mirror of
https://github.com/Colton-z/AstraBox.git
synced 2026-09-28 06:02:56 +08:00
Strengthen sandbox isolation and authentication, make all five engines work through the bundled installer, and preserve conversations across sandbox and service restarts. Add team login and single-container deployment, with upgrade instructions for replacing existing 0.1.0 sandboxes. Co-Authored-By: Claude <noreply@anthropic.com>
118 lines
6.9 KiB
Bash
118 lines
6.9 KiB
Bash
# Copy to `.env` and fill in your own values. `.env` is gitignored.
|
|
# AstraBox brings your own LLM key; nothing here is baked into the image.
|
|
#
|
|
# This is the hand-picked operator-facing quickstart set. For the complete,
|
|
# generated list of every environment variable AstraBox reads (tuning knobs,
|
|
# SSO/JWT, sandbox pool sizing, …), see docs/configuration.md.
|
|
|
|
# ── Model endpoint + credentials (the ONLY required setting) ─────────────────
|
|
# One Anthropic-compatible endpoint + key. This single block is enough for a
|
|
# working first turn — no duplicate ASTRABOX_MODEL_* copies, no extra flags.
|
|
ANTHROPIC_BASE_URL=https://api.anthropic.com
|
|
# One of API_KEY (x-api-key) or AUTH_TOKEN (Bearer) — either auth path works.
|
|
ANTHROPIC_API_KEY=sk-your-key-here
|
|
#ANTHROPIC_AUTH_TOKEN=
|
|
ANTHROPIC_MODEL=claude-opus-4-8
|
|
|
|
# ── Host runtime (defaults and deployment examples shown) ───────────────────
|
|
# The built-in backend reaches sandboxes through the OpenSandbox lifecycle API.
|
|
# Left unset, the AstraBox image starts that server itself against your local
|
|
# Docker daemon; set ASTRABOX_SANDBOX_OPENAPI_BASE_URL to point at your own
|
|
# instead. Metadata is stored in PostgreSQL; Compose and scripts/dev.sh start it.
|
|
#ASTRABOX_SANDBOX_BACKEND=open_sandbox
|
|
# Redis carries disposable coordination for OpenSandbox's official client-side
|
|
# prewarm pool. Compose injects its internal URL; set one explicitly for a
|
|
# multi-machine deployment.
|
|
#ASTRABOX_AGENT_PREWARM_REDIS_URL=redis://127.0.0.1:56379/0
|
|
# Optional host port, image and volume names adjust this deployment without
|
|
# editing containers/compose.yaml. Several AstraBox installations can share one
|
|
# Docker daemon when each has its own COMPOSE_PROJECT_NAME, host ports and
|
|
# PostgreSQL and state volumes: an installation is its database, and it removes
|
|
# only sandboxes its own database created. scripts/compose.sh runs the images
|
|
# built from this checkout (astrabox/<component>:latest); name another server
|
|
# image here.
|
|
#ASTRABOX_SERVER_HOST_PORT=8088
|
|
#ASTRABOX_SERVER_IMAGE=astrabox/server:latest
|
|
#ASTRABOX_POSTGRES_VOLUME=astrabox-postgres
|
|
#ASTRABOX_STATE_VOLUME=astrabox-state
|
|
#ASTRABOX_DB_BACKEND=postgresql
|
|
# Maintained Compose/source-dev commands generate persistent random passwords
|
|
# under .astrabox/database-secrets. Do not copy database passwords into .env.
|
|
# Set a full async SQLAlchemy URL only when using an external database.
|
|
#ASTRABOX_DB_URL=postgresql+asyncpg://astrabox:change-me@db.example.com:5432/astrabox
|
|
#LITELLM_DATABASE_URL=postgresql://litellm:change-me@db.example.com:5432/litellm
|
|
# When the bundled lifecycle service runs inside the AstraBox container, it
|
|
# reaches protected sandbox ports through the Docker host. Compose supplies the
|
|
# bridge gateway; override it only when `docker network inspect bridge` reports
|
|
# a different address.
|
|
#ASTRABOX_PUBLISH_HOST_IP=172.17.0.1
|
|
# Docker publishes each sandbox's three ports from this host port range
|
|
# (default 20000-32000, at least 100 ports, outside the kernel's ephemeral
|
|
# range). Narrow it to match a firewall policy.
|
|
#ASTRABOX_SANDBOX_SERVER_PORT_RANGE=20000-21000
|
|
|
|
# Multi-node Kubernetes deployments should send browser traffic through the
|
|
# official OpenSandbox ingress component. URI mode works with ordinary browser
|
|
# links; Secure Access makes those links short-lived. The signing key must also
|
|
# be configured on the ingress component. See docs/providers/opensandbox.md.
|
|
#ASTRABOX_SANDBOX_SERVER_RUNTIME=kubernetes
|
|
#ASTRABOX_SANDBOX_SERVER_INGRESS_MODE=gateway
|
|
#ASTRABOX_SANDBOX_SERVER_INGRESS_GATEWAY_ADDRESS=sandbox.example.com
|
|
#ASTRABOX_SANDBOX_SERVER_INGRESS_ROUTE_MODE=uri
|
|
#ASTRABOX_SANDBOX_ENDPOINT_SCHEME=https
|
|
#ASTRABOX_SANDBOX_SECURE_ACCESS=true
|
|
#ASTRABOX_SANDBOX_SERVER_INGRESS_SIGNING_KEY=
|
|
|
|
# Local mode: relaxes dev-only conveniences (accepts a plaintext model key
|
|
# stored INSIDE a template, uses `latest` for the in-sandbox CLI install
|
|
# fallback, enables debug file paths). NOT required for the env key above —
|
|
# operator env vars always work.
|
|
#ASTRABOX_LOCAL_MODE=1
|
|
|
|
# Sandboxes reach callbacks and the private model route through sandbox-edge;
|
|
# their DNS goes through a separate DNS-only edge. Leave this unset for the
|
|
# maintained Compose and source-development commands so they can discover the
|
|
# dynamic edge addresses. Set it only when another deployment component owns
|
|
# the callback route.
|
|
#ASTRABOX_MCP_PROXY_BASE_URL=https://sandbox-callback.example.com
|
|
|
|
# ── Model endpoint provider (optional gateway) ───────────────────────────────
|
|
# `litellm` is the default. The server image starts the bundled gateway and
|
|
# routes the model names above through it. A plugin can register another gateway
|
|
# at the astrabox.providers.model entry-point group.
|
|
#ASTRABOX_MODEL_ENDPOINT_PROVIDER=litellm
|
|
# This URL is used from INSIDE a sandbox. Leave it unset to use the bundled
|
|
# gateway. With protected delivery on, an external gateway must be available on
|
|
# HTTP port 80 or HTTPS port 443 so OpenSandbox can bind the credential to it.
|
|
# For a gateway on the host, use an address reachable from the sandbox, usually
|
|
# the Docker bridge gateway rather than 127.0.0.1.
|
|
#ASTRABOX_LITELLM_BASE_URL=https://gateway.example.com
|
|
# Require the sandbox-facing gateway to be an HTTPS FQDN on port 443. The
|
|
# compose.team-gateway.yaml overlay enables this automatically. It is separate
|
|
# from the Credential Vault switch below.
|
|
#ASTRABOX_MODEL_GATEWAY_REQUIRE_HTTPS=1
|
|
# Only set this when the AstraBox service reaches that same gateway at a
|
|
# different address (for example, sandboxes use private DNS while the service
|
|
# uses loopback). It is used for server-side model discovery, not model turns.
|
|
#ASTRABOX_LITELLM_SERVER_BASE_URL=http://127.0.0.1:4000
|
|
#ASTRABOX_LITELLM_API_KEY=sk-astrabox-local
|
|
# Select the extension catalog/runtime provider by seam name. Empty selects the
|
|
# provider that declares itself as the deployment default.
|
|
#ASTRABOX_EXTENSION_PROVIDER=litellm
|
|
|
|
# ── Vault (user credential stores) ───────────────────────────────────────────
|
|
# Single-server default: AES-GCM under a key atomically generated at
|
|
# <state_dir>/vault.key (0600). Back it up with the state dir; losing it makes
|
|
# sealed values unrecoverable. A multi-replica AWS deployment should select the
|
|
# KMS provider and grant its workload identity kms:GenerateDataKey + kms:Decrypt.
|
|
#ASTRABOX_SECRET_STORE=aws_kms
|
|
#ASTRABOX_AWS_KMS_KEY_ARN=arn:aws:kms:us-west-2:123456789012:key/00000000-0000-0000-0000-000000000000
|
|
# Multi-replica deployments that deliberately keep the local provider must set
|
|
# this same urlsafe-base64 32-byte value in every replica:
|
|
#ASTRABOX_VAULT_MASTER_KEY=
|
|
|
|
# Model/gateway credentials stay in the OpenSandbox egress sidecar by default.
|
|
# The sandbox receives a placeholder, and outbound access is deny-by-default.
|
|
# Turn this off only when you accept that the Agent process can read the key.
|
|
#ASTRABOX_SANDBOX_CREDENTIAL_VAULT=0
|