-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy path.env.example
More file actions
96 lines (71 loc) · 4.21 KB
/
Copy path.env.example
File metadata and controls
96 lines (71 loc) · 4.21 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
# .env.example — copy this file to .env and fill in your values.
# Never commit .env to version control.
# ── Required ──────────────────────────────────────────────────────────────────
# Numeric App ID shown on the GitHub App settings page.
GITHUB_APP_ID=
# RSA private key from the downloaded .pem file.
# Paste the full PEM on a SINGLE LINE, replacing each real newline with \n.
# Run this command to convert the downloaded file:
# awk 'NF {sub(/\r/, ""); printf "%s\\n",$0;}' layne-dev.pem
GITHUB_APP_PRIVATE_KEY=
# Webhook secret you set when creating the GitHub App.
# Generate one with: openssl rand -hex 32
GITHUB_WEBHOOK_SECRET=
# ── Optional ──────────────────────────────────────────────────────────────────
# Redis connection string. Defaults to redis://localhost:6379.
# When running docker-compose.dev.yml, the default is already correct.
# REDIS_URL=redis://localhost:6379
# Port for the webhook server. Defaults to 3000.
# PORT=3000
# Set to true to enable verbose debug logging (git commands, file lists, API calls).
# DEBUG_MODE=true
# ── AI scanners (optional) ────────────────────────────────────────────────────
# Claude scanner, and Spectre when provider is "anthropic".
# ANTHROPIC_API_KEY=
# Spectre — add the key for whichever provider you configure in layne.json.
# OPENAI_API_KEY=
# GEMINI_API_KEY=
# MISTRAL_API_KEY=
# AWS_BEARER_TOKEN_BEDROCK=
# AWS_ACCESS_KEY_ID=
# AWS_SECRET_ACCESS_KEY=
# AWS_REGION=us-east-1
# ── Spectre provider governor ────────────────────────────────────────────────
# Use "redis" for provider limits shared by all worker processes. The default
# "in_process" backend limits one process only and is suitable for one worker.
# SPECTRE_GOVERNOR_BACKEND=in_process
# Provider-scoped limits. With the Redis backend these are deployment-wide.
# SPECTRE_GLOBAL_CONCURRENCY=4
# SPECTRE_REQUESTS_PER_MINUTE=35
# SPECTRE_REQUEST_BURST=35
# SPECTRE_QUEUE_TIMEOUT_MS=2000
# SPECTRE_CIRCUIT_FAILURES=3
# SPECTRE_CIRCUIT_WINDOW_SECONDS=60
# SPECTRE_CIRCUIT_COOLDOWN_SECONDS=60
# ── Spectre response cache ───────────────────────────────────────────────────
# Operational mode. Cache entries are also gated by spectre.cache.enabled in
# config/layne.json. Clean entries require two matching live scans before use.
# SPECTRE_CACHE_MODE=off
# At least 32 random bytes. Generate with: openssl rand -hex 32
# SPECTRE_CACHE_HMAC_KEY=
# SPECTRE_CACHE_MAX_BYTES=134217728
# SPECTRE_CACHE_EPOCH=1
# SPECTRE_CACHE_REDIS_URL=redis://localhost:6379
# Required outside off; use the immutable deployed commit or image digest.
# LAYNE_BUILD_SHA=
# ── Notifications ─────────────────────────────────────────────────────────────
# Global Rocket.Chat incoming webhook URL.
# Reference this in config/layne.json as "$ROCKETCHAT_WEBHOOK_URL".
# ROCKETCHAT_WEBHOOK_URL=
# Add extra per-repo webhook variables here as needed, for example:
# PAYMENTS_ROCKETCHAT_WEBHOOK_URL=
# ── Production only (not needed for local development) ────────────────────────
# Your public domain name. Used for TLS termination and Rocket.Chat icon URLs.
# DOMAIN=layne.example.com
# Email address for Let's Encrypt expiry notifications.
# LETSENCRYPT_EMAIL=you@example.com
# ── Metrics (optional) ────────────────────────────────────────────────────────
# Set to true to enable Prometheus metrics endpoints.
# METRICS_ENABLED=false
# Port for the worker Prometheus metrics server.
# METRICS_PORT=9091