Files
fire-safety-ymd/.env.example
2026-09-06 01:40:15 +08:00

90 lines
4.8 KiB
Plaintext

# HTTP server
FIRE_SAFETY_HTTP_ADDR=:8080
# Build-time Go module proxy (not a runtime secret). Compose defaults to the
# official Go proxy with a direct, checksum-verified VCS fallback when this is
# empty or omitted. On a test server that cannot reach proxy.golang.org, set
# this to an approved reachable proxy, for example:
# FIRE_SAFETY_BUILD_GOPROXY=https://<approved-go-proxy>,direct
# Do not set GOPROXY=off or disable GOSUMDB/checksum verification.
FIRE_SAFETY_BUILD_GOPROXY=https://proxy.golang.org,direct
# SuperAgent Open API (disabled until a project-specific test credential is supplied)
FIRE_SAFETY_SUPERAGENT_ENABLED=false
# Required when enabled, for example: https://superagent.example.com
FIRE_SAFETY_SUPERAGENT_BASE_URL=
FIRE_SAFETY_SUPERAGENT_OPEN_API_KEY=
# Default to the provider-compatible no-Trace stream. Its strict completion
# requires an AI stop, a non-empty message.final, and the top-level end event.
# Set true only when the external application's trace_policy.enabled is enabled.
# This controls trace visibility/validation; it does not disable Agent MCP calls.
FIRE_SAFETY_SUPERAGENT_INCLUDE_TRACE=false
FIRE_SAFETY_SUPERAGENT_CONNECT_TIMEOUT=15s
FIRE_SAFETY_SUPERAGENT_RECOVERY_MAX_ATTEMPTS=5
FIRE_SAFETY_SUPERAGENT_RECOVERY_INITIAL_BACKOFF=250ms
FIRE_SAFETY_SUPERAGENT_MAX_MESSAGE_BYTES=65536
# Connectivity probe only; do not use a real user ID or production data.
FIRE_SAFETY_SUPERAGENT_PROBE_SUBJECT_ID=fire-safety-ymd-connectivity-probe
FIRE_SAFETY_SUPERAGENT_PROBE_TIMEOUT=10m
# User-facing chat API (disabled by default; requires SuperAgent above)
FIRE_SAFETY_CHAT_ENABLED=false
# Optional public test chat page at /chat. Enabling it also requires Chat,
# FIRE_SAFETY_CHAT_COMPAT_APP_ID, and at least one exact allowed browser origin.
FIRE_SAFETY_CHAT_PAGE_ENABLED=false
# Test-stage static Bearer only. By default, generate a distinct high-entropy
# value of at least 32 printable ASCII characters.
# Never reuse FIRE_SAFETY_SUPERAGENT_OPEN_API_KEY or FIRE_SAFETY_MCP_AUTH_TOKEN.
FIRE_SAFETY_CHAT_AUTH_TOKEN=
# Compatibility exception for an already-issued legacy client credential that
# is shorter than 32 characters. Keep false for new environments. Set true
# only for a controlled test/migration window; even then the value must be
# non-empty, at most 4096 bytes, and contain only ASCII 0x21-0x7e (no spaces,
# controls, or Unicode). Rotate the credential, then restore false.
FIRE_SAFETY_CHAT_ALLOW_LEGACY_SHORT_TOKEN=false
# Server-controlled test subject. This is not final end-user identity or authorization.
FIRE_SAFETY_CHAT_SUBJECT_ID=fire-safety-ymd-chat-test-subject
# Optional legacy-client compatibility route:
# /api/v1/apps/{this-value}/completion. This is a public identifier, not a secret.
# Leave empty to expose only the native /api/chat route.
FIRE_SAFETY_CHAT_COMPAT_APP_ID=
# Exact comma-separated browser origins, for example: http://localhost:5173,https://fire.example.com
# Leave empty to allow only clients that do not send Origin, such as curl or a backend service.
FIRE_SAFETY_CHAT_ALLOWED_ORIGINS=
FIRE_SAFETY_CHAT_MAX_BODY_BYTES=131072
FIRE_SAFETY_CHAT_RUN_TIMEOUT=10m
# Conversations are process-local and disappear on restart.
FIRE_SAFETY_CHAT_SESSION_TTL=30m
FIRE_SAFETY_CHAT_MAX_SESSIONS=1000
# Inbound MCP for SuperAgent (disabled by default)
FIRE_SAFETY_MCP_ENABLED=false
# Required when enabled. Use a new per-environment high-entropy token (at least 32 printable ASCII characters).
# FIRE_SAFETY_CHAT_ALLOW_LEGACY_SHORT_TOKEN never relaxes this MCP requirement.
# Never reuse FIRE_SAFETY_SUPERAGENT_OPEN_API_KEY.
FIRE_SAFETY_MCP_AUTH_TOKEN=
# Trusted server-side data scope: town_allowlist (default) or all.
# Use all only when every record in the MCP's fixed query tables is authorized for this credential.
FIRE_SAFETY_MCP_SCOPE_MODE=town_allowlist
# Required for town_allowlist and must be empty for all. This scope is not accepted from MCP tool arguments.
FIRE_SAFETY_MCP_ALLOWED_TOWNS=
FIRE_SAFETY_MCP_MAX_BODY_BYTES=262144
FIRE_SAFETY_MCP_TOOL_TIMEOUT=5s
# PostgreSQL/PostGIS (disabled by default)
FIRE_SAFETY_POSTGIS_ENABLED=false
# Secret. Example for local development only:
# postgresql://fire_safety_readonly:password@127.0.0.1:5432/fire_safety?sslmode=disable
FIRE_SAFETY_POSTGIS_DSN=
# One-off operator credential for cmd/postgis-srid-migrate only. It must be able
# to UPDATE all 8 source tables and ALTER the 7 legacy 2D geometry typmods.
# Never use this credential for cmd/server; remove it after the migration.
# compose.yaml additionally overrides it to empty inside the server container.
FIRE_SAFETY_POSTGIS_MIGRATION_DSN=
# Project source CRS is confirmed as EPSG:4326; strict readiness rejects raw SRID 0 imports.
FIRE_SAFETY_POSTGIS_EXPECTED_SRID=4326
FIRE_SAFETY_POSTGIS_CONNECT_TIMEOUT=5s
FIRE_SAFETY_POSTGIS_QUERY_TIMEOUT=3s
FIRE_SAFETY_POSTGIS_MAX_CONNS=4