Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
184 lines (174 loc) · 12.2 KB
/
Copy path.env.example
File metadata and controls
184 lines (174 loc) · 12.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
# ── Code-Compression Bench — environment template ──
# Copy to .env and fill in. NEVER commit .env (gitignored).
#
# The benchmark drives ONE fixed agent — headless Claude Code via the Python
# Claude Agent SDK — for every arm. Only the compression layer (the "arm")
# differs. You bring your own model auth; the per-run usage gateway is internal
# (no config — the runner starts it and points Claude Code at it automatically).
# ── Model = claude-sonnet on Vertex (the bottom bridge) ──
# The model every arm runs against is claude-sonnet on Vertex, reached through the
# internal usage gateway (the SINGLE BOTTOM BRIDGE). The gateway speaks the
# Anthropic API on its front (so Claude Code and the vendor compression proxies,
# which only speak Anthropic, work unchanged) and bridges to Vertex via litellm on
# its back. The runner starts the gateway and wires ANTHROPIC_BASE_URL itself — do
# NOT set ANTHROPIC_BASE_URL here.
#
# Vertex auth = Application Default Credentials ON THE BOX. Run once:
# gcloud auth application-default login
# NO API key is used for the model; ANTHROPIC_API_KEY below is NOT needed for the
# model (the runner clears it and hands Claude Code a dummy bridge token). Leave it
# unset unless a specific vendor proxy expects a real Anthropic key for its OWN
# upstream (configured on the vendor, not here).
# ANTHROPIC_API_KEY= # not used for the model (Vertex uses ADC)
#
# Vertex routing for the gateway (defaults shown; override to retarget):
# VERTEX_MODEL=vertex_ai/claude-sonnet-4-6
# VERTEX_PROJECT=your-gcp-project
# VERTEX_LOCATION=us-east5
#
# ── Shared standalone gateway (OPTIONAL; required for PROXY arms) ──
# By default the runner starts a FRESH gateway per solve on a random ephemeral port
# (fine for baseline/woz). A vendor proxy can't be provisioned to chase a moving
# port, so for the proxy arms launch ONE long-lived gateway at a FIXED address and
# share it (run-id-isolated, ThreadingHTTPServer, concurrency-safe under 8 workers):
# python -m bench.gateway_server --port 8080 --usage-dir runs/usage
# then point the runner at it by setting BOTH:
# CCB_GATEWAY_URL=http://127.0.0.1:8080 # the shared gateway's fixed URL; baseline/woz
# # point Claude Code here, proxy vendors' UPSTREAM = this
# CCB_GATEWAY_USAGE_DIR=runs/usage # == the gateway's --usage-dir; the runner reads each
# # run's usage from <dir>/<run_id>.usage.jsonl
# Leave BOTH unset to keep the per-run ephemeral behaviour (back-compat).
# CCB_GATEWAY_URL=http://127.0.0.1:8080
# CCB_GATEWAY_USAGE_DIR=runs/usage
# Model id Claude Code SENDS on the wire (just a label; the gateway routes to the
# Vertex model regardless). Keep identical across arms.
MODEL=claude-sonnet-4-5
# Dummy/bridge token handed to Claude Code (it needs a non-empty auth token to
# attach to the proxy/gateway; the real Vertex credential is ADC on the gateway).
# CCB_BRIDGE_AUTH_TOKEN=ccb-bridge-token
# Where each SWE-bench task repo is checked out on the runner box (the agent's
# cwd is <AC_REPO_ROOT>/<instance_id>). Required for the agent to EDIT the repo;
# without it the patch is empty. (Smoke-time wiring on the Linux box — see README.)
# AC_REPO_ROOT=/path/to/task/repos
# ── Per-arm credentials ──
# Self-hosted proxy arms (no CLIENT key): Edgee Compressor, Headroom, Compresr — see
# arms/README.md to run their local proxies. (Compresr's local Context Gateway is run the
# same self-hosted way: no client bearer; its api.compresr.ai cmp_ key is configured ON THE
# GATEWAY, not sent by the client.)
# rtk is NOT a proxy: it's the rtk-ai/rtk CLI binary run as a Claude Code PreToolUse
# HOOK. For a Bash call the arm delegates the rewrite decision to the product's OWN
# `rtk rewrite -- <cmd>` (the single source of truth the real rtk-rewrite.sh hook calls)
# and uses its output verbatim, so it wraps rtk's full command set (Bash <cmd> -> rtk
# <cmd>, compressing shell stdout). Install rtk >= 0.24.0 on the runner (the version that
# ships `rtk rewrite`); no key, no URL; the model goes straight to the gateway like
# baseline. See arms/README.md.
# bear-1.2 (The Token Company) — NO-OP: sales-gated (no self-serve API), excluded from runs.
# Opt back in once access is granted: set BEAR_ENABLED=1 and fill these.
# BEAR_ENABLED=1
# BEAR_API_KEY=REPLACE_ME
# BEAR_BASE_URL=https://api.thetokencompany.example
# Dasein arm — hosted compression service (request a key). The service processes each turn
# server-side and forwards to the run gateway.
DASEIN_API_KEY=REPLACE_ME
DASEIN_BASE_URL=https://REPLACE_ME
# Harness-hook runner: argv for the hosted service's hook-runner CLI on the runner box. Enables the
# agent-loop-owned hooks (an optional turn-0 brief and an optional stop verdict) via the Arm's
# step0_injection + stop_decision hooks. The arm shells out to it (clean-room: the public repo never
# imports any vendor internals). Unset -> proxy-only.
# DASEIN_HOOK_CMD=<hook-runner-cli-invocation>
# DASEIN_HOOK_TIMEOUT_S=300
# Woz — paid Claude Code plugin (account/license required to run its arm).
# The runner loads the WHOLE plugin (SDK plugins=[{type:local,path:WOZ_PLUGIN_DIR}]),
# so Claude Code activates Woz's OWN code/explore subagents (the haiku explorer with
# Woz's Search/Sql tools), its `code` MCP server (mcp__plugin_woz_code__*), hooks and
# skills — the shipped product. We do NOT spawn a bare server or reconstruct the explorer.
#
# ⚠️ WOZ_API_KEY is a SHORT-LIVED website token, NOT a durable license key: it is a
# {refreshToken,organizationId} blob minted by the browser /woz-login flow and it
# EXPIRES / gets server-revoked, so it must be PERIODICALLY RE-MINTED by a human.
# setup()/ready() detect a stale-or-absent session and SKIP the arm cleanly, but they
# CANNOT self-heal a stale token (re-login with the same revoked token just reprints
# "WozCode session is stale" and writes no session file → setup() raises
# WozStaleSessionError). To refresh: complete /woz-login in a browser to mint a fresh
# token, run `wozcode-cli.js login --token <fresh>` on the runner (or copy a logged-in
# ~/.claude/wozcode/), then update this value. Headless: the login CLI's callback server
# is loopback-only and a raw IAP TCP tunnel to it is firewall-blocked — bridge it with an
# SSH local port-forward over the port-22 IAP tunnel (--ssh-flag="-L <port>:localhost:<port>").
WOZ_API_KEY=REPLACE_ME
# Clone of the plugin on the RUNNER box (Linux): git clone https://github.com/WithWoz/wozcode-plugin
# Point WOZ_PLUGIN_DIR at the clone root (must contain .claude-plugin/plugin.json + agents/explore.md).
# NOTE: the plugin's native addon (queryparser.node) is platform-specific — it must be
# built/run on the Linux runner (matching node ABI + arch), NOT copied from a dev box.
WOZ_PLUGIN_DIR=/path/to/wozcode-plugin
# Optional: WOZ_NODE pins the node binary used for the one-time login (must be >= 20.12;
# Claude Code spawns the plugin's MCP server with the system node, which must also be >= 20.12).
# WOZ_NODE=/usr/bin/node
# ── Proxy arms ──
# TOPOLOGY: for every proxy arm Claude Code points ANTHROPIC_BASE_URL at the
# VENDOR proxy (<ARM>_BASE_URL below), and the vendor proxy's OWN UPSTREAM must be
# configured (at provisioning) to forward to THIS RUN's gateway URL — so the chain
# is ClaudeCode -> vendor proxy (compresses) -> gateway -> Vertex. Launch the
# SHARED standalone gateway (above) at a FIXED CCB_GATEWAY_URL so each vendor's
# upstream can be provisioned ONCE to a stable address (the per-run ephemeral
# gateway's random port can't be a vendor upstream); the runner also logs the
# gateway URL per run ("its UPSTREAM must be <gateway_url>"). Where each vendor's upstream is
# set: edgee -> EDGEE_ANTHROPIC_UPSTREAM=<gateway_url> on the forked `edgee
# local-gateway` (selfhost/edgee/launch.sh); headroom
# (Anthropic-native) -> its upstream Anthropic endpoint via ANTHROPIC_TARGET_API_URL
# (or the `--anthropic-api-url` flag) on `headroom proxy --port 8787 --mode token
# --anthropic-api-url <gateway>`; compresr -> the Context Gateway's upstream Anthropic
# endpoint via ANTHROPIC_PROVIDER_URL=<gateway_url> set ON THE COMPRESR PROCESS (Claude
# Code points COMPRESR_GATEWAY_URL=http://127.0.0.1:18081 at the gateway).
# (See arms/README.md.) NB: rtk is NOT in this list — it is a hook arm, not a proxy
# (no upstream to set; the model goes straight to the gateway like baseline).
# Vendor auth lives ON THE VENDOR PROXY (configured at provisioning), NOT here —
# Claude Code talks straight to the vendor, so we no longer inject arm headers().
#
# Edgee — self-hosted Rust CLI (a FORK of edgee-ai/edgee; build with
# selfhost/edgee/build.sh). EDGEE_BASE_URL is the LOCAL `edgee local-gateway`
# endpoint Claude Code points ANTHROPIC_BASE_URL at (real default port 8787). Its
# Anthropic upstream is the run gateway, set via EDGEE_ANTHROPIC_UPSTREAM on the
# gateway process (selfhost/edgee/launch.sh) — NOT a client key (no EDGEE_API_KEY).
EDGEE_BASE_URL=http://127.0.0.1:8787
# Compresr — Context Gateway (Compresr-ai/Context-Gateway, Anthropic-native Go proxy).
# COMPRESR_GATEWAY_URL is the LOCAL Context Gateway endpoint Claude Code points at (the
# var the arm reads; default http://127.0.0.1:18081 — the product's real default port).
COMPRESR_GATEWAY_URL=http://127.0.0.1:18081
# The gateway's UPSTREAM Anthropic endpoint is redirected to THIS run's gateway by setting
# ANTHROPIC_PROVIDER_URL=<gateway_url> ON THE COMPRESR PROCESS (its real upstream-redirect
# var; see internal/gateway/providers.go). NOT set here — it's a provisioning step.
# COMPRESR_BASE_URL/COMPRESR_API_KEY are the *compression-SERVICE* creds (the gateway's call
# OUT to https://api.compresr.ai for its haiku summarizer) — they live ON THE GATEWAY, not as
# a client bearer, so they are NOT set in this template.
# Headroom — self-host, no key. (Headroom's real default port is 8787; its
# Anthropic-native proxy is `headroom proxy --port 8787 --mode token`.)
HEADROOM_BASE_URL=http://127.0.0.1:8787
# rtk has NO *_BASE_URL: it is a hook arm (install the rtk-ai/rtk binary >= 0.24.0
# on the runner; ready() probes `rtk --version` AND smokes `rtk rewrite -- 'git
# status'`, so a legacy binary lacking the `rewrite` subcommand is caught and the
# arm SKIPs). The model goes straight to the gateway like baseline. CRITICAL
# PROVISIONING NOTE: the runner process is NON-INTERACTIVE
# (`gcloud … ssh --command '<…>'` does NOT source .bashrc/.profile), so a binary
# under ~/.local/bin is INVISIBLE to it and the arm self-SKIPs. Land rtk on a
# SYSTEM PATH dir (selfhost/cc_setup.sh symlinks ~/.local/bin/rtk -> /usr/local/bin/rtk),
# AND/OR pin its ABSOLUTE path here so ready() + the rewrite resolve it without a
# login shell. (On the runner box, prefer the absolute path.)
# RTK_BIN=/usr/local/bin/rtk
# ── fermat — Quotient Labs “Fermat's Last Token” shim (paid, entitlement-gated) ──
# Fermat ships a `claude` shim + local proxy daemon and swaps native file tools for MCP
# Search/Edit facades. It needs a paid `fermat login` (browser OAuth); without an entitled
# account the arm skips to vanilla, and there is NO self-host recipe. Fill in your own paths;
# real tokens/keys are NEVER committed — keep them in ~/secrets/fermat.env and ~/.fermat/credentials.
# FERMAT_SHIM=/path/to/fermat/bin/claude # REQUIRED: the Fermat `claude` shim
# FERMAT_BIN=fermat # the `fermat` CLI (default: sibling of the shim / PATH)
# FERMAT_RUNTIME=/path/to/fermat/runtime # Fermat runtime dir (default: <shim>/../runtime)
# FERMAT_CLAUDE_BIN=/path/to/real/claude # the real Claude Code binary Fermat wraps
# FERMAT_UPSTREAM= # proxy upstream = this run's gateway URL
# FERMAT_API_TOKEN= # Stage-2/3 bearer; keep in ~/secrets/fermat.env, never here
# FERMAT_CREDENTIALS=~/.fermat/credentials # login credentials json (from `fermat login`)
# FERMAT_AUTH_URL=https://auth.quotientlabs.com # auth base for token refresh (placeholder / public default)
# FERMAT_SUPABASE_ANON_KEY= # Fermat's PUBLIC Supabase client anon key (placeholder;
# # Fermat decodes its own value live from the runtime)
# ── Run config ──
WORKERS=8
COMPRESSION_TARGET_RATIO=0.5