-
Notifications
You must be signed in to change notification settings - Fork 14
Expand file tree
/
Copy path.env.example
More file actions
169 lines (135 loc) · 7.96 KB
/
Copy path.env.example
File metadata and controls
169 lines (135 loc) · 7.96 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
# =============================================================================
# Scoped - Local Development Environment Variables
# =============================================================================
# Copy to .env and fill in required values.
#
# These values are for running services NATIVELY (outside Docker) while
# connecting to infrastructure running in Docker Compose.
#
# When services run INSIDE Docker Compose, the compose file overrides these
# with Docker-internal hostnames (e.g. mongodb instead of localhost).
#
# WORKTREE PORT OFFSETS:
# When working in a git worktree, run `source scripts/worktree-env.sh` (or any
# `pnpm docker:*` command) to auto-generate a managed section at the bottom
# of .env with offset ports. Base ports are defined in .env.base.
# The offset is persisted in .port-offset (gitignored, auto-cleaned on
# `git worktree remove`). Do NOT edit the managed section manually.
# =============================================================================
# ---------------------------------------------------------------------------
# Docker image builds — npm registry (usually nothing to do)
# ---------------------------------------------------------------------------
# `pnpm docker:*` builds resolve npm packages through the registry configured on
# your host: scripts/dev-compose.sh runs `npm config get registry` (reads ~/.npmrc)
# and forwards it into every image build. External contributors and CI hit the
# public registry automatically; engineers behind a private proxy (e.g. Microsoft's
# npm proxy) build with no extra setup. To force a specific registry, export it in
# your shell before running docker compose (do NOT put it in .env, which
# worktree-env regenerates per-worktree):
# export NPM_CONFIG_REGISTRY=https://packagefeedproxy.microsoft.io/npm/
# ---------------------------------------------------------------------------
# CLI Configuration
# ---------------------------------------------------------------------------
# API base URL for CLI commands (default: http://localhost:3000)
SCOPE_API_URL=http://localhost:3100
# Fallback port used by the CLI when SCOPE_API_URL is unset. Picked up
# automatically from the worktree port-offset mechanism (.env.base) so the
# CLI talks to the right API instance per worktree without further config.
SCOPE_API_PORT=3100
# ---------------------------------------------------------------------------
# Infrastructure connections (for host-native runs)
# ---------------------------------------------------------------------------
# MongoDB (host port 27000 matches docker-compose mapping)
MONGO_CONNECTION_STRING=mongodb://localhost:27000
MONGO_DATABASE=requests-db
MONGO_COLLECTION=requests
# Redis
REDIS_HOST=localhost
REDIS_PORT=6300
REDIS_PASSWORD=
# Azure Storage (Azurite)
AZURE_STORAGE_ACCOUNT_NAME=devstoreaccount1
STORAGE_CONNECTION_STRING=DefaultEndpointsProtocol=http;AccountName=devstoreaccount1;AccountKey=Eby8vdM02xNOcqFlqUwJPLlmEtlCDXJ1OUzFT50uSRZ6IFsuFq2UVErCz4I6tq/K1SZFPTOtr/KBHBeksoGMGw==;QueueEndpoint=http://127.0.0.1:10200/devstoreaccount1;BlobEndpoint=http://127.0.0.1:10100/devstoreaccount1;
# Queue names (used by API to route to workers)
AZURE_STORAGE_QUEUE_WORKER_1=queue-coder-acp-claude-code
AZURE_STORAGE_QUEUE_WORKER_2=queue-coder-acp-copilot
# Judge service URL (when running a worker natively while judge is in Docker)
JUDGE_SERVICE_URL=http://localhost:3200
# ---------------------------------------------------------------------------
# Per-worker queue name (set when running a specific worker natively)
# ---------------------------------------------------------------------------
# QUEUE_NAME=queue-coder-acp-claude-code
# QUEUE_NAME=queue-coder-acp-copilot
# ---------------------------------------------------------------------------
# API keys (required by workers - also read by Docker Compose via ${VAR})
# ---------------------------------------------------------------------------
# Required for: coder-acp-claude-code (profile: claude-code)
ANTHROPIC_API_KEY=
# Required for: coder-acp-copilot (profile: copilot)
# (Copilot SDK / ACP — does NOT need `models` permission)
GITHUB_TOKEN=
# Required for: API criteria AI generation (GitHub Models inference)
# PAT must have the `models` (read) permission.
# Used as a *fallback* when Azure AI Foundry is not fully configured
# (that is, when both AZURE_AI_INFERENCE_ENDPOINT and
# AZURE_AI_INFERENCE_API_KEY are not set; public GitHub Models endpoint —
# slow under load, fine for local dev).
GITHUB_MODELS_API_KEY=
# NOTE: Azure AI Foundry credentials (AZURE_AI_INFERENCE_ENDPOINT,
# AZURE_AI_INFERENCE_API_KEY) and the LLM_MODEL override belong in
# .env.local instead of .env. The .env file in this repo is auto-generated
# per worktree by worktree-env (from .env.base) and would overwrite any
# values you put here. Copy .env.local.example to .env.local and set them
# there; the api service in docker-compose.yml loads .env.local
# automatically (and the file is gitignored).
# ---------------------------------------------------------------------------
# Judge Criteria System Configuration
# ---------------------------------------------------------------------------
# Strategy for evaluating criteria:
# - bundled: Evaluate all criteria in one session (faster, less granular)
# - independent: Evaluate criteria separately with DAG awareness (slower, more accurate)
JUDGE_STRATEGY=bundled
# Max parallel evaluations for independent strategy (default: 3)
JUDGE_MAX_PARALLELISM=3
# Max failed criteria to mention in feedback per iteration (default: 1)
# Focus on root-cause failures only
FEEDBACK_MAX_CRITERIA=1
# Whether to guard against hinting about descendant criteria (default: true)
# Prevents feedback from mentioning requirements not yet introduced
FEEDBACK_DESCENDANT_GUARD=true
# ---------------------------------------------------------------------------
# API Authentication (Microsoft Entra ID) — identity-only, non-breaking
# ---------------------------------------------------------------------------
# Leave AUTH_PROVIDER unset to keep auth disabled: the API boots and treats
# every caller as anonymous when all IdP settings are absent. Configured clients
# enroll through GET /api/v1/users/me?login=true, then use IdP bearer tokens on
# ordinary requests. Active Scope users/roles are cached in Redis.
# See ENV_VARIABLES.md → "API Authentication" for details.
# Identity provider. Set to `entra` to enable token verification.
# AUTH_PROVIDER=entra
# OIDC authority for JWKS discovery + issuer validation (multi-tenant example).
# Point at the entra-local emulator for offline development.
# AUTH_AUTHORITY=https://login.microsoftonline.com/common
# Per-tenant issuer template ({tenantid} is substituted from the token `tid`).
# Override only for a self-hosted issuer, e.g. the entra-local emulator:
# https://localhost:8443/{tenantid}/v2.0
# AUTH_ISSUER_TEMPLATE=https://login.microsoftonline.com/{tenantid}/v2.0
# Explicit JWKS URI. Leave unset to derive it as <AUTH_AUTHORITY>/discovery/v2.0/keys.
# Every signing key must publish an `issuer` matching the token issuer (with
# `{tenantid}` substitution supported); missing issuer metadata is rejected.
# AUTH_JWKS_URI=
# The API App Registration (client) ID — verified as the token audience (aud).
# AUTH_API_CLIENT_ID=00000000-0000-0000-0000-000000000000
# Public client ID advertised to the CLI for interactive sign-in.
# AUTH_CLI_CLIENT_ID=00000000-0000-0000-0000-000000000000
# Public client ID advertised to the Portal for interactive sign-in.
# AUTH_PORTAL_CLIENT_ID=00000000-0000-0000-0000-000000000000
# Scopes the CLI/Portal request for the API access token.
# AUTH_SCOPES=api://00000000-0000-0000-0000-000000000000/access
# Promote-only admin bootstrap: comma-separated `${idp}:${tenant}/${subject}`.
# AUTH_BOOTSTRAP_ADMINS=
# Required tenant allowlist when AUTH_BOOTSTRAP_ADMINS is configured.
# AUTH_BOOTSTRAP_TENANTS=
# Fixed active-user cache lifetime, in seconds (positive integer, default 300).
# Cache hits do not extend expiry; Redis outages fall back to MongoDB.
# AUTH_USER_CACHE_TTL_SECONDS=300