127 lines
5.9 KiB
Bash
127 lines
5.9 KiB
Bash
# ============================================================================
|
|||
|
|
# Hermy HQ — environment template
|
||
|
|
# ----------------------------------------------------------------------------
|
||
|
|
# Copy this file to `.env` and fill in your own values:
|
||
|
|
# cp .env.example .env
|
||
|
|
#
|
||
|
|
# NEVER commit your real .env. The values below are FAKE placeholders — replace
|
||
|
|
# every one of them. When you deploy, set the same vars in your host (Vercel →
|
||
|
|
# Project → Settings → Environment Variables).
|
||
|
|
# ============================================================================
|
||
|
|
|
||
|
|
|
||
|
|
# ─── REQUIRED · Core ─────────────────────────────────────────────
|
||
|
|
# The dashboard will not run without these.
|
||
|
|
|
||
|
|
# Postgres connection string. This same database is the message bus shared
|
||
|
|
# with your Hermes bridge. Get one from Neon, Prisma Postgres, Supabase, or
|
||
|
|
# Vercel Postgres. Keep sslmode=require for hosted databases.
|
||
|
|
DATABASE_URL="postgresql://user:pass@host:5432/db?sslmode=require"
|
||
|
|
|
||
|
|
# Same Postgres URL again (some tooling reads POSTGRES_URL). Usually identical
|
||
|
|
# to DATABASE_URL.
|
||
|
|
POSTGRES_URL="postgresql://user:pass@host:5432/db?sslmode=require"
|
||
|
|
|
||
|
|
# Public URL of the site. Use http://localhost:3000 locally, and your real
|
||
|
|
# domain in production (e.g. https://your-app.vercel.app).
|
||
|
|
NEXTAUTH_URL="http://localhost:3000"
|
||
|
|
|
||
|
|
# Secret used to sign NextAuth sessions. Generate one with:
|
||
|
|
# openssl rand -base64 32
|
||
|
|
NEXTAUTH_SECRET="your-generated-secret"
|
||
|
|
|
||
|
|
# Google OAuth credentials for login. Create an OAuth 2.0 Client (type: Web)
|
||
|
|
# at https://console.cloud.google.com/apis/credentials and add the redirect
|
||
|
|
# URI: <NEXTAUTH_URL>/api/auth/callback/google
|
||
|
|
GOOGLE_CLIENT_ID="xxxxxxxxxxxx.apps.googleusercontent.com"
|
||
|
|
GOOGLE_CLIENT_SECRET="your-google-client-secret"
|
||
|
|
|
||
|
|
# Comma-separated allowlist of emails permitted to sign in. Anyone else is
|
||
|
|
# rejected even with a valid Google account.
|
||
|
|
ALLOWED_EMAILS="you@example.com,teammate@example.com"
|
||
|
|
|
||
|
|
# Your display name, shown in the dashboard UI. Public (NEXT_PUBLIC_).
|
||
|
|
NEXT_PUBLIC_OWNER_NAME="Owner"
|
||
|
|
|
||
|
|
# Public base URL of the site. Usually the same as NEXTAUTH_URL. Public.
|
||
|
|
NEXT_PUBLIC_BASE_URL="http://localhost:3000"
|
||
|
|
|
||
|
|
|
||
|
|
# ─── Hermes / bridge ─────────────────────────────────────────────
|
||
|
|
# How the website coordinates with your local Hermes agent via the bridge.
|
||
|
|
# The bridge (hermes-bridge/) reads HERMES_* and DATABASE_URL on your machine;
|
||
|
|
# the website reads the shared ones below for scheduling and internal calls.
|
||
|
|
|
||
|
|
# Kanban board slug the bridge mirrors into HermesTask.
|
||
|
|
HERMES_BOARD="default"
|
||
|
|
|
||
|
|
# Path to the `hermes` CLI on the bridge machine, if it is not already on PATH.
|
||
|
|
HERMES_BIN="hermes"
|
||
|
|
|
||
|
|
# Path to your Hermes memory-wiki root (git-tracked markdown) that the bridge
|
||
|
|
# mirrors into HermesMemory. Set on the bridge machine.
|
||
|
|
HERMES_WIKI="/path/to/hermes/wiki"
|
||
|
|
|
||
|
|
# Hour of day (0-23, local time) to generate the Chief-of-Staff daily brief.
|
||
|
|
BRIEF_HOUR="7"
|
||
|
|
|
||
|
|
# Shared secret required by internal API routes (agent bus, bridge callbacks).
|
||
|
|
# Generate with: openssl rand -hex 32
|
||
|
|
INTERNAL_API_SECRET="your-internal-api-secret"
|
||
|
|
|
||
|
|
# Shared secret required by scheduled/cron endpoints so only your scheduler can
|
||
|
|
# trigger them. Generate with: openssl rand -hex 32
|
||
|
|
CRON_SECRET="your-cron-secret"
|
||
|
|
|
||
|
|
|
||
|
|
# ─── OPTIONAL · AI providers ─────────────────────────────────────
|
||
|
|
# Only needed for features that call an LLM (briefs, scoring, content). Leave
|
||
|
|
# blank to disable those features.
|
||
|
|
|
||
|
|
# OpenAI API key — https://platform.openai.com/api-keys
|
||
|
|
OPENAI_API_KEY="sk-xxxxx"
|
||
|
|
|
||
|
|
# OpenRouter API key (multi-model gateway) — https://openrouter.ai/keys
|
||
|
|
OPENROUTER_API_KEY="sk-or-xxxxx"
|
||
|
|
|
||
|
|
# xAI (Grok) API key — https://console.x.ai
|
||
|
|
XAI_API_KEY="xai-xxxxx"
|
||
|
|
|
||
|
|
# Brave Search API key, used for web lookups — https://brave.com/search/api
|
||
|
|
BRAVE_API_KEY="your-brave-api-key"
|
||
|
|
|
||
|
|
|
||
|
|
# ─── OPTIONAL · YouTube ──────────────────────────────────────────
|
||
|
|
# Only needed for the YouTube idea/script features. Get a key from the Google
|
||
|
|
# Cloud console (enable "YouTube Data API v3").
|
||
|
|
|
||
|
|
YOUTUBE_API_KEY="your-youtube-api-key"
|
||
|
|
# The channel ID you want to pull stats/videos for (starts with UC...).
|
||
|
|
YOUTUBE_CHANNEL_ID="UCxxxxxxxxxxxxxxxxxxxxxx"
|
||
|
|
|
||
|
|
|
||
|
|
# ─── OPTIONAL · X / Twitter ──────────────────────────────────────
|
||
|
|
# Only needed for Content OS metrics. Create an app at
|
||
|
|
# https://developer.twitter.com and copy the Bearer token.
|
||
|
|
TWITTER_BEARER_TOKEN="your-twitter-bearer-token"
|
||
|
|
|
||
|
|
|
||
|
|
# ─── OPTIONAL · Notion ───────────────────────────────────────────
|
||
|
|
# Only needed if you sync clients/data from Notion. Create an integration at
|
||
|
|
# https://www.notion.so/my-integrations and share the relevant pages with it.
|
||
|
|
NOTION_API_KEY="secret_xxxxx"
|
||
|
|
|
||
|
|
|
||
|
|
# ─── OPTIONAL · Client Pulse ─────────────────────────────────────
|
||
|
|
# The Client Pulse board reads client-health data from your Postgres. This
|
||
|
|
# template ships the dashboard + API only — wire up your own ingestion (a cron,
|
||
|
|
# a bot, a webhook) to populate it. Skip this block if you don't use the board.
|
||
|
|
# Admin secret for the Client Pulse admin/map-chat routes (falls back to CRON_SECRET).
|
||
|
|
CLIENT_PULSE_ADMIN_SECRET="your-client-pulse-admin-secret"
|
||
|
|
|
||
|
|
|
||
|
|
# ─── OPTIONAL · Trading / Watchlist Radar ────────────────────────
|
||
|
|
# Only needed if you use the trading-related widgets. Leave blank otherwise.
|
||
|
|
# A public wallet address to display balances/positions for (read-only).
|
||
|
|
HL_WALLET="0xyour-wallet-address"
|