There are two ways to configure Flipt: using a configuration file or through environment variables.

Configuration File

The default way that Flipt is configured is with the use of a configuration file default.yml.

This file is read when Flipt starts up and configures several important properties for the server.

You can edit any of these properties to your liking, and on restart Flipt will pick up the new changes.

These defaults are commented out in default.yml to give you an idea of what they are. To change them you'll first need to uncomment them.

These properties are as follows:

log.levelLevel at which messages are logged (trace, debug, info, warn, error, fatal, panic)info
log.fileFile to log to instead of STDOUT
ui.enabledEnable UI and API docstrue
cors.enabledEnable CORS supportfalse
cors.allowed_originsSets Access-Control-Allow-Origin header on server“*” (all domains)
cache.memory.enabledEnable in-memory cachingfalse
cache.memory.itemsNumber of items in-memory cache can hold500
server.protocolhttp or httpshttp
server.hostThe host address on which to serve the Flipt application0.0.0.0
server.http_portThe HTTP port on which to serve the Flipt REST API and UI8080
server.https_portThe HTTPS port on which to serve the Flipt REST API and UI443
server.grpc_portThe port on which to serve the Flipt GRPC server9000
server.cert_filePath to the certificate file (if protocol is set to https)
server.cert_keyPath to the certificate key file (if protocol is set to https)
db.urlURL to access Flipt databasefile:/var/opt/flipt/flipt.db
db.migrations.pathWhere the Flipt database migration files are kept/etc/flipt/config/migrations

Environment Variables

All options in the configuration file can be overridden using environment variables using the syntax:

Using environment variables to override defaults is especially helpful when running with Docker as described in the Installation documentation.

Everything should be upper case, . should be replaced by _. For example, given these configuration settings:

  grpc_port: 9000

  url: file:/var/opt/flipt/flipt.db

You can override them using:

export FLIPT_DB_URL="postgres://postgres@localhost:5432/flipt?sslmode=disable"


Flipt supports both SQLite and Postgres databases as of v0.5.0.

SQLite is enabled by default for simplicity, however you should use Postgres if you intend to run multiple copies of Flipt in a high availability configuration.

The database connection can be configured as follows:


  # file: informs flipt to use SQLite
  url: file:/var/opt/flipt/flipt.db


  url: postgres://postgres@localhost:5432/flipt?sslmode=disable
The Postgres database must exist and be up and running before Flipt will be able to connect to it.


From time to time the Flipt database must be updated with new schema. To accomplish this, Flipt includes a migrate command that will run any pending database migrations for you.

If Flipt is started and there are pending migrations, you will see the following error in the console:

migrations pending, please backup your database and run `flipt migrate`

If it is your first run of Flipt, all migrations will automatically be run before starting the Flipt server.

You should backup your database before running flipt migrate to ensure that no data is lost if an error occurs during migration.

If running Flipt via Docker, you can run the migrations in a separate container before starting Flipt by running:

docker run -it markphelps/flipt:latest /bin/sh -c './flipt migrate'



In-memory caching is currently only available for flags. When enabled, in-memory caching has been shown to speed up the fetching of individual flags by 10x.

To enable caching set the following in your config:

    enabled: true

Work is planned to add caching support to rule evaluation soon.

Enabling in-memory caching when running more that one instance of Flipt is not advised as it will lead to unpredictable results.


Flipt exposes Prometheus metrics at the /metrics HTTP endpoint. To see which metrics are currently supported, point your browser to FLIPT_HOST/metrics (ex: localhost:8080/metrics).

You should see a bunch of metrics being recorded such as:

flipt_cache_hit_total{cache="memory",type="flag"} 1
flipt_cache_miss_total{cache="memory",type="flag"} 1
go_gc_duration_seconds{quantile="0"} 8.641e-06
go_gc_duration_seconds{quantile="0.25"} 2.499e-05
go_gc_duration_seconds{quantile="0.5"} 3.5359e-05
go_gc_duration_seconds{quantile="0.75"} 6.6594e-05
go_gc_duration_seconds{quantile="1"} 0.00026651
go_gc_duration_seconds_sum 0.000402094
go_gc_duration_seconds_count 5


There is currently no built in authentication, authorization or encryption as Flipt was designed to work inside your trusted architecture and not be exposed publicly.

If you do wish to expose the Flipt dashboard and REST API publicly using HTTP Basic Authentication, you can do so by using a reverse proxy. There is an example provided in the GitHub repository showing how this could work.