Repository navigation
Expand file tree
/
Copy pathapp.env.example
More file actions
154 lines (124 loc) · 6.47 KB
/
Copy pathapp.env.example
File metadata and controls
154 lines (124 loc) · 6.47 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
# Coneshare Environment Variables Template
#
# Copy this file to .env and fill in the values for your own custom setup.
# ------------------------------------------------------------------------------
# Core Django Settings (backend/backend/settings.py)
# ------------------------------------------------------------------------------
# SECURITY WARNING: a secure, randomly generated key is required for production.
SECRET_KEY=django-insecure-development-key-for-coneshare
# Set to "True" for development, "False" for production.
DEBUG=False
# The public-facing domain of the frontend. Used for generating absolute URLs.
# This value is also used to automatically configure ALLOWED_HOSTS and CSRF_TRUSTED_ORIGINS.
SITE_DOMAIN=http://localhost:5173
# IANA timezone used for user-facing notification timestamps (e.g. Asia/Shanghai).
# https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
DISPLAY_TIME_ZONE=UTC
# ALLOWED_HOSTS and CSRF_TRUSTED_ORIGINS are derived from SITE_DOMAIN in settings.py.
# You can uncomment and set them manually here to override this behavior.
#ALLOWED_HOSTS=127.0.0.1,localhost,backend
#CSRF_TRUSTED_ORIGINS=http://localhost:5173
# ------------------------------------------------------------------------------
# Document Preview Engine Settings
# ------------------------------------------------------------------------------
# PDF preview engine. Options: pdfjs, server_pages
PDF_PREVIEW_ENGINE=server_pages
# Whether to enable LibreOffice conversion for Office documents.
ENABLE_OFFICE_PREVIEW=true
# Whether to enable video transcoding/previews (disabled by default due to high CPU/memory requirements).
ENABLE_VIDEO_PREVIEW=false
# ------------------------------------------------------------------------------
# Celery Worker Concurrency Settings
# ------------------------------------------------------------------------------
# Default concurrency for the main celery worker.
# If unset, the Docker Compose configuration defaults this value to 4.
CELERY_WORKER_CONCURRENCY=4
# Concurrency for the video worker (1 is highly recommended to protect host CPU).
CELERY_VIDEO_WORKER_CONCURRENCY=1
# ------------------------------------------------------------------------------
# Security Settings
# ------------------------------------------------------------------------------
# The minimum number of characters required for authentication password.
PASSWORD_MIN_LENGTH=8
# A comma-separated list of password validators to enable.
# Available options: similarity, min_length, common, numeric
ENABLED_PASSWORD_VALIDATORS=similarity,min_length,common,numeric
# ------------------------------------------------------------------------------
# Database Settings
# ------------------------------------------------------------------------------
# URL format: driver://user:password@host:port/dbname
# Example for PostgreSQL: DATABASE_URL=postgres://coneshare:password@db:5432/coneshare
DATABASE_URL=postgres://postgres@postgres:5432/postgres
# ------------------------------------------------------------------------------
# Redis Settings (Cache & Celery)
# ------------------------------------------------------------------------------
# URL format: redis://:password@host:port
# This base URL is used to construct the connections for both the cache and Celery.
# The application will append /0 for Celery and /1 for the cache.
# If unset, it defaults to redis://redis:6379.
REDIS_URL=redis://redis:6379
# ------------------------------------------------------------------------------
# Email Settings (for password resets, notifications, etc.)
# ------------------------------------------------------------------------------
# For a real SMTP server (e.g., Gmail, SendGrid), configure the following:
EMAIL_BACKEND=django.core.mail.backends.smtp.EmailBackend
EMAIL_HOST=
EMAIL_PORT=587
EMAIL_USE_TLS=True
EMAIL_HOST_USER=
EMAIL_HOST_PASSWORD=
DEFAULT_FROM_EMAIL=noreply@example.com
# From-address for Django's AdminEmailHandler crash emails
SERVER_EMAIL=errors@example.com
# Recipients for Django AdminEmailHandler error emails when DEBUG=False
# Format: "Name:email,Name2:email2" or "email1,email2"
ADMINS=Ops-Admin:ops@example.com
# ------------------------------------------------------------------------------
# Logging Settings
# ------------------------------------------------------------------------------
# Log level for the application. Options: DEBUG, INFO, WARNING, ERROR, CRITICAL
#LOG_LEVEL=INFO
# ------------------------------------------------------------------------------
# Error Monitoring (Sentry)
# ------------------------------------------------------------------------------
# Optional. Leave blank to disable Sentry for self-hosted installs.
SENTRY_DSN=https://5770de357e72d0dabddc3a12b9a89421@o15570.ingest.us.sentry.io/4511465277882368
# Sentry environment and release metadata.
SENTRY_ENVIRONMENT=ce
SENTRY_RELEASE=rolling
# Whether Sentry may collect default personally identifiable information such as
# request headers, cookies, user identifiers, and IP addresses.
SENTRY_SEND_DEFAULT_PII=false
# ------------------------------------------------------------------------------
# Service Communication (docker-compose.yml)
# ------------------------------------------------------------------------------
# Internal token for secure communication between backend and core services.
INTERNAL_API_TOKEN=supersecrettoken
# URL for the Go file server, as seen from the backend/celery containers.
CORE_API_URL=http://web:8080
# Port for the Go file server.
PORT=8080
# Path inside the core container where files are stored.
STORAGE_PATH=/data
# ------------------------------------------------------------------------------
# Malware Scan (ClamAV)
# ------------------------------------------------------------------------------
# Default OFF. Set to true to enable malware scanning in backend logic.
MALWARE_SCAN_ENABLED=false
# ClamAV service endpoint (used when MALWARE_SCAN_ENABLED=true)
CLAMAV_HOST=clamav
CLAMAV_PORT=3310
# Scan timeout in milliseconds
MALWARE_SCAN_TIMEOUT_MS=10000
# Behavior when scanner is unavailable: closed|open
# closed = reject upload/finalize (recommended for security)
MALWARE_SCAN_FAIL_MODE=closed
# ------------------------------------------------------------------------------
# Remote MCP Server (coneshare-mcp)
# ------------------------------------------------------------------------------
# Target REST API URL as seen from mcp_server container
CONESHARE_API_URL=http://web:80/api/v1
# Transport mode (streamable-http or sse)
MCP_TRANSPORT=streamable-http
# HTTP SSE endpoint path
MCP_PATH=/mcp/sse