-
-
Notifications
You must be signed in to change notification settings - Fork 81
Environment Variables
- Introduction
- Environment Variable Expansion
- GUI
- CLI Option:
--envVars - CLI Example
- PowerShell Option:
-EnvVars - PowerShell Example
- Tips
Servy allows you to define environment variables for the service process, enabling fine-grained control over the runtime context.
Environment variable expansion is supported in multiple areas of Servy configuration:
- Service binary paths (
--path/-Path) -
Startup directories (
--startupDir/-StartupDir) -
Process parameters (
--params/-Params) -
Environment variables (
--envVars/-EnvVars)
This makes it possible to reference existing system variables, user-defined variables, or paths dynamically in your configuration.
Servy uses a sophisticated expansion engine that allows variables to reference each other. The resolution follows this specific order:
- System Environment: All current system and process environment variables are loaded first.
-
Custom Overrides: Variables defined in the Environment Variables field (or
--envVars) are added next. If a custom variable has the same name as a system variable, the custom value wins. -
Cross-Reference Expansion: Finally, all variables are scanned for
%VAR%placeholders. These placeholders are resolved using the final merged set of variables.
For security reasons Servy refuses to let --envVars / -EnvVars override a hard-coded list of variables that would otherwise enable privilege escalation or runtime injection (DLL/JIT profiler hijacking, debugger probes, search-path attacks, etc.). Any attempt to override one of these is silently ignored each time the service starts (during environment-variable expansion) and a warning is recorded in %ProgramData%\Servy\logs\Servy.Service.log:
Security: Blocked an attempt to override protected variable 'PATH'. Custom values for this variable are ignored to prevent privilege escalation.
The current list includes:
| Category | Variables | Security / Integrity Purpose |
|---|---|---|
| System Integrity |
PATH, COMSPEC, SYSTEMROOT, WINDIR, SYSTEMDRIVE, TEMP, TMP, PATHEXT, PROGRAMFILES*, COMMONPROGRAMFILES*
|
Protects core OS paths, binary resolution, and temporary storage locations. |
| Identity Redirection |
APPDATA, LOCALAPPDATA, PUBLIC, HOMEDRIVE, HOMEPATH, HOME, USERDOMAIN*, LOGONSERVER
|
Prevents redirection of user profile data, credentials, and network identity. |
| User & Profile |
USERNAME, USERPROFILE, ALLUSERSPROFILE, PROGRAMDATA, PSMODULEPATH
|
Safeguards user profile boundaries and PowerShell module lookup paths. |
| .NET Injection |
COR_*, CORECLR_*, DOTNET_STARTUP_HOOKS, DOTNET_ROOT, DOTNET_ADDITIONAL_DEPS
|
Prevents unauthorized profiler loading, startup hooks, and shared library hijacking. |
| Java Injection |
JAVA_*, CATALINA_*, MAVEN_*, M2_OPTS, GRADLE_OPTS, ANT_OPTS, JBOSS_*, WILDFLY_*, CLASSPATH
|
Blocks RCE via -javaagent and other launch-time injections through wrapper scripts and JVM flags. |
| Node.js Injection |
NODE_OPTIONS, NODE_PATH, NODE_EXTRA_CA_CERTS, NPM_CONFIG_*
|
Prevents runtime hijacking, rogue CA injection (MITM), and npm configuration tampering. |
| Scripting (Python/Ruby/Perl/PHP) |
PYTHON*, RUBY*, PERL*, PHPRC, PHP_INI_SCAN_DIR
|
Blocks arbitrary code execution via interpreter library overrides and malicious configuration files. |
| Global/Unix Fallback |
LD_PRELOAD, LD_LIBRARY_PATH
|
Prevents dynamic linker hijacking in compatibility (WSL/MinGW) environments. |
| Windows AppCompat |
__COMPAT_LAYER, SHIM_*, _NT_*, MICROSOFT_TELEMETRY_*
|
Prevents debugger injection and application compatibility shim exploitation. |
| PowerShell Hardening |
__PSLockDownPolicy, PSExecutionPolicyPreference
|
Prevents bypasses of ExecutionPolicy and LanguageMode security restrictions. |
If you need to extend PATH for the service process, modify the system PATH or use a custom variable name and reference it inside your application configuration.
If your system has TEMP=C:\Windows\Temp and you define:
MY_ROOT=C:\ServyAppMY_LOGS=%MY_ROOT%\logsAPP_TEMP=%TEMP%
The final environment seen by your process will be:
-
MY_ROOT:C:\ServyApp -
MY_LOGS:C:\ServyApp\logs -
APP_TEMP:C:\Windows\Temp
Note
Variable Ordering and Circular References:
Variables are resolved using a multi-pass fixed-point algorithm, so the order in which you define them does not matter — MY_LOGS=%MY_ROOT%\logs resolves correctly even if MY_ROOT is defined later in the list. The expansion engine runs up to 5 passes; chains deeper than that will leave unresolved %VAR% placeholders and Servy logs a warning ("Environment variable expansion reached maximum pass limit").
Avoid circular references: A direct two-variable cycle (A=%B%, B=%A%) is immediately caught and logged as a warning (Direct cycle detected for variable...), falling back to a safe literal placeholder state. Longer indirect cycles (A=%B%\suffix, B=%C%\suffix, C=%A%\suffix) are detected and logged as a warning once the 5-pass limit is exceeded.
The advanced tab in Servy allows setting environment variables for the service process:
The --envVars command-line option lets you specify environment variables for the service process.
-
Syntax:
--envVars="VAR1=value1; VAR2=value2" - Separate multiple variables with semicolons (;) - Special characters can be escaped:
-
\=to escape= -
\"to escape" -
\;to escape; -
\\to escape\ -
%%to escape%(collapses to a single%, matchingcmd.exebehaviors) (starting from v8.5+)
-
- Supports environment variable expansion. Example:
--envVars="VAR1=%ProgramData%\MyApp; VAR2=%VAR1%\bin; CHANCE=100%%" - Useful for setting runtime context without changing system-wide environment variables.
servy-cli install `
--name="MyNodeService" `
--description="My NodeJS Server" `
--path="%ProgramFiles%\nodejs\node.exe" `
--startupDir="C:\Apps\App" `
--params="C:\Apps\App\index.js" `
--startupType="Automatic" `
--envVars="NODE_ENV=production; APP_CONFIG=C:\Apps\App\config.json"The -EnvVars parameter lets you define environment variables when installing a service via PowerShell.
-
Type:
string(semicolon-separated list, optional) - Apply the same escaping rules as the CLI.
- Multiple variables are separated with semicolons (;)
- Variables are applied only to the service process, not system-wide.
Import-Module "C:\Program Files\Servy\Servy.psm1" -Force
$installParams = @{
Name = "MyNodeService"
Description = "My NodeJS Server"
Path = "C:\Program Files\nodejs\node.exe"
StartupDir = "C:\Apps\App"
Params = "C:\Apps\App\index.js"
StartupType = "Automatic"
EnvVars = "NODE_ENV=production; APP_CONFIG=C:\Apps\App\config.json"
}
Install-ServyService @installParams-
Case Insensitivity: Environment variable names are case-insensitive. Defining
node_envwill correctly override an existingNODE_ENV. -
Expansion Order: You can reference both existing system variables (like
%ProgramData%) and other custom variables defined in the same list. -
Safe Percent Escaping: To pass a literal percent character into your environment safely and prevent it from being processed as an expansion block, use a double percent sign (
%%). For example, definingALERT_MSG=Battery at 100%%will expand correctly toBattery at 100%inside the service process. - Verification: To troubleshoot, if you aren't sure if your variables are applying correctly, run this to dump the environment to a file (PowerShell Admin):
servy-cli install --name="EnvTest" --path="C:\Windows\System32\cmd.exe" --params="/c set > C:\servy_env.txt && timeout /t 3600 /nobreak > nul" --envVars="MY_ROOT=C:\ServyApp; MY_LOGS=%MY_ROOT%\logs"
servy-cli restart --name="EnvTest"
Get-Content C:\servy_env.txt | Select-String "MY_LOGS"Copyright © Akram El Assas. All rights reserved.
- Home
- Overview
- Installation Guide
- Advanced Configuration
- Usage
- Servy Desktop App
- Servy Manager
- Servy CLI
- PowerShell Module
- Examples & Recipes
- Logging & Log Rotation
- Health Monitoring & Recovery
- Environment Variables
- Service Dependencies
- Pre-Launch & Post-Launch Actions
- Pre-Stop & Post-Stop Actions
- Shutdown & Teardown
- Export/Import Services
- Automation & CI/CD
- Integration with Monitoring Tools
- Service Event Notifications
- Comparison with Alternatives
- Security
- Architecture
- Building from Source
- Troubleshooting
- FAQ