-
Notifications
You must be signed in to change notification settings - Fork 371
Expand file tree
/
Copy path.env.example
More file actions
229 lines (205 loc) · 8.64 KB
/
Copy path.env.example
File metadata and controls
229 lines (205 loc) · 8.64 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
# SERVER CONFIG
HOST='localhost'
PORT='3000'
PROTO='https'
SERVER_SECRET='key_SERVER_SECRET'
# Use this for webhook development when you need to reference an ngrok address
DEV_WEBHOOK_URL=''
# Separate key for generating client facing page ids. Falls back to the SERVER_SECRET if not set. Changing this will invalidate all existing page ids, so all page links will break.
#PAGE_CIPHER_KEY='key_PAGE_CIPHER_KEY'
# Cluster node number 0 - 1023. Must be unique per process.
SERVER_ID='1'
# Used to read the client IP from the X-Forwarded-For header, if not set, it will use the first IP in the list.
# If configured, it must match the number of proxies in the stack, otherwise it might rate limit all traffic coming from the proxy.
# TRUSTED_PROXY_COUNT='1'
# Websocket port for the websocket server, only used in development
SOCKET_PORT='3001'
# Folder where heap dumps are generated. If empty, it defaults to system tmp folder
# HEAP_DUMP_FOLDER=''
# AI MODELS
AI_EMBEDDING_MODELS='[{"model": "text-embeddings-inference:Svenni551/Qwen3-Embedding-0.6B-ONNX-INT8", "url": "http://localhost:3040/", "maxTokens": 4096}]'
AI_GENERATION_MODELS='[{"model": "text-generation-inference:TheBloke/zephyr-7b-beta", "url": "http://localhost:3050/", "maxTokens": 4096}]'
AI_EMBEDDER_WORKERS='1'
# APPLICATION
# AMPLITUDE_WRITE_KEY='key_AMPLITUDE_WRITE_KEY'
# Enter a short url redirect service for invitations, it needs to redirecto to /invitation-link
# INVITATION_SHORTLINK='example.com'
# If true, all new orgs will default to being enterprise tier. Use for PPMIs
# IS_ENTERPRISE=false
# If true and IS_ENTERPRISE=true, disable creating new orgs
# IS_SINGLE_ORG=true
# PPMI single tenant use only. Will set the SAML issuer to this value.
# SAML_ISSUER=''
# AUTHENTICATION
# AUTH_INTERNAL_DISABLED='false'
# AUTH_GOOGLE_DISABLED='false'
# AUTH_MICROSOFT_DISABLED='false'
# AUTH_SSO_DISABLED='false'
# GOOGLE_OAUTH_CLIENT_ID=''
# GOOGLE_OAUTH_CLIENT_SECRET=''
# URL to a microservice that links 1 oauth2 integration to multiple parabol instances on different hosts. If missing, uses the app route /auth/service
# OAUTH2_REDIRECT=''
# could be a specific tenant for on premise installs
# MICROSOFT_TENANT_ID='common'
# MICROSOFT_CLIENT_ID=''
# MICROSOFT_CLIENT_SECRET=''
# AWS
# AWS_ACCESS_KEY_ID='key_AWS_ACCESS_KEY_ID'
# AWS_REGION='key_AWS_REGION'
# AWS_SECRET_ACCESS_KEY='key_AWS_SECRET_ACCESS_KEY'
# AWS_S3_BUCKET='key_AWS_BUCKET'
# MONITORING
# Prometheus metrics endpoint
# ENABLE_METRICS='false'
# METRICS_PORT=9090
# CDN SETTINGS
# CDN_BASE_URL must start with // and end with a path. Examples: '//action-files.parabol.co/production', '//action-files.parabol.fun/staging'
CDN_BASE_URL=''
# If true, the server will sign and redirect calls from /build to the CDN. This is required for PPMIs where a public bucket is not allowed.
PROXY_CDN=false
# FILE_STORE_PROVIDER: local | s3 | gcs
FILE_STORE_PROVIDER='local'
# Google Cloud credentials are required to use FILE_STORE_PROVIDER='gcs'
# GOOGLE_GCS_BUCKET='BUCKET_NAME'
# WEB SERVER
# Time window, in seconds, used by the web server to kick its users off. If empty or not declared it defaults to 60.
# WEB_SERVER_RECONNECT_WINDOW='60'
# CHRONOS
# Optional. Used to log each tick of chronos to the console.
# CHRONOS_DEBUG='true'
# Optional. Used to broadcast signups/logins to slack.
CHRONOS_PULSE_EMAIL=''
CHRONOS_PULSE_CHANNEL=''
CHRONOS_PULSE_DAILY='0 0 4 * * *'
CHRONOS_PULSE_WEEKLY='0 0 4 * * 1'
# Required. See sendBatchNotificationEmails
CHRONOS_BATCH_EMAILS='0 0 10 * * *'
# Required. See runScheduledJobs
CHRONOS_SCHEDULE_JOBS='0 */10 * * * *'
# Required if using Jira. See updateOAuthRefreshTokens
CHRONOS_UPDATE_TOKENS='0 0 0 1,15 * *'
# Required if using standups. See processRecurrence
CHRONOS_PROCESS_RECURRENCE='0 */5 * * * *'
# Required. See autopauseUsers
CHRONOS_AUTOPAUSE='0 0 5 * * *'
# Optional. Prunes DB rows like failed embedding jobs
CHRONOS_PRUNE_PG='0 0 6 * * *'
# DATABASES
POSTGRES_PASSWORD=parabol
POSTGRES_USER=pgparaboladmin
POSTGRES_DB=parabol-saas
POSTGRES_HOST=localhost
POSTGRES_PORT=5432
POSTGRES_USE_PGVECTOR=true
# POSTGRES_POOL_SIZE=5
# POSTGRES_SSL_REJECT_UNAUTHORIZED=false
# POSTGRES_SSL_DIR='/var/lib/postgresql'
REDIS_PASSWORD=''
REDIS_URL='redis://localhost:6379'
# REDIS_TLS_CERT_FILE=./docker/stacks/development/redis/certs/redis.crt
# REDIS_TLS_KEY_FILE=./docker/stacks/development/redis/certs/redis.key
# REDIS_TLS_CA_FILE=./docker/stacks/development/redis/certs/redisCA.crt
# REDIS_TLS_REJECT_UNAUTHORIZED='false'
# DATADOG DD-Trace
# https://ddtrace.readthedocs.io/en/stable/configuration.html
# DD_APM_ENABLED='false'
# DD_API_KEY=''
# DD_APPSEC_ENABLED='true'
# DD_CLIENTTOKEN=''
# DD_ENV=''
# DD_LOGS_INJECTION='true'
# DD_RUNTIME_METRICS_ENABLED='true'
# DD_SERVICE='DD_SERVICE_NAME'
# DD_TRACE_AGENT_URL='http://localhost:8126'
# DD_TRACE_ENABLED='false'
# GOOGLE
# Google Analytics Tracking ID
# GA_TRACKING_ID=''
# GOOGLE_CLOUD_CLIENT_EMAIL=''
# GOOGLE_CLOUD_PRIVATE_KEY=''
# GOOGLE_CLOUD_PRIVATE_KEY_ID=''
# Google Cloud credentials are required to use the GCP Natural Language API.
# Disable Google Cloud Natural Language API for generating retro group titles
# DISABLE_GOOGLE_CLOUD_NATURAL_LANGUAGE='true'
# INTEGRATIONS
# ATLASSIAN_CLIENT_ID='key_ATLASSIAN_CLIENT_ID'
# ATLASSIAN_CLIENT_SECRET='key_ATLASSIAN_CLIENT_SECRET'
# AZURE_DEVOPS_CLIENT_ID=''
# AZURE_DEVOPS_CLIENT_SECRET=''
# GITHUB_CLIENT_ID='key_GITHUB_CLIENT_ID'
# GITHUB_CLIENT_SECRET='key_GITHUB_CLIENT_SECRET'
# GITLAB_CLIENT_ID='key_GITLAB_CLIENT_ID'
# GITLAB_CLIENT_SECRET='key_GITLAB_CLIENT_SECRET'
# GITLAB_SERVER_URL='https://gitlab.com'
# DEEPSEEK_API_KEY=''
# DEEPSEEK_MODEL='deepseek-chat'
# LINEAR_CLIENT_ID=''
# LINEAR_CLIENT_SECRET=''
# OPEN_AI_API_KEY=''
# OPEN_AI_ORG_ID=''
# RECALL_AI_KEY=''
# SLACK_CLIENT_ID='key_SLACK_CLIENT_ID'
# SLACK_CLIENT_SECRET='key_SLACK_CLIENT_SECRET'
# STRIPE_SECRET_KEY=''
# STRIPE_PUBLISHABLE_KEY=''
# STRIPE_WEBHOOK_SECRET=''
# Disable the built in Mattermost webhook integration
# MATTERMOST_WEBHOOK_INTEGRATION_DISABLED='false'
# For private instances with SSO and the Mattermost plugin, set the secret and URL
# MATTERMOST_SECRET='key_MATTERMOST_SECRET'
# MATTERMOST_URL='https://mattermost.example.com'
# Outbound requests to user-supplied URLs (webhooks, embedded images) may not reach private
# networks. Self-hosted deployments can allow specific destinations here.
# Comma separated hostnames, IPs, or CIDR ranges, e.g. 'mattermost.internal,localhost,10.0.0.0/8'
# SSRF_ALLOWED_HOSTS=''
# Disable the built in MS Teams webbhook integration
# MSTEAMS_WEBHOOK_INTEGRATION_DISABLED ='false'
# Use for zoom transcriptions
ZOOM_WEBHOOK_SECRET_TOKEN=''
ZOOM_CLIENT_ID=''
ZOOM_CLIENT_SECRET=''
# MAIL
# MAIL GLOBALS. PROVIDER: mailgun | google | debug | smtp
MAIL_PROVIDER='debug'
# MAIL_FROM='key_MAIL_FROM'
# MAILGUN_API_KEY='key_MAILGUN_API_KEY'
# MAILGUN_DOMAIN='key_MAILGUN_DOMAIN'
# MAIL_GOOGLE_USER='key_MAIL_GOOGLE_USER'
# MAIL_GOOGLE_PASS='key_MAIL_GOOGLE_PASS'
# For SMTP, MAIL_SMTP_URL is mutually exclusive to the other env vars with the MAIL_SMTP_ prefix
# Use it when custom configs are required
# MAIL_SMTP_URL='smtps://username:password@smtp.example.com/?pool=true&tls.rejectUnauthorized=false'
# MAIL_SMTP_HOST='key_MAIL_SMTP_HOST'
# MAIL_SMTP_PORT=587
# MAIL_SMTP_USER='key_MAIL_SMTP_USER'
# MAIL_SMTP_PASSWORD='key_MAIL_SMTP_PASSWORD'
# MAIL_SMTP_USE_TLS='1' # set to '0' for false
# MAIL_SMTP_CIPHERS='HIGH:MEDIUM:!aNULL:!eNULL:@STRENGTH:!DH:!kEDH'
# When true, verifies DNS resolution, TCP handshake, and authentication on server startup
# MAIL_SMTP_DEBUG=false
# GLOBAL BANNER
# GLOBAL_BANNER_ENABLED='true'
# GLOBAL_BANNER_TEXT='UNCLASSIFIED CUI (IL4)'
# GLOBAL_BANNER_BG_COLOR='#007A33'
# GLOBAL_BANNER_COLOR='#FFFFFF'
# gifabol | klipy | '' to hide gif selection tab
# GIF_PROVIDER=klipy
# GIF_SECRET=''
# Google Form URL for error boundary feedback (formResponse endpoint)
# Field entry IDs are configured as query params: _email, _subject, _content, _eventId
# GOOGLE_ERROR_FORM_URL='https://docs.google.com/forms/d/e/FORM_ID/formResponse?_email=entry.XXXXXXXX&_subject=entry.XXXXXXXX&_content=entry.XXXXXXXX&_eventId=entry.XXXXXXXX'
# LOGGING
# Enable additional audit logs for select mutations
AUDIT_LOGS='true'
# highest log level, 'debug' | 'info' | 'warn' | 'error', defaults to 'info'
# LOG_LEVEL='info'
#
# DEVELOPER VARIABLES
#
# CI='true'
# ULTRAHOOK_API_KEY='key_ULTRAHOOK_API_KEY'
# Only run these apps in development. Leave empty to run all. CSV format
DEV_RUN_ONLY="Webpack Servers,Socket Server,Embedder,Dev Server,Flush Redis,PG Migrations,Relay Compiler,GraphQL Codegen,Kysely Codegen,Mattermost Relay Compiler,Mattermost Plugin Dev Server"
# PGAdmin - used only with `db:start` command
PGADMIN_DEFAULT_EMAIL='pgadmin4@pgadmin.org'
PGADMIN_DEFAULT_PASSWORD='admin'