# Portable deployment example. Keep this file secret-free; supply SESSION_SECRET via a secret manager. APP_ENV=production LOG_LEVEL=INFO API_PORT=8000 WEB_PORT=8080 CORS_ORIGINS=https://your-approved-web-origin.example DATA_DIR=/data # Required in production; generate at least 32 random characters outside this file. SESSION_SECRET= # Mandatory for first-run administrator provisioning. Remove both after bootstrap. BOOTSTRAP_ADMIN_EMAIL= BOOTSTRAP_ADMIN_PASSWORD= # Hard safety default; this release has no delivery capability. AUTOMATED_OUTREACH_ENABLED=false # Runtime provider configuration is managed in the authenticated admin API: # POST /api/v1/admin/ai-provider-config. It is stored per organization with # encrypted credentials in SQLite and a generated 0600 key at /data/provider-config.key. # On startup, a database row takes precedence over every provider environment # variable. Environment values are bootstrap fallback only when no DB row exists; # they are never copied into API responses. Connectivity tests use bounded GET # requests only and report outbound_calls=false (no outreach is implemented). # The following variables are legacy/bootstrap fallback values only. # AI_RESEARCH_PROVIDER is set below for the primary self-hosted mode. # NOUS_MODEL=Hermes-4-405B # NOUS_BASE_URL=https://inference-api.nousresearch.com/v1 # NOUS_ALLOWED_HOSTS=inference-api.nousresearch.com # NOUS_API_KEY= # FIRECRAWL_BASE_URL=https://api.firecrawl.dev/v2 # FIRECRAWL_ALLOWED_HOSTS=api.firecrawl.dev # FIRECRAWL_API_KEY= # Primary no-paid-scraper mode: Nous orchestrates, internal SearXNG searches, # and the API's SSRF-safe crawler reads pages. No Firecrawl key is required. AI_RESEARCH_PROVIDER=nous_portal NOUS_API_KEY= NOUS_MODEL=Hermes-4-405B NOUS_BASE_URL=https://inference-api.nousresearch.com/v1 NOUS_ALLOWED_HOSTS=inference-api.nousresearch.com SEARXNG_BASE_URL=http://searxng:8080 SEARXNG_ALLOWED_HOSTS=searxng SEARXNG_SECRET_KEY= # Optional legacy fallback only; never required by self-hosted mode. FIRECRAWL_API_KEY= FIRECRAWL_BASE_URL=https://api.firecrawl.dev/v2 FIRECRAWL_ALLOWED_HOSTS=api.firecrawl.dev # Legacy provider settings (only used by compatibility adapters). AI_RESEARCH_PROVIDER_MODEL= AI_RESEARCH_PROVIDER_URL= AI_RESEARCH_PROVIDER_ALLOWED_HOSTS= AI_RESEARCH_PROVIDER_API_KEY= OPENAI_API_KEY= # Deprecated migration-only generic URL search adapter; not used by the AI workflow. SEARCH_PROVIDER_URL= SEARCH_PROVIDER_ALLOWED_HOSTS= SEARCH_PROVIDER_API_KEY= # Backup operations (host-side, never mounted into the web container). BACKUP_DIR=/var/backups/prospect-platform BACKUP_RETENTION=30