# ============================================================================= # shared-memory — example environment file # Copy to `.env` and fill in real values. Never commit `.env`. # ============================================================================= # ----------------------------------------------------------------------------- # Public URL the app is reached at. # Used for OIDC redirect URIs, MCP discovery metadata, and Auth.js callbacks. # ----------------------------------------------------------------------------- PUBLIC_URL=https://memory.example.com # ----------------------------------------------------------------------------- # Deployment mode # ----------------------------------------------------------------------------- # By default the app exposes a plain HTTP port to the host for use behind an # external reverse proxy (HAProxy, nginx, Traefik, Cloudflare Tunnel, etc.). APP_PORT=3000 # Bind interface for the exposed port. Use 127.0.0.1 to only accept traffic # from a proxy on the same host. Default 0.0.0.0 accepts from anywhere. APP_BIND=0.0.0.0 # The two settings below are ONLY consumed by the optional `caddy` service, # which is started with: `docker compose --profile tls up -d`. # Leave them as-is if you terminate TLS upstream (HAProxy, etc.). APP_HOSTNAME=memory.example.com ACME_EMAIL=you@example.com # ----------------------------------------------------------------------------- # Authentik OIDC # Create two Applications in Authentik (one for the Web UI, one for the MCP # resource server). See README.md for exact provider settings. # ----------------------------------------------------------------------------- OIDC_ISSUER=https://auth.example.com/application/o/shared-memory/ OIDC_CLIENT_ID_WEB=replace-me OIDC_CLIENT_SECRET_WEB=replace-me OIDC_CLIENT_ID_MCP=replace-me OIDC_AUDIENCE=shared-memory # ----------------------------------------------------------------------------- # Database (Postgres 16 + pgvector — pgvector/pgvector:pg16 image) # ----------------------------------------------------------------------------- POSTGRES_USER=memory POSTGRES_PASSWORD=replace-me-with-a-strong-password POSTGRES_DB=memory # Built automatically by docker-compose from the values above. Override only # if you point at an external Postgres. # DATABASE_URL=postgres://memory:...@db:5432/memory # ----------------------------------------------------------------------------- # Embedder sidecar. Default points at the in-compose service. # ----------------------------------------------------------------------------- EMBEDDER_URL=http://embedder:8080 EMBEDDING_MODEL=Xenova/bge-small-en-v1.5 EMBEDDING_DIM=384 # ----------------------------------------------------------------------------- # NextAuth session signing — generate with: openssl rand -base64 32 # ----------------------------------------------------------------------------- NEXTAUTH_SECRET=replace-me-with-32-bytes-of-random # ----------------------------------------------------------------------------- # CLI token signing key. Used to mint HMAC-signed JWTs from /connect for # pasting into MCP clients (Claude Code etc.). Rotate to invalidate all # outstanding CLI tokens at once. Generate with: openssl rand -base64 32 # ----------------------------------------------------------------------------- CLI_TOKEN_SECRET=replace-me-with-32-bytes-of-random # ----------------------------------------------------------------------------- # App # ----------------------------------------------------------------------------- LOG_LEVEL=info # Optional: pin to a specific built image (e.g. for a registry-pushed build). # IMAGE_REF=registry.example.com/shared-memory-web:0.1.0