App Properties
The $app.* namespace exposes platform-injected properties of the deployed app itself. These are resolved at deploy time by whichever provider is running the app, so a Launchfile can reference its own public URL without hardcoding environment-specific values.
| Property | Description |
|---|---|
$app.url |
The app's public URL (e.g. https://myapp.example.com) |
$app.host |
The app's public hostname (e.g. myapp.example.com) |
$app.port |
The app's allocated public port number |
$app.name |
The app name as deployed |
$app.authority |
The app's public host and port, port omitted when it's the default for the scheme (e.g. myapp.example.com or myapp.lvh.me:10001) |
$app.scheme |
The public URL's scheme — http or https |
$app.tls |
Whether the public URL is HTTPS — the string true or false |
The values are determined by the provider's routing strategy at deploy time. A Cloudflare Tunnel deployment might resolve $app.url to https://myapp.example.com; a local development provider might resolve it to http://myapp.lvh.me:10001; a Kubernetes deployment behind an Ingress might resolve it to https://myapp.k8s.internal. The Launchfile stays the same.
The standard set above is the portable vocabulary every provider must support. Providers MAY expose additional $app.* properties (e.g. $app.region, $app.deployment_id) as platform-specific extensions; portable Launchfiles should use only the standard set. Unknown $app.* properties resolve to empty string, matching the behavior of unknown resource properties (see L-4).
$app.url differs from $components.<this>.url in two ways. First, it gives the public URL — the address external users reach the app on — not the internal component port. Second, it works in single-component mode where there is no component name to reference. Use $app.url for public-facing values (auth callback URLs, webhook registration, public-facing email links) and $components.<name>.url for internal cross-component wiring.
Similarly, $app.port is the allocated external port that the platform exposes; provides[].port is the container port the component binds inside its sandbox. They can differ — a component might bind 3000 while the platform exposes 10001.
$app.authority, $app.scheme, and $app.tls are derived directly from $app.url, so a provider that can resolve the URL can resolve all three. $app.authority is the WHATWG URL host — the hostname plus the port, with the port omitted when it is the default for the scheme (:443 under https, :80 under http). $app.scheme is the URL scheme (http or https); $app.tls is the boolean form of that scheme (true when https, else false), provided for apps whose config expects a literal SSL on/off flag rather than a scheme string. Prefer $app.url for the single-string case; reach for these three only when an app needs the public address split into its component fields.
Example use:
env:
PUBLIC_URL: $app.url # Drupal, BookStack, Mealie, Firefly III
BETTER_AUTH_URL: $app.url # better-auth callback base
OAUTH_REDIRECT_URI: "${app.url}/oauth/callback"
WEBHOOK_URL: "${app.url}/webhooks/incoming"
# Apps that need the public address split into separate fields (HedgeDoc):
CMD_DOMAIN: $app.authority # public host[:port] HedgeDoc serves from
CMD_PROTOCOL_USESSL: $app.tls # whether the public URL is HTTPS
CMD_URL_ADDPORT: "false" # authority already carries the public portPer-endpoint properties
$app.* describes the app's primary endpoint only. An app that publishes more than one endpoint reaches the others through $app.endpoints.<name>.*, where <name> is the provides entry's name: (named endpoints) and the entry is exposed: true (D-63):
| Property | Description |
|---|---|
$app.endpoints.<name>.url |
The endpoint's public URL; "" for a tcp or udp endpoint, which has no origin |
$app.endpoints.<name>.host |
The endpoint's public hostname |
$app.endpoints.<name>.port |
The published host-side port the provider allocated for that endpoint — never the container port |
$app.endpoints.<name>.authority |
Public host and port, port omitted when it is the scheme default; a tcp/udp endpoint always carries its port |
$app.endpoints.<name>.scheme |
The public URL's scheme — http or https; "" for a tcp or udp endpoint |
$app.endpoints.<name>.tls |
The string true when the scheme is https, else false |
The six are the standard $app.* set less name, each defined per endpoint exactly as App Properties defines it for the primary, and each is a public address: $components.<name>.* stays the component-side address. Five rules:
- A provider computes every endpoint's address through the same derivation it uses for
$app.*. Where a provider publishes a per-endpoint address, the primary endpoint's$app.endpoints.<name>.urlis$app.url— the same value, never a second computation. scheme,tlsandurlread the entry's effective listener (Native TLS): an active certificate binding makes them readhttpsandtrue.- Unnamed endpoints are not addressable — add a
name:. An endpoint name is app-wide: the same name on two components is a validation error naming both. - Anything else resolves
""with avalidatewarning naming it: an unknown name, a named endpoint that is notexposed: true,$app.endpointswith no name,$app.endpoints.<name>with no property, a property outside the six, and an endpoint the provider publishes no address for (@launchfile/macos-devand@launchfile/awstoday, where this reaches the primary too and$app.urlkeeps its own value). Atcp/udpendpoint's""urlandschemeare a defined answer and draw no warning. - An orchestrator-supplied publication context asserts the primary endpoint's address only (D-58 rule 4): while one is supplied, every other named endpoint resolves
"".
# gitea — the clone URL wants the published SSH address in two pieces
provides:
- name: web
protocol: http
port: 3000
exposed: true
- name: ssh
protocol: tcp
port: 22
exposed: true
env:
GITEA__server__ROOT_URL:
default: $app.url # the primary — same value as $app.endpoints.web.url
GITEA__server__SSH_DOMAIN:
default: $app.endpoints.ssh.host # the published SSH hostname
GITEA__server__SSH_PORT:
default: $app.endpoints.ssh.port # the published SSH port, not 22