Underground-Digital/Workflow-Engine
0
1# ------------------------------2# Environment Variables for API service & worker3# ------------------------------4 5# ------------------------------6# Common Variables7# ------------------------------8 9# The backend URL of the console API,10# used to concatenate the authorization callback.11# If empty, it is the same domain.12# Example: https://api.console.dify.ai13CONSOLE_API_URL=14 15# The front-end URL of the console web,16# used to concatenate some front-end addresses and for CORS configuration use.17# If empty, it is the same domain.18# Example: https://console.dify.ai19CONSOLE_WEB_URL=20 21# Service API Url,22# used to display Service API Base Url to the front-end.23# If empty, it is the same domain.24# Example: https://api.dify.ai25SERVICE_API_URL=26 27# WebApp API backend Url,28# used to declare the back-end URL for the front-end API.29# If empty, it is the same domain.30# Example: https://api.app.dify.ai31APP_API_URL=32 33# WebApp Url,34# used to display WebAPP API Base Url to the front-end.35# If empty, it is the same domain.36# Example: https://app.dify.ai37APP_WEB_URL=38 39# File preview or download Url prefix.40# used to display File preview or download Url to the front-end or as Multi-model inputs;41# Url is signed and has expiration time.42FILES_URL=43 44# ------------------------------45# Server Configuration46# ------------------------------47 48# The log level for the application.49# Supported values are `DEBUG`, `INFO`, `WARNING`, `ERROR`, `CRITICAL`50LOG_LEVEL=INFO51# Log file path52LOG_FILE=53# Log file max size, the unit is MB54LOG_FILE_MAX_SIZE=2055# Log file max backup count56LOG_FILE_BACKUP_COUNT=557 58# Debug mode, default is false.59# It is recommended to turn on this configuration for local development60# to prevent some problems caused by monkey patch.61DEBUG=false62 63# Flask debug mode, it can output trace information at the interface when turned on,64# which is convenient for debugging.65FLASK_DEBUG=false66 67# A secretkey that is used for securely signing the session cookie68# and encrypting sensitive information on the database.69# You can generate a strong key using `openssl rand -base64 42`.70SECRET_KEY=sk-9f73s3ljTXVcMT3Blb3ljTqtsKiGHXVcMT3BlbkFJLK7U71 72# Password for admin user initialization.73# If left unset, admin user will not be prompted for a password74# when creating the initial admin account.75INIT_PASSWORD=76 77# Deployment environment.78# Supported values are `PRODUCTION`, `TESTING`. Default is `PRODUCTION`.79# Testing environment. There will be a distinct color label on the front-end page,80# indicating that this environment is a testing environment.81DEPLOY_ENV=PRODUCTION82 83# Whether to enable the version check policy.84# If set to empty, https://updates.dify.ai will be called for version check.85CHECK_UPDATE_URL=https://updates.dify.ai86 87# Used to change the OpenAI base address, default is https://api.openai.com/v1.88# When OpenAI cannot be accessed in China, replace it with a domestic mirror address,89# or when a local model provides OpenAI compatible API, it can be replaced.90OPENAI_API_BASE=https://api.openai.com/v191 92# When enabled, migrations will be executed prior to application startup93# and the application will start after the migrations have completed.94MIGRATION_ENABLED=true95 96# File Access Time specifies a time interval in seconds for the file to be accessed.97# The default value is 300 seconds.98FILES_ACCESS_TIMEOUT=30099 100# Access token expiration time in minutes101ACCESS_TOKEN_EXPIRE_MINUTES=60102 103# The maximum number of active requests for the application, where 0 means unlimited, should be a non-negative integer.104APP_MAX_ACTIVE_REQUESTS=0105 106# ------------------------------107# Container Startup Related Configuration108# Only effective when starting with docker image or docker-compose.109# ------------------------------110 111# API service binding address, default: 0.0.0.0, i.e., all addresses can be accessed.112DIFY_BIND_ADDRESS=0.0.0.0113 114# API service binding port number, default 5001.115DIFY_PORT=5001116 117# The number of API server workers, i.e., the number of gevent workers.118# Formula: number of cpu cores x 2 + 1119# Reference: https://docs.gunicorn.org/en/stable/design.html#how-many-workers120SERVER_WORKER_AMOUNT=121 122# Defaults to gevent. If using windows, it can be switched to sync or solo.123SERVER_WORKER_CLASS=124 125# Similar to SERVER_WORKER_CLASS. Default is gevent.126# If using windows, it can be switched to sync or solo.127CELERY_WORKER_CLASS=128 129# Request handling timeout. The default is 200,130# it is recommended to set it to 360 to support a longer sse connection time.131GUNICORN_TIMEOUT=360132 133# The number of Celery workers. The default is 1, and can be set as needed.134CELERY_WORKER_AMOUNT=135 136# Flag indicating whether to enable autoscaling of Celery workers.137#138# Autoscaling is useful when tasks are CPU intensive and can be dynamically139# allocated and deallocated based on the workload.140#141# When autoscaling is enabled, the maximum and minimum number of workers can142# be specified. The autoscaling algorithm will dynamically adjust the number143# of workers within the specified range.144#145# Default is false (i.e., autoscaling is disabled).146#147# Example:148# CELERY_AUTO_SCALE=true149CELERY_AUTO_SCALE=false150 151# The maximum number of Celery workers that can be autoscaled.152# This is optional and only used when autoscaling is enabled.153# Default is not set.154CELERY_MAX_WORKERS=155 156# The minimum number of Celery workers that can be autoscaled.157# This is optional and only used when autoscaling is enabled.158# Default is not set.159CELERY_MIN_WORKERS=160 161# API Tool configuration162API_TOOL_DEFAULT_CONNECT_TIMEOUT=10163API_TOOL_DEFAULT_READ_TIMEOUT=60164 165 166# ------------------------------167# Database Configuration168# The database uses PostgreSQL. Please use the public schema.169# It is consistent with the configuration in the 'db' service below.170# ------------------------------171 172DB_USERNAME=postgres173DB_PASSWORD=difyai123456174DB_HOST=db175DB_PORT=5432176DB_DATABASE=dify177# The size of the database connection pool.178# The default is 30 connections, which can be appropriately increased.179SQLALCHEMY_POOL_SIZE=30180# Database connection pool recycling time, the default is 3600 seconds.181SQLALCHEMY_POOL_RECYCLE=3600182# Whether to print SQL, default is false.183SQLALCHEMY_ECHO=false184 185# Maximum number of connections to the database186# Default is 100187#188# Reference: https://www.postgresql.org/docs/current/runtime-config-connection.html#GUC-MAX-CONNECTIONS189POSTGRES_MAX_CONNECTIONS=100190 191# Sets the amount of shared memory used for postgres's shared buffers.192# Default is 128MB193# Recommended value: 25% of available memory194# Reference: https://www.postgresql.org/docs/current/runtime-config-resource.html#GUC-SHARED-BUFFERS195POSTGRES_SHARED_BUFFERS=128MB196 197# Sets the amount of memory used by each database worker for working space.198# Default is 4MB199#200# Reference: https://www.postgresql.org/docs/current/runtime-config-resource.html#GUC-WORK-MEM201POSTGRES_WORK_MEM=4MB202 203# Sets the amount of memory reserved for maintenance activities.204# Default is 64MB205#206# Reference: https://www.postgresql.org/docs/current/runtime-config-resource.html#GUC-MAINTENANCE-WORK-MEM207POSTGRES_MAINTENANCE_WORK_MEM=64MB208 209# Sets the planner's assumption about the effective cache size.210# Default is 4096MB211#212# Reference: https://www.postgresql.org/docs/current/runtime-config-query.html#GUC-EFFECTIVE-CACHE-SIZE213POSTGRES_EFFECTIVE_CACHE_SIZE=4096MB214 215# ------------------------------216# Redis Configuration217# This Redis configuration is used for caching and for pub/sub during conversation.218# ------------------------------219 220REDIS_HOST=redis221REDIS_PORT=6379222REDIS_USERNAME=223REDIS_PASSWORD=difyai123456224REDIS_USE_SSL=false225 226# Whether to use Redis Sentinel mode.227# If set to true, the application will automatically discover and connect to the master node through Sentinel.228REDIS_USE_SENTINEL=false229 230# List of Redis Sentinel nodes. If Sentinel mode is enabled, provide at least one Sentinel IP and port.231# Format: `<sentinel1_ip>:<sentinel1_port>,<sentinel2_ip>:<sentinel2_port>,<sentinel3_ip>:<sentinel3_port>`232REDIS_SENTINELS=233REDIS_SENTINEL_SERVICE_NAME=234REDIS_SENTINEL_USERNAME=235REDIS_SENTINEL_PASSWORD=236REDIS_SENTINEL_SOCKET_TIMEOUT=0.1237 238# ------------------------------239# Celery Configuration240# ------------------------------241 242# Use redis as the broker, and redis db 1 for celery broker.243# Format as follows: `redis://<redis_username>:<redis_password>@<redis_host>:<redis_port>/<redis_database>`244# Example: redis://:difyai123456@redis:6379/1245# If use Redis Sentinel, format as follows: `sentinel://<sentinel_username>:<sentinel_password>@<sentinel_host>:<sentinel_port>/<redis_database>`246# Example: sentinel://localhost:26379/1;sentinel://localhost:26380/1;sentinel://localhost:26381/1247CELERY_BROKER_URL=redis://:difyai123456@redis:6379/1248BROKER_USE_SSL=false249 250# If you are using Redis Sentinel for high availability, configure the following settings.251CELERY_USE_SENTINEL=false252CELERY_SENTINEL_MASTER_NAME=253CELERY_SENTINEL_SOCKET_TIMEOUT=0.1254 255# ------------------------------256# CORS Configuration257# Used to set the front-end cross-domain access policy.258# ------------------------------259 260# Specifies the allowed origins for cross-origin requests to the Web API,261# e.g. https://dify.app or * for all origins.262WEB_API_CORS_ALLOW_ORIGINS=*263 264# Specifies the allowed origins for cross-origin requests to the console API,265# e.g. https://cloud.dify.ai or * for all origins.266CONSOLE_CORS_ALLOW_ORIGINS=*267 268# ------------------------------269# File Storage Configuration270# ------------------------------271 272# The type of storage to use for storing user files.273# Supported values are `local` , `s3` , `azure-blob` , `google-storage`, `tencent-cos`, `huawei-obs`, `volcengine-tos`, `baidu-obs`, `supabase`274# Default: `local`275STORAGE_TYPE=local276STORAGE_LOCAL_PATH=storage277 278# S3 Configuration279# Whether to use AWS managed IAM roles for authenticating with the S3 service.280# If set to false, the access key and secret key must be provided.281S3_USE_AWS_MANAGED_IAM=false282# The endpoint of the S3 service.283S3_ENDPOINT=284# The region of the S3 service.285S3_REGION=us-east-1286# The name of the S3 bucket to use for storing files.287S3_BUCKET_NAME=difyai288# The access key to use for authenticating with the S3 service.289S3_ACCESS_KEY=290# The secret key to use for authenticating with the S3 service.291S3_SECRET_KEY=292 293# Azure Blob Configuration294# The name of the Azure Blob Storage account to use for storing files.295AZURE_BLOB_ACCOUNT_NAME=difyai296# The access key to use for authenticating with the Azure Blob Storage account.297AZURE_BLOB_ACCOUNT_KEY=difyai298# The name of the Azure Blob Storage container to use for storing files.299AZURE_BLOB_CONTAINER_NAME=difyai-container300# The URL of the Azure Blob Storage account.301AZURE_BLOB_ACCOUNT_URL=https://<your_account_name>.blob.core.windows.net302 303# Google Storage Configuration304# The name of the Google Storage bucket to use for storing files.305GOOGLE_STORAGE_BUCKET_NAME=your-bucket-name306# The service account JSON key to use for authenticating with the Google Storage service.307GOOGLE_STORAGE_SERVICE_ACCOUNT_JSON_BASE64=your-google-service-account-json-base64-string308 309# The Alibaba Cloud OSS configurations,310# only available when STORAGE_TYPE is `aliyun-oss`311ALIYUN_OSS_BUCKET_NAME=your-bucket-name312ALIYUN_OSS_ACCESS_KEY=your-access-key313ALIYUN_OSS_SECRET_KEY=your-secret-key314ALIYUN_OSS_ENDPOINT=https://oss-ap-southeast-1-internal.aliyuncs.com315ALIYUN_OSS_REGION=ap-southeast-1316ALIYUN_OSS_AUTH_VERSION=v4317# Don't start with '/'. OSS doesn't support leading slash in object names.318ALIYUN_OSS_PATH=your-path319 320# Tencent COS Configuration321# The name of the Tencent COS bucket to use for storing files.322TENCENT_COS_BUCKET_NAME=your-bucket-name323# The secret key to use for authenticating with the Tencent COS service.324TENCENT_COS_SECRET_KEY=your-secret-key325# The secret id to use for authenticating with the Tencent COS service.326TENCENT_COS_SECRET_ID=your-secret-id327# The region of the Tencent COS service.328TENCENT_COS_REGION=your-region329# The scheme of the Tencent COS service.330TENCENT_COS_SCHEME=your-scheme331 332# Huawei OBS Configuration333# The name of the Huawei OBS bucket to use for storing files.334HUAWEI_OBS_BUCKET_NAME=your-bucket-name335# The secret key to use for authenticating with the Huawei OBS service.336HUAWEI_OBS_SECRET_KEY=your-secret-key337# The access key to use for authenticating with the Huawei OBS service.338HUAWEI_OBS_ACCESS_KEY=your-access-key339# The server url of the HUAWEI OBS service.340HUAWEI_OBS_SERVER=your-server-url341 342# Volcengine TOS Configuration343# The name of the Volcengine TOS bucket to use for storing files.344VOLCENGINE_TOS_BUCKET_NAME=your-bucket-name345# The secret key to use for authenticating with the Volcengine TOS service.346VOLCENGINE_TOS_SECRET_KEY=your-secret-key347# The access key to use for authenticating with the Volcengine TOS service.348VOLCENGINE_TOS_ACCESS_KEY=your-access-key349# The endpoint of the Volcengine TOS service.350VOLCENGINE_TOS_ENDPOINT=your-server-url351# The region of the Volcengine TOS service.352VOLCENGINE_TOS_REGION=your-region353 354# Baidu OBS Storage Configuration355# The name of the Baidu OBS bucket to use for storing files.356BAIDU_OBS_BUCKET_NAME=your-bucket-name357# The secret key to use for authenticating with the Baidu OBS service.358BAIDU_OBS_SECRET_KEY=your-secret-key359# The access key to use for authenticating with the Baidu OBS service.360BAIDU_OBS_ACCESS_KEY=your-access-key361# The endpoint of the Baidu OBS service.362BAIDU_OBS_ENDPOINT=your-server-url363 364# Supabase Storage Configuration365# The name of the Supabase bucket to use for storing files.366SUPABASE_BUCKET_NAME=your-bucket-name367# The api key to use for authenticating with the Supabase service.368SUPABASE_API_KEY=your-access-key369# The project endpoint url of the Supabase service.370SUPABASE_URL=your-server-url371 372# ------------------------------373# Vector Database Configuration374# ------------------------------375 376# The type of vector store to use.377# Supported values are `weaviate`, `qdrant`, `milvus`, `myscale`, `relyt`, `pgvector`, `pgvecto-rs`, `chroma`, `opensearch`, `tidb_vector`, `oracle`, `tencent`, `elasticsearch`, `analyticdb`, `couchbase`, `vikingdb`.378VECTOR_STORE=weaviate379 380# The Weaviate endpoint URL. Only available when VECTOR_STORE is `weaviate`.381WEAVIATE_ENDPOINT=http://weaviate:8080382# The Weaviate API key.383WEAVIATE_API_KEY=WVF5YThaHlkYwhGUSmCRgsX3tD5ngdN8pkih384 385# The Qdrant endpoint URL. Only available when VECTOR_STORE is `qdrant`.386QDRANT_URL=http://qdrant:6333387# The Qdrant API key.388QDRANT_API_KEY=difyai123456389# The Qdrant client timeout setting.390QDRANT_CLIENT_TIMEOUT=20391# The Qdrant client enable gRPC mode.392QDRANT_GRPC_ENABLED=false393# The Qdrant server gRPC mode PORT.394QDRANT_GRPC_PORT=6334395 396# Milvus configuration Only available when VECTOR_STORE is `milvus`.397# The milvus uri.398MILVUS_URI=http://127.0.0.1:19530399# The milvus token.400MILVUS_TOKEN=401# The milvus username.402MILVUS_USER=root403# The milvus password.404MILVUS_PASSWORD=Milvus405 406# MyScale configuration, only available when VECTOR_STORE is `myscale`407# For multi-language support, please set MYSCALE_FTS_PARAMS with referring to:408# https://myscale.com/docs/en/text-search/#understanding-fts-index-parameters409MYSCALE_HOST=myscale410MYSCALE_PORT=8123411MYSCALE_USER=default412MYSCALE_PASSWORD=413MYSCALE_DATABASE=dify414MYSCALE_FTS_PARAMS=415 416# Couchbase configurations, only available when VECTOR_STORE is `couchbase`417# The connection string must include hostname defined in the docker-compose file (couchbase-server in this case)418COUCHBASE_CONNECTION_STRING=couchbase://couchbase-server419COUCHBASE_USER=Administrator420COUCHBASE_PASSWORD=password421COUCHBASE_BUCKET_NAME=Embeddings422COUCHBASE_SCOPE_NAME=_default423 424# pgvector configurations, only available when VECTOR_STORE is `pgvector`425PGVECTOR_HOST=pgvector426PGVECTOR_PORT=5432427PGVECTOR_USER=postgres428PGVECTOR_PASSWORD=difyai123456429PGVECTOR_DATABASE=dify430PGVECTOR_MIN_CONNECTION=1431PGVECTOR_MAX_CONNECTION=5432 433# pgvecto-rs configurations, only available when VECTOR_STORE is `pgvecto-rs`434PGVECTO_RS_HOST=pgvecto-rs435PGVECTO_RS_PORT=5432436PGVECTO_RS_USER=postgres437PGVECTO_RS_PASSWORD=difyai123456438PGVECTO_RS_DATABASE=dify439 440# analyticdb configurations, only available when VECTOR_STORE is `analyticdb`441ANALYTICDB_KEY_ID=your-ak442ANALYTICDB_KEY_SECRET=your-sk443ANALYTICDB_REGION_ID=cn-hangzhou444ANALYTICDB_INSTANCE_ID=gp-ab123456445ANALYTICDB_ACCOUNT=testaccount446ANALYTICDB_PASSWORD=testpassword447ANALYTICDB_NAMESPACE=dify448ANALYTICDB_NAMESPACE_PASSWORD=difypassword449 450# TiDB vector configurations, only available when VECTOR_STORE is `tidb`451TIDB_VECTOR_HOST=tidb452TIDB_VECTOR_PORT=4000453TIDB_VECTOR_USER=xxx.root454TIDB_VECTOR_PASSWORD=xxxxxx455TIDB_VECTOR_DATABASE=dify456 457# Tidb on qdrant configuration, only available when VECTOR_STORE is `tidb_on_qdrant`458TIDB_ON_QDRANT_URL=http://127.0.0.1459TIDB_ON_QDRANT_API_KEY=dify460TIDB_ON_QDRANT_CLIENT_TIMEOUT=20461TIDB_ON_QDRANT_GRPC_ENABLED=false462TIDB_ON_QDRANT_GRPC_PORT=6334463TIDB_PUBLIC_KEY=dify464TIDB_PRIVATE_KEY=dify465TIDB_API_URL=http://127.0.0.1466TIDB_IAM_API_URL=http://127.0.0.1467TIDB_REGION=regions/aws-us-east-1468TIDB_PROJECT_ID=dify469TIDB_SPEND_LIMIT=100470 471# Chroma configuration, only available when VECTOR_STORE is `chroma`472CHROMA_HOST=127.0.0.1473CHROMA_PORT=8000474CHROMA_TENANT=default_tenant475CHROMA_DATABASE=default_database476CHROMA_AUTH_PROVIDER=chromadb.auth.token_authn.TokenAuthClientProvider477CHROMA_AUTH_CREDENTIALS=xxxxxx478 479# Oracle configuration, only available when VECTOR_STORE is `oracle`480ORACLE_HOST=oracle481ORACLE_PORT=1521482ORACLE_USER=dify483ORACLE_PASSWORD=dify484ORACLE_DATABASE=FREEPDB1485 486# relyt configurations, only available when VECTOR_STORE is `relyt`487RELYT_HOST=db488RELYT_PORT=5432489RELYT_USER=postgres490RELYT_PASSWORD=difyai123456491RELYT_DATABASE=postgres492 493# open search configuration, only available when VECTOR_STORE is `opensearch`494OPENSEARCH_HOST=opensearch495OPENSEARCH_PORT=9200496OPENSEARCH_USER=admin497OPENSEARCH_PASSWORD=admin498OPENSEARCH_SECURE=true499 500# tencent vector configurations, only available when VECTOR_STORE is `tencent`501TENCENT_VECTOR_DB_URL=http://127.0.0.1502TENCENT_VECTOR_DB_API_KEY=dify503TENCENT_VECTOR_DB_TIMEOUT=30504TENCENT_VECTOR_DB_USERNAME=dify505TENCENT_VECTOR_DB_DATABASE=dify506TENCENT_VECTOR_DB_SHARD=1507TENCENT_VECTOR_DB_REPLICAS=2508 509# ElasticSearch configuration, only available when VECTOR_STORE is `elasticsearch`510ELASTICSEARCH_HOST=0.0.0.0511ELASTICSEARCH_PORT=9200512ELASTICSEARCH_USERNAME=elastic513ELASTICSEARCH_PASSWORD=elastic514 515# baidu vector configurations, only available when VECTOR_STORE is `baidu`516BAIDU_VECTOR_DB_ENDPOINT=http://127.0.0.1:5287517BAIDU_VECTOR_DB_CONNECTION_TIMEOUT_MS=30000518BAIDU_VECTOR_DB_ACCOUNT=root519BAIDU_VECTOR_DB_API_KEY=dify520BAIDU_VECTOR_DB_DATABASE=dify521BAIDU_VECTOR_DB_SHARD=1522BAIDU_VECTOR_DB_REPLICAS=3523 524# VikingDB configurations, only available when VECTOR_STORE is `vikingdb`525VIKINGDB_ACCESS_KEY=your-ak526VIKINGDB_SECRET_KEY=your-sk527VIKINGDB_REGION=cn-shanghai528VIKINGDB_HOST=api-vikingdb.xxx.volces.com529VIKINGDB_SCHEMA=http530VIKINGDB_CONNECTION_TIMEOUT=30531VIKINGDB_SOCKET_TIMEOUT=30532 533 534# Lindorm configuration, only available when VECTOR_STORE is `lindorm`535LINDORM_URL=http://ld-***************-proxy-search-pub.lindorm.aliyuncs.com:30070536LINDORM_USERNAME=username537LINDORM_PASSWORD=password538 539# OceanBase Vector configuration, only available when VECTOR_STORE is `oceanbase`540OCEANBASE_VECTOR_HOST=oceanbase-vector541OCEANBASE_VECTOR_PORT=2881542OCEANBASE_VECTOR_USER=root@test543OCEANBASE_VECTOR_PASSWORD=544OCEANBASE_VECTOR_DATABASE=test545OCEANBASE_MEMORY_LIMIT=6G546 547# ------------------------------548# Knowledge Configuration549# ------------------------------550 551# Upload file size limit, default 15M.552UPLOAD_FILE_SIZE_LIMIT=15553 554# The maximum number of files that can be uploaded at a time, default 5.555UPLOAD_FILE_BATCH_LIMIT=5556 557# ETl type, support: `dify`, `Unstructured`558# `dify` Dify's proprietary file extraction scheme559# `Unstructured` Unstructured.io file extraction scheme560ETL_TYPE=dify561 562# Unstructured API path, needs to be configured when ETL_TYPE is Unstructured.563# For example: http://unstructured:8000/general/v0/general564UNSTRUCTURED_API_URL=565 566# ------------------------------567# Model Configuration568# ------------------------------569 570# The maximum number of tokens allowed for prompt generation.571# This setting controls the upper limit of tokens that can be used by the LLM 572# when generating a prompt in the prompt generation tool.573# Default: 512 tokens.574PROMPT_GENERATION_MAX_TOKENS=512575 576# The maximum number of tokens allowed for code generation.577# This setting controls the upper limit of tokens that can be used by the LLM 578# when generating code in the code generation tool.579# Default: 1024 tokens.580CODE_GENERATION_MAX_TOKENS=1024581 582# ------------------------------583# Multi-modal Configuration584# ------------------------------585 586# The format of the image sent when the multi-modal model is input,587# the default is base64, optional url.588# The delay of the call in url mode will be lower than that in base64 mode.589# It is generally recommended to use the more compatible base64 mode.590# If configured as url, you need to configure FILES_URL as an externally accessible address so that the multi-modal model can access the image.591MULTIMODAL_SEND_IMAGE_FORMAT=base64592 593# Upload image file size limit, default 10M.594UPLOAD_IMAGE_FILE_SIZE_LIMIT=10595 596# Upload video file size limit, default 100M.597UPLOAD_VIDEO_FILE_SIZE_LIMIT=100598 599# Upload audio file size limit, default 50M.600UPLOAD_AUDIO_FILE_SIZE_LIMIT=50601 602# ------------------------------603# Sentry Configuration604# Used for application monitoring and error log tracking.605# ------------------------------606 607# API Service Sentry DSN address, default is empty, when empty,608# all monitoring information is not reported to Sentry.609# If not set, Sentry error reporting will be disabled.610API_SENTRY_DSN=611 612# API Service The reporting ratio of Sentry events, if it is 0.01, it is 1%.613API_SENTRY_TRACES_SAMPLE_RATE=1.0614 615# API Service The reporting ratio of Sentry profiles, if it is 0.01, it is 1%.616API_SENTRY_PROFILES_SAMPLE_RATE=1.0617 618# Web Service Sentry DSN address, default is empty, when empty,619# all monitoring information is not reported to Sentry.620# If not set, Sentry error reporting will be disabled.621WEB_SENTRY_DSN=622 623# ------------------------------624# Notion Integration Configuration625# Variables can be obtained by applying for Notion integration: https://www.notion.so/my-integrations626# ------------------------------627 628# Configure as "public" or "internal".629# Since Notion's OAuth redirect URL only supports HTTPS,630# if deploying locally, please use Notion's internal integration.631NOTION_INTEGRATION_TYPE=public632# Notion OAuth client secret (used for public integration type)633NOTION_CLIENT_SECRET=634# Notion OAuth client id (used for public integration type)635NOTION_CLIENT_ID=636# Notion internal integration secret.637# If the value of NOTION_INTEGRATION_TYPE is "internal",638# you need to configure this variable.639NOTION_INTERNAL_SECRET=640 641# ------------------------------642# Mail related configuration643# ------------------------------644 645# Mail type, support: resend, smtp646MAIL_TYPE=resend647 648# Default send from email address, if not specified649MAIL_DEFAULT_SEND_FROM=650 651# API-Key for the Resend email provider, used when MAIL_TYPE is `resend`.652RESEND_API_KEY=your-resend-api-key653 654# SMTP server configuration, used when MAIL_TYPE is `smtp`655SMTP_SERVER=656SMTP_PORT=465657SMTP_USERNAME=658SMTP_PASSWORD=659SMTP_USE_TLS=true660SMTP_OPPORTUNISTIC_TLS=false661 662# ------------------------------663# Others Configuration664# ------------------------------665 666# Maximum length of segmentation tokens for indexing667INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH=1000668 669# Member invitation link valid time (hours),670# Default: 72.671INVITE_EXPIRY_HOURS=72672 673# Reset password token valid time (minutes),674RESET_PASSWORD_TOKEN_EXPIRY_MINUTES=5675 676# The sandbox service endpoint.677CODE_EXECUTION_ENDPOINT=http://sandbox:8194678CODE_MAX_NUMBER=9223372036854775807679CODE_MIN_NUMBER=-9223372036854775808680CODE_MAX_DEPTH=5681CODE_MAX_PRECISION=20682CODE_MAX_STRING_LENGTH=80000683TEMPLATE_TRANSFORM_MAX_LENGTH=80000684CODE_MAX_STRING_ARRAY_LENGTH=30685CODE_MAX_OBJECT_ARRAY_LENGTH=30686CODE_MAX_NUMBER_ARRAY_LENGTH=1000687 688# Workflow runtime configuration689WORKFLOW_MAX_EXECUTION_STEPS=500690WORKFLOW_MAX_EXECUTION_TIME=1200691WORKFLOW_CALL_MAX_DEPTH=5692MAX_VARIABLE_SIZE=204800693WORKFLOW_FILE_UPLOAD_LIMIT=10694 695# HTTP request node in workflow configuration696HTTP_REQUEST_NODE_MAX_BINARY_SIZE=10485760697HTTP_REQUEST_NODE_MAX_TEXT_SIZE=1048576698 699# SSRF Proxy server HTTP URL700SSRF_PROXY_HTTP_URL=http://ssrf_proxy:3128701# SSRF Proxy server HTTPS URL702SSRF_PROXY_HTTPS_URL=http://ssrf_proxy:3128703 704# ------------------------------705# Environment Variables for web Service706# ------------------------------707 708# The timeout for the text generation in millisecond709TEXT_GENERATION_TIMEOUT_MS=60000710 711# ------------------------------712# Environment Variables for db Service713# ------------------------------714 715PGUSER=${DB_USERNAME}716# The password for the default postgres user.717POSTGRES_PASSWORD=${DB_PASSWORD}718# The name of the default postgres database.719POSTGRES_DB=${DB_DATABASE}720# postgres data directory721PGDATA=/var/lib/postgresql/data/pgdata722 723# ------------------------------724# Environment Variables for sandbox Service725# ------------------------------726 727# The API key for the sandbox service728SANDBOX_API_KEY=dify-sandbox729# The mode in which the Gin framework runs730SANDBOX_GIN_MODE=release731# The timeout for the worker in seconds732SANDBOX_WORKER_TIMEOUT=15733# Enable network for the sandbox service734SANDBOX_ENABLE_NETWORK=true735# HTTP proxy URL for SSRF protection736SANDBOX_HTTP_PROXY=http://ssrf_proxy:3128737# HTTPS proxy URL for SSRF protection738SANDBOX_HTTPS_PROXY=http://ssrf_proxy:3128739# The port on which the sandbox service runs740SANDBOX_PORT=8194741 742# ------------------------------743# Environment Variables for weaviate Service744# (only used when VECTOR_STORE is weaviate)745# ------------------------------746WEAVIATE_PERSISTENCE_DATA_PATH=/var/lib/weaviate747WEAVIATE_QUERY_DEFAULTS_LIMIT=25748WEAVIATE_AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED=true749WEAVIATE_DEFAULT_VECTORIZER_MODULE=none750WEAVIATE_CLUSTER_HOSTNAME=node1751WEAVIATE_AUTHENTICATION_APIKEY_ENABLED=true752WEAVIATE_AUTHENTICATION_APIKEY_ALLOWED_KEYS=WVF5YThaHlkYwhGUSmCRgsX3tD5ngdN8pkih753WEAVIATE_AUTHENTICATION_APIKEY_USERS=hello@dify.ai754WEAVIATE_AUTHORIZATION_ADMINLIST_ENABLED=true755WEAVIATE_AUTHORIZATION_ADMINLIST_USERS=hello@dify.ai756 757# ------------------------------758# Environment Variables for Chroma759# (only used when VECTOR_STORE is chroma)760# ------------------------------761 762# Authentication credentials for Chroma server763CHROMA_SERVER_AUTHN_CREDENTIALS=difyai123456764# Authentication provider for Chroma server765CHROMA_SERVER_AUTHN_PROVIDER=chromadb.auth.token_authn.TokenAuthenticationServerProvider766# Persistence setting for Chroma server767CHROMA_IS_PERSISTENT=TRUE768 769# ------------------------------770# Environment Variables for Oracle Service771# (only used when VECTOR_STORE is Oracle)772# ------------------------------773ORACLE_PWD=Dify123456774ORACLE_CHARACTERSET=AL32UTF8775 776# ------------------------------777# Environment Variables for milvus Service778# (only used when VECTOR_STORE is milvus)779# ------------------------------780# ETCD configuration for auto compaction mode781ETCD_AUTO_COMPACTION_MODE=revision782# ETCD configuration for auto compaction retention in terms of number of revisions783ETCD_AUTO_COMPACTION_RETENTION=1000784# ETCD configuration for backend quota in bytes785ETCD_QUOTA_BACKEND_BYTES=4294967296786# ETCD configuration for the number of changes before triggering a snapshot787ETCD_SNAPSHOT_COUNT=50000788# MinIO access key for authentication789MINIO_ACCESS_KEY=minioadmin790# MinIO secret key for authentication791MINIO_SECRET_KEY=minioadmin792# ETCD service endpoints793ETCD_ENDPOINTS=etcd:2379794# MinIO service address795MINIO_ADDRESS=minio:9000796# Enable or disable security authorization797MILVUS_AUTHORIZATION_ENABLED=true798 799# ------------------------------800# Environment Variables for pgvector / pgvector-rs Service801# (only used when VECTOR_STORE is pgvector / pgvector-rs)802# ------------------------------803PGVECTOR_PGUSER=postgres804# The password for the default postgres user.805PGVECTOR_POSTGRES_PASSWORD=difyai123456806# The name of the default postgres database.807PGVECTOR_POSTGRES_DB=dify808# postgres data directory809PGVECTOR_PGDATA=/var/lib/postgresql/data/pgdata810 811# ------------------------------812# Environment Variables for opensearch813# (only used when VECTOR_STORE is opensearch)814# ------------------------------815OPENSEARCH_DISCOVERY_TYPE=single-node816OPENSEARCH_BOOTSTRAP_MEMORY_LOCK=true817OPENSEARCH_JAVA_OPTS_MIN=512m818OPENSEARCH_JAVA_OPTS_MAX=1024m819OPENSEARCH_INITIAL_ADMIN_PASSWORD=Qazwsxedc!@#123820OPENSEARCH_MEMLOCK_SOFT=-1821OPENSEARCH_MEMLOCK_HARD=-1822OPENSEARCH_NOFILE_SOFT=65536823OPENSEARCH_NOFILE_HARD=65536824 825# ------------------------------826# Environment Variables for Nginx reverse proxy827# ------------------------------828NGINX_SERVER_NAME=_829NGINX_HTTPS_ENABLED=false830# HTTP port831NGINX_PORT=80832# SSL settings are only applied when HTTPS_ENABLED is true833NGINX_SSL_PORT=443834# if HTTPS_ENABLED is true, you're required to add your own SSL certificates/keys to the `./nginx/ssl` directory835# and modify the env vars below accordingly.836NGINX_SSL_CERT_FILENAME=dify.crt837NGINX_SSL_CERT_KEY_FILENAME=dify.key838NGINX_SSL_PROTOCOLS=TLSv1.1 TLSv1.2 TLSv1.3839 840# Nginx performance tuning841NGINX_WORKER_PROCESSES=auto842NGINX_CLIENT_MAX_BODY_SIZE=15M843NGINX_KEEPALIVE_TIMEOUT=65844 845# Proxy settings846NGINX_PROXY_READ_TIMEOUT=3600s847NGINX_PROXY_SEND_TIMEOUT=3600s848 849# Set true to accept requests for /.well-known/acme-challenge/850NGINX_ENABLE_CERTBOT_CHALLENGE=false851 852# ------------------------------853# Certbot Configuration854# ------------------------------855 856# Email address (required to get certificates from Let's Encrypt)857CERTBOT_EMAIL=your_email@example.com858 859# Domain name860CERTBOT_DOMAIN=your_domain.com861 862# certbot command options863# i.e: --force-renewal --dry-run --test-cert --debug864CERTBOT_OPTIONS=865 866# ------------------------------867# Environment Variables for SSRF Proxy868# ------------------------------869SSRF_HTTP_PORT=3128870SSRF_COREDUMP_DIR=/var/spool/squid871SSRF_REVERSE_PROXY_PORT=8194872SSRF_SANDBOX_HOST=sandbox873 874# ------------------------------875# docker env var for specifying vector db type at startup876# (based on the vector db type, the corresponding docker877# compose profile will be used)878# if you want to use unstructured, add ',unstructured' to the end879# ------------------------------880COMPOSE_PROFILES=${VECTOR_STORE:-weaviate}881 882# ------------------------------883# Docker Compose Service Expose Host Port Configurations884# ------------------------------885EXPOSE_NGINX_PORT=80886EXPOSE_NGINX_SSL_PORT=443887 888# ----------------------------------------------------------------------------889# ModelProvider & Tool Position Configuration890# Used to specify the model providers and tools that can be used in the app.891# ----------------------------------------------------------------------------892 893# Pin, include, and exclude tools894# Use comma-separated values with no spaces between items.895# Example: POSITION_TOOL_PINS=bing,google896POSITION_TOOL_PINS=897POSITION_TOOL_INCLUDES=898POSITION_TOOL_EXCLUDES=899 900# Pin, include, and exclude model providers901# Use comma-separated values with no spaces between items.902# Example: POSITION_PROVIDER_PINS=openai,openllm903POSITION_PROVIDER_PINS=904POSITION_PROVIDER_INCLUDES=905POSITION_PROVIDER_EXCLUDES=906 907# CSP https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP908CSP_WHITELIST=909 