Repository navigation
Expand file tree
/
Copy pathexample.env
More file actions
237 lines (202 loc) · 10.9 KB
/
Copy pathexample.env
File metadata and controls
237 lines (202 loc) · 10.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
# IMPORTANT: Values must not be wrapped in quotes. This file is passed through to the
# containers as is, and 'docker stack deploy' treats quotes as part of the value.
# The environment setting.
# Use 'development' for local development, and 'production' in production.
ENVIRONMENT=development
# Ports that will be mapped to the host during development.
WEB_DEV_PORT=8000
POSTGRES_DEV_PORT=5432
# Ports that will be mapped to the host during production.
WEB_HTTP_PORT=80
WEB_HTTPS_PORT=443
# The Docker image to use for the app services.
# Defaults to the official GHCR image. Override this to use a locally built image
# (e.g. RADIS_IMAGE=radis-staging:latest for a staging deployment).
# RADIS_IMAGE=ghcr.io/openradx/radis:latest
# Override the Docker Swarm stack name. Defaults to {project_name}_{environment}
# (e.g. radis_dev, radis_prod). Also used to derive unique session and CSRF cookie names
# to prevent cookie conflicts when running multiple stacks on the same host.
# Set explicitly for additional deployments like staging.
# STACK_NAME=radis_staging
# Django debug settings (only used in development).
FORCE_DEBUG_TOOLBAR=true
REMOTE_DEBUGGING_ENABLED=false
REMOTE_DEBUGGING_PORT=5678
# The Django secret key used for cryptographic signing.
# IMPORTANT: Use a unique and secure key in production!
DJANGO_SECRET_KEY=your_django_secret_key_here
# The Postgres database password (only used in production).
POSTGRES_PASSWORD=your_postgres_password_here
# Miscellaneous Django security settings.
DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1
DJANGO_CSRF_TRUSTED_ORIGINS=
DJANGO_INTERNAL_IPS=127.0.0.1
# Redirect all HTTP requests to HTTPS (only used in production).
DJANGO_SECURE_SSL_REDIRECT=true
# The salt that is used for hashing tokens in the token authentication app.
# Cave, changing the salt after some tokens were already generated makes them all invalid!
TOKEN_AUTHENTICATION_SALT=your_token_authentication_salt_here
# Email configuration.
# The email address that is used for sending emails to the users and critical errors
# to the admins. The smtp server is only used in production. In development the emails
# are just logged to the console.
DJANGO_SERVER_EMAIL=server@example-project.example
DJANGO_EMAIL_URL=smtp://localhost:25
# The Django server admins that will receive critical error notifications.
# Also used by django-registration-redux to send account approval emails to.
DJANGO_ADMIN_EMAIL=admin@radis.example
DJANGO_ADMIN_FULL_NAME=RADIS Admin
# A support Email address that is presented to the users where they can get support.
SUPPORT_EMAIL=support@radis.example
# A superuser that will have access to the Django admin interface.
# Optionally with a provided auth token for the API.
SUPERUSER_USERNAME=superuser
SUPERUSER_EMAIL=superuser@radis.example
SUPERUSER_PASSWORD=your_superuser_password_here
SUPERUSER_AUTH_TOKEN=your_superuser_auth_token_here
# Location of the backup folder.
BACKUP_DIR=./.docker-data/backups
# Enable the daily database backup periodic task.
# Set to "false" to no-op the shared backup_db task (e.g. in test environments).
BACKUP_ENABLED=true
# Cron schedule for the shared backup_db periodic task.
BACKUP_CRON=0 3 * * *
# Site information that is synced to the database and used by the sites framework.
SITE_NAME=RADIS
SITE_DOMAIN=localhost
# Settings for SSL encryption (only used in production).
# SSL_HOSTNAME and SSL_IP_ADDRESSES are used to generate self-signed certificates
# with 'uv run cli generate-certificate-files', but you can also provide both files
# on your own.
SSL_HOSTNAME=localhost
SSL_IP_ADDRESSES=127.0.0.1
SSL_SERVER_CERT_FILE=./cert.pem
SSL_SERVER_KEY_FILE=./key.pem
SSL_SERVER_CHAIN_FILE=./chain.pem
# The timezone used by the server.
TIME_ZONE=Europe/Berlin
# LLM configuration.
# RADIS runs no inference server of its own. All inference is sent to the OpenAI-compatible
# endpoint below, which must support the OpenAI API (beta) client and structured outputs.
#
# The default expects a provider running on the Docker host (e.g. Ollama, LM Studio,
# llama.cpp). Use 'uv run cli get-host-ip' if host.docker.internal cannot be resolved.
# On Linux, that provider must listen on more than loopback, otherwise the containers get a
# connection refused. Ollama has no authentication, so prefer binding it to the Docker bridge
# (OLLAMA_HOST=172.17.0.1 for the default docker0) over every interface (0.0.0.0). See
# docs/dev-docs/contributing.md.
#
# IMPORTANT: host.docker.internal is a development convenience and is NOT injected into the
# production stack. A production deployment must point this at an endpoint its nodes can
# actually reach, or every LLM job fails with a connection error.
# See docs/dev-docs/contributing.md for how to run Ollama on your machine.
LLM_BASE_URL=http://host.docker.internal:11434/v1
# Not all providers really use that key, but the OpenAI API client needs it to be set.
LLM_API_KEY=whatever
# The model every feature uses unless it has its own setting below. Must name a model the
# endpoint above serves (an Ollama tag when using Ollama). The default is small and fast:
# enough to check that everything works, not to judge the results by.
#
# Request parameters can be appended as a query string. They are merged into the request
# body, so both standard OpenAI fields (temperature, top_p, seed) and provider extensions
# work, and a dotted key becomes a nested object:
# LLM_DEFAULT_MODEL=qwen3:8b?temperature=0&chat_template_kwargs.enable_thinking=false
# Values are read as JSON where possible, so temperature=0 sends a number while
# reasoning_effort=none sends the string "none".
#
# 'reasoning_effort=none' below turns off "thinking", which makes reasoning models much
# faster and their structured output cleaner. That spelling is Ollama's and matches the
# default endpoint; vLLM and SGLang want chat_template_kwargs.enable_thinking=false
# instead, as each server silently ignores the other's. Drop it for providers that reject
# parameters they don't know, such as OpenAI and Azure OpenAI.
LLM_DEFAULT_MODEL=qwen3.5:0.8b?reasoning_effort=none
# Per-feature overrides. Leave blank to use LLM_DEFAULT_MODEL. Useful to spend a stronger
# (or cheaper) model where it matters, e.g. a large model for labeling and a fast one for
# chat. Each takes the same 'model?param=value' form.
LLM_CHATS_MODEL=
LLM_QUERY_GENERATION_MODEL=
LLM_EXTRACTIONS_MODEL=
LLM_SUBSCRIPTIONS_MODEL=
LLM_LABELING_MODEL=
#
# The LLM request timeout, rate-limit gate, and transient-retry knobs have sensible defaults
# in settings (LLM_REQUEST_TIMEOUT_SECONDS, LLM_RATE_LIMIT_*, LLM_TRANSIENT_RETRY_*);
# override them here only if needed.
# The language of the example reports that will be seeded to the development database.
# Possible values are 'en' or 'de'.
EXAMPLE_REPORTS_LANGUAGE=en
# Dedicated LLM configuration for generating sample reports via the CLI. These do not
# impact inference. The provider must support the OpenAI API client.
REPORT_LLM_MODEL_NAME=gemma3
REPORT_LLM_PROVIDER_URL=http://host.docker.internal:11434/v1
# API key (if required by the generation provider). Only used with
# 'cli generate-example-reports'.
REPORT_LLM_PROVIDER_API_KEY=ollama
# Embedding service (OpenAI-compatible /v1/embeddings), used by hybrid search.
#
# Leave EMBEDDINGS_MODEL empty to run full-text search only — reports stay fully
# searchable, no embedding jobs are queued and the service is never called.
#
# The endpoint and key default to LLM_BASE_URL and LLM_API_KEY, which is what you want
# when one provider serves both (OpenAI, Ollama, an LLM gateway). Set them only when
# embeddings live somewhere else — a self-hosted vLLM or SGLang serves one model per
# process, so there the embedding model is a second server.
#EMBEDDINGS_BASE_URL=
#EMBEDDINGS_API_KEY=
# The model, as 'model[?param=value&...]' — the same spec the LLM_*_MODEL settings take.
# Parameters are merged into the request body, so a provider that supports OpenAI's
# 'dimensions' can be asked for the width directly:
# EMBEDDINGS_MODEL=Qwen/Qwen3-Embedding-4B
# EMBEDDINGS_MODEL=text-embedding-3-large?dimensions=1024
# For Ollama in dev: ollama pull dengcao/Qwen3-Embedding-4B:Q5_K_M
EMBEDDINGS_MODEL=
# Vector dimension. Schema-coupled: changing this after deploy requires dropping the
# embedding column, re-migrating, and running `./manage.py embed_pending`. When the
# model spec also sets 'dimensions', the two must agree (checked at startup).
EMBEDDINGS_DIM=1024
# Instruction prefix prepended to search queries before embedding. Model-specific:
# Qwen3-Embedding wants one, text-embedding-3 wants none. Not a request parameter, so
# it is not part of the model spec. The default contains a literal newline
# ("...reports.\nQuery: "); to reproduce a multi-line instruction here, wrap the value
# in double quotes so the \n is escape-processed (a single-quoted or unquoted value
# keeps the literal backslash-n instead of a newline).
#EMBEDDINGS_QUERY_INSTRUCTION=
# Throughput tuning (all optional).
# EMBEDDINGS_REQUEST_TIMEOUT_SECONDS defaults to LLM_REQUEST_TIMEOUT_SECONDS (itself 60
# by default), not to a fixed 60 — raising the LLM timeout for a slow endpoint raises
# this one too unless set here explicitly.
#EMBEDDINGS_REQUEST_TIMEOUT_SECONDS=
#EMBEDDINGS_BATCH_SIZE=200
#EMBEDDINGS_SUBJOB_SIZE=1000
#EMBEDDINGS_WORKER_CONCURRENCY=2
# How long a search query's embedding stays cached, in seconds (default 900 = 15 min).
# This is the knob to reach for right after a model or provider swap: cached query
# vectors from the old model can otherwise keep serving stale results for up to this
# long. Lower it temporarily, or clear the cache, if you need the swap to take effect
# immediately.
#EMBEDDINGS_QUERY_CACHE_TIMEOUT_SECONDS=900
# Auto-labeling (radis.labels)
# Both prompts have sensible built-in defaults; override only to customize.
# LABELING_SYSTEM_PROMPT=... # generic per-label prompt; only $report is substituted
# LABELING_GATE_SYSTEM_PROMPT=... # generic group gate (Yes/No) prompt
LABELING_JOB_PRIORITY=1
LABELING_TASK_BATCH_SIZE=100
LABELING_LLM_CONCURRENCY_LIMIT=2
LABELING_GATE_BATCH_SIZE=10
LABELING_SCAN_CRON=0 2 * * *
# Recovery of analysis tasks left IN_PROGRESS by a killed worker.
# The grace period must never be set below 30 (Procrastinate's own stall threshold).
ANALYSIS_STALLED_WORKER_GRACE_SECONDS=30
ANALYSIS_SWEEP_CRON=* * * * *
# OpenTelemetry Configuration
# Set this to the OTLP HTTP endpoint of the centralized openradx-observability stack.
# See https://github.com/openradx/openradx-observability for setup instructions.
OTEL_EXPORTER_OTLP_ENDPOINT=http://otel-collector.local:4318
# Docker swarm mode does not respect the Docker Proxy client configuration
# (see https://docs.docker.com/network/proxy/#configure-the-docker-client),
# but we can set those environment variables manually.
# Malke sure to use .local in NO_PROXY as otherwise the communication with
# the other services will not work.
# HTTP_PROXY="http://user:pass@myproxy.net:8080"
# HTTPS_PROXY="http://user:pass@myproxy.net:8080"
# NO_PROXY="localhost,.local"