# Set to true to require the single-user login screen for every page and API. WEBUI_AUTH_ENABLED=true # These values are read only on the server. Keep .env private and never commit it. WEBUI_AUTH_USERNAME=admin WEBUI_AUTH_PASSWORD=replace-with-a-long-unique-password # Generate with: openssl rand -hex 32 WEBUI_AUTH_SECRET=replace-with-at-least-32-random-characters # Optional. Defaults to 12 hours. WEBUI_AUTH_SESSION_TTL_HOURS=12 # Provider editor. Integrated `EvoSci` WebUI mode sets these automatically. # For a standalone or remote WebUI, point at the trusted EvoScientist backend # and use the same random token configured on that backend. EVOSCIENTIST_BACKEND_URL=http://127.0.0.1:6174 # Deployment workspace root. This is not a browser-selectable directory and is # shared with the trusted EvoScientist backend. Defaults to ~/.evoscientist/workspace. EVOSCIENTIST_WORKSPACE_DIR= # Deployment id, matching the backend's EVOSCIENTIST_DEPLOYMENT_ID. Only needed # when the backend was started manually (no deploy sidecar); otherwise the # sidecar value wins. Defaults to a uuid derived from the workspace root. EVOSCIENTIST_DEPLOYMENT_ID= # Usage-attribution deployment id, matching the backend's # EVOSCIENTIST_USAGE_DEPLOYMENT_ID (stored in /deployment-id). This is # intentionally separate from the scope deployment id above so the usage # identity cannot repartition workspace scopes. EVOSCIENTIST_USAGE_DEPLOYMENT_ID= # Optional for local processes running as the same OS user: both sides share # ~/.config/evoscientist/provider-admin-token automatically. Set this explicitly # when the WebUI and backend run on different hosts, users, or containers. EVOSCIENTIST_PROVIDER_ADMIN_TOKEN= # Conversation workspace policy. This value must match the trusted backend and # is read by the BFF only; never expose it as a browser-provided path or scope. # # - legacy: every WebUI conversation uses the deployment root. It is an explicit # compatibility rollback and shared files are visible across conversations. # - optional: default. Each new conversation receives an isolated scope folder; # a missing Registry, token, or scope rejects the operation rather than falling # back to the shared root. # - required: isolated scopes plus strict server-side validation. Shared legacy # workspaces are unavailable; backend startup also requires cutover and its # pinned OCI executor configuration. # # Change this deployment-level setting only in a maintenance window, restart # both backend and WebUI, and do not use it to move an existing conversation. # For a same-host standalone WebUI, the BFF reads the server-only token from # /.evoscientist/control automatically. Set the token below only # when the WebUI and trusted backend cannot share that control-plane directory; # it is never exposed to the browser. EVOSCIENTIST_WORKSPACE_ISOLATION=optional EVOSCIENTIST_BACKEND_SERVICE_TOKEN= # Required mode is validated by the backend and must use an immutable image # digest, never a mutable tag. Keep this aligned with the backend .env. EVOSCIENTIST_STRICT_EXECUTOR_IMAGE=registry.example/evoscientist-runtime@sha256:replace-with-verified-digest # Token statistics for a local `EvoSci deploy` need no explicit secret here: # both processes dynamically share /usage-sink-token. Set the same # absolute data directory on both sides only when overriding the default. EVOSCIENTIST_DATA_DIR= # Office document preview. DOCX and supported Excel Open XML files render in # the browser. Other Office formats, and DOCX rendering failures, convert to a # private PDF cache. Leave enabled to auto-detect `soffice`; set to false to # keep browser-side DOCX and SpreadJS Excel previews only. # In production, point COMMAND to a sandboxed, no-network converter wrapper. EVOSCIENTIST_OFFICE_PREVIEW_ENABLED=true EVOSCIENTIST_OFFICE_PREVIEW_COMMAND=soffice # Concurrent conversions per WebUI process (1-8; default 2). EVOSCIENTIST_OFFICE_PREVIEW_CONCURRENCY=2 # SpreadJS renders supported Excel files in the browser. The key is delivered # to the browser by design, so use only a web deployment license. Omit it for # local evaluation; production deployments must provide a valid license. NEXT_PUBLIC_SPREADJS_LICENSE_KEY=