mirror of
https://github.com/trevorsandy/ai-suite.git
synced 2026-10-01 22:15:18 +02:00
662 lines
21 KiB
Bash
662 lines
21 KiB
Bash
# Change this file name to .env after updating it if not using auto-configuration!
|
|
|
|
############
|
|
# Auto-Configuration:
|
|
# AI-Suite uses this file as the .env template. You should update default settings
|
|
# you wish to set before running install or update using suite_services.py.
|
|
#
|
|
# If an existing .env is encountered during auto-configuration, defaults from this
|
|
# file are overlayed with the existing .env values. This means secrets for variables
|
|
# in the existing .env will not be generated by AI-Suite during install or update.
|
|
#
|
|
# Variables that hold generated secrets will have a specific default value
|
|
# format: <variable>=generate using <generator>[:<argument>]
|
|
# Examples: N8N_RUNNERS_AUTH_TOKEN=generate using gen_hex:32
|
|
# SERVICE_ROLE_KEY=generate using gen_token:service_role_sym
|
|
# PROXY_AUTH_PASSWORD=generate using gen_bcrypt
|
|
#
|
|
# Generating Credentials:
|
|
# All secrets are generated when using auto-configure except N8N_ENCRYPTION_KEY
|
|
# which can also be set by exporting the environment variable or by placing the
|
|
# key=value pair in n8n/.n8n.encryption.key.
|
|
|
|
# When using your existing n8n encryption key placed in n8n/.n8n.encryption.key,
|
|
# be sure to properly terminate the line entry with a new line (hit enter key to
|
|
# move your cursor to the next line). Also ensure the file format is LF (Unix)
|
|
# and not CRLF (Windows).
|
|
#
|
|
# OpenSSL: Available by default on Linux/Mac via command `openssl rand -hex 32`
|
|
# For Windows, use 'WSL2', 'Git Bash' terminal installed with git or from cmd
|
|
# run the command: python -c "import secrets; print(secrets.token_hex(32))"
|
|
#
|
|
# Password: Use Python command to generate 16-character strong password:
|
|
# python3 -c "import secrets;import string; alphabet = string.ascii_letters + string.digits;\
|
|
# password = ''.join(secrets.choice(alphabet) for i in range(16));\
|
|
# print(password)"
|
|
#
|
|
# JWT Tokens: Use https://jwtsecrets.com/#generator to generate keys and tokens
|
|
# ranging from 8 to 128 characters long.
|
|
############
|
|
|
|
############
|
|
# [required for Auto-Configuration] - automatically set when enabled (AC=True)
|
|
# Access Control - Proxy, Identity and Access Management configuration
|
|
############
|
|
|
|
# Enable proxy, identity and access auto-configure mode -credentials are auto-generated
|
|
AC=True
|
|
# Your public/private domain name. An arbitrary name is allowed for private domain
|
|
AC_DOMAIN=local.pc
|
|
# Configure AI-Suite as a local (private) vs. global (public) installation
|
|
AC_LOCAL=True
|
|
# The reverse proxy to use (Caddy or Nginx)
|
|
AC_PROXY=caddy
|
|
# User name for PROXY configuration (alphanumeric characters only)
|
|
AC_USERNAME=AISuiteProxyUser
|
|
# User password for PROXY configuration
|
|
# Keep default '*******' to trigger password prompt during setup
|
|
AC_PASSWORD='*******'
|
|
# Send confirmation email on user registration - SMTP server required
|
|
AC_CONFIRM=False
|
|
# Enable Authelia 2FA (two factor authentication) support
|
|
AC_WITH_AUTHELIA=True
|
|
# User email address for Authelia - required if AC_WITH_AUTHELIA=True
|
|
AC_EMAIL=ai-suite-internal@local.pc
|
|
# User display name for Authelia - required if AC_WITH_AUTHELIA=True (alphanumeric chars and spaces only)
|
|
AC_DISPLAY_NAME='AI Suite Authelia User'
|
|
# Use Redis with Authelia - recommended if AC_WITH_AUTHELIA=True and public
|
|
AC_WITH_REDIS=False
|
|
# Auto-configuration runtime log relative path without filename
|
|
AC_LOG_PATH=./access
|
|
|
|
############
|
|
# [required] - automatically set when auto-configure (AC=True) is enabled
|
|
# n8n credentials - use OpenSSL `openssl rand -hex 32` for all
|
|
############
|
|
|
|
# Master key used to encrypt sensitive credentials that n8n stores
|
|
N8N_ENCRYPTION_KEY=generate using gen_n8ncrypt
|
|
# Shared secret between n8n containers and runners sidecars
|
|
N8N_RUNNERS_AUTH_TOKEN=generate using gen_hex:32
|
|
# Specific JWT secret. By default, n8n generates one on start
|
|
N8N_USER_MANAGEMENT_JWT_SECRET=generate using gen_hex:32
|
|
|
|
############
|
|
# [required] - automatically set when auto-configure (AC=True) is enabled
|
|
# PostgreSQL database user password - use OpenSSL `openssl rand -hex 16`
|
|
############
|
|
|
|
POSTGRES_PASSWORD=generate using gen_hex:16
|
|
|
|
# Following settings are required if you enable the respective module.
|
|
|
|
#
|
|
#
|
|
#######
|
|
#####
|
|
#
|
|
|
|
############
|
|
# [required for Supabase] - automatically set when auto-configure (AC=True) is enabled
|
|
# Supabase Secrets
|
|
|
|
# Read these docs for any help: https://supabase.com/docs/guides/self-hosting/docker
|
|
# For the JWT Secret and keys, see: https://supabase.com/docs/guides/self-hosting/docker#generate-api-keys
|
|
# For the other secrets, see: https://supabase.com/docs/guides/self-hosting/docker#update-secrets
|
|
|
|
# Note that using special symbols (like '%') can complicate things a bit for your Postgres password.
|
|
# If you use special symbols in your Postgres password, you must remember to percent-encode your password later if using the
|
|
# Postgres connection string, for example, postgresql://postgres.projectref:p%3Dword@aws-0-us-east-1.pooler.supabase.com:6543/postgres
|
|
#
|
|
# To enable the new asymmetric key support, uncomment these lines in docker-compose.yml:
|
|
# Auth : GOTRUE_JWT_KEYS: ${JWT_KEYS:-[]}
|
|
# Realtime: API_JWT_JWKS: ${JWT_JWKS:-{"keys":[]}}
|
|
# Storage : JWT_JWKS: ${JWT_JWKS:-{"keys":[]}}
|
|
############
|
|
|
|
# Legacy symmetric HS256 key
|
|
JWT_SECRET=generate using gen_key:secret
|
|
# Legacy symmetric API key (HS256-signed JWT) for anon role.
|
|
ANON_KEY=generate using gen_key:anon_sym
|
|
# Legacy symmetric API key (HS256-signed JWT) for service role.
|
|
SERVICE_ROLE_KEY=generate using gen_key:service_role_sym
|
|
# Pre-signed ES256 JWT "API key" for anon role.
|
|
ANON_KEY_ASYMMETRIC=generate using gen_key:anon_asym
|
|
# Pre-signed ES256 JWT "API key" for service role.
|
|
SERVICE_ROLE_ASYMMETRIC=generate using gen_key:service_role_asym
|
|
# Opaque API key for client-side use (anon role).
|
|
SUPABASE_PUBLISHABLE_KEY=generate using gen_key:client
|
|
# Opaque API key for server-side use (service_role). Never expose in client code.
|
|
SUPABASE_SECRET_KEY=generate using gen_key:server
|
|
# JSON array of signing JWKs (EC private + legacy symmetric).
|
|
# Used by Auth.
|
|
JWT_KEYS=generate using gen_key:keys
|
|
# JWKS for token verification (EC public + legacy symmetric).
|
|
# Used by PostgREST, Realtime, Storage to verify tokens.
|
|
JWT_JWKS=generate using gen_key:jwks
|
|
# Used by Realtime and Supavisor
|
|
SECRET_KEY_BASE=generate using gen_token:48
|
|
# Used by Supavisor
|
|
VAULT_ENC_KEY=generate using gen_hex:16
|
|
# Used by Studio to access Postgres via postgres-meta
|
|
PG_META_CRYPTO_KEY=generate using gen_token:24
|
|
# Used by Kong dashboard user
|
|
DASHBOARD_PASSWORD=generate using gen_hex:16
|
|
|
|
############
|
|
# [required for Supabase] - automatically set when auto-configure (AC=True) is enabled
|
|
# Logs - Configuration for Supabase Analytics
|
|
# Please refer to https://supabase.com/docs/reference/self-hosting-analytics/introduction
|
|
############
|
|
|
|
# Change vector.toml sinks to reflect this change
|
|
# These cannot be the same value
|
|
# Must be at least 32 characters; generate with 'openssl rand -base64 24'
|
|
LOGFLARE_PUBLIC_ACCESS_TOKEN=generate using gen_token:24
|
|
LOGFLARE_PRIVATE_ACCESS_TOKEN=generate using gen_token:24
|
|
|
|
############
|
|
# [required for Supabase S3] - automatically set when auto-configure (AC=True) is enabled
|
|
# S3 - Supabase alternative storage
|
|
############
|
|
|
|
S3_PROTOCOL_ACCESS_KEY_ID=generate using gen_hex:16
|
|
S3_PROTOCOL_ACCESS_KEY_SECRET=generate using gen_hex:32
|
|
|
|
############
|
|
# [required for Supabase and Langfuse] - automatically set when auto-configure (AC=True) is enabled
|
|
# MinIO - authentication configuration - use OpenSSL `openssl rand -hex 16`
|
|
############
|
|
|
|
MINIO_ROOT_PASSWORD=generate using gen_hex:16
|
|
|
|
############
|
|
# [required for Flowise] - automatically set when auto-configure (AC=True) is enabled
|
|
# Flowise - authentication configuration - use OpenSSL `openssl rand -hex 16`
|
|
############
|
|
|
|
FLOWISE_PASSWORD=generate using gen_hex:16
|
|
|
|
############
|
|
# [required for Neo4j] - automatically set when auto-configure (AC=True) is enabled
|
|
# Neo4j admin username and password
|
|
# The admin username must remain "neo4j".
|
|
# Replace "password" with your chosen password.
|
|
# Keep the "/" as a separator between the two.
|
|
############
|
|
|
|
NEO4J_PASSWORD=generate using gen_hex:16
|
|
NEO4J_AUTH=neo4j/${NEO4J_PASSWORD}
|
|
|
|
############
|
|
# [required for Langfuse] - automatically set when auto-configure (AC=True) is enabled
|
|
# Langfuse credentials
|
|
# Each of the secret keys you can set to whatever you want, just make it secure!
|
|
# For salt, secret and encryption key, use OpenSSL command specified above
|
|
############
|
|
|
|
CLICKHOUSE_PASSWORD=generate using gen_hex:16
|
|
LANGFUSE_SALT=generate using gen_hex:16
|
|
NEXTAUTH_SECRET=generate using gen_token:32
|
|
ENCRYPTION_KEY=generate using gen_hex:32
|
|
|
|
# Following settings are required for production.
|
|
|
|
#
|
|
#
|
|
#######
|
|
#####
|
|
#
|
|
|
|
############
|
|
# [required for production if using Authelia]
|
|
# Automatically set when auto-configure (AC=True) is enabled
|
|
# Authelia Config
|
|
############
|
|
|
|
AUTHELIA_SESSION_SECRET=generate using gen_hex:32
|
|
AUTHELIA_STORAGE_ENCRYPTION_KEY=generate using gen_hex:32
|
|
AUTHELIA_IDENTITY_VALIDATION_RESET_PASSWORD_JWT_SECRET=generate using gen_hex:32
|
|
|
|
AUTHELIA_SCHEMA=authelia
|
|
|
|
############
|
|
# [required for production if using TLS Proxy]
|
|
# Automatically set when auto-configure (AC=True) is enabled
|
|
# Config for optional Caddy or Nginx reverse proxy with Let's Encrypt
|
|
############
|
|
|
|
# Generated bcrypt password for basic authentication without Authelia
|
|
PROXY_AUTH_PASSWORD=generate using gen_bcrypt
|
|
PROXY_AUTH_USERNAME=AISuiteProxyUser
|
|
|
|
############
|
|
# [required for production if using Caddy]
|
|
# Automatically set when auto-configure (AC=True) is enabled
|
|
# Caddy Config
|
|
|
|
# By default listen on https://localhost:[service port] and don't use an email for SSL
|
|
# To change this for production:
|
|
# Uncomment all of these environment variables for the services you want exposed
|
|
# Note that you might not want to expose Ollama or SearXNG since they aren't secured by default
|
|
############
|
|
|
|
# Domain name for the proxy (must point to your server)
|
|
PROXY_DOMAIN=${AC_DOMAIN}
|
|
|
|
# WEBUI_HOSTNAME=openwebui.${AC_DOMAIN}
|
|
# N8N_HOSTNAME=n8n.${AC_DOMAIN}
|
|
# OPENCLAW_HOSTNAME=openclaw.${AC_DOMAIN}
|
|
# FLOWISE_HOSTNAME=flowise.${AC_DOMAIN}
|
|
# SUPABASE_HOSTNAME=supabase.${AC_DOMAIN}
|
|
# LANGFUSE_HOSTNAME=langfuse.${AC_DOMAIN}
|
|
# OLLAMA_HOSTNAME=ollama.${AC_DOMAIN}
|
|
# LLAMACPP_HOSTNAME=llamacpp.${AC_DOMAIN}
|
|
# SEARXNG_HOSTNAME=searxng.${AC_DOMAIN}
|
|
# NEO4J_HOSTNAME=neo4j.${AC_DOMAIN}
|
|
# WEBHOOK_URL=https:n8n.${AC_DOMAIN}
|
|
# LETSENCRYPT_EMAIL=${AC_EMAIL}
|
|
|
|
############
|
|
# [required for production if using Nginx]
|
|
# Automatically set when auto-configure (AC=True) is enabled
|
|
# Ngnix Config
|
|
############
|
|
|
|
NGINX_SERVER_NAME=generated-primary-hostname
|
|
CERTBOT_EMAIL=ai-suite-internal@local.pc
|
|
# This must be set to 0 for public installation
|
|
USE_LOCAL_CA=1
|
|
|
|
# Everything below this point is optional.
|
|
# Default values will suffice unless you need more features/customization.
|
|
|
|
#
|
|
#
|
|
#######
|
|
#####
|
|
#
|
|
|
|
############
|
|
# n8n
|
|
############
|
|
|
|
N8N_PORT=5678
|
|
|
|
# Set as N8N_HOST=${N8N_HOSTNAME:-${N8N_HOST}} in compose.yaml
|
|
N8N_HOST=localhost
|
|
|
|
# If using HTTPS via reverse proxy, uncomment these environment variables
|
|
# N8N_PROTOCOL=https
|
|
# N8N_PROXY_HOPS=3
|
|
|
|
# Permissions 0644 for n8n settings file /home/node/.n8n/config are too wide.
|
|
N8N_ENFORCE_SETTINGS_FILE_PERMISSIONS=true
|
|
# https://docs.n8n.io/hosting/configuration/task-runners/
|
|
N8N_RUNNERS_ENABLED=true
|
|
# https://docs.n8n.io/hosting/configuration/environment-variables/security/
|
|
N8N_BLOCK_ENV_ACCESS_IN_NODE=false
|
|
# https://docs.n8n.io/hosting/configuration/environment-variables/security/
|
|
N8N_GIT_NODE_DISABLE_BARE_REPOS=true
|
|
N8N_DEFAULT_BINARY_DATA_MODE=filesystem
|
|
|
|
N8N_NODE_ENV=production
|
|
N8N_DIAGNOSTICS_ENABLED=false
|
|
N8N_VERSION_NOTIFICATIONS_ENABLED=true
|
|
|
|
# Community package tools
|
|
N8N_COMMUNITY_PACKAGES_ALLOW_TOOL_USAGE=true
|
|
N8N_DB_TYPE=postgresdb
|
|
|
|
# Task runners (2.0)
|
|
N8N_RUNNERS_BROKER_LISTEN_ADDRESS=0.0.0.0
|
|
N8N_RUNNERS_MODE=external
|
|
|
|
N8N_MEMORY_LIMIT=4G
|
|
N8N_RESERVE_MEMORY=1G
|
|
|
|
# Security dials:
|
|
N8N_RESTRICT_FILE_ACCESS_TO=/home/node
|
|
N8N_SKIP_AUTH_ON_OAUTH_CALLBACK=true
|
|
N8N_NODES_EXCLUDE='[]'
|
|
|
|
############
|
|
# Redis / Queue
|
|
############
|
|
|
|
EXECUTIONS_MODE=queue
|
|
QUEUE_BULL_REDIS_HOST=redis
|
|
QUEUE_BULL_REDIS_PORT=6379
|
|
QUEUE_HEALTH_CHECK_ACTIVE=true
|
|
OFFLOAD_MANUAL_EXECUTIONS_TO_WORKERS=true
|
|
|
|
############
|
|
# PostgreSQL - You can change these to any PostgreSQL database that has logical replication enabled.
|
|
############
|
|
|
|
POSTGRES_DB=postgres
|
|
POSTGRES_USER=postgres
|
|
POSTGRES_HOST=postgres
|
|
POSTGRES_PORT=5432
|
|
|
|
############
|
|
# Time Zone
|
|
############
|
|
|
|
GENERIC_TIMEZONE=France/Paris
|
|
|
|
############
|
|
# Projects
|
|
############
|
|
|
|
# Set to '.' resolves to current work directory
|
|
# leaving empty resolves to '~/projects'
|
|
PROJECTS_PATH=
|
|
|
|
############
|
|
# Document Processing Settings
|
|
############
|
|
|
|
# Document watch folder
|
|
DOCUMENTS_FOLDER=${PROJECTS_PATH}/ai_documents
|
|
|
|
# Settings for large document processing
|
|
DOCUMENTS_KV_CACHE_DIR=${DOCUMENTS_FOLDER}/kv_caches
|
|
DOCUMENTS_CHUNKS_DIR=${DOCUMENTS_FOLDER}/temp_chunks
|
|
|
|
# Advanced settings for large document processing
|
|
MAX_CHUNK_SIZE=40000 # Larger chunks for CAG (character count)
|
|
CHUNK_OVERLAP=500 # Overlap between chunks if needed
|
|
MIN_DOCUMENT_SIZE_FOR_CHUNKING=100000 # Only chunk very large documents
|
|
|
|
############
|
|
# Ollama - LLM
|
|
############
|
|
|
|
OLLAMA_PORT=11434
|
|
|
|
# Docker backend connect when running Ollama in the Host:
|
|
#OLLAMA_HOST=host.docker.internal:${OLLAMA_PORT}
|
|
# When accessing Ollama from the Host:
|
|
OLLAMA_HOST=localhost:${OLLAMA_PORT}
|
|
# When running Ollama in Docker:
|
|
#OLLAMA_HOST=ollama:${OLLAMA_PORT}
|
|
|
|
# Tuning
|
|
OLLAMA_CONTEXT_LENGTH=4096
|
|
OLLAMA_FLASH_ATTENTION=1
|
|
OLLAMA_KV_CACHE_TYPE=q4_0
|
|
OLLAMA_MAX_LOADED_MODELS=2
|
|
|
|
# Models
|
|
OLLAMA_DEFAULT_MODEL=llama3.2
|
|
OLLAMA_SUPPLEMENT_MODEL=qwen3:8b
|
|
OLLAMA_EMBEDDING_MODEL=nomic-embed-text
|
|
|
|
# Ollama server arguments - use ollama serve --help for available 'serve' arguments
|
|
OLLAMA_SERVER_ARGS=serve
|
|
|
|
############
|
|
# LLaMA.cpp - LLM
|
|
############
|
|
|
|
LLAMA_ARG_PORT=8040
|
|
|
|
# Docker backend connect when running LLaMA.cpp in the Host:
|
|
#LLAMA_ARG_HOST=host.docker.internal
|
|
# When running LLaMA.cpp in Docker:
|
|
LLAMA_ARG_HOST=0.0.0.0
|
|
|
|
# Backend connect
|
|
LLAMACPP_HOST=${LLAMA_ARG_HOST}:${LLAMA_ARG_PORT}
|
|
|
|
# Model names - Dictionary keys for model download identifier values below.
|
|
# Keys, and values below include an empty slot for a user-defined model
|
|
LLAMACPP_MODEL_GEMMA=gemma-4b # Default
|
|
LLAMACPP_MODEL_DEEPSEEK=deepseek-7b
|
|
LLAMACPP_MODEL_MISTRAL=mistral-7b
|
|
LLAMACPP_MODEL_LLAMA=llama-8b
|
|
LLAMACPP_MODEL_QWEN=qwen-8b
|
|
LLAMACPP_MODEL_USER=
|
|
|
|
# Model download identifier - Dictionary values for model keys above.
|
|
# Model selected by 'best match' to LLAMACPP_MODEL_NAME
|
|
# To specify a local model, change '-hf' to '-m' in LLAMACPP_SERVER_ARGS below
|
|
# and replace the respective model id value below with 'models/<model filename>'.
|
|
LLAMACPP_MODEL_GEMMA_ID=ggml-org/gemma-3-4b-it-GGUF
|
|
LLAMACPP_MODEL_DEEPSEEK_ID=mradermacher/DeepSeek-R1-Distill-Qwen-7B-Uncensored-i1-GGUF
|
|
LLAMACPP_MODEL_MISTRAL_ID=bartowski/mistralai_Ministral-3-8B-Instruct-2512-GGUF
|
|
LLAMACPP_MODEL_LLAMA_ID=bartowski/allura-forge_Llama-3.3-8B-Instruct-GGUF
|
|
LLAMACPP_MODEL_QWEN_ID=bartowski/Qwen_Qwen3-8B-GGUF
|
|
LLAMACPP_MODEL_USER_ID=
|
|
|
|
# Model and paths
|
|
LLAMACPP_PATH=llama.cpp
|
|
LLAMACPP_DEFAULT_MODEL=${LLAMACPP_MODEL_GEMMA} # IMPORTANT: should reasonably match dictionary model name above.
|
|
LLAMACPP_MODELS_DIR=${LLAMACPP_PATH}/models
|
|
LLAMACPP_MODEL_PATH=${LLAMACPP_MODELS_DIR}/${LLAMACPP_DEFAULT_MODEL}
|
|
|
|
# Model management - automatically download specified model if not downloaded.
|
|
LLAMA_ARG_HF_REPO=${LLAMACPP_MODEL_GEMMA_ID}
|
|
|
|
# Tuning
|
|
LLAMA_ARG_CTX_SIZE=4096
|
|
LLAMA_ARG_FLASH_ATTN=1
|
|
LLAMA_ARG_N_GPU_LAYERS=0
|
|
LLAMA_ARG_THREADS=4
|
|
LLAMA_ARG_MODELS_MAX=4
|
|
|
|
# LLaMA.cpp server arguments - use 'llama-server --help' for available arguments
|
|
# To specify a local model, append '-m' or '––model'.
|
|
# To auto-download model (if not already downloaded) and if LLAMA_ARG_HF_REPO is
|
|
# not used (commented), append '-hf' or '--hf-file'.
|
|
LLAMACPP_SERVER_ARGS=--jinja
|
|
|
|
############
|
|
# LLAMA (Ollama/LLaMA.cpp) - Shared environment variables
|
|
############
|
|
|
|
# Application Installation path
|
|
# Set for LLaMA.cpp or if using custom Ollama installation path
|
|
# e.g. LLAMA_PATH=~\Projects\ai-suite\llama.cpp\bin\llama-server.exe
|
|
# Omit '<value>' to return 'False' when queried
|
|
LLAMA_PATH=
|
|
|
|
# Conecting to LLAMA using OpenAI API connection
|
|
# When running Ollama: ${OLLAMA_HOST}
|
|
# When running LLaMA.cpp: ${LLAMACPP_HOST}
|
|
OPENAI_API_BASE_URL=${OLLAMA_HOST}
|
|
#OPENAI_API_KEY - OpenAI API key declared below at Studio
|
|
|
|
############
|
|
# Open-WebUI
|
|
############
|
|
|
|
# For production, you should only need one host as fastapi serves
|
|
# the svelte-kit built frontend and backend from the same host and port.
|
|
#CORS_ALLOW_ORIGIN=http://localhost:8080
|
|
CORS_ALLOW_ORIGIN='*'
|
|
|
|
# For production, set this to match the proxy configuration (127.0.0.1)
|
|
#FORWARDED_ALLOW_IPS=127.0.0.1
|
|
FORWARDED_ALLOW_IPS='*'
|
|
|
|
# If running Open WebUI in an offline environment, set to 1 to prevent attempts to download models from the internet.
|
|
# Omit '<value>' to return 'False' when queried
|
|
HF_HUB_OFFLINE=
|
|
|
|
# AUTOMATIC1111_BASE_URL="http://localhost:7860"
|
|
|
|
# Analytics and Telemetry Tracking
|
|
DO_NOT_TRACK=true
|
|
SCARF_NO_ANALYTICS=true
|
|
ANONYMIZED_TELEMETRY=false
|
|
|
|
# MCPO
|
|
MCPO_HOT_RELOAD=true
|
|
|
|
############
|
|
# Flowise - Authentication Configuration for Flowise
|
|
############
|
|
|
|
FLOWISE_USERNAME=AISuiteFloweseUser
|
|
|
|
############
|
|
# Optional SearXNG Config
|
|
# If you run a very small or a very large instance, you might want to
|
|
# change the amount of used uwsgi workers and threads per worker
|
|
# More workers (= processes) means that more search requests can be
|
|
# handled at the same time, but it also causes more resource usage
|
|
############
|
|
|
|
# SEARXNG_UWSGI_WORKERS=4
|
|
# SEARXNG_UWSGI_THREADS=4
|
|
|
|
############
|
|
# Docker Compose
|
|
############
|
|
|
|
# Docker socket location - this value will differ depending on your OS
|
|
DOCKER_SOCKET_LOCATION=/var/run/docker.sock
|
|
|
|
# Set Docker Compose ignore orphans to 'true' for locally built comtainers
|
|
# Omit '<value>' to return 'False' when queried
|
|
COMPOSE_IGNORE_ORPHANS=
|
|
|
|
############
|
|
# Google - Supabase and Cloud Project Config
|
|
# Get these values from the Google Admin Console
|
|
############
|
|
|
|
# - Authentication for Supabase
|
|
# ENABLE_GOOGLE_SIGNUP=true
|
|
# GOOGLE_CLIENT_ID=
|
|
# GOOGLE_CLIENT_SECRET=
|
|
# GOOGLE_REDIRECT_URI=
|
|
|
|
# - Google Cloud Project details
|
|
GOOGLE_PROJECT_ID=GOOGLE_PROJECT_ID
|
|
GOOGLE_PROJECT_NUMBER=GOOGLE_PROJECT_NUMBER
|
|
|
|
############
|
|
# Supavisor -- Database pooler and others that can be left as default values
|
|
############
|
|
|
|
POOLER_PROXY_PORT_TRANSACTION=6543
|
|
POOLER_DEFAULT_POOL_SIZE=20
|
|
POOLER_MAX_CLIENT_CONN=100
|
|
# Pool size for internal metadata storage used by Supavisor
|
|
# This is separate from client connections and used only by Supavisor itself
|
|
POOLER_DB_POOL_SIZE=5
|
|
# You can decide your value for POOLER_TENANT_ID like 1000.
|
|
POOLER_TENANT_ID=1042
|
|
|
|
############
|
|
# API Proxy - Configuration for the Kong Reverse proxy
|
|
############
|
|
|
|
KONG_HTTP_PORT=8000
|
|
KONG_HTTPS_PORT=8443
|
|
|
|
############
|
|
# API - Configuration for PostgREST
|
|
############
|
|
|
|
PGRST_DB_SCHEMAS=public,storage,graphql_public
|
|
# Max number of rows returned by a request
|
|
PGRST_DB_MAX_ROWS=1000
|
|
# Extra schemas added to the search_path of every request
|
|
PGRST_DB_EXTRA_SEARCH_PATH=public
|
|
|
|
############
|
|
# API - Dashboard user
|
|
############
|
|
|
|
DASHBOARD_USERNAME=supabase
|
|
|
|
############
|
|
# S3 storage backend
|
|
############
|
|
|
|
GLOBAL_S3_BUCKET=stub
|
|
|
|
############
|
|
# API - MinIO user
|
|
# Used by MinIO when added via:
|
|
# docker compose -f docker-compose.yml -f docker-compose.s3.yml up -d
|
|
############
|
|
|
|
MINIO_ROOT_USER=supa-storage
|
|
|
|
############
|
|
# File storage backend
|
|
# Equivalent to project_ref as described here:
|
|
# https://supabase.com/docs/guides/storage/s3/authentication#session-token
|
|
############
|
|
|
|
STORAGE_TENANT_ID=stub
|
|
|
|
############
|
|
# Auth - Configuration for the GoTrue authentication server
|
|
############
|
|
|
|
## General
|
|
SITE_URL=http://localhost:3000
|
|
ADDITIONAL_REDIRECT_URLS=http://localhost:8000
|
|
JWT_EXPIRY=3600
|
|
DISABLE_SIGNUP=false
|
|
API_EXTERNAL_URL=http://localhost:8000
|
|
ENABLE_EMAIL_AUTOCONFIRM=False
|
|
REGION=local
|
|
|
|
## Mailer Config
|
|
MAILER_URLPATHS_CONFIRMATION="/auth/v1/verify"
|
|
MAILER_URLPATHS_INVITE="/auth/v1/verify"
|
|
MAILER_URLPATHS_RECOVERY="/auth/v1/verify"
|
|
MAILER_URLPATHS_EMAIL_CHANGE="/auth/v1/verify"
|
|
|
|
## Email auth
|
|
ENABLE_EMAIL_SIGNUP=true
|
|
ENABLE_EMAIL_AUTOCONFIRM=false
|
|
SMTP_ADMIN_EMAIL=admin@example.com
|
|
SMTP_HOST=supabase-mail
|
|
SMTP_PORT=2500
|
|
SMTP_USER=fake_mail_user
|
|
SMTP_PASS=generate using gen_hex:16
|
|
SMTP_SENDER_NAME=fake_sender
|
|
ENABLE_ANONYMOUS_USERS=false
|
|
|
|
## Phone auth
|
|
ENABLE_PHONE_SIGNUP=true
|
|
ENABLE_PHONE_AUTOCONFIRM=true
|
|
|
|
############
|
|
# Studio - Configuration for the Dashboard
|
|
############
|
|
|
|
STUDIO_DEFAULT_ORGANIZATION=Default Organization
|
|
STUDIO_DEFAULT_PROJECT=Default Project
|
|
|
|
STUDIO_PORT=3000
|
|
# replace if you intend to use Studio outside of localhost
|
|
SUPABASE_PUBLIC_URL=http://localhost:8000
|
|
|
|
############
|
|
# imgproxy - Enable webp support
|
|
############
|
|
|
|
IMGPROXY_AUTO_WEBP=true
|
|
|
|
# Add your OpenAI API key to enable SQL Editor Assistant
|
|
OPENAI_API_KEY=
|
|
|
|
############
|
|
# Functions - Configuration for Functions
|
|
############
|
|
|
|
# NOTE: VERIFY_JWT applies to all functions. Per-function VERIFY_JWT is not supported yet.
|
|
FUNCTIONS_VERIFY_JWT=false
|
|
|
|
# End of document
|
|
############
|