# Optional external generative model. Leave empty for infrastructure-only tests. DEEPSEEK_API_KEY= # Required before using AI rule interpretation or creating rule drafts. # Generate a dedicated value with: openssl rand -hex 32 RULE_GENERATION_RECEIPT_SECRET=replace-with-dedicated-64-hex-random-value # Dedicated HMAC key for WP12 governance audit evidence seals. # Generate independently with: openssl rand -hex 32 AUDIT_EVIDENCE_SECRET=replace-with-dedicated-64-hex-random-value AUDIT_EVIDENCE_KEY_VERSION=v1 # Create this key in the local n8n UI after owner setup, then restart backend. N8N_API_KEY= # External business data-source pools. This does not configure the platform DB. DATASOURCE_CREDENTIAL_MASTER_KEY=replace-with-base64-32-byte-key DATASOURCE_CREDENTIAL_KEY_VERSION=v1 DATASOURCE_POOL_SIZE=2 DATASOURCE_MAX_OVERFLOW=3 DATASOURCE_POOL_TIMEOUT=10 DATASOURCE_POOL_RECYCLE=1800 DATASOURCE_POOL_IDLE_TTL=900 DATASOURCE_MAX_IDLE_POOLS=20 DATASOURCE_QUERY_TIMEOUT=30 DATASOURCE_CERT_DIR=/etc/dataops-platform/datasource-certs # Runner task tokens are short-lived and contain no data-source credentials. RUNNER_TASK_TOKEN_SECRET=replace-with-at-least-32-random-bytes RUNNER_HTTP_ALLOWED_HOSTS= # Open only after disabled-deploy/canary/rollback/restart acceptance succeeds. DATA_FACTORY_ACTIVATION_ENABLED=false # DataOps MCP processes fail closed when any identity scope is empty. # Generate a fresh UUID correlation ID for each agent session. DATAOPS_MCP_SUBJECT= DATAOPS_MCP_ROLES= DATAOPS_MCP_BUSINESS_DOMAINS= DATAOPS_MCP_ENVIRONMENTS= DATAOPS_MCP_CORRELATION_ID=