Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
81 lines (73 loc) · 3.24 KB
/
Copy path.env.example
File metadata and controls
81 lines (73 loc) · 3.24 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
# Sandcastle Configuration
#
# LOCAL MODE (zero-config):
# Leave DATABASE_URL and REDIS_URL empty (or remove them).
# Sandcastle will use SQLite + filesystem + in-process queue automatically.
#
# PRODUCTION MODE:
# Set DATABASE_URL and REDIS_URL to use PostgreSQL + Redis + S3.
# --- Required ---
# Base URL the CLI targets. `sandcastle serve` listens on port 8080 by default.
SANDCASTLE_URL=http://localhost:8080
ANTHROPIC_API_KEY=sk-ant-...
# --- Sandbox backend credentials ---
# Required only for the E2B sandbox backend (SANDBOX_BACKEND=e2b).
E2B_API_KEY=e2b_...
# --- Database ---
# Empty = local SQLite mode (auto-created in DATA_DIR)
# PostgreSQL = production mode
# DATABASE_URL=postgresql+asyncpg://sandcastle:sandcastle@localhost:5432/sandcastle
DATABASE_URL=
# --- Redis ---
# Empty = in-process queue (no separate worker needed)
# Redis URL = production mode (requires `arq` worker)
# REDIS_URL=redis://localhost:6379/0
REDIS_URL=
# --- NVIDIA DGX Spark / local model server ---
# docker-compose.spark.yml defaults these for container-to-host access.
# SANDCASTLE_SPARK_MODE=on
# DATA_RESIDENCY=local
# NIM_BASE_URL=http://host.docker.internal:8000
# OLLAMA_HOST=http://host.docker.internal:11434
# SPARK_SANDBOX_BACKEND=docker
# DOCKER_IMAGE=sandcastle-runner:latest
# DOCKER_GID= # set with: stat -c '%g' /var/run/docker.sock
# --- Storage ---
# "local" = filesystem (default), "s3" = S3/MinIO
STORAGE_BACKEND=local
# S3 settings (only needed when STORAGE_BACKEND=s3)
# STORAGE_BUCKET=sandcastle-data
# STORAGE_ENDPOINT=http://localhost:9000
# AWS_ACCESS_KEY_ID=minioadmin
# AWS_SECRET_ACCESS_KEY=minioadmin
# --- Local mode data directory ---
DATA_DIR=./data
# --- Optional ---
WEBHOOK_SECRET=your-webhook-signing-secret
AUTH_REQUIRED=false
# The CLI binds 127.0.0.1 by default; binding a non-loopback host with
# AUTH_REQUIRED=false is refused unless SANDCASTLE_ALLOW_INSECURE_BIND=true.
# Required when AUTH_REQUIRED=true (Docker production mode sets it to true).
# Generate with: openssl rand -hex 32
API_KEY_PEPPER=
# Bootstrap admin key created on startup when set.
# Generate with: printf 'sc_%s\n' "$(openssl rand -hex 24)"
ADMIN_API_KEY=
# In-process "code" steps run untrusted Python in-process. They are admin-only
# by default. Single-tenant self-hosted operators who intentionally use code
# steps can opt in; leave false on multi-tenant deployments.
CODE_STEPS_ALLOW_UNTRUSTED=false
# Run "code" steps in a separate Python subprocess (out-of-process isolation) so
# a sandbox escape cannot reach the parent process memory (settings, DB session,
# other tenants' data). On by default; set false to use the legacy in-process path.
CODE_STEPS_OUT_OF_PROCESS=true
# Bearer token for the Memory MCP server over streamable-http. Required to start
# streamable-http outside local mode (it fails closed without it). stdio is
# unaffected. Callers must send: Authorization: Bearer <token>
# MEMORY_MCP_TOKEN=
# Optional tenant scope prefix for the Memory MCP server. When set, every tool
# call (add/search/forget/list_memories) must operate within this prefix, so an
# authenticated token cannot read/write/delete another tenant's memories. Leave
# unset for single-tenant/local deployments (no cross-tenant enforcement).
# MEMORY_MCP_SCOPE_PREFIX=
LOG_LEVEL=info