Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
88 lines (74 loc) · 4.97 KB
/
Copy path.env.example
File metadata and controls
88 lines (74 loc) · 4.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
# Copy to backend/.env and fill in real values before deploying.
# Never commit a .env file with real secrets.
# ── Security ──────────────────────────────────────────────────────────────────
# Generate with: python -c "import secrets; print(secrets.token_hex(32))"
JWT_SECRET=change-me-in-production-please
# ── Encryption key (AES-256 for provider API keys at rest) ───────────────────
# Generate with: python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
ENCRYPTION_KEY=
# ── Database ─────────────────────────────────────────────────────────────────
# Docker Compose runs PostgreSQL (pgvector) and sets DATABASE_URL for you; set a
# strong POSTGRES_PASSWORD here for prod/cloud. For a non-Docker local run the
# app falls back to sqlite:///./data/app.db.
POSTGRES_USER=agentic
POSTGRES_PASSWORD=
POSTGRES_DB=agentic
# Override only if pointing at an external database:
# DATABASE_URL=postgresql+psycopg2://user:pass@host:5432/dbname
# ── LLM Provider keys (stored in DB; these seed the first provider key) ──────
OPENAI_API_KEY=
ANTHROPIC_API_KEY=
GOOGLE_API_KEY=
MISTRAL_API_KEY=
# ── GitHub integration ────────────────────────────────────────────────────────
GITHUB_TOKEN=
GITHUB_OWNER=
GITHUB_REPO=
# ── Telegram bot (optional — for agent invite links and notifications) ────────
TELEGRAM_BOT_TOKEN=
# ── Backup / Object Storage (optional) ───────────────────────────────────────
BACKUP_PROVIDER= # s3 | r2 | minio
BACKUP_BUCKET=
AWS_ACCESS_KEY_ID=
AWS_SECRET_ACCESS_KEY=
AWS_REGION=us-east-1
BACKUP_ENDPOINT_URL= # for R2/MinIO: https://<account>.r2.cloudflarestorage.com
# ── App ───────────────────────────────────────────────────────────────────────
VITE_API_URL=http://localhost:8000
# ── Runtime ──────────────────────────────────────────────────────────────────
# production: refuses to start with a placeholder or <32-char JWT_SECRET and
# drops the localhost dev origins from CORS. The prod/cloud compose files set it.
# ENVIRONMENT=development
# Browser origins allowed to call the API cross-origin (comma-separated).
# Default: APP_URL, plus http://localhost:5173 outside production.
# CORS_ORIGINS=
# With several uvicorn workers, exactly one runs cron flows, background jobs
# and Telegram polling (flock on data/scheduler.lock). Set false on extra
# replicas that should never run them.
# SCHEDULER_ENABLED=true
# ── Workspaces (ADR-0018) ────────────────────────────────────────────────────
# The workspace API fails closed (503) until a runtime is configured.
# "fake" is an in-memory runtime for local development and tests only — it does
# not start any container. The production runtime is the workspace-controller.
# WORKSPACE_RUNTIME=fake
# WORKSPACE_MAX_UPLOAD_MB=50
# WORKSPACE_MAX_DOWNLOAD_MB=200
# ── Workspace agent / subagent runs (ADR-0019) ───────────────────────────────
# Model for the agent created with each person's workspace (AppConfig
# `workspace.agent_model[:<company_id>]` takes precedence). Default gpt-4o-mini.
# WORKSPACE_AGENT_MODEL=
# Deepest subagent nesting a run token may reach; 0 disables subagents. Default 2.
# RUN_MAX_DEPTH=2
# ── Prompt assembly and intent breakdown (ADR-0020) ──────────────────────────
# Token budget for an agent's system prompt; optional sections are dropped past it.
# PROMPT_BUDGET_TOKENS=2000
# TypeSafe Jev intent classification. OFF unless BOTH a key is set AND AppConfig
# `intent.enabled` is true: requests leave the premises with this feature.
# TYPESAFE_API_KEY=
# INTENT_TIMEOUT_SECONDS=1.5
# Only classify when the prompt is at least this many (estimated) tokens.
# INTENT_MIN_PROMPT_TOKENS=800
# ── Work review (ADR-0019 §6) ────────────────────────────────────────────────
# Off for every company until a founder enables it (PUT /work-review/settings, which
# requires acknowledge_notice). Smallest group whose totals may be shown (min 2).
# WORK_REVIEW_MIN_GROUP=3