MicroFish/.env.example

48 lines
2.4 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# LLM API配置(支持 OpenAI SDK 格式的任意 LLM API)
# 推荐使用阿里百炼平台qwen-plus模型:https://bailian.console.aliyun.com/
# 注意消耗较大,可先进行小于40轮的模拟尝试
LLM_API_KEY=your_api_key_here
LLM_BASE_URL=https://dashscope.aliyuncs.com/compatible-mode/v1
LLM_MODEL_NAME=qwen-plus
# ===== ZEP记忆图谱配置 =====
# 每月免费额度即可支撑简单使用:https://app.getzep.com/
ZEP_API_KEY=your_zep_api_key_here
# ===== 加速 LLM 配置(可选)=====
# 注意如果不使用加速配置,env文件中就不要出现下面的配置项
LLM_BOOST_API_KEY=your_api_key_here
LLM_BOOST_BASE_URL=your_base_url_here
LLM_BOOST_MODEL_NAME=your_model_name_here
# ===== 安全配置(C1)=====
# 生产模式下必须设置自定义 SECRET_KEY(否则启动校验失败)。生成示例:python -c "import secrets;print(secrets.token_hex(32))"
SECRET_KEY=change_me_to_a_random_secret
# 调试模式默认关闭;设为 true 会启用 Werkzeug 交互式调试器(可远程 RCE),切勿在联网/生产开启
FLASK_DEBUG=false
# ===== API 鉴权(C2)=====
# 所有 /api/* 端点需携带 `X-API-Key: <API_KEY>`(或 `Authorization: Bearer <API_KEY>`)
# AUTH_ENABLED=true(默认)时必须设置 API_KEY;本地开发可设 AUTH_ENABLED=false 关闭鉴权
AUTH_ENABLED=true
API_KEY=change_me_to_a_strong_api_key
# 前端构建期变量:必须等于 API_KEY。docker compose 会把它作为 build-arg 注入前端构建,
# 使打包后的 UI 自动带上 X-API-Key。注意:它会被打进客户端包、可被任何访问者提取(见 README 安全说明)。
VITE_API_KEY=change_me_to_a_strong_api_key
# ===== CORS 允许来源(H4)=====
# 逗号分隔的前端来源;不再用通配 '*'。生产填前端域名,例如 https://app.example.com
ALLOWED_ORIGINS=http://localhost:3000,http://127.0.0.1:3000
# ===== 模拟成本上限(C3,denial-of-wallet 防护)=====
# 客户端未传 max_rounds 时的默认轮数上限(完整长度模拟请按请求传 max_rounds 或调高此值)
# 默认 150 覆盖典型配置(72h/30min=144 轮)以免悄悄截断标准演示
OASIS_DEFAULT_MAX_ROUNDS=150
# 硬上限:无论客户端传入何值都不得超过
OASIS_MAX_ROUNDS_CAP=200
OASIS_MAX_AGENTS_CAP=1000
# ===== 模拟超时(C4,秒)=====
# 单轮 env.step 超时 + 整轮模拟总超时,防止 LLM/网络挂起导致 run 永久 wedge
OASIS_ROUND_TIMEOUT_SEC=600
OASIS_RUN_TIMEOUT_SEC=7200