# Copy to .env before the first `docker compose up`. Every value here is # optional — the defaults are the safe ones. # # cp .env.example .env # # See RUNNING_IN_DOCKER.md. # --------------------------------------------------------------------------- # EXPOSURE. This is the part worth reading. # --------------------------------------------------------------------------- # Caddy publishes one port per app. Each of these is the HOST INTERFACE that # port binds to — not a hostname, not a URL. 127.0.0.1 means "this machine # only": not the LAN, not the internet, not another container. # # All four default to loopback, INCLUDING the two public sites. Opening one is a # deliberate edit of a single line. # # 127.0.0.1 this machine only (the default) # 0.0.0.0 every interface — LAN, and the internet if your router forwards # 192.168.x.y one specific interface # # The archive itself. Serving this to the world is what it is for; it is static # files with no write path. Still off by default. #SITE_BIND=0.0.0.0 # The EDITOR. Read the auth section below before changing this. The editor has # no login of its own: anyone who reaches it can download, delete and # re-transcribe anything in your corpus. The container REFUSES TO START if you # put it on a network with no auth in front. #EDITOR_BIND=0.0.0.0 # The project's own site (marketing + docs). Only useful if you're mirroring it. #HOMEPAGE_BIND=0.0.0.0 # umtool. Private, same rules as the editor. #UMTOOL_BIND=0.0.0.0 # The published port numbers, if 8080-8083 collide with something you run. # These are the OUTSIDE ports; the ports inside the containers never change. #SITE_HTTP_PORT=8080 #EDITOR_HTTP_PORT=8081 #HOMEPAGE_HTTP_PORT=8082 #UMTOOL_HTTP_PORT=8083 # --------------------------------------------------------------------------- # AUTH for the two private apps (editor, umtool). # --------------------------------------------------------------------------- # basic (default) Caddy's built-in basic_auth, when a hash is set below. # Nothing to install, nothing extra to keep running. # forward hand the decision to Tinyauth or Authelia — see the # docker-compose.tinyauth.yml / docker-compose.authelia.yml # overlays, which set this for you. # none you have your own auth in front, or you are on a tailnet and # mean it. This is the explicit escape hatch from the startup # refusal — nothing else disables it. #ARCHILYZER_AUTH_MODE=basic # Generate the hash (the `$` characters need no escaping in this file): # # docker run --rm caddy:2.11-alpine caddy hash-password --plaintext 'your-password' # #ARCHILYZER_AUTH_USER=you #ARCHILYZER_AUTH_HASH=$2a$14$replace.this.with.the.hash.the.command.printed # --------------------------------------------------------------------------- # First run # --------------------------------------------------------------------------- # The speech model fetched into the models volume on first boot, and used by the # seeded transcription worker. Which FAMILY depends on the image you run: # # default / CUDA image a whisper.cpp model. base.en (~142 MB) is a sane # starting point; small.en (~466 MB) and medium.en # (~1.5 GB) are better and slower; tiny.en (~75 MB) is # faster and noticeably worse. # Vulkan image a parakeet GGUF from mudler/parakeet-cpp-gguf, named # without the extension. Default tdt_ctc-110m-q8_0; # tdt-0.6b-v3-q5_k and tdt_ctc-1.1b-q5_k are better and # slower. # # `none` skips the download entirely. # # Changing this AFTER the first boot fetches the new model but does not switch # the worker over — do that on the editor's Workers page, which is where model # choice actually lives. #ARCHILYZER_FETCH_MODEL=base.en # Run `yt-dlp -U` on every boot. An image pins yt-dlp at build time and a stale # yt-dlp is the most common reason downloads start failing. Off by default # because it is a network call at startup. It updates the IMAGE's yt-dlp only: # with YTDLP_BIN pointing elsewhere (below) it warns and leaves that one alone. #YTDLP_AUTO_UPDATE=1 # --------------------------------------------------------------------------- # Substituting yt-dlp (your own build, no image rebuild) # --------------------------------------------------------------------------- # The image ships the release yt-dlp at /usr/local/bin/yt-dlp # (ARCHILYZER_IMAGE_YTDLP — baked, do not set it). To run another one, point # YTDLP_BIN at it. Two ways: # # a zipapp built on the host (`make yt-dlp` in a yt-dlp checkout; it runs on # the image's python3), copied into the config volume: # docker compose exec editor mkdir -p /data/config/bin # docker compose cp ./yt-dlp editor:/data/config/bin/yt-dlp # docker compose exec editor chmod 755 /data/config/bin/yt-dlp #YTDLP_BIN=/data/config/bin/yt-dlp # # a SOURCE checkout, run with the image's python — set the checkout's host # path and start with the overlay, which sets YTDLP_BIN for you: # docker compose -f docker-compose.yml -f docker-compose.ytdlp.yml up -d #YTDLP_SOURCE_HOST_DIR=/home/you/yt-dlp-patched # # Every editor boot logs `yt-dlp: (image|override)`. # --------------------------------------------------------------------------- # Publishing to Cloudflare (deploys run IN the container) # --------------------------------------------------------------------------- # The editor reads these and every publish stage it runs inherits them. Values # are never printed — `docker compose exec editor pnpm archilyzer doctor` says # only whether each is set. A container has no browser for `wrangler login`, so # deploying from one needs the token. # # An API token with "Cloudflare Pages: Edit" (dash.cloudflare.com → My Profile → # API Tokens), and your account id. #CLOUDFLARE_API_TOKEN= #CLOUDFLARE_ACCOUNT_ID= # # R2 S3 credentials — only when Settings → archive storage names a bucket for # oversize archive zips. #R2_ACCESS_KEY_ID= #R2_SECRET_ACCESS_KEY= # # The wrangler deploys run. Default: the one pinned in the workspace # (common/node_modules/.bin/wrangler); nothing is fetched at deploy time. #WRANGLER_BIN= # # Driving the editor from a shell or an agent (`pnpm ops`, the MCP's # fetch_clip): the bearer token /api/ops/* and /api/worker/* answer to. Unset, # both surfaces are off. #WORKER_TOKEN= # --------------------------------------------------------------------------- # The homepage's /source mirror (optional) # --------------------------------------------------------------------------- # Publishing the homepage mirrors this repo's `main`, and the image has no .git. # docker-compose.source.yml mounts the host's git dir read-only and sets # ARCHILYZER_SOURCE_REPO=/data/source.git for you. Default `./.git`; in a git # worktree, the primary checkout's `.git`. #ARCHILYZER_SOURCE_HOST_DIR=./.git # # The scrub rules and denylist it needs live in ARCHILYZER_CONFIG_DIR, which # docker-compose.yml sets to /data/config/archilyzer (the config volume): # docker compose cp source-scrub.txt editor:/data/config/archilyzer/ # docker compose cp source-denylist.txt editor:/data/config/archilyzer/ # Boot the editor WITHOUT resuming the schedulers, the auto-queue runners or the # digest/backfill sweeps. Set this the first time you point a container at a # corpus somebody else configured: its stored policies may say "sweep", and you # probably want to look around before GPU-weeks of work starts on its own. # Unset (the default) matches a host install: everything armed on boot. #ARCHILYZER_IDLE_BOOT=1 # Which compute device parakeet uses — Vulkan image only (see # docker-compose.vulkan.yml). Unset lets parakeet.cpp choose, which is usually # right. "Vulkan0"/"Vulkan1" pin a specific GPU (`vulkaninfo --summary` lists # them in order). "cpu" takes the GPU out of the picture with everything else # identical — the honest way to measure what it is buying you. #PARAKEET_DEVICE=Vulkan0 # --------------------------------------------------------------------------- # Image # --------------------------------------------------------------------------- #ARCHILYZER_TAG=local # # Which commit and branch the image is built from, baked in for the publish # stamps (the image has no .git). Usually passed from the shell instead: # ARCHILYZER_COMMIT=$(git rev-parse HEAD) ARCHILYZER_BRANCH=$(git branch --show-current) docker compose build #ARCHILYZER_COMMIT= #ARCHILYZER_BRANCH=