Files
EvoScientist/.env.example
T
m4 1a01fb5d74 docs(env): drop stale LLM-key and provider-admin-token entries from .env.example
Provider credentials now live exclusively in the Model Registry and the
x-evoscientist-admin-token / provider-admin-token mechanism was removed;
no code reads these variables anymore.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-21 21:14:31 +08:00

42 lines
2.2 KiB
Bash

# EvoScientist — cp .env.example .env && fill in your keys
#
# LLM providers, models, and API keys are managed exclusively through the
# Model Registry (WebUI 大模型配置 / Config API); no provider credential is
# read from environment variables. See
# docs/unified-model-configuration-architecture.md.
# Web search (optional)
TAVILY_API_KEY= # app.tavily.com
# WebUI conversation workspace policy. EVOSCIENTIST_WORKSPACE_DIR is the
# deployment root, not a per-conversation directory. In isolated modes each
# conversation is stored under <root>/.evoscientist/conversations/<scope-id>/.
#
# EVOSCIENTIST_WORKSPACE_ISOLATION accepts exactly:
# - legacy: all WebUI conversations share the deployment root. Compatibility
# rollback only; files are visible to every conversation using this deployment.
# - optional: default. New WebUI conversations receive isolated scope folders;
# missing Registry/token/scope fails the request instead of silently sharing.
# - required: isolated scopes plus strict runtime validation. It requires a
# completed cutover and a verified OCI executor; no legacy fallback exists.
#
# This is a deployment-startup security setting. Change it only during a
# maintenance window, restart backend and WebUI afterwards, and never use it to
# convert an existing conversation between shared and isolated directories.
EVOSCIENTIST_WORKSPACE_DIR=
EVOSCIENTIST_WORKSPACE_ISOLATION=optional
# Required mode supports only a single-host Registry topology in v1.
EVOSCIENTIST_SCOPE_REGISTRY_TOPOLOGY=single-host
# Required mode: use a pinned image digest, preserve single-host topology, and
# keep the Code Interpreter disabled unless its scoped implementation is enabled.
# Do not put EVOSCIENTIST_BACKEND_SERVICE_TOKEN here for a same-host `EvoSci
# deploy`: it is generated and passed privately at startup.
# EVOSCIENTIST_WORKSPACE_ISOLATION=required
# EVOSCIENTIST_STRICT_EXECUTOR=oci
# EVOSCIENTIST_STRICT_EXECUTOR_IMAGE=registry.example/evoscientist-runtime@sha256:replace-with-verified-digest
# EVOSCIENTIST_STRICT_CODE_INTERPRETER=disabled
# Conversation workspace isolation retention defaults (used by workspace_maintenance.py).
EVOSCIENTIST_DRAFT_WORKSPACE_TTL_HOURS=24
EVOSCIENTIST_WORKSPACE_TRASH_RETENTION_DAYS=7