109 lines
4.0 KiB
Plaintext
109 lines
4.0 KiB
Plaintext
# Public routing. Terminate TLS in front of HTTP_PORT and preserve the Host header.
|
|
APP_HOST=studio.example.com
|
|
MEDIA_HOST=media.example.com
|
|
WEB_ORIGIN=https://studio.example.com
|
|
API_PUBLIC_ORIGIN=https://studio.example.com
|
|
S3_PUBLIC_ENDPOINT=https://media.example.com
|
|
HTTP_BIND=0.0.0.0
|
|
HTTP_PORT=8080
|
|
MAX_UPLOAD_SIZE=100m
|
|
|
|
# Image/version naming and local-only operator ports.
|
|
COMPOSE_PROJECT_NAME=frameflow-prod
|
|
FRAMEFLOW_VERSION=latest
|
|
MINIO_CONSOLE_BIND=127.0.0.1
|
|
MINIO_CONSOLE_PORT=9001
|
|
PROMETHEUS_BIND=127.0.0.1
|
|
PROMETHEUS_PORT=9090
|
|
PROMETHEUS_RETENTION=30d
|
|
# Host directory shared by backup.sh and Node Exporter's textfile collector.
|
|
FRAMEFLOW_BACKUP_METRICS_DIR=/var/lib/frameflow/metrics
|
|
ALERTMANAGER_BIND=127.0.0.1
|
|
ALERTMANAGER_PORT=9093
|
|
# Replace with the operator endpoint that receives firing and resolved alerts.
|
|
ALERTMANAGER_WEBHOOK_URL=https://alerts.example.com/frameflow-webhook
|
|
|
|
# Replace every value below before deployment. Keep URL passwords URL-safe.
|
|
POSTGRES_DB=frameflow
|
|
POSTGRES_USER=frameflow
|
|
POSTGRES_PASSWORD=replace_with_strong_postgres_password
|
|
DATABASE_URL=postgresql://frameflow:replace_with_strong_postgres_password@postgres:5432/frameflow
|
|
REDIS_PASSWORD=replace_with_strong_redis_password
|
|
REDIS_URL=redis://default:replace_with_strong_redis_password@redis:6379
|
|
JWT_ACCESS_SECRET=replace_with_at_least_32_random_characters_access
|
|
JWT_REFRESH_SECRET=replace_with_at_least_32_random_characters_refresh
|
|
CREDENTIAL_ENCRYPTION_KEY=replace_with_independent_credential_encryption_key
|
|
S3_BUCKET=frameflow
|
|
S3_REGION=us-east-1
|
|
S3_ACCESS_KEY=replace_with_minio_access_key
|
|
S3_SECRET_KEY=replace_with_minio_secret_key
|
|
|
|
# Metrics stay on the private Compose network. Set a token only when the
|
|
# Prometheus scrape configuration is updated to send the same token.
|
|
METRICS_TOKEN=
|
|
LOG_LEVEL=info
|
|
ACCESS_TOKEN_TTL=15m
|
|
REFRESH_TOKEN_TTL_DAYS=30
|
|
EMAIL_VERIFICATION_REQUIRED=true
|
|
EMAIL_VERIFICATION_TTL_HOURS=24
|
|
PASSWORD_RESET_TTL_MINUTES=30
|
|
# Used for verification, password-reset, and workspace-invitation emails.
|
|
RESEND_API_KEY=replace_with_resend_api_key
|
|
EMAIL_FROM=FrameFlow <noreply@example.com>
|
|
|
|
# AI providers. Missing values fail jobs explicitly and never create fake media.
|
|
OPENAI_API_KEY=
|
|
OPENAI_TEXT_MODEL=gpt-5.6-sol
|
|
OPENAI_IMAGE_MODEL=gpt-image-2
|
|
OPENAI_TTS_MODEL=gpt-4o-mini-tts
|
|
OPENAI_TTS_VOICE=alloy
|
|
# Agnes OpenAI-compatible gateway (text, image and video)
|
|
AGNES_API_KEY=
|
|
AGNES_TEXT_MODEL=agnes-2.5-flash
|
|
AGNES_IMAGE_MODEL=agnes-image-2.1-flash
|
|
AGNES_VIDEO_MODEL=agnes-video-v2.0
|
|
AGNES_VIDEO_PREDICTION_DEADLINE_SECONDS=900
|
|
AGNES_VIDEO_POLL_INTERVAL_MS=4000
|
|
# Generic OpenAI-compatible providers. Configure each capability as a complete triple.
|
|
# BASE_URL is the API root including its version path, for example https://api.vendor.com/v1.
|
|
GENERIC_TEXT_API_KEY=
|
|
GENERIC_TEXT_BASE_URL=
|
|
GENERIC_TEXT_MODEL=
|
|
GENERIC_IMAGE_API_KEY=
|
|
GENERIC_IMAGE_BASE_URL=
|
|
GENERIC_IMAGE_MODEL=
|
|
GENERIC_VIDEO_API_KEY=
|
|
GENERIC_VIDEO_BASE_URL=
|
|
GENERIC_VIDEO_MODEL=
|
|
GENERIC_VIDEO_PREDICTION_DEADLINE_SECONDS=900
|
|
GENERIC_VIDEO_POLL_INTERVAL_MS=4000
|
|
REPLICATE_API_TOKEN=
|
|
REPLICATE_IMAGE_VERSION=
|
|
REPLICATE_VIDEO_VERSION=
|
|
REPLICATE_LIPSYNC_VERSION=
|
|
# Sent to Replicate as Cancel-After; valid range is 5 seconds to 24 hours.
|
|
REPLICATE_PREDICTION_DEADLINE_SECONDS=900
|
|
|
|
# Stripe subscriptions. Leave all values empty to keep billing read-only.
|
|
STRIPE_SECRET_KEY=
|
|
STRIPE_WEBHOOK_SECRET=
|
|
STRIPE_PRO_PRICE_ID=
|
|
STRIPE_STUDIO_PRICE_ID=
|
|
STRIPE_PORTAL_CONFIGURATION_ID=
|
|
BILLING_SUCCESS_URL=https://studio.example.com
|
|
BILLING_CANCEL_URL=https://studio.example.com
|
|
|
|
# Optional platform connector for Douyin, Kuaishou, Bilibili, and Xiaohongshu.
|
|
# Configure both values together. The connector must expose the documented /v1 endpoints.
|
|
PUBLISHING_CONNECTOR_URL=
|
|
PUBLISHING_CONNECTOR_SECRET=
|
|
PUBLISHING_CONNECTOR_TIMEOUT_MS=30000
|
|
|
|
WORKER_CONCURRENCY=2
|
|
WORKER_HEARTBEAT_KEY=frameflow:worker:heartbeat
|
|
WORKER_HEARTBEAT_INTERVAL_MS=5000
|
|
WORKER_HEARTBEAT_TTL_SECONDS=20
|
|
MAX_UPLOAD_BYTES=104857600
|
|
PROVIDER_DOWNLOAD_TIMEOUT_MS=180000
|
|
PROVIDER_DOWNLOAD_MAX_REDIRECTS=3
|