f2a12f9fed
v0.4 (Operator Tier — Cohort Dashboard + Auth + Postgres) milestone complete. Phases: ✓ P0 pre-execution (planning) → v0.1.6 ✓ P1 operator foundation (Postgres+auth+VC migration) → v0.1.7 ✓ P2 cohort dashboard + aggregation → v0.1.8 ✓ P3 final review + ship → v0.1.9 (= v0.4 milestone release) Requirements covered (8/8): REQ-MT-01 (Postgres store), REQ-MT-02 (aggregation pipeline), REQ-AUTH-01 (operator auth), REQ-DASH-01 (cohort dashboard), REQ-NFR-AUTH-01 (auth NFRs), REQ-NFR-MT-01 (Postgres-in-LXC), REQ-NFR-DASH-01 (k-anonymity ≥10), REQ-NFR-DASH-02 (freshness ≤24h) Grill MUSTs honored (6/6): G-008, G-011, G-027, G-031, G-038, G-041 Tests: 317 pytest pass, 36 skip (Postgres-requiring), 0 fail; 17/17 vitest pass Review: APPROVE_WITH_NOTES (6/6 personas, 0 P0, 8 P1+ carry-forward) Audit: HEALTHY (reconstruction PASS, 8/8 REQ, 6/6 grill) ---ci--- project: praxis phase: 3 milestone: v0.4 status: complete phase_role: final milestone_complete: true milestone_merged_to_main: true tag: v0.1.9 requirements: covered: [REQ-MT-01, REQ-MT-02, REQ-AUTH-01, REQ-DASH-01, REQ-NFR-AUTH-01, REQ-NFR-MT-01, REQ-NFR-DASH-01, REQ-NFR-DASH-02] partial: [] ---/ci---
110 lines
6.0 KiB
Bash
110 lines
6.0 KiB
Bash
# Praxis — Environment Configuration (v0.2)
|
|
# Copy to `.env` and fill in real values.
|
|
# Voice-service keys are in .ciagent/.env.secrets (not this file).
|
|
# Proxmox deployment vars are sourced from ~/coreci/.ciagent/.env.secrets (D-026).
|
|
|
|
# ─── Voice services ──────────────────────────────────────────────────────────
|
|
# Deepgram Nova-3 ASR (D-013). Get from https://console.deepgram.com/
|
|
DEEPGRAM_API_KEY=
|
|
|
|
# Cartesia Sonic TTS (D-014, primary). Get from https://cartesia.ai/
|
|
CARTESIA_API_KEY=
|
|
|
|
# Ollama Cloud direct API (D-020). Get from https://ollama.com/ → Settings → API Keys
|
|
OLLAMA_API_KEY=
|
|
|
|
# ─── TTS selection (D-014) ────────────────────────────────────────────────────
|
|
# cartesia (default, cloud, ~120ms first-audio) | piper (self-hosted, ~80ms, R4 mitigation)
|
|
PRAXIS_TTS=cartesia
|
|
|
|
# ─── Ollama Cloud endpoints (D-020) ───────────────────────────────────────────
|
|
# Direct API mode (no local daemon). Pipecat's OLLamaLLMService uses the OpenAI-compatible path.
|
|
OLLAMA_BASE_URL=https://ollama.com/v1
|
|
OLLAMA_CHAT_URL=https://ollama.com/api/chat
|
|
# Role-play fast path (256K ctx, low-latency)
|
|
OLLAMA_ROLEPLAY_MODEL=gemma4:cloud
|
|
# Debrief + branch classifier (1M ctx, no-think mode for latency)
|
|
OLLAMA_DEBRIEF_MODEL=deepseek-v4-flash:cloud
|
|
|
|
# ─── Server ───────────────────────────────────────────────────────────────────
|
|
PRAXIS_HOST=0.0.0.0
|
|
PRAXIS_PORT=8789
|
|
# In Docker: /app/data/praxis.db (volume-mounted). Local dev: ./praxis.db
|
|
PRAXIS_DB_PATH=./praxis.db
|
|
PRAXIS_SCENARIOS_DIR=./scenarios
|
|
# Client dist directory (for FastAPI StaticFiles serving, D-023)
|
|
PRAXIS_CLIENT_DIST=client/dist
|
|
|
|
# ─── Deepgram live options (D-013) ────────────────────────────────────────────
|
|
DEEPGRAM_MODEL=nova-3
|
|
DEEPGRAM_LANGUAGE=en
|
|
DEEPGRAM_REGION=na
|
|
|
|
# ─── Cartesia voice (D-006 — one voice for role-play + mentor) ────────────────
|
|
CARTESIA_VOICE_ID=a3536a36-1d18-4efb-a95a-7c44b7b5e384
|
|
|
|
# ─── Proxmox LXC deployment (v0.2) ────────────────────────────────────────────
|
|
# These are sourced from ~/coreci/.ciagent/.env.secrets (D-026 — same cluster).
|
|
# Listed here for documentation; do NOT duplicate in .ciagent/.env.secrets.
|
|
# PROXMOX_API_URL=https://proxmox:8006/api2/json
|
|
# PROXMOX_API_TOKEN=root@pam!praxis-deploy=SECRET
|
|
# PROXMOX_NODE=ns1003845
|
|
# PROXMOX_STORAGE=local
|
|
# PROXMOX_TEMPLATE_VOLID=local:vztmpl/debian-12-standard_12.2-1_amd64.tar.zst
|
|
# PROXMOX_LXC_VMID=auto
|
|
# PROXMOX_TLS_SKIP_VERIFY=true
|
|
# v0.4: bumped to 6144 (Postgres ~400MB + praxis ~500MB + Docker ~200MB
|
|
# + build headroom ~1GB + margin — REQ-NFR-MT-01).
|
|
# PROXMOX_MEMORY_MB=6144
|
|
|
|
# ─── CI/Gitea (operational — not voice) ───────────────────────────────────────
|
|
# GITEA_TOKEN is provisioned in .ciagent/.env.secrets (not this file).
|
|
# PRAXIS_VERSION (git ref to deploy, default: main)
|
|
|
|
# ─── v0.4 Operator Tier (Postgres + Auth) ────────────────────────────────────
|
|
# These configure the operator surface (cohort dashboard, auth, VC migration).
|
|
# Real values are secrets — put them in .ciagent/.env.secrets, not here.
|
|
# This file is documentation-only (committed); .env.secrets is gitignored.
|
|
|
|
# Postgres password. Secret. Used in the DSN below + docker-compose postgres
|
|
# service (POSTGRES_PASSWORD). Generate with: openssl rand -base64 32
|
|
PRAXIS_PG_PASSWORD=
|
|
|
|
# Postgres DSN (D-050). host=postgres is the docker-compose service DNS name
|
|
# on the praxis-net bridge. Format:
|
|
# postgresql://praxis:${PRAXIS_PG_PASSWORD}@postgres:5432/praxis
|
|
# When unset/empty, the server starts in graceful no-pool mode (learner voice
|
|
# loop works; operator auth + cohort endpoints return 503).
|
|
PRAXIS_PG_DSN=
|
|
|
|
# Cookie signing secret (D-056, R-AUTH-01). >=32 random bytes, base64 or hex.
|
|
# Secret. Generate with: openssl rand -base64 48
|
|
# When unset, the server generates an ephemeral random secret (dev ONLY —
|
|
# sessions won't survive a restart; NOT for pilot/production).
|
|
PRAXIS_COOKIE_SECRET=
|
|
|
|
# Cookie Secure flag (D-041, R-AUTH-01, G-031). Default true (HTTPS).
|
|
# Set to false ONLY for the HTTP pilot (no TLS in the LXC pilot — D-030).
|
|
# NOTE (G-031): the PRIMARY mitigation for a sniffed cookie is the k-anon
|
|
# defense-in-depth (the cohort dashboard reads only k-anonymized aggregates,
|
|
# so a sniffed operator cookie leaks NO learner PII). This flag is the
|
|
# SECONDARY mitigation (operational convenience for when TLS arrives).
|
|
PRAXIS_COOKIE_SECURE=true
|
|
|
|
# Bootstrap operator credentials (D-052). Secret. Used by
|
|
# scripts/create-operator.py on first run to create the initial operator.
|
|
# If either is missing, the CLI exits 1 (R-BOOT-02).
|
|
PRAXIS_BOOTSTRAP_OPERATOR_USER=
|
|
PRAXIS_BOOTSTRAP_OPERATOR_PASS=
|
|
|
|
# VC issuer root key (v0.3 + v0.4). Secret. Used by nacl.SecretBox to encrypt
|
|
# Ed25519 private keys at rest (D-042). In v0.4 the migration script
|
|
# (server/vc/migrate_keys.py) uses this to encrypt the fresh v0.4 keypair;
|
|
# the v0.3 root key is kept for the v0.3 SQLite verification path (R-VC-MIG-02).
|
|
# Generate with: python3 -c "import nacl.utils; print(nacl.utils.random(32).hex())"
|
|
PRAXIS_VC_ISSUER_KEY=
|
|
|
|
# Issuer URL (D-042). The public base URL for VC issuer + key identifiers.
|
|
# v0.4 changes the default to /issuers/v0.4 (v0.3 VCs keep their v0.3 URLs
|
|
# embedded in their proofs — verification fetches keys by id, not by URL).
|
|
PRAXIS_ISSUER_URL=https://praxis.example/issuers/v0.4 |