-
-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Expand file tree
/
Copy path.env-template
More file actions
135 lines (118 loc) · 6.87 KB
/
Copy path.env-template
File metadata and controls
135 lines (118 loc) · 6.87 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
API_KEY=<LLM api key (for example, open ai key)>
LLM_NAME=docsgpt
VITE_API_STREAMING=true
# Required: the worker hands finished indexes to the API with it; without it every ingest fails.
# Same value on the API and the worker. Generate one with: openssl rand -hex 32
INTERNAL_KEY=<internal key for worker-to-backend authentication>
# Address other machines open DocsGPT at, if any: http://<server-address>:7091, or the public https://
# address behind a proxy. The backend builds agent image, webhook, device pairing and MCP OAuth
# callback links from it (default http://localhost:7091). The Docker Compose worker keeps
# http://backend:7091 from the compose file.
# API_URL=https://docs.example.com
# Provider-specific API keys (optional - use these to enable multiple providers)
# OPENAI_API_KEY=<your-openai-api-key>
# ANTHROPIC_API_KEY=<your-anthropic-api-key>
# GOOGLE_API_KEY=<your-google-api-key>
# GROQ_API_KEY=<your-groq-api-key>
# NOVITA_API_KEY=<your-novita-api-key>
# OPEN_ROUTER_API_KEY=<your-openrouter-api-key>
# Embedding model. Leave it commented out and DocsGPT picks one for you: a
# fresh install is pinned to granite (multilingual, 32k context, the same 768
# dimensions as the legacy model), and an install that already has sources
# keeps the model its index was built with.
#
# Setting it here overrides that pin, so only set it deliberately. On an index
# that already has vectors, changing it without re-embedding leaves queries
# searching a different vector space than the stored vectors -- which fails
# silently, because both models are 768-dimensional. To switch, set it and then
# run:
# python -m docsgpt.scripts.reembed
# EMBEDDINGS_NAME=ibm-granite/granite-embedding-311m-multilingual-r2
# Remote Embeddings (Optional - for using a remote embeddings API instead of
# running the model in-process). When set, the app calls the remote API and
# never loads a local model, which keeps the API and worker containers small.
EMBEDDINGS_BASE_URL=
EMBEDDINGS_KEY=
# Run the embedding model on the Celery worker instead of in every process that
# embeds. The API embeds each query it serves, so without this it holds its own
# copy of the model (~660 MB resident instead of ~285 MB). Costs a broker
# round trip per query. Retrieval then needs a worker consuming
# EMBEDDINGS_QUEUE -- set this to false if you run the API on its own.
# EMBEDDINGS_DELEGATE_TO_WORKER=true
# EMBEDDINGS_QUEUE=embeddings
# EMBEDDINGS_DELEGATE_TIMEOUT=60
# Documents per local ONNX forward pass. Each pass pads every input up to the
# longest one in it, and that waste grows with the square of chunk length, so
# larger is not faster here: on a 30-document ingest at the 1250-token default
# chunk size, 32 peaked at 7.7 GB and took 154s, while 1 peaked at 1.5 GB and
# took 53s. Raise it only if your chunks are short and uniform. Distinct from
# EMBEDDINGS_BATCH_SIZE, which is chunks per store transaction / per remote
# embed request.
# EMBEDDINGS_MODEL_BATCH_SIZE=1
#For Azure (you can delete it if you don't use Azure)
OPENAI_API_BASE=
OPENAI_API_VERSION=
AZURE_DEPLOYMENT_NAME=
AZURE_EMBEDDINGS_DEPLOYMENT_NAME=
# SharePoint / OneDrive connector (optional). Uncomment and fill in to enable it.
#Azure AD Application (client) ID
# MICROSOFT_CLIENT_ID=your-azure-ad-client-id
#Azure AD Application client secret
# MICROSOFT_CLIENT_SECRET=your-azure-ad-client-secret
#Azure AD Tenant ID (or 'common' for multi-tenant)
# MICROSOFT_TENANT_ID=your-azure-ad-tenant-id
#If you are using a Microsoft Entra ID tenant,
#configure the AUTHORITY variable as
#"https://login.microsoftonline.com/TENANT_GUID"
#or "https://login.microsoftonline.com/contoso.onmicrosoft.com".
#Alternatively, use "https://login.microsoftonline.com/common" for multi-tenant app.
# MICROSOFT_AUTHORITY=https://{tenantId}.ciamlogin.com/{tenantId}
# POSTGRES_URI=postgresql://docsgpt:docsgpt@localhost:5432/docsgpt
# Authentication (optional - default is no auth; see docs: Deploying -> Security)
# No auth: every visitor shares one account. simple_jwt: one shared token, one shared user.
# session_jwt: separates browsers, but anyone who can reach the app gets in. oidc: real per-user sign-in.
# AUTH_TYPE=None|simple_jwt|session_jwt|oidc
# JWT_SECRET_KEY=<long random string; set it whenever more than one process or container runs, same value on each>
# When unset, the API generates .jwt_secret_key in the data home (fine for one local process only).
# DEPLOYMENT_TYPE=production # makes a missing JWT_SECRET_KEY fatal at startup instead
# Seals stored connector, MCP and tool credentials; the default is public. Set it on a fresh install
# (openssl rand -hex 32). Never just replace it: rotate with ENCRYPTION_SECRET_KEY_PREVIOUS and
# `docsgpt connectors reencrypt` (see docs: Deploying -> Security).
# ENCRYPTION_SECRET_KEY=<long random string>
# OIDC SSO (only when AUTH_TYPE=oidc; works with Authentik, Keycloak, Okta, ...)
# OIDC_ISSUER=<issuer URL, e.g. https://auth.example.com/application/o/docsgpt/>
# OIDC_CLIENT_ID=<client id registered at the IdP>
# OIDC_CLIENT_SECRET=<only for confidential clients; PKCE is always used>
# OIDC_FRONTEND_URL=<browser-facing app URL, e.g. http://localhost:5173>
# OIDC_SCOPES=openid profile email
# OIDC_USER_ID_CLAIM=sub
# OIDC_REDIRECT_URI=<override callback URL when behind a reverse proxy>
# OIDC_SESSION_LIFETIME_SECONDS=28800
# OIDC_PROVIDER_NAME=<sign-in button label, e.g. Acme SSO; unset shows "SSO">
# OIDC_ALLOWED_GROUPS=<comma-separated IdP group allowlist; unset = any authenticated user>
# OIDC_GROUPS_CLAIM=groups
# OIDC_ADMIN_GROUPS=<comma-separated IdP groups granted the admin role; unset = no OIDC admin mapping>
# Add offline_access to OIDC_SCOPES for silent session renewal on IdPs that
# require it for refresh tokens (Authentik does; Keycloak does not).
# RBAC (admin/user roles). Persisted admin grants live in the user_roles table
# and apply only under AUTH_TYPE=oidc — manage them with `docsgpt grant-admin`
# (bootstrap the first admin) or OIDC_ADMIN_GROUPS above. LOCAL_MODE_ADMIN is the
# ONLY non-DB admin path; it applies solely to AUTH_TYPE=None (no-auth self-host)
# and MUST stay false in any networked deployment.
# LOCAL_MODE_ADMIN=false
# SCIM 2.0 provisioning (IdP-driven user create/deactivate at /scim/v2;
# pair with OIDC_USER_ID_CLAIM=email so SCIM userName matches the OIDC user id)
# SCIM_ENABLED=false
# SCIM_TOKEN=<long random bearer token presented by the IdP's SCIM client>
# Personal access tokens (scoped API tokens for CLI and CI/CD; Settings → Access Tokens).
# Available with AUTH_TYPE=oidc or unset.
# PAT_ENABLED=true
# PAT_DEFAULT_LIFETIME_DAYS=90
# PAT_MAX_LIFETIME_DAYS=365
# PAT_ALLOW_NON_EXPIRING=false
# PAT_MAX_PER_USER=25
# Usage quotas (set limits in Admin → Quotas). Usage is counted per calendar
# day, week or month in UTC. Models without a declared price are recorded at $0
# unless a fallback [input, output] USD rate per 1M tokens is given.
# QUOTA_PERIOD=month
# QUOTA_UNPRICED_RATE_PER_MILLION=[0.5, 1.5]