Configuration reference
Every environment variable an operator sets for a production deployment, which are required, and which are fixed by the compose file.
You configure a production deployment through the .env file that sits next to
docker-compose.prod.yml (/opt/wi/.env on the AWS path). Docker Compose reads that file
automatically, so you never type these values on a command line.
The app service also loads every KEY=value line of .env straight into the
application's environment. Any setting in the application's WI_ namespace therefore reaches
it as soon as you add the line and restart the app container. The values the compose file
sets itself (listed at the end) take precedence over .env, so do not try to change those
there.
After editing .env, apply the change:
cd /opt/wi
sudo docker compose -f docker-compose.prod.yml up -d
Each key must appear once. Edit an existing line rather than adding a second one.
Required#
| Variable | What it is |
|---|---|
WI_MASTER_KEY |
Base64 key that encrypts every stored provider key. Generated once, never regenerated. See Master key custody. The stack will not start without it. |
WI_SESSION_SECRET |
Secret that signs sign-in sessions. Generated once, for example with openssl rand -base64 32. The stack will not start without it. |
WI_ALLOWED_ORIGIN |
The origin your users browse to, for example https://wi.example.com or http://203.0.113.10. Include the port if you changed WI_HTTP_PORT or WI_HTTPS_PORT. The compose file also uses it as the public base URL for emailed links and for the address of deployed Apps. The stack will not start without it. |
WI_DOKKU_SSH_HOST |
The public hostname Builders use for their git push to deployed Apps. install.sh adds it to .env if it is missing, from WI_DOMAIN, otherwise from the host part of WI_ALLOWED_ORIGIN. Set it yourself only when pushes should go to a different name. The compose file requires it. |
Optional#
| Variable | Default | What it does |
|---|---|---|
WI_DOMAIN |
blank (plain HTTP on port 80) | Your domain name. When set, the web container obtains and renews a certificate and serves HTTPS. See Domains and HTTPS. |
WI_HTTP_PORT |
80 |
Host port published for HTTP. |
WI_HTTPS_PORT |
443 |
Host port published for HTTPS. |
WI_DOKKU_SSH_PORT |
22 |
Host port published for Dokku's SSH. Change it when the box's own SSH server uses 22. |
WI_IMAGE_OWNER |
radialventures |
The GitHub account or organization that owns the wi-server and wi-web images. |
WI_IMAGE_TAG |
latest |
The image tag the app and web services run. |
WI_DOCKER_CONFIG_DIR |
/root/.docker |
The host directory holding the registry login that the in-app updater reads. See Registry credentials for updates. |
WI_SESSION_COOKIE_DOMAIN |
blank | Scopes the session cookie to a parent domain, for example example.com. Leave blank to keep the cookie on the exact host. Setting it widens where the cookie is sent. |
WI_TRIGGER_SCHEDULER |
dbos |
dbos runs Coworker triggers on their schedules. none turns off automatic firing, so triggers fire only when run by hand. |
WI_COMPACTION_TOKEN_THRESHOLD |
100000 |
Estimated tokens of conversation history before a Coworker's conversation is condensed to a summary. |
WI_CRAWLER_MAX_PAGES_PER_RUN |
200 |
Safety cap on pages one knowledge-source crawl may collect. |
WI_CRAWLER_MAX_FETCHES_PER_RUN |
400 |
Safety cap on fetches one knowledge-source crawl may make. |
Fixed by the compose file#
The compose file sets these for you. Do not change them. A value in .env does not override
them.
| Variable | Value | Why it is fixed |
|---|---|---|
WI_ENV |
prod |
Turns on the production boot checks. |
WI_DATABASE_URL |
postgresql+psycopg://wi:wi@postgres:5432/wi |
Points at the Postgres container on the private Compose network. |
WI_PUBLIC_BASE_URL |
the value of WI_ALLOWED_ORIGIN |
Base URL for emailed links. |
WI_API_BASE_URL |
the value of WI_ALLOWED_ORIGIN |
Base URL for links the API hands out, such as webhook trigger URLs. A production boot check requires it. |
WI_DATA_DIR |
/data |
The durable application volume. |
DOCKER_CONFIG |
/run/host-docker-config |
Where the application finds the mounted registry login. |
WI_DEPLOY_DRIVER |
dokku |
Deployed Apps run on the Dokku container. |
WI_DOKKU_CONTAINER_NAME |
wi-prod-dokku |
Must match the Dokku container's name. |
WI_APPS_BASE_URL |
the value of WI_ALLOWED_ORIGIN |
Deployed Apps are served on the same origin under /apps/serve/. |
WI_APPS_PLATFORM_BASE_URL |
http://app:8300 |
How a deployed App's container reaches the application. |
WI_DOKKU_APP_NETWORK |
wi-prod_default |
The Compose network that deployed Apps join. |
WI_DOKKU_ADMIN_SSH_HOST |
dokku |
The application reaches Dokku by its service name. |
WI_DOKKU_ADMIN_SSH_PORT |
22 |
Dokku's internal SSH port, independent of the published one. |
The postgres service uses the database user, password, and database name wi. The database
port is not published, so only the other containers on the Compose network can reach it.
Where the files live#
| Path | What it holds |
|---|---|
.env |
Secrets and deployment settings. Root-only, mode 0600. |
docker-compose.prod.yml |
The stack definition, extracted from the wi-server image by install.sh (it is replaced on every run, so do not edit it). |
install.sh, find-setup-token.sh |
The installer and the token helper. |
On the AWS path all of these are in /opt/wi.