1a01fb5d74
Provider credentials now live exclusively in the Model Registry and the x-evoscientist-admin-token / provider-admin-token mechanism was removed; no code reads these variables anymore. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
42 lines
2.2 KiB
Bash
42 lines
2.2 KiB
Bash
# EvoScientist — cp .env.example .env && fill in your keys
|
|
#
|
|
# LLM providers, models, and API keys are managed exclusively through the
|
|
# Model Registry (WebUI 大模型配置 / Config API); no provider credential is
|
|
# read from environment variables. See
|
|
# docs/unified-model-configuration-architecture.md.
|
|
|
|
# Web search (optional)
|
|
TAVILY_API_KEY= # app.tavily.com
|
|
|
|
# WebUI conversation workspace policy. EVOSCIENTIST_WORKSPACE_DIR is the
|
|
# deployment root, not a per-conversation directory. In isolated modes each
|
|
# conversation is stored under <root>/.evoscientist/conversations/<scope-id>/.
|
|
#
|
|
# EVOSCIENTIST_WORKSPACE_ISOLATION accepts exactly:
|
|
# - legacy: all WebUI conversations share the deployment root. Compatibility
|
|
# rollback only; files are visible to every conversation using this deployment.
|
|
# - optional: default. New WebUI conversations receive isolated scope folders;
|
|
# missing Registry/token/scope fails the request instead of silently sharing.
|
|
# - required: isolated scopes plus strict runtime validation. It requires a
|
|
# completed cutover and a verified OCI executor; no legacy fallback exists.
|
|
#
|
|
# This is a deployment-startup security setting. Change it only during a
|
|
# maintenance window, restart backend and WebUI afterwards, and never use it to
|
|
# convert an existing conversation between shared and isolated directories.
|
|
EVOSCIENTIST_WORKSPACE_DIR=
|
|
EVOSCIENTIST_WORKSPACE_ISOLATION=optional
|
|
# Required mode supports only a single-host Registry topology in v1.
|
|
EVOSCIENTIST_SCOPE_REGISTRY_TOPOLOGY=single-host
|
|
# Required mode: use a pinned image digest, preserve single-host topology, and
|
|
# keep the Code Interpreter disabled unless its scoped implementation is enabled.
|
|
# Do not put EVOSCIENTIST_BACKEND_SERVICE_TOKEN here for a same-host `EvoSci
|
|
# deploy`: it is generated and passed privately at startup.
|
|
# EVOSCIENTIST_WORKSPACE_ISOLATION=required
|
|
# EVOSCIENTIST_STRICT_EXECUTOR=oci
|
|
# EVOSCIENTIST_STRICT_EXECUTOR_IMAGE=registry.example/evoscientist-runtime@sha256:replace-with-verified-digest
|
|
# EVOSCIENTIST_STRICT_CODE_INTERPRETER=disabled
|
|
|
|
# Conversation workspace isolation retention defaults (used by workspace_maintenance.py).
|
|
EVOSCIENTIST_DRAFT_WORKSPACE_TTL_HOURS=24
|
|
EVOSCIENTIST_WORKSPACE_TRASH_RETENTION_DAYS=7
|