Files
Colton QiandClaude 5ed0137859 Release 0.1.1
Strengthen sandbox isolation and authentication, make all five engines work
through the bundled installer, and preserve conversations across sandbox and
service restarts. Add team login and single-container deployment, with upgrade
instructions for replacing existing 0.1.0 sandboxes.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-26 19:09:28 -07:00

118 lines
6.9 KiB
Bash

# Copy to `.env` and fill in your own values. `.env` is gitignored.
# AstraBox brings your own LLM key; nothing here is baked into the image.
#
# This is the hand-picked operator-facing quickstart set. For the complete,
# generated list of every environment variable AstraBox reads (tuning knobs,
# SSO/JWT, sandbox pool sizing, …), see docs/configuration.md.
# ── Model endpoint + credentials (the ONLY required setting) ─────────────────
# One Anthropic-compatible endpoint + key. This single block is enough for a
# working first turn — no duplicate ASTRABOX_MODEL_* copies, no extra flags.
ANTHROPIC_BASE_URL=https://api.anthropic.com
# One of API_KEY (x-api-key) or AUTH_TOKEN (Bearer) — either auth path works.
ANTHROPIC_API_KEY=sk-your-key-here
#ANTHROPIC_AUTH_TOKEN=
ANTHROPIC_MODEL=claude-opus-4-8
# ── Host runtime (defaults and deployment examples shown) ───────────────────
# The built-in backend reaches sandboxes through the OpenSandbox lifecycle API.
# Left unset, the AstraBox image starts that server itself against your local
# Docker daemon; set ASTRABOX_SANDBOX_OPENAPI_BASE_URL to point at your own
# instead. Metadata is stored in PostgreSQL; Compose and scripts/dev.sh start it.
#ASTRABOX_SANDBOX_BACKEND=open_sandbox
# Redis carries disposable coordination for OpenSandbox's official client-side
# prewarm pool. Compose injects its internal URL; set one explicitly for a
# multi-machine deployment.
#ASTRABOX_AGENT_PREWARM_REDIS_URL=redis://127.0.0.1:56379/0
# Optional host port, image and volume names adjust this deployment without
# editing containers/compose.yaml. Several AstraBox installations can share one
# Docker daemon when each has its own COMPOSE_PROJECT_NAME, host ports and
# PostgreSQL and state volumes: an installation is its database, and it removes
# only sandboxes its own database created. scripts/compose.sh runs the images
# built from this checkout (astrabox/<component>:latest); name another server
# image here.
#ASTRABOX_SERVER_HOST_PORT=8088
#ASTRABOX_SERVER_IMAGE=astrabox/server:latest
#ASTRABOX_POSTGRES_VOLUME=astrabox-postgres
#ASTRABOX_STATE_VOLUME=astrabox-state
#ASTRABOX_DB_BACKEND=postgresql
# Maintained Compose/source-dev commands generate persistent random passwords
# under .astrabox/database-secrets. Do not copy database passwords into .env.
# Set a full async SQLAlchemy URL only when using an external database.
#ASTRABOX_DB_URL=postgresql+asyncpg://astrabox:change-me@db.example.com:5432/astrabox
#LITELLM_DATABASE_URL=postgresql://litellm:change-me@db.example.com:5432/litellm
# When the bundled lifecycle service runs inside the AstraBox container, it
# reaches protected sandbox ports through the Docker host. Compose supplies the
# bridge gateway; override it only when `docker network inspect bridge` reports
# a different address.
#ASTRABOX_PUBLISH_HOST_IP=172.17.0.1
# Docker publishes each sandbox's three ports from this host port range
# (default 20000-32000, at least 100 ports, outside the kernel's ephemeral
# range). Narrow it to match a firewall policy.
#ASTRABOX_SANDBOX_SERVER_PORT_RANGE=20000-21000
# Multi-node Kubernetes deployments should send browser traffic through the
# official OpenSandbox ingress component. URI mode works with ordinary browser
# links; Secure Access makes those links short-lived. The signing key must also
# be configured on the ingress component. See docs/providers/opensandbox.md.
#ASTRABOX_SANDBOX_SERVER_RUNTIME=kubernetes
#ASTRABOX_SANDBOX_SERVER_INGRESS_MODE=gateway
#ASTRABOX_SANDBOX_SERVER_INGRESS_GATEWAY_ADDRESS=sandbox.example.com
#ASTRABOX_SANDBOX_SERVER_INGRESS_ROUTE_MODE=uri
#ASTRABOX_SANDBOX_ENDPOINT_SCHEME=https
#ASTRABOX_SANDBOX_SECURE_ACCESS=true
#ASTRABOX_SANDBOX_SERVER_INGRESS_SIGNING_KEY=
# Local mode: relaxes dev-only conveniences (accepts a plaintext model key
# stored INSIDE a template, uses `latest` for the in-sandbox CLI install
# fallback, enables debug file paths). NOT required for the env key above —
# operator env vars always work.
#ASTRABOX_LOCAL_MODE=1
# Sandboxes reach callbacks and the private model route through sandbox-edge;
# their DNS goes through a separate DNS-only edge. Leave this unset for the
# maintained Compose and source-development commands so they can discover the
# dynamic edge addresses. Set it only when another deployment component owns
# the callback route.
#ASTRABOX_MCP_PROXY_BASE_URL=https://sandbox-callback.example.com
# ── Model endpoint provider (optional gateway) ───────────────────────────────
# `litellm` is the default. The server image starts the bundled gateway and
# routes the model names above through it. A plugin can register another gateway
# at the astrabox.providers.model entry-point group.
#ASTRABOX_MODEL_ENDPOINT_PROVIDER=litellm
# This URL is used from INSIDE a sandbox. Leave it unset to use the bundled
# gateway. With protected delivery on, an external gateway must be available on
# HTTP port 80 or HTTPS port 443 so OpenSandbox can bind the credential to it.
# For a gateway on the host, use an address reachable from the sandbox, usually
# the Docker bridge gateway rather than 127.0.0.1.
#ASTRABOX_LITELLM_BASE_URL=https://gateway.example.com
# Require the sandbox-facing gateway to be an HTTPS FQDN on port 443. The
# compose.team-gateway.yaml overlay enables this automatically. It is separate
# from the Credential Vault switch below.
#ASTRABOX_MODEL_GATEWAY_REQUIRE_HTTPS=1
# Only set this when the AstraBox service reaches that same gateway at a
# different address (for example, sandboxes use private DNS while the service
# uses loopback). It is used for server-side model discovery, not model turns.
#ASTRABOX_LITELLM_SERVER_BASE_URL=http://127.0.0.1:4000
#ASTRABOX_LITELLM_API_KEY=sk-astrabox-local
# Select the extension catalog/runtime provider by seam name. Empty selects the
# provider that declares itself as the deployment default.
#ASTRABOX_EXTENSION_PROVIDER=litellm
# ── Vault (user credential stores) ───────────────────────────────────────────
# Single-server default: AES-GCM under a key atomically generated at
# <state_dir>/vault.key (0600). Back it up with the state dir; losing it makes
# sealed values unrecoverable. A multi-replica AWS deployment should select the
# KMS provider and grant its workload identity kms:GenerateDataKey + kms:Decrypt.
#ASTRABOX_SECRET_STORE=aws_kms
#ASTRABOX_AWS_KMS_KEY_ARN=arn:aws:kms:us-west-2:123456789012:key/00000000-0000-0000-0000-000000000000
# Multi-replica deployments that deliberately keep the local provider must set
# this same urlsafe-base64 32-byte value in every replica:
#ASTRABOX_VAULT_MASTER_KEY=
# Model/gateway credentials stay in the OpenSandbox egress sidecar by default.
# The sandbox receives a placeholder, and outbound access is deny-by-default.
# Turn this off only when you accept that the Agent process can read the key.
#ASTRABOX_SANDBOX_CREDENTIAL_VAULT=0