# Portable deployment example. Keep this file secret-free; supply SESSION_SECRET via a secret manager. APP_ENV=production LOG_LEVEL=INFO API_PORT=8000 WEB_PORT=8080 CORS_ORIGINS=https://your-approved-web-origin.example DATA_DIR=/data # Required in production; generate at least 32 random characters outside this file. SESSION_SECRET= # Mandatory for first-run administrator provisioning. Remove both after bootstrap. BOOTSTRAP_ADMIN_EMAIL= BOOTSTRAP_ADMIN_PASSWORD= # Hard safety default; this release has no delivery capability. AUTOMATED_OUTREACH_ENABLED=false # Optional criteria-first AI web research. OpenAI's native Responses API setup: # AI_RESEARCH_PROVIDER=openai_web_search # AI_RESEARCH_PROVIDER_MODEL= # AI_RESEARCH_PROVIDER_URL=https://api.openai.com/v1/responses # AI_RESEARCH_PROVIDER_ALLOWED_HOSTS=api.openai.com # OPENAI_API_KEY= # The server sends tools:[{type:web_search}], accepts only bounded URL citations/ # sources, and fetches targets through its SSRF-safe crawler. All values are # server-side only. AI_RESEARCH_PROVIDER_API_KEY is only for generic providers. AI_RESEARCH_PROVIDER= AI_RESEARCH_PROVIDER_MODEL= AI_RESEARCH_PROVIDER_URL= AI_RESEARCH_PROVIDER_ALLOWED_HOSTS= AI_RESEARCH_PROVIDER_API_KEY= OPENAI_API_KEY= # Deprecated migration-only generic URL search adapter; not used by the AI workflow. SEARCH_PROVIDER_URL= SEARCH_PROVIDER_ALLOWED_HOSTS= SEARCH_PROVIDER_API_KEY= # Backup operations (host-side, never mounted into the web container). BACKUP_DIR=/var/backups/prospect-platform BACKUP_RETENTION=30