Files
ai-memory/docker/.env.production.example
Lucas Oliveira 00151a4e39 docs(llm): correct the session-header description after reconciling
Review pass over the merged state found three statements left over from the
per-process session id this branch used to carry: `docs/install.md` and
`docker/.env.production.example` still described the default as one id per
process, stable only if set explicitly. It is one id per logical operation,
stable across retries and the structured-output fallback, so the advice to
set it "to keep it stable across restarts" pointed at a problem that no
longer exists. Both now describe what the code does and why an operator
would still override it.

Also re-exports `OPENCODE_SESSION_HEADER` from the crate root, where its
sibling opencode constants already live.
2026-09-03 15:10:38 +00:00

103 lines
5.0 KiB
Bash

# Production env vars for ai-memory.
#
# Copy to docker/.env.production, fill in real values, then scp it to
# your homelab alongside docker-compose.yml. The live copy is
# gitignored; never commit it.
#
# The container reads these via env_file (see docker-compose.prod.yml.example).
# Everything is optional — without any LLM/embedding keys, ai-memory
# still runs in pure-FTS5 mode with rule-based session summaries.
# -- Workspace + project labels stamped on every observation -----------
# Match whatever name you want for your homelab knowledge silo. These
# strings are user-visible labels, not paths.
# AI_MEMORY_WORKSPACE=default
# AI_MEMORY_PROJECT=homelab
# -- LLM provider ------------------------------------------------------
# Pick one of: anthropic | openai | openai-oauth | copilot | gemini | openai-compat | opencode
# anthropic -> Anthropic Messages API (needs ANTHROPIC_API_KEY)
# openai -> OpenAI Chat Completions (needs OPENAI_API_KEY)
# openai-oauth -> ChatGPT/Codex OAuth. Run `ai-memory auth login
# openai-oauth` against this same data volume first.
# copilot -> GitHub Copilot Chat. Run `ai-memory auth login
# copilot` against this same data volume first, or set
# COPILOT_GITHUB_TOKEN below.
# gemini -> Google Gemini (needs GEMINI_API_KEY or GOOGLE_API_KEY)
# openai-compat -> Any OpenAI-compatible endpoint: Ollama, vLLM,
# LM Studio, OpenRouter, Together, etc. Set
# AI_MEMORY_LLM_BASE_URL + LLM_API_KEY.
# opencode -> OpenCode cloud. Defaults to the Go endpoint
# (https://opencode.ai/zen/go/v1), a cost-optimised
# subset. For Zen's full catalogue set
# AI_MEMORY_LLM_BASE_URL=https://opencode.ai/zen/v1 and
# an AI_MEMORY_LLM_MODEL from that catalogue.
# Get your key at opencode.ai/auth. Set OPENCODE_API_KEY.
# Default model: claude-sonnet-4-6 (a Go model id).
#
# Without AI_MEMORY_LLM_PROVIDER set, consolidation falls back to
# rule-based summaries (no LLM cost; lower-signal handoffs).
AI_MEMORY_LLM_PROVIDER=openai-compat
AI_MEMORY_LLM_BASE_URL=https://openrouter.ai/api/v1
AI_MEMORY_LLM_MODEL=moonshotai/kimi-k2.6
# Provider-specific API keys. Set whichever matches your
# AI_MEMORY_LLM_PROVIDER above.
# ANTHROPIC_API_KEY=sk-ant-...
# OPENAI_API_KEY=sk-...
# COPILOT_GITHUB_TOKEN=ghu_or_github_pat_REPLACE_ME
# OPENCODE_API_KEY=sk-... (from opencode.ai/auth, for AI_MEMORY_LLM_PROVIDER=opencode)
LLM_API_KEY=sk-or-v1-REPLACE_ME
# -- Extra headers on every LLM request --------------------------------
# Every chat request already carries `User-Agent: ai-memory/<version>` so a
# gateway can tell what is calling it. Add this only for a gateway that also
# requires a header of its own for request correlation.
#
# Comma-separated `Name=Value` (or `Name: Value`) entries. A header *value*
# cannot contain a comma here — use `llm_headers = [...]` in config.toml if
# one must. Headers ai-memory sets itself (authorization, content-type,
# x-api-key, ...) are refused at startup. Values are never logged.
#
# The `opencode` provider needs nothing here: it already sends one
# `x-opencode-session` per logical operation, stable across retries. Set one
# explicitly only to override that — e.g. to tell several instances apart.
# AI_MEMORY_LLM_HEADERS=x-opencode-session=homelab-01,x-opencode-client=ai-memory
# -- Embeddings (hybrid retrieval) -------------------------------------
# Optional. When set, ai-memory computes + stores embeddings for every
# page and uses Reciprocal Rank Fusion to combine FTS5 with vector
# cosine. Better recall on paraphrased queries; needs a key.
#
# Pick: openai | voyage
AI_MEMORY_EMBEDDING_PROVIDER=openai
AI_MEMORY_EMBEDDING_MODEL=text-embedding-3-small
AI_MEMORY_EMBEDDING_DIM=1536
OPENAI_API_KEY=sk-REPLACE_ME
# VOYAGE_API_KEY=...
#
# Optional: an embedding-only key, checked before OPENAI_API_KEY and
# LLM_API_KEY. Set it when embeddings should authenticate against a
# different provider than AI_MEMORY_LLM_PROVIDER above.
# EMBEDDING_API_KEY=sk-...
# -- Listen address inside the container -------------------------------
# The compose file maps the host port to this. Don't change unless
# you also change the compose port mapping.
# AI_MEMORY_BIND=0.0.0.0:49374
# -- Bearer-token auth -------------------------------------------------
# Required when the server is reachable from anything beyond loopback
# (i.e. any LAN-binding deploy). When set, every /mcp + /hook + /handoff
# request must carry `Authorization: Bearer <token>`. The matching
# token goes into each client's MCP config (use `ai-memory install-mcp
# --client <name> --auth-token <token>` to render the snippet).
#
# Generate with:
# ai-memory generate-auth-token
#
# Without this set, the server logs a loud warning at startup AND
# accepts every request — fine for loopback-only `serve --bind 127...`
# but a critical hole on a LAN binding.
AI_MEMORY_AUTH_TOKEN=REPLACE_WITH_OUTPUT_OF_GENERATE_AUTH_TOKEN