescription
ALERT_EVALUATOR_ENABLEDtrueNoEnables WEM's internal alert rule evaluation.
ALERT_EVALUATION_INTERVAL15sNoFrequency at which WEM evaluates alert rules.

Log scan

ParameterDefaultRequiredDescription
LOG_SCAN_ENABLEDtrueNoEnables periodic agent-driven scanning of the coordinator's WHPG log into wem.query_log_history.
LOG_SCAN_INTERVAL60sNoFrequency at which the log-scan job is enqueued.

AI Assistant

ParameterDefaultRequiredDescription
ANTHROPIC_API_KEY—NoAPI key for the integrated AI Assistant. Requires an active Anthropic account. The assistant is disabled when this parameter is unset.
ANTHROPIC_MODELclaude-sonnet-5NoClaude model used for AI-powered query plan explanations.

PXF

WEM never invokes pxf itself. The PXF tab in Data Analysis dispatches pxf cluster actions to the coordinator's host agent instead, so PXF no longer needs to share a host, or an OS user, with WEM. See Analyzing data distribution.

ParameterDefaultRequiredDescription
WHPG_PXF_OP_TIMEOUT_SECONDS60 (180 with --high-load)NoHow long WEM waits for the coordinator's host agent to finish a pxf cluster job. Applies to every action the same way, except restart, which gets double this budget since it's a stop followed by a start. Clamped to 30–600 seconds.

Service identity

ParameterDefaultRequiredDescription
WHPG_ALLOW_ROOT—NoSet to 1 to allow the WEM service to run as root. By default, WEM refuses to start as root. WEM logs a warning on every restart when this is set.

Host agent

WEM dispatches jobs to the host agent through its internal job-execution engine, and authenticates every host agent connection with mutual TLS through WEM's internal certificate authority. See Installing the host agent.

ParameterDefaultRequiredDescription
WEM_AGENT_PORTPORT + 1NoPort the host agent connects to for WEM's internal job-execution engine. Leave unset to derive it automatically from PORT.
WEM_AGENT_JOIN_SECRET— (disabled)NoShared secret that lets a self-registering host agent skip manual admin approval. When set, an agent that presents a matching token — pre-provisioned in /etc/edb/acp-host-agent/join-token on the agent host — moves straight to approved status instead of waiting in the Host Agents tab. Leave unset to require an Admin to approve every new agent explicitly, comparing the token shown in the Host Agents tab against the agent host's join-token file.

The host agent's callback address for file transfers is derived automatically from WEM_AGENT_PORT and is no longer configurable through wem.conf.


Could this page be better? Report a problem or suggest an addition!