This page is machine-translated from French. Read the French original.
Environmental variables
A server instance is configured using environment variables. It is complementary interface: most settings are made in the application, and variables are used for automated deployment and parameters that must exist before the first start.
This page describes the categories and structuring variables. The complete list is available in the example file provided with the installation.
Mandatory
These three values must be long, random and specific to your installation. Never reuse the ones from the example file: they are public.
| Variable | Role |
|---|---|
JWT_SECRET |
User session signing |
SIG_KEY |
Internal signature key |
SIG_SALT |
Salt associated |
A change of JWT_SECRET invalidates all current sessions: users will have to log in again.
Storage
| Variable | Role |
|---|---|
STORAGE_DIR |
Directory containing database, documents, index and models |
This is the most important variable in operations. It must point towards a volume persistent. If the storage is not persistent, everything is lost when the container is restarted.
Network and service
| Variable | Role |
|---|---|
SERVER_PORT |
Application listening port |
COLLECTOR_PORT |
Port of the document extraction service |
ENABLE_HTTPS |
Enables TLS directly within the application |
HTTPS_CERT_PATH, HTTPS_KEY_PATH |
Location of the certificate and key |
If you are using a reverse proxy for TLS, leave application TLS disabled.
Authentication
| Variable | Role |
|---|---|
AUTH_TOKEN |
Unique password, in single-user mode |
JWT_EXPIRY |
Validity period of sessions |
In multi-user mode, accounts are managed within the application; ;
AUTH_TOKEN has no effect.
AI Providers
Each supplier has its own variables, following a consistent pattern:
- a API key or a service address ;
- a model preference ;
- sometimes a context limit when it cannot be discovered automatically.
Three general variables define active selection:
| Variable | Role |
|---|---|
LLM_PROVIDER |
Language model provider |
EMBEDDING_ENGINE |
Embeddings engine |
VECTOR_DB |
Vector base |
These settings can be modified in the interface, and the values saved in the application are the ones that prevail once onboarding is complete. The variables are therefore primarily used to preconfigure a deployment.
Segmentation and indexing
| Variable | Role |
|---|---|
EMBEDDING_MODEL_MAX_CHUNK_LENGTH |
Maximum size of a fragment sent to the embeddings engine |
MAX_EMBED_CHUNK_SIZE |
Fragment size ceiling |
These values can also be adjusted in the interface.
Agents Verification Status
| Variable | Role |
|---|---|
AGENT_MAX_TOOL_CALLS |
Maximum number of tool calls per task — safeguard against loops |
| Search engine keywords | Web search skill configuration |
AGENT_AUTO_APPROVED_SKILLS |
Skills that can be performed without confirmation |
Confidentiality and exploitation
| Variable | Role |
|---|---|
DISABLE_TELEMETRY |
Completely disable telemetry |
DISABLE_SWAGGER_DOCS |
Hides the interactive API documentation |
DISABLE_VIEW_CHAT_HISTORY |
Prevents users from viewing their history |
On a sovereignty-required installation, explicitly disable telemetry and document it.
Best practices
Treat the configuration file like a secret. It contains all your keys. Restrict its access rights, do not version it, and back it up separately and in encrypted form.
Generate real secrets. A long random string, produced by a generator, for each of the three required values.
Check storage persistence Before commissioning: restart the instance and confirm that the settings and documents are still there.
Document your choices. Which supplier, which embeddings engine, which database: this information will be necessary for your processing register and for any subsequent intervention.
