Environment Variables
“Required” is contextual: startup validation requires Slack/model/default GitHub values plus credentials for the selected runtime and GitHub mode. Integration-specific values are required only when that integration is used. Never put real credentials in documentation.
| Name | Default | Requirement | Purpose | Sensitivity | Area |
|---|---|---|---|---|---|
|
empty |
Runtime required |
Slack Web API credential |
Secret |
Slack |
|
empty |
Required in HTTP mode |
HTTP request verification |
Secret |
Slack |
|
empty |
Required in Socket Mode |
Socket authentication |
Secret |
Slack |
|
false |
Optional |
Development-only signature bypass |
Sensitive control |
Slack |
|
empty |
Required when Galileo key absent |
Direct/fallback model credential |
Secret |
Model |
|
configured Roche model name |
Optional |
Model identifier |
No |
Model |
|
false in code; true in example/Helm |
Optional |
Select gateway routing |
No |
Model |
|
empty |
Required for gateway unless OpenAI key used |
Gateway credential |
Secret |
Model |
|
Roche US gateway shown in example |
Optional |
OpenAI-compatible gateway URL |
Internal endpoint |
Model |
|
slack-kb-agent |
Optional |
Portkey metadata application |
No |
Model |
|
empty |
Legacy/optional |
Pipeline token when no authorization service credential is supplied |
Secret |
GitHub |
|
installation |
Optional |
installation, delegated, or hybrid |
No |
GitHub |
|
true |
Hybrid only |
Allow installation fallback |
Sensitive control |
GitHub |
|
empty |
Installation/hybrid required |
GitHub App identity |
Sensitive |
GitHub |
|
empty |
Delegated/hybrid required |
OAuth client identity |
Sensitive |
GitHub |
|
empty |
Delegated/hybrid required |
OAuth exchange credential |
Secret |
GitHub |
|
empty |
Installation/hybrid required |
Signs App JWTs |
Secret |
GitHub |
|
empty |
Installation/hybrid required |
Installation selection |
Sensitive |
GitHub |
|
empty |
Delegated/hybrid required |
OAuth callback URL |
Internal URL |
GitHub |
|
empty |
Delegated/hybrid and Confluence storage required |
Encrypt stored tokens |
Secret |
GitHub/Confluence |
|
600 |
Optional |
OAuth state lifetime |
No |
GitHub |
|
empty |
Optional |
SQLite authorizations/state; empty is memory |
Filesystem path |
Persistence |
|
empty |
Optional |
SQLite drafts; empty is memory |
Filesystem path |
Persistence |
|
empty |
Runtime required |
Default target owner |
No |
GitHub |
|
empty |
Runtime required |
Default target repository |
No |
GitHub |
|
main |
Optional |
PR base branch |
No |
GitHub |
|
docs/pages |
Optional |
Target content root |
No |
GitHub |
|
generated |
Optional |
Generated-content subdirectory |
No |
GitHub |
|
empty (deny all) |
Operationally required |
Comma-separated exact or owner wildcard targets |
Authorization control |
GitHub |
|
mdx |
Optional |
md or mdx |
No |
GitHub |
|
5 |
Optional |
Parser link limit |
No |
Runtime |
|
86400 |
Optional |
Draft expiry timestamp |
No |
Persistence |
|
3000 |
Optional |
HTTP listen port |
No |
Runtime |
|
empty |
Jira required |
Jira site root |
Internal URL |
Jira |
|
empty |
Required for basic auth |
Jira account identity |
Personal/sensitive |
Jira |
|
empty |
Jira required |
Jira credential |
Secret |
Jira |
|
empty |
Required unless flag supplied |
Default project |
No |
Jira |
|
Task |
Optional |
Default issue type |
No |
Jira |
|
false |
Optional |
Create Jira unless command overrides |
No |
Jira |
|
basic |
Optional |
basic or bearer |
No |
Jira |
|
3 |
Optional |
2 or 3 |
No |
Jira |
|
adf |
Optional |
adf or text |
No |
Jira |
|
true |
Optional |
TLS certificate verification |
Security control |
Jira |
|
empty |
Optional pair |
Access service identity |
Sensitive |
Jira |
|
empty |
Optional pair |
Access service credential |
Secret |
Jira |
|
empty |
Confluence required |
MCP endpoint |
Internal URL |
Confluence |
|
empty |
Confluence required |
Gateway identity |
Sensitive |
Confluence |
|
empty |
Confluence required |
Gateway credential |
Secret |
Confluence |
|
create_page |
Optional |
MCP tool name |
No |
Confluence |
|
empty |
Required unless command flag |
Default space |
No |
Confluence |
|
empty |
Optional |
Default parent page |
No |
Confluence |
|
/tmp/knowledge-assistant/confluence |
Optional |
Encrypted per-user PAT files |
Sensitive path |
Confluence |
.env.example also lists MAX_THREAD_MESSAGES, but the Python Settings model does not define or use it. It currently has no application effect.
|