diff --git a/.env.example b/.env.example new file mode 100644 index 0000000..7fc2d86 --- /dev/null +++ b/.env.example @@ -0,0 +1,50 @@ +# Local development environment (.env file) +# Copy to .env and fill in your local/dev URLs +# .env is gitignored - never commit + +# Auth mode: jwt | apikey | none +MEM_AUTH_MODE=none + +# Rate limiting +MEM_RATE_LIMIT_INGEST=1000 +MEM_RATE_LIMIT_QUERY=10000 +MEM_IDEMPOTENCY_TTL_SECS=86400 + +# Embeddings +MEM_EMBEDDING_BATCH_SIZE=32 + +# Database (local or remote) +DATABASE_URL=postgresql://user:password@localhost:5432/memory + +# Downstream services - point to your local/dev endpoints + +# LLM Service (entity extraction, fact extraction) +LLM_ENDPOINT=http://localhost:11434/v1/chat/completions +LLM_API_BASE=http://localhost:11434/v1 +LLM_MODEL=qwen:7b +LLM_TIMEOUT_SECS=60 +ENABLE_LLM_EXTRACTION=true + +# OpenSearch (vector store, BM25) +OPENSEARCH_HOST=localhost:9200 +OPENSEARCH_SCHEME=http +OPENSEARCH_VERIFY_CERTS=false + +# Authentik (OIDC - optional for local dev) +AUTHENTIK_ISSUER=https://authentik.riotpiao.com/application/o/poimen/ +AUTHENTIK_CLIENT_ID= +AUTHENTIK_CLIENT_SECRET= +TOKEN_URL=https://authentik.riotpiao.com/application/o/token/ +AUTHENTIK_VERIFY_SSL=false + +# Temporal (workflow orchestration - future) +TEMPORAL_ENDPOINT=localhost:7233 +TEMPORAL_NAMESPACE=poimen + +# API Gateway (route optimization - future) +GATEWAY_URL=http://localhost:8080 + +# Server config +MEM_PORT=8080 +MEM_API_KEY=test-key +MEM_HOME=/tmp diff --git a/LOCAL_DEV.md b/LOCAL_DEV.md new file mode 100644 index 0000000..c11b6e4 --- /dev/null +++ b/LOCAL_DEV.md @@ -0,0 +1,84 @@ +# Local Development Setup + +Running poimen-memory locally for development. + +## Quick Start + +1. **Copy env template**: + ```bash + cp .env.example .env + ``` + +2. **Edit `.env`** with your local endpoints: + ```bash + # Edit .env with your local/dev service URLs + # Example: LLM service on localhost:11434, OpenSearch on localhost:9200 + ``` + +3. **Run the service**: + ```bash + cargo run --release -- serve --port 8080 + ``` + +The application loads configuration from `.env` (via `dotenvy` or similar). + +## `.env` File + +**Location**: Project root (`.env`) +**Status**: Gitignored - never committed +**Template**: `.env.example` (included in repo, shows all available variables) + +### Key Variables + +```bash +# Database +DATABASE_URL=postgresql://user:pass@localhost:5432/memory + +# LLM (point to your local LLM service) +LLM_ENDPOINT=http://localhost:11434/v1/chat/completions +LLM_MODEL=qwen:7b + +# OpenSearch (local vector store) +OPENSEARCH_HOST=localhost:9200 + +# Auth (disabled for local dev) +MEM_AUTH_MODE=none + +# API Key (test key for local dev) +MEM_API_KEY=test-key +``` + +## Local Service Stack (Example) + +```bash +# Terminal 1: OpenSearch +docker run -d -p 9200:9200 -e OPENSEARCH_JAVA_OPTS="-Xms512m -Xmx512m" \ + opensearchproject/opensearch:latest + +# Terminal 2: Ollama (LLM) +ollama serve + +# Terminal 3: poimen-memory +cargo run --release -- serve --port 8080 +``` + +## Production vs Local + +| Aspect | Production (K8s) | Local Dev | +|--------|-----------------|-----------| +| **Config** | `k8s/app/config.yaml` (SOPS-encrypted) | `.env` (gitignored) | +| **Injection** | ConfigMap via `envFrom:` | dotenv via `dotenvy` crate | +| **Services** | Cluster-internal DNS | localhost/127.0.0.1 | +| **Auth** | JWT (Authentik) | None (disabled) | +| **Commit?** | Yes (encrypted) | No (gitignored) | + +## Switching to Production Config + +To run against production services (not recommended locally): +1. Edit `.env` with production URLs +2. Set credentials appropriately +3. Ensure network access to production services + +--- + +See `.env.example` for all available environment variables. diff --git a/k8s/app/kustomization.yaml b/k8s/app/kustomization.yaml index 6e0eed2..7ec3af7 100644 --- a/k8s/app/kustomization.yaml +++ b/k8s/app/kustomization.yaml @@ -6,7 +6,6 @@ resources: - deployment.yaml - service.yaml - config.yaml # Production config (SOPS-encrypted) - # config.local.yaml # Optional: plaintext local/dev overrides generators: - secret-generator.yaml