2026-05-15 06:46:18 -07:00
|
|
|
# =============================================================================
|
|
|
|
|
# shared-memory — example environment file
|
|
|
|
|
# Copy to `.env` and fill in real values. Never commit `.env`.
|
|
|
|
|
# =============================================================================
|
|
|
|
|
|
|
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
# Public URL the app is reached at.
|
2026-05-15 07:04:11 -07:00
|
|
|
# Used for OIDC redirect URIs, MCP discovery metadata, and Auth.js callbacks.
|
2026-05-15 06:46:18 -07:00
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
PUBLIC_URL=https://memory.example.com
|
|
|
|
|
|
2026-05-15 07:04:11 -07:00
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
# Deployment mode
|
|
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
# By default the app exposes a plain HTTP port to the host for use behind an
|
|
|
|
|
# external reverse proxy (HAProxy, nginx, Traefik, Cloudflare Tunnel, etc.).
|
|
|
|
|
APP_PORT=3000
|
|
|
|
|
# Bind interface for the exposed port. Use 127.0.0.1 to only accept traffic
|
|
|
|
|
# from a proxy on the same host. Default 0.0.0.0 accepts from anywhere.
|
|
|
|
|
APP_BIND=0.0.0.0
|
|
|
|
|
|
|
|
|
|
# The two settings below are ONLY consumed by the optional `caddy` service,
|
|
|
|
|
# which is started with: `docker compose --profile tls up -d`.
|
|
|
|
|
# Leave them as-is if you terminate TLS upstream (HAProxy, etc.).
|
|
|
|
|
APP_HOSTNAME=memory.example.com
|
|
|
|
|
ACME_EMAIL=you@example.com
|
|
|
|
|
|
2026-05-15 06:46:18 -07:00
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
# Authentik OIDC
|
|
|
|
|
# Create two Applications in Authentik (one for the Web UI, one for the MCP
|
2026-05-15 07:04:11 -07:00
|
|
|
# resource server). See README.md for exact provider settings.
|
2026-05-15 06:46:18 -07:00
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
OIDC_ISSUER=https://auth.example.com/application/o/shared-memory/
|
|
|
|
|
OIDC_CLIENT_ID_WEB=replace-me
|
|
|
|
|
OIDC_CLIENT_SECRET_WEB=replace-me
|
|
|
|
|
OIDC_CLIENT_ID_MCP=replace-me
|
|
|
|
|
OIDC_AUDIENCE=shared-memory
|
|
|
|
|
|
|
|
|
|
# -----------------------------------------------------------------------------
|
2026-05-15 07:04:11 -07:00
|
|
|
# Database (Postgres 16 + pgvector — pgvector/pgvector:pg16 image)
|
2026-05-15 06:46:18 -07:00
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
POSTGRES_USER=memory
|
|
|
|
|
POSTGRES_PASSWORD=replace-me-with-a-strong-password
|
|
|
|
|
POSTGRES_DB=memory
|
2026-05-15 07:04:11 -07:00
|
|
|
|
|
|
|
|
# Built automatically by docker-compose from the values above. Override only
|
|
|
|
|
# if you point at an external Postgres.
|
|
|
|
|
# DATABASE_URL=postgres://memory:...@db:5432/memory
|
2026-05-15 06:46:18 -07:00
|
|
|
|
|
|
|
|
# -----------------------------------------------------------------------------
|
2026-05-15 09:04:44 -07:00
|
|
|
# Embedder sidecar. Default points at the in-compose service.
|
2026-05-15 06:46:18 -07:00
|
|
|
# -----------------------------------------------------------------------------
|
2026-05-15 09:04:44 -07:00
|
|
|
EMBEDDER_URL=http://embedder:8080
|
2026-05-15 06:46:18 -07:00
|
|
|
EMBEDDING_MODEL=Xenova/bge-small-en-v1.5
|
|
|
|
|
EMBEDDING_DIM=384
|
|
|
|
|
|
|
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
# NextAuth session signing — generate with: openssl rand -base64 32
|
|
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
NEXTAUTH_SECRET=replace-me-with-32-bytes-of-random
|
|
|
|
|
|
2026-05-15 08:36:11 -07:00
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
# CLI token signing key. Used to mint HMAC-signed JWTs from /connect for
|
|
|
|
|
# pasting into MCP clients (Claude Code etc.). Rotate to invalidate all
|
|
|
|
|
# outstanding CLI tokens at once. Generate with: openssl rand -base64 32
|
|
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
CLI_TOKEN_SECRET=replace-me-with-32-bytes-of-random
|
|
|
|
|
|
2026-05-15 06:46:18 -07:00
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
# App
|
|
|
|
|
# -----------------------------------------------------------------------------
|
|
|
|
|
LOG_LEVEL=info
|
2026-05-15 07:04:11 -07:00
|
|
|
|
|
|
|
|
# Optional: pin to a specific built image (e.g. for a registry-pushed build).
|
|
|
|
|
# IMAGE_REF=registry.example.com/shared-memory-web:0.1.0
|