# LOCAL/PRODUCTION CONFIGURATION TEMPLATE. Copy to deploy/.env. # Never commit deploy/.env or the files under deploy/secrets/. # Optional application defaults PI_PROVIDER= PI_MODEL= PI_THINKING= # Container-only path is assigned by deploy/compose.production.yaml. THT_MODEL_API_KEY_SECRET_FILE=deploy/secrets/model-api-key MAX_PI_PROCESSES=4 AUTH_MODE=none # External DWH (example workspace uses the HTTP adapters) THT_DB_NAME= THT_DWH_REST_URL= THT_DWH_API_KEY= THT_DWH_API_KEY_SECRET_FILE=deploy/secrets/dwh-api-key # External vector service. Use a distinct write key where the service supports one. THT_VEC_REST_URL= THT_VEC_API_KEY= THT_VEC_WRITE_API_KEY= THT_VEC_API_KEY_SECRET_FILE=deploy/secrets/vector-reader-api-key THT_VEC_WRITE_API_KEY_SECRET_FILE=deploy/secrets/vector-writer-api-key THT_CA_SECRET_FILE=deploy/secrets/ca-chain.pem # Optional local-vector profile. Keep these secret files outside Git and readable by Docker. THT_VECTOR_DATABASE=thoth THT_VECTOR_BOOTSTRAP_USER=postgres THT_VECTOR_MIGRATOR_USER=thoth_vector_migrator THT_VECTOR_READER_USER=thoth_vector_reader THT_VECTOR_WRITER_USER=thoth_vector_writer THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE=deploy/secrets/vector_bootstrap_password # Changing the file alone does not rotate an initialized DB; use # scripts/vector-rotate-bootstrap-password.sh OLD_SECRET_FILE NEW_SECRET_FILE. THT_VECTOR_MIGRATOR_PASSWORD_SECRET_FILE=deploy/secrets/vector_migrator_password THT_VECTOR_READER_PASSWORD_SECRET_FILE=deploy/secrets/vector_reader_password THT_VECTOR_WRITER_PASSWORD_SECRET_FILE=deploy/secrets/vector_writer_password # External embeddings service THT_OLLAMA_URL= # Evidence source visible inside the persistent data volume THT_DOCS_ROOT=/data/workspaces/example/evidence-source # Optional CA file mounted separately by an operator, for example via a Compose override. THT_SSL_CA=