-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
103 lines (85 loc) · 4.56 KB
/
Copy path.env.example
File metadata and controls
103 lines (85 loc) · 4.56 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
# ==============================================================================
# ContextCortex Configuration & Environment Variables
# ==============================================================================
# ------------------------------------------------------------------------------
# 1. PostgreSQL Database Configuration
# ------------------------------------------------------------------------------
# Database credentials used by docker-compose and PostgreSQL pgvector container.
POSTGRES_USER=contextcortex
POSTGRES_PASSWORD=cortexsecret
POSTGRES_DB=contextcortex
POSTGRES_PORT=5432
# Database Connection URL.
# When running with Docker Compose:
# DATABASE_URL=postgresql+psycopg://contextcortex:cortexsecret@postgres:5432/contextcortex
# When running locally connecting to PostgreSQL:
# DATABASE_URL=postgresql+psycopg://contextcortex:cortexsecret@localhost:5432/contextcortex
# When running standalone without PostgreSQL (defaults to embedded SQLite):
# DATABASE_URL=sqlite:///app/data/index_cache.db
DATABASE_URL=postgresql+psycopg://contextcortex:cortexsecret@postgres:5432/contextcortex
# ------------------------------------------------------------------------------
# 2. Server, Vault & Local Storage Paths
# ------------------------------------------------------------------------------
HOST=0.0.0.0
PORT=3000
VAULT_PATH=/docs
# Managed local storage directory for direct file uploads, replacements, and incremental indexing.
# Defaults to data/storage or /app/data/storage if unset.
LOCAL_STORAGE_PATH=/app/data/storage
# ------------------------------------------------------------------------------
# 3. Vector Store & Storage Backend
# ------------------------------------------------------------------------------
# Provider options: pgvector | lancedb | chroma | qdrant
# Default when DATABASE_URL points to PostgreSQL is pgvector; otherwise lancedb/chroma/qdrant.
VECTOR_STORE_PROVIDER=pgvector
# Embedded storage path for file-based vector backends (e.g. LanceDB, SQLite, local chroma)
VECTOR_STORE_STORAGE_PATH=/app/data/vectors
# Vector collection name for documents and chunk embeddings
VECTOR_STORE_COLLECTION=knowledge_rag_v1
# Optional remote connection endpoints for Qdrant / Chroma if using external vector services:
# QDRANT_URL=http://qdrant:6333
# CHROMA_HOST=localhost
# CHROMA_PORT=8000
# CHROMA_SSL=false
# ------------------------------------------------------------------------------
# 4. Dense & Sparse Embedding Models
# ------------------------------------------------------------------------------
# Provider options: fastembed | litellm | huggingface
EMBEDDING_PROVIDER=fastembed
EMBEDDING_MODEL=BAAI/bge-small-en-v1.5
SPARSE_MODEL=prithivida/Splade_PP_en_v1
EMBEDDING_NUM_THREADS=4
EMBEDDING_BATCH_SIZE=32
# Optional LiteLLM proxy settings if using LiteLLM provider:
# LITELLM_URL=http://litellm:4000/v1
# LITELLM_API_KEY=dummy
# ------------------------------------------------------------------------------
# 5. MCP 2026-07-28 Authentication & RBAC Security Engine
# ------------------------------------------------------------------------------
# Enable or disable Bearer token & API key authentication (true | false).
# When false (default), requests operate in unauthenticated local developer bypass mode.
AUTH_ENABLED=false
# RFC 9728 Protected Resource Indicator URI identifying this ContextCortex resource server.
AUTH_RESOURCE_INDICATOR=https://contextcortex.local
# OIDC / OAuth 2.0 Identity Provider issuer and JWKS URI for JWT token validation:
# Examples:
# Keycloak: https://auth.example.com/realms/contextcortex
# Authentik: https://authentik.example.com/application/o/contextcortex/
# Entra ID: https://login.microsoftonline.com/{tenant-id}/v2.0
AUTH_OIDC_ISSUER=
AUTH_JWKS_URI=
# Initial Admin API Key Bootstrap:
# Provide a pre-shared key (e.g. cc_live_admin_secret123) or 'auto' to auto-generate
# an initial admin key during startup if no active admin credentials exist in the database.
ADMIN_INITIAL_KEY=
# ------------------------------------------------------------------------------
# 6. Background Poller, Sync, and Git Integration
# ------------------------------------------------------------------------------
# Interval in seconds for background poller daemon to scan repositories for remote updates.
AUTO_SYNC_INTERVAL=300
# Global webhook secret for HMAC verification of push webhooks from GitHub / GitLab / Gitea.
GLOBAL_WEBHOOK_SECRET=
# Optional GitHub Personal Access Token for higher rate limits during remote repository cloning.
GITHUB_TOKEN=
# Directory used for temporary repository checkouts and shallow clones.
TMP_REPOS_DIR=/tmp/rag_repos