# /etc/klanker-gate/env — loaded by systemd (EnvironmentFile=). # Mirrors the upstream .env.example conventions: a blank value means "leave # the feature off"; secrets ship blank on purpose. Edit, then: # systemctl restart klanker-gate # # Full knob reference: /usr/share/klanker-gate/docs/reference/environment-variables.md # ── core gateway ──────────────────────────────────────────────────────── PORT=8080 # REQUIRED — durable state store. Local Arch postgres created via the # INSTALL-ARCH.md steps: # postgres://klanker:CHANGE_ME@127.0.0.1:5432/klanker # (remote PG, the docker-compose service, or PgBouncer in front all work.) FROSTY_PG_URL= # ── worker topology (an Arch bonus) ───────────────────────────────────── # SO_REUSEPORT fan-out is Linux/darwin only — Windows had to serve # single-process. On Arch this actually unlocks the feature: # FROSTY_WORKERS=4 FROSTY_WORKERS= # ── admin protection (REQUIRED by the SysDeck package) ───── # REQUIRED — upstream serves the ENTIRE admin API unauthenticated when # this is empty ("local-admin mode") while binding 0.0.0.0; the SysDeck # systemd unit refuses to start without a token. Generate one: # openssl rand -hex 24 # The SysDeck klanker module reads the operator API with this token. FROSTY_ADMIN_TOKEN= FROSTY_ALLOWED_HOSTS= FROSTY_ENCRYPTION_KEY= # ── provider credentials (any subset; blank = provider stays off) ─────── OPENAI_API_KEY= ANTHROPIC_API_KEY= GEMINI_API_KEY= OPENROUTER_API_KEY= GROQ_API_KEY= MISTRAL_API_KEY= XAI_API_KEY= COHERE_API_KEY= OLLAMA_BASE_URL= OLLAMA_MODELS= # ── optional subsystems (see the env reference for the full list) ─────── # Cache, semantic cache, MCP clients, OTel export, pricing sync, plugins.