-
Notifications
You must be signed in to change notification settings - Fork 3
Expand file tree
/
Copy path.env.example
More file actions
180 lines (134 loc) · 6.04 KB
/
Copy path.env.example
File metadata and controls
180 lines (134 loc) · 6.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
# AI Dev Control Plane -- Environment Configuration
# =================================================
# Copy this file to .env and fill in your actual values:
# cp .env.example .env
#
# All variables have sensible dev defaults. Only override what you need.
# =============================================================================
# DATABASE
# =============================================================================
# SQLite (default for local development)
DATABASE_URL=file:./data/dev.db?_journal_mode=WAL
# PostgreSQL (for cloud-dev or production)
# DATABASE_URL=postgres://user:pass@localhost:5432/aicp?sslmode=disable
# DATABASE_URL=postgres://user:pass@host.neon.tech/db?sslmode=require
# PostgreSQL DSN used by packages/db migration tests (optional)
# POSTGRES_TEST_DATABASE_URL=postgres://user:pass@localhost:5432/aicp_test?sslmode=disable
# =============================================================================
# AUTHENTICATION
# =============================================================================
# JWT -- minimum 32 characters for production
JWT_SECRET=change-me-in-production-min-32-chars-long
# Comma-separated list of origins allowed by CORS (defaults to http://localhost:3000)
ALLOWED_ORIGINS=http://localhost:3000
# Comma-separated key-id:base64-32-byte-key specs for AES-256-GCM encrypted
# secret storage. First key is used for new writes; keep older keys for decrypting
# previous versions during key rotation.
# Generate: openssl rand -base64 32
# Development placeholder only; replace before storing real secrets.
SECRET_ENCRYPTION_KEYS=primary:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
# GitHub OAuth App credentials
# Create at: https://github.com/settings/developers
GITHUB_CLIENT_ID=your-github-app-client-id
GITHUB_CLIENT_SECRET=your-github-app-secret
# Set to false for local HTTP development; true (default) in production over HTTPS.
OAUTH_COOKIE_SECURE=true
# Token used by PR factory for non-interactive branch push and GitHub PR creation.
# Use a GitHub App installation token or a fine-scoped token with repo push + PR access.
GITHUB_TOKEN=your-github-token
# GitHub App credentials (for repo webhooks & API access)
# Create at: https://github.com/settings/apps
GITHUB_APP_ID=your-github-app-id
GITHUB_APP_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----\n...\n-----END RSA PRIVATE KEY-----"
GITHUB_APP_WEBHOOK_SECRET=your-webhook-secret
# =============================================================================
# SERVICES
# =============================================================================
# NATS JetStream
NATS_URL=nats://localhost:4222
NATS_STREAM_PREFIX=AICP
# Temporal (optional -- start with: docker-compose --profile temporal up -d)
TEMPORAL_HOST=localhost:7233
TEMPORAL_NAMESPACE=default
# AgentVault integration (optional -- logs task lifecycle events to a local inbox)
AGENTVAULT_URL=
AGENTVAULT_TOKEN=
AGENTVAULT_PROJECT=dev-plane
# =============================================================================
# PORTS
# =============================================================================
# API server
PORT=8080
# Next.js frontend
WEB_PORT=3000
# Runner service
RUNNER_PORT=8082
# When set, the worker and API route workspace runtime calls to a remote runner.
# Leave empty to use the in-process runtime provider selected by WORKSPACE_RUNTIME.
RUNNER_URL=http://localhost:8082
RUNNER_AUTH_TOKEN=change-me-in-production
# Worker health HTTP server (used by container health checks)
WORKER_HEALTH_PORT=8081
# =============================================================================
# AI PROVIDERS (via Bifrost gateway or direct)
# =============================================================================
# Bifrost AI Gateway (recommended -- unified interface)
BIFROST_URL=http://localhost:8083
BIFROST_API_KEY=
# Direct provider keys (fallback)
OPENAI_API_KEY=sk-...
OPENAI_BASE_URL=https://api.openai.com/v1
ANTHROPIC_API_KEY=sk-ant-...
ANTHROPIC_BASE_URL=https://api.anthropic.com/v1
GEMINI_API_KEY=
GEMINI_BASE_URL=https://generativelanguage.googleapis.com/v1beta
GROQ_API_KEY=
GROQ_BASE_URL=https://api.groq.com/openai/v1
FIREWORKS_API_KEY=
FIREWORKS_BASE_URL=https://api.fireworks.ai/inference/v1
# Default model for agent runs
DEFAULT_MODEL=gpt-4o
DEFAULT_PROVIDER=openai
# =============================================================================
# RUNTIME
# =============================================================================
# Workspace directory for sandboxed runs
WORKSPACE_BASE_DIR=./data/workspaces
# Optional tmpfs size limit for the workspace base directory (e.g. 4g, 50%).
# Defaults to half of RAM when unset.
# WORKSPACE_TMPFS_SIZE=
# Set to 1 or true to skip tmpfs mounting and store workspace data on disk.
# WORKSPACE_TMPFS_DISABLE=
# Docker socket path (for Linux)
DOCKER_HOST=unix:///var/run/docker.sock
# For macOS Docker Desktop:
# DOCKER_HOST=unix:///Users/$USER/.docker/run/docker.sock
# Runtime provider: docker | local | remote (via RUNNER_URL)
WORKSPACE_RUNTIME=docker
# Container registry for runner images
RUNNER_REGISTRY=localhost:5000
# =============================================================================
# FRONTEND
# =============================================================================
# API URL (used by frontend to reach backend)
NEXT_PUBLIC_API_URL=http://localhost:8080
# GitHub OAuth client ID (public)
NEXT_PUBLIC_GITHUB_CLIENT_ID=your-github-app-client-id
# =============================================================================
# LOGGING
# =============================================================================
# Log level: debug | info | warn | error
LOG_LEVEL=info
# Log format: json | text
LOG_FORMAT=text
# =============================================================================
# FEATURE FLAGS
# =============================================================================
# Enable Temporal workflow engine
ENABLE_TEMPORAL=false
# Enable sandboxed runtime (Phase 2)
ENABLE_SANDBOXED_RUNTIME=false
# Require approval for high-risk tasks
REQUIRE_RISK_APPROVAL=true
# Max concurrent agent runs per organization
MAX_CONCURRENT_RUNS=5