Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
81 lines (70 loc) · 3.58 KB
/
Copy path.env.example
File metadata and controls
81 lines (70 loc) · 3.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
# OpenChamber Environment Variables
# Copy this file to .env and customize values
# === OpenCode Settings ===
# OpenCode server password (required for API access)
OPENCODE_SERVER_PASSWORD=devonly
# OpenCode plugins to load (comma-separated).
# Set here in .env (not via shell export) to avoid host environment leaking into containers.
OPENCODE_PLUGINS=oh-my-openagent
# Custom OpenCode provider(s) to inject into opencode.json (JSON, the value of the "provider" key).
# Multiple providers can be added as sibling keys; escape is not needed in .env files.
# Example (Ollama with Gemma 4):
# OPENCODE_PROVIDER={"ollama":{"npm":"@ai-sdk/openai-compatible","name":"Ollama","options":{"baseURL":"http://host:11434/v1"},"models":{"gemma4:12b":{"name":"gemma4:12b"}}}}
# === UI Settings ===
# Web UI password (required for browser authentication)
OPENCHAMBER_UI_PASSWORD=chamber
# OpenChamber listen address (0.0.0.0 = all interfaces, required for Docker)
OPENCHAMBER_HOST=0.0.0.0
# === Ports ===
# Host port for OpenChamber Web UI
CHAMBER_PORT=8000
# === Admin Dashboard ===
# Admin dashboard port
ADMIN_PORT=8080
# Admin dashboard password (required, no default — set during install)
ADMIN_PASSWORD=
# === Workspace ===
# Workspace volume type (v0.5.0+ uses named volumes by default):
# - Leave commented/unset: Uses Docker named volume `workspace` (recommended, fully managed)
# - Set to an absolute host path: Uses a bind mount for direct editing with a local IDE
# - IMPORTANT for Docker-out-of-Docker (DooD): Never use a relative path such as `./workspace`.
# Admin Dashboard upgrades resolve it from the Compose file location inside the admin
# container (for example `/opt/ai-engkit`), which can mount the wrong host directory.
# WORKSPACE_PATH=/home/user/projects
# === Backup Settings ===
# Number of backup copies to retain during upgrade (default: 5)
BACKUP_RETENTION=5
# === Domain Compose Overlay (optional) ===
# One local overlay that extends the ai-dev service (environment, networks,
# named volumes, labels, healthcheck) so domain integrations survive upgrades,
# restarts, and maintenance recreates. The path resolves beneath
# /opt/ai-engkit/extensions/ and is validated before any recreate; protected
# fields (image, ports, privilege, Docker socket mounts) and other services are
# rejected. The host upgrade.sh path requires jq and applies the same validated
# base+overlay workflow without a silent base-only fallback.
# See docs/DOMAIN_COMPOSE_OVERLAY.md.
# AI_ENGKIT_COMPOSE_OVERLAY=ep-design.yml
# === Version Pinning (optional) ===
# Pin the deployed image version (e.g. v0.4.1). Leave unset to follow the
# stable channel (:latest — updated only when a release is explicitly promoted).
# When set, upgrades fetch compose/.env assets matching this tag.
# AI_ENGKIT_VERSION=
# === Agent Connection (optional) ===
# Enables the outbound agent module. Leave unset to disable agent mode.
#
# Token + CA embedded in the center URL (simplest). The `ca` value is the
# PEM certificate base64url-encoded by the center; no files or extra vars needed.
# CENTER_URL=wss://center.example.com/agent?token=YOUR_TOKEN&ca=<base64url-PEM>
#
# Or token as a separate var, used as fallback when CENTER_URL has no ?token=
# CENTER_TOKEN=YOUR_TOKEN
#
# Agent ID reported during the hello handshake (default: container hostname)
# AGENT_ID=
#
# Alternative: mTLS certificate file paths (all three required together, or TLS
# falls back to plain WebSocket; read at connect time for hot-reload). Files must
# live inside the admin volume (e.g. /opt/ai-engkit/) to survive container recreate.
# CENTER_CA_CERT=
# CENTER_CLIENT_CERT=
# CENTER_CLIENT_KEY=