-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
171 lines (162 loc) · 10.5 KB
/
Copy path.env.example
File metadata and controls
171 lines (162 loc) · 10.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
REMEMBERSTACK_POSTGRES_USER=rememberstack
REMEMBERSTACK_POSTGRES_DB=rememberstack
# PostgreSQL max_connections. The default 300 covers the stock stack's ceiling
# of 215 connections (API 23 + 12 workers x 16) with headroom; raise it when you
# add API replicas or worker containers.
# REMEMBERSTACK_POSTGRES_MAX_CONNECTIONS=300
# Every variable in this file reaches the engine containers (compose.yaml
# loads .env with env_file), so any engine setting can be set here.
#
# No secrets and no deployment id ship. REMEMBERSTACK_POSTGRES_PASSWORD, the S3
# credentials for the bundled SeaweedFS object store (its admin identity, also
# used by the engine) and REMEMBERSTACK_SELFHOST_DEPLOYMENT_ID (a random UUID)
# must be set, or Compose refuses to start. Generate all four once, before the
# first start:
# printf 'REMEMBERSTACK_POSTGRES_PASSWORD=%s\nREMEMBERSTACK_MINIO_ACCESS_KEY=%s\nREMEMBERSTACK_MINIO_SECRET_KEY=%s\nREMEMBERSTACK_SELFHOST_DEPLOYMENT_ID=%s\n' \
# "$(openssl rand -hex 32)" "$(openssl rand -hex 12)" "$(openssl rand -hex 32)" \
# "$(openssl rand -hex 16 | sed -E 's/^(.{8})(.{4}).(.{3}).(.{3})(.{12})$/\1-\2-4\3-8\4-\5/')" >> .env
# The deployment id, slug and name are recorded by the first setup and cannot
# change afterwards; setup refuses a changed value instead of starting empty.
REMEMBERSTACK_SELFHOST_DEPLOYMENT_SLUG=local
REMEMBERSTACK_SELFHOST_DEPLOYMENT_NAME=Local memory
REMEMBERSTACK_SELFHOST_API_PORT=8000
# Host address the API port is published on. Loopback by default, so only this
# machine can reach the API. To accept connections from other machines, set a
# token (REMEMBERSTACK_SELFHOST_API_BEARER_TOKEN plus
# REMEMBERSTACK_SELFHOST_REQUIRE_API_AUTH=true) and then set 0.0.0.0 or one
# interface's address here.
# REMEMBERSTACK_SELFHOST_API_PUBLISH_ADDRESS=127.0.0.1
# MIME -> converter-adapter routes (JSON). Unset = stock table: Markdown and plain
# text pass through; HTML, .docx, .pptx and .xlsx convert locally via markitdown.
# Setting it REPLACES the table, so list the stock routes too. PDFs and images
# need a keyed OCR route; without one they are stored and parked as no_route.
# REMEMBERSTACK_SELFHOST_CONVERSION_ROUTES={"text/markdown": "passthrough", "text/plain": "passthrough", "text/html": "markitdown", "application/vnd.openxmlformats-officedocument.wordprocessingml.document": "markitdown", "application/vnd.openxmlformats-officedocument.presentationml.presentation": "markitdown", "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet": "markitdown", "application/pdf": "mistral_ocr", "image/png": "image_ocr_description", "image/jpeg": "image_ocr_description"}
# BYO key for the provider-backed mistral_ocr route (required when routed, including as the OCR lane of image_ocr_description).
# REMEMBERSTACK_MISTRAL_OCR_API_KEY=
# OpenRouter key for the vision-LLM description lane (required when any route names image_ocr_description).
# The default model google/gemini-2.5-flash is explicitly multimodal; do not point this at a text-only slug.
# REMEMBERSTACK_IMAGE_DESCRIPTION_API_KEY=
# REMEMBERSTACK_IMAGE_DESCRIPTION_MODEL=google/gemini-2.5-flash
# REMEMBERSTACK_IMAGE_DESCRIPTION_MAX_IMAGE_BYTES=10000000
# Optional POST /ingest byte ceiling; unset = no engine-imposed cap.
# REMEMBERSTACK_SELFHOST_INGEST_BODY_MAX_BYTES=100000000
# Optional API perimeter. Unset = open quickstart. The simplest perimeter is one
# shared token (generate it with `openssl rand -hex 32`); clients send it as
# REMEMBER_API_KEY. REQUIRE_API_AUTH=true refuses to start without a token, a
# BIND or an issuer. Managed hosts set BIND={issued_deployment_uuid}:{sha256hex}
# instead of the token so the secret itself never reaches this host.
# REMEMBERSTACK_SELFHOST_API_BEARER_TOKEN=
# REMEMBERSTACK_SELFHOST_REQUIRE_API_AUTH=false
# REMEMBERSTACK_SELFHOST_API_BEARER_BIND=
# Comma-separated https origins allowed to call this deployment from a
# browser, exactly as a browser sends them. Empty advertises no CORS.
# REMEMBERSTACK_SELFHOST_BROWSER_ORIGINS=https://app.example.com
# Signed keys from an issuer (remember.dev or your own). Setting the issuer
# enables them; the tenant id and both URLs are then required.
# REMEMBERSTACK_SELFHOST_API_KEY_ISSUER=https://issuer.example.com
# REMEMBERSTACK_SELFHOST_API_KEY_TENANT_ID=
# REMEMBERSTACK_SELFHOST_API_KEY_PROJECT_ID=
# REMEMBERSTACK_SELFHOST_API_SIGNING_KEYS_URL=https://issuer.example.com/jwks.json
# REMEMBERSTACK_SELFHOST_API_REVOCATION_URL=https://issuer.example.com/revocation
# REMEMBERSTACK_SELFHOST_API_KEY_REFRESH_S=60
# REMEMBERSTACK_SELFHOST_API_REVOCATION_MAX_AGE_S=3600
# Optional direct-path admission limits: requests per minute and in flight, per
# credential and for the whole deployment. All off by default (unset or 0 = no
# limit); set any of them to turn that limit on. Over a limit the API answers
# 429. The values below are examples, not defaults.
# REMEMBERSTACK_SELFHOST_API_ADMISSION_KEY_PER_MINUTE=120
# REMEMBERSTACK_SELFHOST_API_ADMISSION_KEY_IN_FLIGHT=8
# REMEMBERSTACK_SELFHOST_API_ADMISSION_DEPLOYMENT_PER_MINUTE=600
# REMEMBERSTACK_SELFHOST_API_ADMISSION_DEPLOYMENT_IN_FLIGHT=32
# Managed billing is fleet-authored and all-or-nothing, and needs the
# control-plane spend lease (D46): with the METER_* settings below set, the API
# refuses to start without SPEND_LEASE_URL.
# REMEMBERSTACK_SELFHOST_SPEND_LEASE_URL=
# The identity key is a deployment-local HMAC secret; never reuse it or send it
# to the control plane.
# Start the receipt worker with `docker compose --profile managed up -d`.
# REMEMBERSTACK_SELFHOST_METER_INGEST_URL=
# REMEMBERSTACK_SELFHOST_METER_INGEST_TOKEN=
# REMEMBERSTACK_SELFHOST_METER_IDENTITY_KEY=
# REMEMBERSTACK_SELFHOST_METER_ORG_ID=
# REMEMBERSTACK_SELFHOST_METER_PROJECT_ID=
# REMEMBERSTACK_SELFHOST_REQUIRE_METERING=false
# Where clients and the benchmark CLI look for that API. It defaults to
# http://127.0.0.1:8000 independently of the port above, so if you change
# REMEMBERSTACK_SELFHOST_API_PORT you must set this too or every client call
# fails with "Connection refused" against the old port.
# REMEMBER_API_URL=http://127.0.0.1:8000
# Optional dedicated live-graph resource bounds. These defaults match Compose;
# managed hosts must size them together with the PostgreSQL memory admission
# contract rather than increasing one value in isolation.
# REMEMBERSTACK_SELFHOST_GRAPH_POOL_SIZE=4
# REMEMBERSTACK_SELFHOST_GRAPH_POOL_TIMEOUT_S=1
# REMEMBERSTACK_SELFHOST_GRAPH_MAX_CONCURRENCY=2
# REMEMBERSTACK_SELFHOST_GRAPH_WORK_MEM_KIB=16384
# Optional content-free cost export (D91). Unset bind means no HTTP export.
# The listener is a second bind in the API process — not a route on the query API.
# Token must be at least 32 bytes when the bind is set.
# REMEMBERSTACK_COST_EXPORT_BIND=127.0.0.1:8001
# REMEMBERSTACK_COST_EXPORT_TOKEN=
# Optional client settings (D136): the key clients send, and where the CLI
# keeps its owner-only credential file.
# REMEMBER_API_KEY=
# REMEMBER_CONFIG_DIR=
# Required to start the provider adapter. Replace this value before processing
# a corpus; the complete Compose pipeline makes extraction and embedding calls.
REMEMBERSTACK_OPENROUTER_API_KEY=replace-before-real-use
# Optional exact OpenRouter embedding-provider slug (hard pin, no failover).
# Prefer EMBEDDING_PROVIDER_ORDER for price-bounded multi-host routing.
# REMEMBERSTACK_OPENROUTER_EMBEDDING_PROVIDER=nebius
# Ordered shortlist for qwen/qwen3-embedding-8b hosts (order wins over hard pin).
# Policy: design/operations/openrouter-embedding-routing.md
# REMEMBERSTACK_OPENROUTER_EMBEDDING_PROVIDER_ORDER=nebius,deepinfra,siliconflow
# 32k covers reasoning plus content; the provider account cap remains the monetary boundary.
REMEMBERSTACK_OPENROUTER_MAX_COMPLETION_TOKENS=32000
# Optional global reasoning effort for every chat-generation call. Allowed:
# none, minimal, low, medium, high, xhigh, max. Unset uses the model default;
# "none" reduces extraction latency but can reduce adjudication quality, and
# models that require reasoning may reject it.
# REMEMBERSTACK_OPENROUTER_REASONING_EFFORT=none
# Optional per-model overrides as a JSON object of model-id → effort. A model's
# entry wins over the global pin above; models absent from the map fall back to
# the global pin (or the model default when that is also unset). Same allowed
# effort literals. Example: pin flash models to none while keeping high for a
# reasoning model.
# REMEMBERSTACK_OPENROUTER_REASONING_EFFORT_MAP={"z-ai/glm-4.7-flash":"none","openai/gpt-5.6-luna":"high"}
# Debug only: retain raw schema-invalid completions under the private app-state
# volume. Disabled by default because captured output may repeat source text.
# REMEMBERSTACK_OPENROUTER_INVALID_COMPLETION_CAPTURE_DIR=/var/lib/rememberstack/openrouter-invalid-completions
# OBSERVABILITY (optional; empty or unset keeps all exporters disabled).
# Sentry-protocol error tracking works with Sentry, GlitchTip, and Bugsink.
# The environment defaults to REMEMBERSTACK_SELFHOST_DEPLOYMENT_SLUG and the
# error-event sample rate defaults to 1.0.
# REMEMBERSTACK_SENTRY_DSN=
# REMEMBERSTACK_SENTRY_ENVIRONMENT=
# REMEMBERSTACK_SENTRY_SAMPLE_RATE=1.0
# LoCoMo answer/judge tracing activates only when all three values are non-empty.
# LANGFUSE_PUBLIC_KEY=
# LANGFUSE_SECRET_KEY=
# LANGFUSE_HOST=https://cloud.langfuse.com
# Optional benchmark/deployment model overrides. Keep explicit model IDs for a
# reproducible run; do not use a rotating router such as openrouter/free.
# REMEMBERSTACK_E2_EXTRACT_MODEL=nvidia/nemotron-3-super-120b-a12b:free
# REMEMBERSTACK_E3_NORMALIZE_MODEL=nvidia/nemotron-3-super-120b-a12b:free
# D79 structure seats: STRUCTURER names only the string-anchor fallback
# proposer; the routine skeleton path is deterministic and calls no model.
# REMEMBERSTACK_STRUCTURER_MODEL=openai/gpt-5.6-luna
# REMEMBERSTACK_SKELETON_CHECK_MODEL=z-ai/glm-4.7-flash
# REMEMBERSTACK_ROLE_MODEL=z-ai/glm-4.7-flash
# REMEMBERSTACK_SUMMARY_MODEL=z-ai/glm-4.7-flash
# The one embedding model (chunks, claims, facts, entities, queries); it must
# output 1,536 dimensions. Setup refuses to change it once vectors exist.
# REMEMBERSTACK_P1_EMBEDDING_MODEL=qwen/qwen3-embedding-8b
# Fact adjudication engine: "prompt" (default baseline generative LLM) or "jev" (TypeSafe AI System One).
# REMEMBERSTACK_FACT_ADJUDICATION_ENGINE=prompt
# REMEMBERSTACK_FACT_CONFIDENCE_FLOOR=0.75
# REMEMBERSTACK_FACT_FALLBACK_TO_PROMPT=false
# TypeSafe AI System One settings (required when REMEMBERSTACK_FACT_ADJUDICATION_ENGINE=jev)
# REMEMBERSTACK_TYPESAFE_API_KEY=
# REMEMBERSTACK_TYPESAFE_MODEL=jev-latest
# REMEMBERSTACK_TYPESAFE_BASE_URL=https://api.typesafe.ai/v1
# REMEMBERSTACK_TYPESAFE_TIMEOUT_S=30.0