Configuration reference

Every environment variable an operator sets for a production deployment, which are required, and which are fixed by the compose file.

For: Administrators operating a deployment · Last updated

You configure a production deployment through the .env file that sits next to docker-compose.prod.yml (/opt/wi/.env on the AWS path). Docker Compose reads that file automatically, so you never type these values on a command line.

The app service also loads every KEY=value line of .env straight into the application's environment. Any setting in the application's WI_ namespace therefore reaches it as soon as you add the line and restart the app container. The values the compose file sets itself (listed at the end) take precedence over .env, so do not try to change those there.

After editing .env, apply the change:

cd /opt/wi
sudo docker compose -f docker-compose.prod.yml up -d

Each key must appear once. Edit an existing line rather than adding a second one.

Required#

Variable What it is
WI_MASTER_KEY Base64 key that encrypts every stored provider key. Generated once, never regenerated. See Master key custody. The stack will not start without it.
WI_SESSION_SECRET Secret that signs sign-in sessions. Generated once, for example with openssl rand -base64 32. The stack will not start without it.
WI_ALLOWED_ORIGIN The origin your users browse to, for example https://wi.example.com or http://203.0.113.10. Include the port if you changed WI_HTTP_PORT or WI_HTTPS_PORT. The compose file also uses it as the public base URL for emailed links and for the address of deployed Apps. The stack will not start without it.
WI_DOKKU_SSH_HOST The public hostname Builders use for their git push to deployed Apps. install.sh adds it to .env if it is missing, from WI_DOMAIN, otherwise from the host part of WI_ALLOWED_ORIGIN. Set it yourself only when pushes should go to a different name. The compose file requires it.

Optional#

Variable Default What it does
WI_DOMAIN blank (plain HTTP on port 80) Your domain name. When set, the web container obtains and renews a certificate and serves HTTPS. See Domains and HTTPS.
WI_HTTP_PORT 80 Host port published for HTTP.
WI_HTTPS_PORT 443 Host port published for HTTPS.
WI_DOKKU_SSH_PORT 22 Host port published for Dokku's SSH. Change it when the box's own SSH server uses 22.
WI_IMAGE_OWNER radialventures The GitHub account or organization that owns the wi-server and wi-web images.
WI_IMAGE_TAG latest The image tag the app and web services run.
WI_DOCKER_CONFIG_DIR /root/.docker The host directory holding the registry login that the in-app updater reads. See Registry credentials for updates.
WI_SESSION_COOKIE_DOMAIN blank Scopes the session cookie to a parent domain, for example example.com. Leave blank to keep the cookie on the exact host. Setting it widens where the cookie is sent.
WI_TRIGGER_SCHEDULER dbos dbos runs Coworker triggers on their schedules. none turns off automatic firing, so triggers fire only when run by hand.
WI_COMPACTION_TOKEN_THRESHOLD 100000 Estimated tokens of conversation history before a Coworker's conversation is condensed to a summary.
WI_CRAWLER_MAX_PAGES_PER_RUN 200 Safety cap on pages one knowledge-source crawl may collect.
WI_CRAWLER_MAX_FETCHES_PER_RUN 400 Safety cap on fetches one knowledge-source crawl may make.

Fixed by the compose file#

The compose file sets these for you. Do not change them. A value in .env does not override them.

Variable Value Why it is fixed
WI_ENV prod Turns on the production boot checks.
WI_DATABASE_URL postgresql+psycopg://wi:wi@postgres:5432/wi Points at the Postgres container on the private Compose network.
WI_PUBLIC_BASE_URL the value of WI_ALLOWED_ORIGIN Base URL for emailed links.
WI_API_BASE_URL the value of WI_ALLOWED_ORIGIN Base URL for links the API hands out, such as webhook trigger URLs. A production boot check requires it.
WI_DATA_DIR /data The durable application volume.
DOCKER_CONFIG /run/host-docker-config Where the application finds the mounted registry login.
WI_DEPLOY_DRIVER dokku Deployed Apps run on the Dokku container.
WI_DOKKU_CONTAINER_NAME wi-prod-dokku Must match the Dokku container's name.
WI_APPS_BASE_URL the value of WI_ALLOWED_ORIGIN Deployed Apps are served on the same origin under /apps/serve/.
WI_APPS_PLATFORM_BASE_URL http://app:8300 How a deployed App's container reaches the application.
WI_DOKKU_APP_NETWORK wi-prod_default The Compose network that deployed Apps join.
WI_DOKKU_ADMIN_SSH_HOST dokku The application reaches Dokku by its service name.
WI_DOKKU_ADMIN_SSH_PORT 22 Dokku's internal SSH port, independent of the published one.

The postgres service uses the database user, password, and database name wi. The database port is not published, so only the other containers on the Compose network can reach it.

Where the files live#

Path What it holds
.env Secrets and deployment settings. Root-only, mode 0600.
docker-compose.prod.yml The stack definition, extracted from the wi-server image by install.sh (it is replaced on every run, so do not edit it).
install.sh, find-setup-token.sh The installer and the token helper.

On the AWS path all of these are in /opt/wi.