Configuration
Thelia 3 uses Symfony's configuration system with environment variables and YAML files.
Environment variables
.env files
Thelia uses the standard Symfony .env file hierarchy:
| File | Purpose | Committed |
|---|---|---|
.env | Default values | Yes |
.env.local | Local overrides | No |
.env.test | Test defaults | Yes |
.env.test.local | Test local overrides | No |
Key variables
The .env file ships with these defaults:
# Application
APP_ENV=dev
APP_SECRET=your-secret-key
# Mailer
MAILER_DSN=null://null
# CORS
CORS_ALLOW_ORIGIN='^https?://(localhost|127\.0\.0\.1)(:[0-9]+)?$'
# JWT (generated by lexik:jwt:generate-keypair)
JWT_SECRET_KEY=%kernel.project_dir%/config/jwt/private.pem
JWT_PUBLIC_KEY=%kernel.project_dir%/config/jwt/public.pem
JWT_PASSPHRASE=your-passphrase
# Lock
LOCK_DSN=flock
Database configuration
Database credentials are set as individual environment variables (not a DATABASE_URL string):
DATABASE_HOST=localhost
DATABASE_PORT=3306
DATABASE_NAME=thelia
DATABASE_USER=thelia
DATABASE_PASSWORD=your_password
These are written to .env.local by bin/install during setup. With DDEV, they are injected automatically.
Symfony configuration
config/packages/
config/packages/
├── api_platform.yaml
├── cache.yaml
├── framework.yaml
├── lexik_jwt_authentication.yaml
├── mailer.yaml
├── monolog.yaml
├── nelmio_cors.yaml
├── security.yaml
├── translation.yaml
├── twig.yaml
├── twig_component.yaml
├── webpack_encore.yaml
└── web_profiler.yaml
Thelia uses Propel ORM, not Doctrine. There is no doctrine.yaml.
API Platform
config/packages/api_platform.yaml:
api_platform:
title: Hello API Platform
version: 1.0.0
formats:
jsonld: ['application/ld+json']
docs_formats:
jsonld: ['application/ld+json']
jsonopenapi: ['application/vnd.openapi+json']
html: ['text/html']
defaults:
stateless: true
cache_headers:
vary: ['Content-Type', 'Authorization', 'Origin']
extra_properties:
standard_put: true
rfc_7807_compliant_errors: true
Framework
config/packages/framework.yaml:
framework:
secret: '%env(APP_SECRET)%'
annotations: false
http_method_override: false
handle_all_throwables: true
session:
handler_id: null
cookie_secure: auto
cookie_samesite: lax
php_errors:
log: true
Security
config/packages/security.yaml ships with a minimal configuration:
security:
password_hashers:
Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface: 'auto'
providers:
users_in_memory: { memory: null }
firewalls:
dev:
pattern: ^/(_(profiler|wdt)|css|images|js)/
security: false
main:
lazy: true
provider: users_in_memory
The Thelia core handles authentication for both admins and customers, not Symfony's standard security providers.
Thelia configuration
Store settings
Access in back-office: Configuration > Store
- Store name, company information, contact details
- Default currency and language
Theme configuration
php Thelia template:set frontOffice flexy
php Thelia template:set backOffice default-twig
Caching
Clear cache
# Development
php Thelia cache:clear
# Production
php Thelia cache:clear --env=prod
# DDEV
ddev exec php Thelia cache:clear
Cache is stored in var/cache/. Configuration in config/packages/cache.yaml defaults to filesystem adapter.
Debug mode
# Development (default)
APP_ENV=dev
# APP_DEBUG is derived from APP_ENV
# Production
APP_ENV=prod
Never set APP_ENV=dev in production. It exposes sensitive information via the debug toolbar and profiler.
Mail configuration
Configure in .env.local:
# SMTP
MAILER_DSN=smtp://user:password@smtp.example.com:587
# Disable emails (default)
MAILER_DSN=null://null
Next steps
- First Steps: create your first content
- Architecture: understand the system
- Module Development: extend Thelia