# Copy to .env and fill in. Never commit the real .env. # Note: ACME_EMAIL / Traefik itself are configured separately in ~/traefik/.env — # Traefik is shared infra, not part of this stack (see docker-compose.yml comment). # --- domain / TLS --- MATRIX_SERVER_NAME=matrix.apps.williamturner.eu AGENT_HOSTNAME=agent.apps.williamturner.eu HERMES_DASHBOARD_HOSTNAME=hermes.apps.williamturner.eu # Set to true ONLY for the first-boot window while creating the bot account, # then back to false (or unset) and redeploy. See README. MATRIX_ALLOW_REGISTRATION=false # --- gitea --- GITEA_URL=https://gitea.apps.williamturner.eu GITEA_TOKEN= GITEA_WEBHOOK_SECRET= # Image the agent runs from — built and pushed by .gitea/workflows/build.yml GITEA_REGISTRY_IMAGE=gitea.apps.williamturner.eu///claude-agent:latest # --- claude --- # Run `claude setup-token` interactively (needs a browser + Claude Pro/Max subscription) # to generate this — it's a long-lived OAuth token, not an API key. CLAUDE_CODE_OAUTH_TOKEN= # --- litellm (local LLM gateway — used by Hermes, see litellm-config.yaml) --- OPENROUTER_API_KEY= # Any random string; also used as litellm's general_settings.master_key. LITELLM_MASTER_KEY= # --- hermes (the only agent with a Matrix presence — see README) --- # Your own Matrix ID — Hermes only responds to this user, and only when @mentioned # in a room (free-response in DMs). MATRIX_HUMAN_USER_ID=@william:matrix.apps.williamturner.eu # Access token for the @hermes bot account — register it on the homeserver, then log # in as it via /_matrix/client/v3/login to get this token (see README). HERMES_MATRIX_ACCESS_TOKEN= # Any random string — bearer key for Hermes's own OpenAI-compatible API server # (internal network only, not published anywhere). HERMES_API_SERVER_KEY= # --- hermes web dashboard (hermes.apps.williamturner.eu) --- # Two independent auth layers: Hermes's own login (basic auth — its docs call this # "not suitable for direct public-internet exposure" alone) plus a Traefik-level basic # auth gate in front of it. Both required, different credentials recommended. HERMES_DASHBOARD_USERNAME=william HERMES_DASHBOARD_PASSWORD= # 32+ random bytes — `openssl rand -base64 32` HERMES_DASHBOARD_SECRET= # htpasswd-format "user:hash" for Traefik's basicauth middleware. Generate with: # python3 -c "import crypt; print('someuser:' + crypt.crypt('somepassword', crypt.mksalt(crypt.METHOD_SHA512)))" TRAEFIK_HERMES_AUTH_HASH= # --- portainer (GitOps redeploy) --- PORTAINER_STACK_WEBHOOK_URL= # --- gitea actions runner --- ACT_RUNNER_REGISTRATION_TOKEN=