Repository navigation
Expand file tree
/
Copy pathcompose.env.example
More file actions
165 lines (150 loc) · 8.33 KB
/
Copy pathcompose.env.example
File metadata and controls
165 lines (150 loc) · 8.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
# Copy this file to .env. Docker Compose reads it automatically.
# Generate a random hex password with: openssl rand -hex 32
# Set it once before the first start; changing it later does not rotate the database password.
POSTGRES_PASSWORD=
# Optional pull-through registry host (no scheme or trailing slash).
# Unset/empty uses upstream images as usual. For example, registry.home maps
# postgres to registry.home/docker.io/library/postgres, typesense/typesense to
# registry.home/docker.io/typesense/typesense, and ghcr.io/... to registry.home/ghcr.io/...
# Applies to service images, local-build base images, and registry build caches.
# Explicit DEVFEED_*_IMAGE overrides are complete references and stay unchanged.
# DEVFEED_IMAGE_REGISTRY=registry.home
# Publish on every IPv4 interface. Set a specific host IP (or :: for IPv6) if needed.
DEVFEED_BIND_IP=0.0.0.0
DEVFEED_API_PORT=8000
DEVFEED_ADMIN_PORT=3001
# Set this to the IP/hostname used in your browser, including the published port.
# 0.0.0.0 is a bind address, not a browser origin. Register the matching OIDC callback.
DEVFEED_ADMIN_BASE_URL=http://localhost:3001
DEVFEED_ADMIN_COOKIE_SECURE=false
# Each replica handles one job at a time. General workers default to two.
DEVFEED_WORKER_REPLICAS=2
# The separate AI pool starts only with the ai profile; increase for parallel analysis.
DEVFEED_CODEX_CLIENT_REPLICAS=1
# By default the stack connects to its bundled PostgreSQL and Redis services.
# Optional overrides must be reachable INSIDE the containers; localhost is not the host.
# DEVFEED_DATABASE_URL=postgresql+psycopg://devfeed:${POSTGRES_PASSWORD}@postgres:5432/devfeed
# DEVFEED_REDIS_URL=redis://redis:6379/0
# Optional runtime settings from .env.example are forwarded to Python services:
# CORS, cache, feed/page limits, scheduler batch size, job logs, and AI settings.
# List-valued settings use JSON, e.g. DEVFEED_CORS_ORIGINS=["https://user.example.com"].
# Chimely starts by default. Enabled notifications are provisioned during compose up.
# These helpers generate the optional integration settings and build local images:
# python3 scripts/compose_dev.py --notifications
# python3 scripts/compose_dev.py --ai
# COMPOSE_PROFILES=ai
# The rebuild command also records compose.yaml + compose.build.yaml in COMPOSE_FILE.
# AI setup starts with gpt-6-sol; override DEVFEED_CODEX_MODEL for your account.
# DEVFEED_CODEX_MODEL=gpt-6-sol
# DEVFEED_CODEX_APP_SERVER_URL=unix:///run/codex/app-server.sock
# DEVFEED_AI_ENABLED=true
# DEVFEED_WORKER_QUEUE=background
# Autonomous research and publication (requires AI and a connected account):
# DEVFEED_AUTO_RESEARCH_IMPORTS=true
# Full mode researches source tags and publishes/rejects articles.
# Sources require an AI or explicit operator review, including imports and suggestions.
# DEVFEED_FULL_AUTOMATION=true
# DEVFEED_TOPIC_CORRECTION_MAX_ATTEMPTS=3
# DEVFEED_AUTO_REANALYZE_TOPICS=true
# DEVFEED_AUTO_RESEARCH_RELATIONSHIPS=true
# DEVFEED_AUTO_LINK_TAGS=true
# DEVFEED_RELATIONSHIP_RESEARCH_BATCH_SIZE=100
# DEVFEED_RELATIONSHIP_RESEARCH_MAX_PENDING=4
# DEVFEED_AUTO_APPROVE_TOPICS=true
# DEVFEED_AUTO_APPROVE_TOPIC_RELATIONSHIPS=true
# Article publication is configured per approved source in the admin UI.
# Chimely uses its own database/user on the bundled PostgreSQL server.
# The one-off provisioner prepares separate credentials for workers and the admin API.
# Runtime credentials live in scoped Docker volumes; no key copying is needed locally.
# CHIMELY_PORT=8082
# Optional dedicated hex password; otherwise it uses POSTGRES_PASSWORD.
# chimely-db-init reconciles this role password without resetting its database.
# CHIMELY_POSTGRES_PASSWORD=your-random-hex-password
# CHIMELY_ADMIN_EMAIL=admin@devfeed.local
# CHIMELY_ADMIN_PASSWORD=generated-by-setup
# CHIMELY_ADMIN_TLS_TERMINATED=false
# DEVFEED_NOTIFICATIONS_ENABLED=true
# DEVFEED_CHIMELY_API_URL=http://chimely:8080
# DEVFEED_CHIMELY_ADMIN_ENVIRONMENT=devfeed-admin
# Explicit keys are needed only for an externally provisioned Chimely:
# DEVFEED_CHIMELY_ADMIN_API_KEY=your-environment-api-key
# DEVFEED_CHIMELY_ADMIN_HMAC_SECRET=your-environment-hmac-secret
# An external Chimely remains supported; use its container-reachable origin instead.
# By default Compose uses the current verified master images.
# For a release, set all three references from the same verified image manifest.
# Full image references accept either a tag or @sha256: digest.
# DEVFEED_BACKEND_IMAGE=ghcr.io/abhi1693/devfeed.tech/backend:master
# DEVFEED_ADMIN_API_IMAGE=ghcr.io/abhi1693/devfeed.tech/admin-api:master
# DEVFEED_ADMIN_IMAGE=ghcr.io/abhi1693/devfeed.tech/admin:master
# Optional: configure your dedicated OIDC app to enable admin sign-in.
# Unknown optional sign-in values can stay empty; sign-in remains unavailable.
# Register http://localhost:3001/api/v1/admin/auth/callback as its redirect URI.
# DEVFEED_OIDC_ISSUER_URL=https://identity.example.com
# DEVFEED_OIDC_CLIENT_ID=your-devfeed-admin-client-id
# DEVFEED_OIDC_ORGANIZATION_ID=your-organization-id
# DEVFEED_OIDC_TOKEN_ENDPOINT_AUTH_METHOD=none
# DEVFEED_ADMIN_REQUIRED_ROLE=superuser
# Secret-authenticated clients also need DEVFEED_OIDC_CLIENT_SECRET.
# See docs/admin.md for role, organization and scope settings for your provider.
# Anonymous public user (admin remains on port 3001).
# DEVFEED_WEB_PORT=3000
# DEVFEED_WEB_IMAGE=ghcr.io/abhi1693/devfeed.tech/web:master
# Runtime flag: local Compose must not send GA4 page views or custom events.
DEVFEED_ANALYTICS_ENABLED=false
# GOOGLE_ANALYTICS_ID=G-N4V5CW5C0M
# Extension GA4 uses the website property through a server-only Measurement Protocol secret.
DEVFEED_EXTENSION_ANALYTICS_ENABLED=false
MICROSOFT_CLARITY_PROJECT_ID=
# X pixel pc5f8: opt in to browser and server conversion tracking.
DEVFEED_X_PIXEL_ENABLED=false
# Server-only credentials and completed sign-up event from Events Manager.
X_PIXEL_TOKEN=
X_SIGNUP_EVENT_ID=tw-pc5f8-rgbo7
# DEVFEED_EXTENSION_GA_API_SECRET=
# Optional user accounts (separate ZITADEL application, same organization as admin).
# Browsing works without these; only personalization requires sign-in.
# DEVFEED_USER_BASE_URL=http://localhost:3000
# DEVFEED_USER_COOKIE_SECURE=false
# Exact trusted Chrome IDs, JSON array; set identically on web and user-api.
# DEVFEED_USER_EXTENSION_IDS=["hliakjocndflpkmfajndigbpngfcekdm"]
# DEVFEED_USER_SESSION_TTL_SECONDS=2592000
# DEVFEED_USER_OIDC_ISSUER_URL=https://identity.example.com
# DEVFEED_USER_OIDC_CLIENT_ID=your-user-client-id
# DEVFEED_USER_OIDC_ORGANIZATION_ID=your-organization-id
# Shared ZITADEL identity-provider IDs enable direct sign-in for reader and admin.
# Enable these providers for both applications; client IDs remain separate.
# DEVFEED_OIDC_GITHUB_IDP_ID=
# DEVFEED_OIDC_GOOGLE_IDP_ID=
# DEVFEED_USER_OIDC_TOKEN_ENDPOINT_AUTH_METHOD=none
# DEVFEED_USER_OIDC_SCOPES=["openid","profile","email"]
# Set a user-specific secret only for confidential clients:
# DEVFEED_USER_OIDC_CLIENT_SECRET=
# DEVFEED_USER_API_IMAGE=ghcr.io/abhi1693/devfeed.tech/user-api:master
# Outside Compose, the Next server also needs DEVFEED_USER_API_URL=http://127.0.0.1:8002
# Optional Typesense search; see docs/search.md. Preserve other profiles when enabling.
# COMPOSE_PROFILES=search
DEVFEED_SEARCH_ENABLED=false
DEVFEED_SEARCH_URL=http://typesense:8108
DEVFEED_SEARCH_COLLECTION_PREFIX=devfeed
DEVFEED_SEARCH_ADMIN_KEY=
DEVFEED_SEARCH_QUERY_KEY=
DEVFEED_SEARCH_INDEX_BATCH_SIZE=200
# Shared crawler inventory refresh; independent from reader-cache invalidation.
DEVFEED_SITEMAP_REFRESH_SECONDS=900
# Image storage: worker-only credentials; public URL is also needed by reader APIs.
# Enable the `images` Compose profile for imgproxy and the dedicated Images worker.
DEVFEED_IMAGE_STORAGE_ENABLED=false
DEVFEED_IMAGE_STORAGE_ENDPOINT=https://492e25f5f18ef59e38763f58a78362f7.r2.cloudflarestorage.com
DEVFEED_IMAGE_STORAGE_BUCKET=devfeed-images-dev
DEVFEED_IMAGE_PUBLIC_URL=https://pub-5902d9886c3d4a00beeba906c0cbe154.r2.dev
DEVFEED_IMAGE_STORAGE_ACCESS_KEY=
DEVFEED_IMAGE_STORAGE_SECRET_KEY=
DEVFEED_IMGPROXY_URL=http://imgproxy:8080
# Generate separate hex secrets (openssl rand -hex 32). Never expose in frontend config.
DEVFEED_IMGPROXY_KEY=
DEVFEED_IMGPROXY_SALT=
DEVFEED_IMAGE_MAX_BYTES=10000000
# Superseded successful analysis input retention (results and current evidence remain).
DEVFEED_JOB_PAYLOAD_RETENTION_DAYS=30
DEVFEED_JOB_PAYLOAD_PRUNE_BATCH_SIZE=100
DEVFEED_USER_SESSION_ABSOLUTE_TTL_SECONDS=7776000