From d1c3bec5f160bc29baa1b186a761c0ad6bec94c5 Mon Sep 17 00:00:00 2001 From: Gang Tao Date: Wed, 23 Sep 2026 12:58:23 +0800 Subject: [PATCH] fix(compose): pass the anonymous-access and MCP env vars through to the app container docker-compose.yml lists the env vars it forwards to the app explicitly, so TPK_ANONYMOUS_ACCESS / TPK_ANONYMOUS_DAILY_TOKEN_LIMIT (#95) and TPK_MCP_HTTP_ENABLED / TPK_MCP_ALLOWED_HOSTS (#74) set in .env never reached the container -- the login page could not offer anonymous access on a compose stack. Both compose files now forward them; the k8s README lists them. Co-Authored-By: Claude Fable 5.1 --- deploy/k8s/README.md | 2 ++ docker-compose.allinone.yml | 4 ++++ docker-compose.yml | 4 ++++ 3 files changed, 10 insertions(+) diff --git a/deploy/k8s/README.md b/deploy/k8s/README.md index 140aeca..1ff1f48 100644 --- a/deploy/k8s/README.md +++ b/deploy/k8s/README.md @@ -246,6 +246,8 @@ manifests, others stubbed as commented-out examples): | `TPK_DB_BACKEND` | `timeplusd` (Enterprise, mutable streams) or `proton` | | `TIMEPLUS_DATABASE` | database all tpk streams live under (default `tpk`; app-only: user needs CREATE DATABASE) | | `TPK_DB_WAIT_SECONDS` | how long the app waits for the DB on boot | +| `TPK_ANONYMOUS_ACCESS` / `TPK_ANONYMOUS_DAILY_TOKEN_LIMIT` | unauthenticated chat over the `public` corpus entries (off by default) and its shared daily token budget | +| `TPK_MCP_HTTP_ENABLED` / `TPK_MCP_ALLOWED_HOSTS` | the remote MCP endpoint (`/mcp`, on by default) and its optional `Host` allow-list | ### Custom corpus (`repos.toml`) via ConfigMap diff --git a/docker-compose.allinone.yml b/docker-compose.allinone.yml index c5f1f7e..fcde1a9 100644 --- a/docker-compose.allinone.yml +++ b/docker-compose.allinone.yml @@ -49,6 +49,10 @@ services: # Global fallback daily token budget for non-admin chat (0 = unlimited); # a role's own daily_token_limit (Users -> Roles) overrides it. TPK_DAILY_TOKEN_LIMIT: ${TPK_DAILY_TOKEN_LIMIT:-} + TPK_ANONYMOUS_ACCESS: ${TPK_ANONYMOUS_ACCESS:-} + TPK_ANONYMOUS_DAILY_TOKEN_LIMIT: ${TPK_ANONYMOUS_DAILY_TOKEN_LIMIT:-} + TPK_MCP_HTTP_ENABLED: ${TPK_MCP_HTTP_ENABLED:-} + TPK_MCP_ALLOWED_HOSTS: ${TPK_MCP_ALLOWED_HOSTS:-} # Semantic-extraction (graphify) backend. `auto` is ambiguous when both # API keys are set (picks claude), so set this to openai|claude to choose. # The model comes from OPENAI_MODEL / ANTHROPIC_MODEL (graphify reads them). diff --git a/docker-compose.yml b/docker-compose.yml index 17cc9cb..ace35ac 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -94,6 +94,10 @@ services: # Global fallback daily token budget for non-admin chat (0 = unlimited); # a role's own daily_token_limit (Users -> Roles) overrides it. TPK_DAILY_TOKEN_LIMIT: ${TPK_DAILY_TOKEN_LIMIT:-} + TPK_ANONYMOUS_ACCESS: ${TPK_ANONYMOUS_ACCESS:-} + TPK_ANONYMOUS_DAILY_TOKEN_LIMIT: ${TPK_ANONYMOUS_DAILY_TOKEN_LIMIT:-} + TPK_MCP_HTTP_ENABLED: ${TPK_MCP_HTTP_ENABLED:-} + TPK_MCP_ALLOWED_HOSTS: ${TPK_MCP_ALLOWED_HOSTS:-} # Semantic-extraction (graphify) backend: openai|claude|auto. `auto` is # ambiguous when both API keys are set; model comes from OPENAI_MODEL / # ANTHROPIC_MODEL.