Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
108 lines (96 loc) · 5.09 KB
/
Copy path.env.example
File metadata and controls
108 lines (96 loc) · 5.09 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
# Veoveo local deployment configuration.
#
# Copy this file to `.env` and replace empty values. `.env` is gitignored.
# Provisioning commands read this file and project only the required values into
# Kubernetes ConfigMaps and Secrets. Keep private keys and tokens out of Git.
# Installation identity and deployment mode.
# Canonical public origin used for OAuth issuers, audiences, callback URLs, and
# MCP resource identities. Use the externally reachable HTTPS origin in production.
PUBLIC_BASE_URL=https://veoveo.example
# Version tag used for locally built Veoveo OCI images.
VEOVEO_IMAGE_TAG=0.1.0
# `connected` permits configured external providers. `offline` requires bundled
# dependencies and disables runtime network acquisition.
VEOVEO_CONNECTIVITY_MODE=connected
# Media generation and geospatial imagery providers.
# WaveSpeed credential used by Media MCP and the documentation image generator.
MEDIA_PROVIDER_API_KEY=
# Secret used to verify signed terminal media-provider webhooks.
MEDIA_PROVIDER_WEBHOOK_SECRET=
# Google Maps Platform key with Map Tiles API access, consumed only by View MCP.
GOOGLE_MAPS_API_KEY=
# Cesium ion token consumed only by the Isaac Sim photorealistic 3D Tiles runtime.
CESIUM_ION_ACCESS_TOKEN=
# Optional Mapbox token used by native Rerun map backgrounds.
MAPBOX_ACCESS_TOKEN=
# Cloudflare AI and the optional Bioma public tunnel.
# Account identity and scoped API token used by live Cloudflare model calls and
# Bioma tunnel administration. Tunnel management needs Tunnel:Edit and DNS:Edit.
CLOUDFLARE_ACCOUNT_ID=
CLOUDFLARE_API_TOKEN=
# Connector token presented by the cloudflared process for the managed tunnel.
CLOUDFLARED_TUNNEL_TOKEN=
# SurrealDB bootstrap and runtime identity.
# Admin credentials are used only by the one-shot schema/bootstrap job. Platform
# services use the least-privilege runtime account and the logical namespace/database.
VEOVEO_SURREAL_ADMIN_USERNAME=root
VEOVEO_SURREAL_ADMIN_PASSWORD=
VEOVEO_SURREAL_RUNTIME_USERNAME=veoveo_runtime
VEOVEO_SURREAL_RUNTIME_PASSWORD=
VEOVEO_SURREAL_NAMESPACE=veoveo
VEOVEO_SURREAL_DATABASE=platform
# Artifact object storage.
# Credentials address the installation's RustFS or external S3-compatible store.
# The public endpoint must be reachable by clients following authorized, short-lived
# presigned download redirects.
VEOVEO_OBJECT_STORE_ACCESS_KEY=
VEOVEO_OBJECT_STORE_SECRET_KEY=
ARTIFACT_S3_PUBLIC_ENDPOINT=https://objects.enterprise.example
# Gateway signing, internal trust, and enterprise login.
# Base64 PKCS#8 DER Ed25519 private key used only by the gateway to sign short-lived
# gateway-to-service identity assertions.
VEOVEO_INTERNAL_SIGNING_KEY_DER_B64=
# `kid` placed on internal assertions; it must identify the matching key in the JWKS.
VEOVEO_INTERNAL_SIGNING_KEY_ID=veoveo-internal-1
# Public JWKS trusted by hosted services and Recording Hub. Wrap JSON in single
# quotes so dotenv and shell loaders preserve its quotes:
# VEOVEO_INTERNAL_TRUST_JWKS='{"keys":[...]}'
VEOVEO_INTERNAL_TRUST_JWKS=
# Base64 DER private key used by the gateway authorization server to sign OAuth tokens.
VEOVEO_AUTHORIZATION_SERVER_PRIVATE_KEY_DER_B64=
# Client secret for the enterprise OIDC application used by browser login.
VEOVEO_IDP_OIDC_CLIENT_SECRET=
# Gateway refresh-token delivery protection.
# Canonical base64 of exactly 32 random bytes, used only to encrypt short-lived
# refresh-successor delivery envelopes shared by gateway replicas.
VEOVEO_REFRESH_DELIVERY_KEY_B64=
# Seconds in which concurrent presentation may receive the same rotated successor.
VEOVEO_REFRESH_DELIVERY_WINDOW_SECONDS=5
# Operations console browser session and OAuth client.
# Canonical base64 of exactly 32 random bytes used to encrypt HttpOnly BFF sessions.
VEOVEO_CONSOLE_SESSION_KEY=
# Registered public OAuth client used by the console BFF.
VEOVEO_CONSOLE_OAUTH_CLIENT_ID=admin-console
# Gateway MCP resource and scopes requested for console administration.
VEOVEO_CONSOLE_OAUTH_RESOURCE=https://veoveo.example/mcp/admin
VEOVEO_CONSOLE_OAUTH_SCOPES="operator:use admin:manage"
# Simulation View private control plane.
# Generate each token independently with `openssl rand -hex 32`. These tokens
# authorize only MCP-to-renderer and MCP-to-pose control calls inside the cluster.
SIMULATION_VIEW_RENDERER_CONTROL_TOKEN=
SIMULATION_VIEW_POSE_CONTROL_TOKEN=
# Recording governance defaults applied by Recording Hub.
RECORDING_TENANT_KEY=enterprise
RECORDING_WORK_CONTEXT=operations
RECORDING_CLASSIFICATION=unclassified
# Recording producer OAuth identity.
# PEM private key used by producer-side forwarders for private_key_jwt. Its public
# key must be registered in the gateway; the private key never enters the gateway.
VEOVEO_RECORDING_PRODUCER_PRIVATE_KEY_PEM=
# `kid` identifying the matching public producer key registered by the gateway.
VEOVEO_RECORDING_PRODUCER_KEY_ID=recording-producer-2026
# Ubuntu GPU perception mounts.
# The config directory contains catalog.json and referenced DeepStream configs.
# TensorRT engines and label files live under the read-only model directory.
PERCEPTION_CONFIG_DIR=/opt/veoveo/perception/config
PERCEPTION_MODEL_DIR=/opt/veoveo/perception/models