-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
87 lines (78 loc) · 3.75 KB
/
Copy path.env.example
File metadata and controls
87 lines (78 loc) · 3.75 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
# =========================================================================
# BRAIN — environment variables (single source of truth)
# Copy to .env and fill values. Never commit .env.
#
# All services (web, api, vault-syncer, caddy, ts-edge) read their values
# from this file via docker-compose interpolation. Do NOT create per-service
# .env files — the compose env blocks already wire everything from here.
#
# Full reference: docs/configuration.md
# =========================================================================
# -------- Auth / web (Next.js) --------
# In dev: keep http://localhost:3000.
# In prod: set to your public URL, e.g. https://brain.example.com.
NEXTAUTH_URL=http://localhost:3000
NEXTAUTH_SECRET= # openssl rand -base64 32
GITHUB_CLIENT_ID=
GITHUB_CLIENT_SECRET=
# Your GitHub login. Only this account can sign in.
ALLOWED_GITHUB_USER=your-github-username
API_BASE_URL=http://api:8000 # internal Docker hostname; in dev outside Docker use http://localhost:8000
# Shared HMAC key for the internal web↔api JWT. 32+ bytes; openssl rand -base64 32.
INTERNAL_API_SECRET=
# -------- Public domain (prod) --------
# The domain Caddy serves (e.g. brain.example.com). Required when running prod.
# Leave blank for local dev.
DOMAIN=
# Same value as DOMAIN, exposed to the Next.js client for serverActions allowedOrigins.
NEXT_PUBLIC_DOMAIN=
# -------- API (FastAPI) --------
# Path inside the api container that contains wiki/ and raw/.
# In prod: the syncer clones into /vault. If your vault repo has an inner
# directory (e.g. the repo root contains MyVault/wiki and MyVault/raw),
# set this to /vault/MyVault.
# In dev: docker-compose.dev.yml bind-mounts the host VAULT_PATH directly to
# /vault, so the in-container path is just /vault.
VAULT_PATH=/vault
# Embedded Chroma persistent store. Mounted as the chroma_data Docker volume.
# Override only if you want a non-default location inside the container.
CHROMA_PATH=/data/chroma
VOYAGE_API_KEY=
OPENROUTER_API_KEY=
OPENROUTER_BASE_URL=https://openrouter.ai/api/v1
LLM_MODEL=anthropic/claude-sonnet-4
ADMIN_REINDEX_TOKEN= # X-Admin-Token for /admin/reindex; vault-syncer reuses
ALLOWED_ORIGINS=http://web:3000 # FastAPI CORS allowlist (comma-separated)
RATE_LIMIT_PER_MINUTE=60
# -------- Vault syncer (prod) --------
# Public or private git repo containing your vault.
VAULT_REPO=https://github.com/your-username/your-vault-repo.git
VAULT_BRANCH=main
SYNC_INTERVAL_MIN=5
# Required when VAULT_REPO is private. Create at:
# https://github.com/settings/personal-access-tokens/new
# Fine-grained PAT, repo access = "Only select repositories" -> your vault.
# Permissions: Contents = Read-only. Set an expiry and rotate.
VAULT_GIT_TOKEN=
# -------- TLS (prod) --------
# Email Let's Encrypt uses to send expiry/incident notifications.
ACME_EMAIL=
# Cloudflare API token used by Caddy for the DNS-01 ACME challenge.
# Only required if you choose DNS-01 over HTTP-01 (e.g. running on a tailnet
# where port 80 is not publicly reachable).
# Permissions: Zone:DNS:Edit + Zone:Zone:Read, scoped to YOUR domain only.
# Create at: https://dash.cloudflare.com/profile/api-tokens
CF_API_TOKEN=
# -------- Optional: Tailscale path --------
# Only used with: docker compose -f docker-compose.yml -f docker-compose.tailscale.yml
# Tutorial: docs/deployment/tailscale.md
# Reusable, tagged auth key from the Tailscale admin console.
# Generate at: https://login.tailscale.com/admin/settings/keys
TS_AUTHKEY=
TS_HOSTNAME=brain
# -------- Dev only (not used in prod) --------
# Path on the host machine to your local Obsidian vault, OR the bundled
# sample at $(pwd)/vault.example. Required for ./scripts/dev.sh.
# Examples:
# VAULT_PATH=$(pwd)/vault.example
# VAULT_PATH=/path/to/your/Obsidian/Vault