Files
ai-suite/.env.example
T

484 lines
15 KiB
Bash

# Change the name of this file to .env after updating it!
############
# Generating Credentials
# OpenSSL: Available by default on Linux/Mac via command `openssl rand -hex 32`
# For Windows, use 'WSL2', 'Git Bash' terminal installed with git or from cmd
# run the command: python -c "import secrets; print(secrets.token_hex(32))"
#
# Password: Use Python command to generate 16-character strong password:
# python3 -c "import secrets;import string; alphabet = string.ascii_letters + string.digits;\
# password = ''.join(secrets.choice(alphabet) for i in range(16));\
# print(password)"
#
# JWT Tokens: Use https://jwtsecrets.com/#generator to generate keys and tokens
# ranging from 8 to 128 characters long.
############
############
# [required]
# n8n credentials - use OpenSSL for all
############
# Master key used to encrypt sensitive credentials that n8n stores
N8N_ENCRYPTION_KEY=change_me_to_a_long_super-secret-key
# Shared secret between n8n containers and runners sidecars
N8N_RUNNERS_AUTH_TOKEN=change_me_to_a_long_super-secret-key
# Specific JWT secret. By default, n8n generates one on start
N8N_USER_MANAGEMENT_JWT_SECRET=change_me_to_a_longer_even-more-secret
############
# [required]
# PostgreSQL database user password
############
POSTGRES_PASSWORD=your-super-secret-postgres-password
############
# [required]
# Supabase Secrets
# YOU MUST CHANGE THESE BEFORE GOING INTO PRODUCTION
# Read these docs for any help: https://supabase.com/docs/guides/self-hosting/docker
# For the JWT Secret and keys, see: https://supabase.com/docs/guides/self-hosting/docker#generate-api-keys
# For the other secrets, see: https://supabase.com/docs/guides/self-hosting/docker#update-secrets
# You can really decide any value for POOLER_TENANT_ID like 1000.
# Note that using special symbols (like '%') can complicate things a bit for your Postgres password.
# If you use special symbols in your Postgres password, you must remember to percent-encode your password later if using the Postgres connection string, for example, postgresql://postgres.projectref:p%3Dword@aws-0-us-east-1.pooler.supabase.com:6543/postgres
############
JWT_SECRET=your-super-secret-jwt-token-with-at-least-40-characters-long
ANON_KEY=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyAgCiAgICAicm9sZSI6ICJhbm9uIiwKICAgICJpc3MiOiAic3VwYWJhc2UtZGVtbyIsCiAgICAiaWF0IjogMTY0MTc2OTIwMCwKICAgICJleHAiOiAxNzk5NTM1NjAwCn0.dc_X5iR_VP_qT0zsiyj_I_OZ2T9FtRU2BBNWN8Bu4GE
SERVICE_ROLE_KEY=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyAgCiAgICAicm9sZSI6ICJzZXJ2aWNlX3JvbGUiLAogICAgImlzcyI6ICJzdXBhYmFzZS1kZW1vIiwKICAgICJpYXQiOiAxNjQxNzY5MjAwLAogICAgImV4cCI6IDE3OTk1MzU2MDAKfQ.DaYlNEoUrrEn2Ig7tqibS-PHK5vgusbcbo7X36XVt4Q
DASHBOARD_USERNAME=supabase
DASHBOARD_PASSWORD=your-super-secret-password-1
POOLER_TENANT_ID=your-tenant-id
############
# [required]
# Flowise - authentication configuration
############
FLOWISE_PASSWORD=your-super-secret-postgres-password
############
# [required]
# Neo4j admin username and password
# The admin username must remain "neo4j".
# Replace "password" with your chosen password.
# Keep the "/" as a separator between the two.
############
NEO4J_AUTH=neo4j/your-super-secret-password-2
############
# [required]
# Langfuse credentials
# Each of the secret keys you can set to whatever you want, just make it secure!
# For salt, secret and encryption key, use OpenSSL command specified above
############
CLICKHOUSE_PASSWORD=your-super-secret-password-3
MINIO_ROOT_PASSWORD=your-super-secret-password-4
LANGFUSE_SALT=your-super-secret-key-1
NEXTAUTH_SECRET=your-super-secret-key-2
ENCRYPTION_KEY=your-super-secret-key-3
############
# [required for production]
# Access Auto-configuration settings
############
AC_SUDO_USER='change_this_user'
AC_USERNAME='ai_suite_user'
AC_PASSWORD='*******'
AC_LOG_PATH=scripts
AC_LOCAL=True
AC_DOMAIN='local.com'
AC_CONFIRM=False
AC_PROXY=caddy
AC_WITH_AUTHELIA=False
AC_EMAIL='ai.suite.user@local.com'
AC_DISPLAY_NAME='AI-Suite User'
AC_WITH_REDIS=False
############
# [required for production]
# Caddy Config
# By default listen on https://localhost:[service port] and don't use an email for SSL
# To change this for production:
# Uncomment all of these environment variables for the services you want exposed
# Note that you might not want to expose Ollama or SearXNG since they aren't secured by default
# Replace the placeholder value with the host for each service (like n8n.yourdomain.com)
# Replace internal by your email (require to create a Let's Encrypt certificate)
############
# N8N_HOSTNAME=n8n.${AC_DOMAIN}
# WEBHOOK_URL=https:n8n.${AC_DOMAIN}
# WEBUI_HOSTNAME=openwebui.${AC_DOMAIN}
# FLOWISE_HOSTNAME=flowise.${AC_DOMAIN}
# SUPABASE_HOSTNAME=supabase.${AC_DOMAIN}
# LANGFUSE_HOSTNAME=langfuse.${AC_DOMAIN}
# OLLAMA_HOSTNAME=ollama.${AC_DOMAIN}
# LLAMACPP_HOSTNAME=llamacpp.${AC_DOMAIN}
# SEARXNG_HOSTNAME=searxng.${AC_DOMAIN}
# NEO4J_HOSTNAME=neo4j.${AC_DOMAIN}
# LETSENCRYPT_EMAIL=${AC_EMAIL}
# Everything below this point is optional.
# Default values will suffice unless you need more features/customization.
#
#
#######
#####
#
############
# n8n
############
N8N_PORT=5678
# Set as N8N_HOST=${N8N_HOSTNAME:-${N8N_HOST}} in compose.yaml
N8N_HOST=localhost
# Permissions 0644 for n8n settings file /home/node/.n8n/config are too wide.
N8N_ENFORCE_SETTINGS_FILE_PERMISSIONS=true
# https://docs.n8n.io/hosting/configuration/task-runners/
N8N_RUNNERS_ENABLED=true
# https://docs.n8n.io/hosting/configuration/environment-variables/security/
N8N_BLOCK_ENV_ACCESS_IN_NODE=false
# https://docs.n8n.io/hosting/configuration/environment-variables/security/
N8N_GIT_NODE_DISABLE_BARE_REPOS=true
N8N_DEFAULT_BINARY_DATA_MODE=filesystem
NODE_ENV=production
N8N_DIAGNOSTICS_ENABLED=false
N8N_VERSION_NOTIFICATIONS_ENABLED=true
# Community package tools
N8N_COMMUNITY_PACKAGES_ALLOW_TOOL_USAGE=true
# Security dials:
N8N_RESTRICT_FILE_ACCESS_TO=/home/node
N8N_SKIP_AUTH_ON_OAUTH_CALLBACK=true
NODES_EXCLUDE='[]'
# Queue / Redis
EXECUTIONS_MODE=queue
QUEUE_BULL_REDIS_HOST=redis
QUEUE_BULL_REDIS_PORT=6379
QUEUE_HEALTH_CHECK_ACTIVE=true
OFFLOAD_MANUAL_EXECUTIONS_TO_WORKERS=true
# Task runners (2.0)
N8N_RUNNERS_BROKER_LISTEN_ADDRESS=0.0.0.0
N8N_RUNNERS_MODE=external
N8N_MEMORY_LIMIT=4G
N8N_RESERVE_MEMORY=1G
# Time
GENERIC_TIMEZONE=France/Paris
############
# PostgreSQL - You can change these to any PostgreSQL database that has logical replication enabled.
############
DB_TYPE=postgresdb
POSTGRES_DB=postgres
POSTGRES_USER=postgres
POSTGRES_HOST=postgres
POSTGRES_PORT=5432
############
# Projects
############
# Set to '.' resolves to current work directory
# leaving empty resolves to '~/projects'
PROJECTS_PATH=
############
# Document Processing Settings
############
# Document watch folder
DOCUMENTS_FOLDER=${PROJECTS_PATH}/ai_documents
# Settings for large document processing
DOCUMENTS_KV_CACHE_DIR=${DOCUMENTS_FOLDER}/kv_caches
DOCUMENTS_CHUNKS_DIR=${DOCUMENTS_FOLDER}/temp_chunks
# Advanced settings for large document processing
MAX_CHUNK_SIZE=40000 # Larger chunks for CAG (character count)
CHUNK_OVERLAP=500 # Overlap between chunks if needed
MIN_DOCUMENT_SIZE_FOR_CHUNKING=100000 # Only chunk very large documents
############
# Ollama - LLM
############
OLLAMA_PORT=11434
# When running Ollama in the Host:
#OLLAMA_HOST=host.docker.internal:11434
# When running Ollama in Docker:
#OLLAMA_HOST=ollama:11434
OLLAMA_HOST=host.docker.internal:11434
# Tuning
OLLAMA_CONTEXT_LENGTH=4096
OLLAMA_FLASH_ATTENTION=1
OLLAMA_KV_CACHE_TYPE=q4_0
OLLAMA_MAX_LOADED_MODELS=2
# Models
OLLAMA_DEFAULT_MODEL=llama3.2
OLLAMA_SUPPLEMENT_MODEL=qwen3:8b
OLLAMA_EMBEDDING_MODEL=nomic-embed-text
# Ollama server arguments - use ollama serve --help for available 'serve' arguments
OLLAMA_SERVER_ARGS=serve
############
# LLaMA.cpp - LLM
############
LLAMA_ARG_PORT=8040
# When running LLaMA.cpp in the host:
#LLAMA_ARG_HOST=host.docker.internal
# When running LLaMA.cpp in Docker:
#LLAMA_ARG_HOST=0.0.0.0
LLAMA_ARG_HOST=0.0.0.0
# Backend connect
LLAMACPP_HOST=${LLAMA_ARG_HOST}:${LLAMA_ARG_PORT}
# Model names - Dictionary keys for model download identifier values below.
# Keys, and values below include an empty slot for a user-defined model
LLAMACPP_MODEL_GEMMA=gemma-4b # Default
LLAMACPP_MODEL_DEEPSEEK=deepseek-7b
LLAMACPP_MODEL_MISTRAL=mistral-7b
LLAMACPP_MODEL_LLAMA=llama-8b
LLAMACPP_MODEL_QWEN=qwen-8b
LLAMACPP_MODEL_USER=
# Model download identifier - Dictionary values for model keys above.
# Model selected by 'best match' to LLAMACPP_MODEL_NAME
# To specify a local model, change '-hf' to '-m' in LLAMACPP_SERVER_ARGS below
# and replace the respective model id value below with 'models/<model filename>'.
LLAMACPP_MODEL_GEMMA_ID=ggml-org/gemma-3-4b-it-GGUF
LLAMACPP_MODEL_DEEPSEEK_ID=mradermacher/DeepSeek-R1-Distill-Qwen-7B-Uncensored-i1-GGUF
LLAMACPP_MODEL_MISTRAL_ID=bartowski/mistralai_Ministral-3-8B-Instruct-2512-GGUF
LLAMACPP_MODEL_LLAMA_ID=bartowski/allura-forge_Llama-3.3-8B-Instruct-GGUF
LLAMACPP_MODEL_QWEN_ID=bartowski/Qwen_Qwen3-8B-GGUF
LLAMACPP_MODEL_USER_ID=
# Model and paths
LLAMACPP_PATH=llama.cpp
LLAMACPP_DEFAULT_MODEL=${LLAMACPP_MODEL_GEMMA} # IMPORTANT: should reasonably match dictionary model name above.
LLAMACPP_MODELS_DIR=${LLAMACPP_PATH}/models
LLAMACPP_MODEL_PATH=${LLAMACPP_MODELS_DIR}/${LLAMACPP_MODEL_NAME}
# Model management - automatically download specified model if not downloaded.
LLAMA_ARG_HF_REPO=${LLAMACPP_MODEL_GEMMA_ID}
# Tuning
LLAMA_ARG_CTX_SIZE=4096
LLAMA_ARG_FLASH_ATTN=1
LLAMA_ARG_N_GPU_LAYERS=0
LLAMA_ARG_THREADS=4
LLAMA_ARG_MODELS_MAX=4
# LLaMA.cpp server arguments - use 'llama-server --help' for available arguments
# To specify a local model, append '-m' or '––model'.
# To auto-download model (if not already downloaded) and if LLAMA_ARG_HF_REPO is
# not used (commented), append '-hf' or '--hf-file'.
LLAMACPP_SERVER_ARGS=--jinja
############
# LLAMA (Ollama/LLaMA.cpp) - Shared environment variables
############
# Application Installation path
# Set for LLaMA.cpp or if using custom Ollama installation path
# e.g. LLAMA_PATH=~\Projects\ai-suite\llama.cpp\bin\llama-server.exe
# Omit '<value>' to return 'False' when queried
LLAMA_PATH=
# Conecting to LLAMA using OpenAI API connection
# When running Ollama: ${OLLAMA_HOST}
# When running LLaMA.cpp: ${LLAMACPP_HOST}
OPENAI_API_BASE_URL=${OLLAMA_HOST}
#OPENAI_API_KEY - OpenAI API key declared below at Studio
############
# Open-WebUI
############
# For production, you should only need one host as fastapi serves
# the svelte-kit built frontend and backend from the same host and port.
#CORS_ALLOW_ORIGIN=http://localhost:8080
CORS_ALLOW_ORIGIN='*'
# For production, set this to match the proxy configuration (127.0.0.1)
#FORWARDED_ALLOW_IPS=127.0.0.1
FORWARDED_ALLOW_IPS='*'
# If running Open WebUI in an offline environment, set to 1 to prevent attempts to download models from the internet.
# Omit '<value>' to return 'False' when queried
HF_HUB_OFFLINE=
# AUTOMATIC1111_BASE_URL="http://localhost:7860"
# Analytics and Telemetry Tracking
DO_NOT_TRACK=true
SCARF_NO_ANALYTICS=true
ANONYMIZED_TELEMETRY=false
# MCPO
MCPO_HOT_RELOAD=true
############
# Docker Compose
############
# Docker socket location - this value will differ depending on your OS
DOCKER_SOCKET_LOCATION=/var/run/docker.sock
# Set Docker Compose ignore orphans to 'true' for locally built comtainers
# Omit '<value>' to return 'False' when queried
COMPOSE_IGNORE_ORPHANS=
############
# Google
# - Authentication for Supabase
# - Google Cloud Project details
# Get these values from the Google Admin Console
############
# ENABLE_GOOGLE_SIGNUP=true
# GOOGLE_CLIENT_ID=
# GOOGLE_CLIENT_SECRET=
# GOOGLE_REDIRECT_URI=
GOOGLE_PROJECT_ID=GOOGLE_PROJECT_ID
GOOGLE_PROJECT_NUMBER=GOOGLE_PROJECT_NUMBER
############
# Optional SearXNG Config
# If you run a very small or a very large instance, you might want to change the amount of used uwsgi workers and threads per worker
# More workers (= processes) means that more search requests can be handled at the same time, but it also causes more resource usage
############
# SEARXNG_UWSGI_WORKERS=4
# SEARXNG_UWSGI_THREADS=4
############
# Supavisor -- Database pooler and others that can be left as default values
############
POOLER_PROXY_PORT_TRANSACTION=6543
POOLER_DEFAULT_POOL_SIZE=20
POOLER_MAX_CLIENT_CONN=100
# Must be at least 64 characters; generate with 'openssl rand -base64 48'
SECRET_KEY_BASE=UpNVntn3cDxHJpq99YMc1T1AQgQpc8kfYTuRgBiYa15BLrx8etQoXz3gZv1/u2oq
# Must be exactly 32 characters; generate with 'openssl rand -hex 16'
VAULT_ENC_KEY=your-32-character-encryption-key
# Must be at least 32 characters; generate with 'openssl rand -base64 24'
PG_META_CRYPTO_KEY=your-super-secret—long-encryption-key
# Pool size for internal metadata storage used by Supavisor
# This is separate from client connections and used only by Supavisor itself
POOLER_DB_POOL_SIZE=5
############
# API Proxy - Configuration for the Kong Reverse proxy
############
KONG_HTTP_PORT=8000
KONG_HTTPS_PORT=8443
############
# API - Configuration for PostgREST
############
PGRST_DB_SCHEMAS=public,storage,graphql_public
############
# Flowise - Authentication Configuration for Flowise
############
FLOWISE_USERNAME=ai_suite_user
############
# Auth - Configuration for the GoTrue authentication server
############
## General
SITE_URL=http://localhost:3000
ADDITIONAL_REDIRECT_URLS=http://localhost:8000
JWT_EXPIRY=3600
DISABLE_SIGNUP=false
API_EXTERNAL_URL=http://localhost:8000
## Mailer Config
MAILER_URLPATHS_CONFIRMATION="/auth/v1/verify"
MAILER_URLPATHS_INVITE="/auth/v1/verify"
MAILER_URLPATHS_RECOVERY="/auth/v1/verify"
MAILER_URLPATHS_EMAIL_CHANGE="/auth/v1/verify"
## Email auth
ENABLE_EMAIL_SIGNUP=true
ENABLE_EMAIL_AUTOCONFIRM=true
SMTP_ADMIN_EMAIL=admin@example.com
SMTP_HOST=supabase-mail
SMTP_PORT=2500
SMTP_USER=fake_mail_user
SMTP_PASS=fake_mail_password
SMTP_SENDER_NAME=fake_sender
ENABLE_ANONYMOUS_USERS=false
## Phone auth
ENABLE_PHONE_SIGNUP=true
ENABLE_PHONE_AUTOCONFIRM=true
############
# Studio - Configuration for the Dashboard
############
STUDIO_DEFAULT_ORGANIZATION=Default Organization
STUDIO_DEFAULT_PROJECT=Default Project
STUDIO_PORT=3000
# replace if you intend to use Studio outside of localhost
SUPABASE_PUBLIC_URL=http://localhost:8000
# Enable webp support
IMGPROXY_ENABLE_WEBP_DETECTION=true
# Add your OpenAI API key to enable SQL Editor Assistant
OPENAI_API_KEY=
############
# Functions - Configuration for Functions
############
# NOTE: VERIFY_JWT applies to all functions. Per-function VERIFY_JWT is not supported yet.
FUNCTIONS_VERIFY_JWT=false
############
# Logs - Configuration for Analytics
# Please refer to https://supabase.com/docs/reference/self-hosting-analytics/introduction
############
# Change vector.toml sinks to reflect this change
# These cannot be the same value
# Must be at least 32 characters; generate with 'openssl rand -base64 24'
LOGFLARE_PUBLIC_ACCESS_TOKEN=your-super-secret-and-long-logflare-key-public
LOGFLARE_PRIVATE_ACCESS_TOKEN=your-super-secret-and-long-logflare-key-private