Files
ai-agent/config/config.example.yaml
T
t 2bbf42b741 refactor(auth): delegate access control to be-system
Remove Agent Desk users, roles, login sessions, tokens, and local permission persistence. Expose the backend as an embeddable ai-agent module with host-provided subject lookup and operation authorization callbacks, and complete the frontend/backend repository split.
2026-08-21 00:41:07 +08:00

123 lines
5.2 KiB
YAML

language: zh-CN
server:
port: 8083
# Public address of the independently deployed frontend.
frontendUrl: http://127.0.0.1:3000
cors:
# Browser CORS allowlist. In production, replace this with the actual frontend or embedded-site domains, such as https://support.example.com.
# Leave it empty to reject cross-origin browser requests. Same-origin and non-browser calls are still supported.
allowedOrigins:
- http://127.0.0.1:3000
- http://localhost:3000
db:
# Database driver. Supported values: sqlite, mysql, postgres (postgresql is also accepted).
type: sqlite
# Database connection string.
# SQLite example: file:./data/app.db?_busy_timeout=5000
# MySQL example: user:password@tcp(127.0.0.1:3306)/cs_ai_agent_db?charset=utf8mb4&parseTime=True&multiStatements=true&loc=Local
# For MySQL, keep parseTime=True so datetime fields are scanned into Go time values correctly.
# PostgreSQL example: host=127.0.0.1 user=cs_ai_agent password=change-me dbname=cs_ai_agent port=5432 sslmode=disable TimeZone=Asia/Shanghai
dsn: file:./data/app.db?_busy_timeout=5000
# Maximum number of idle connections kept in the pool. Values <= 0 use the database/sql default.
maxIdleConns: 5
# Maximum number of open connections. Values <= 0 mean no explicit limit.
maxOpenConns: 20
# Maximum time an idle connection may stay in the pool, in seconds. Values <= 0 leave it unset.
connMaxIdleTimeSeconds: 300
# Maximum lifetime of a connection, in seconds. Values <= 0 leave it unset.
connMaxLifetimeSeconds: 1800
logger:
level: info
format: text
addSource: false
storage:
# Default file storage provider used for uploads. Supported values: local, oss.
# Empty value is treated as local by the backend.
default: local
# Maximum size of a single uploaded file, in MB. Values <= 0 fall back to the backend default.
maxUploadSizeMB: 20
local:
# Files are written under this directory, relative to the process working directory unless an absolute path is used.
root: data/storage
# Public URL prefix used when returning local file URLs. The server must expose this path as static files.
# Example: storage key "images/a.png" becomes "/storage/images/a.png".
baseUrl: http://127.0.0.1:8083/storage
oss:
# Aliyun OSS endpoint. Both "oss-cn-hangzhou.aliyuncs.com" and "https://oss-cn-hangzhou.aliyuncs.com" are accepted.
endpoint: ""
# OSS bucket name.
bucket: ""
# OSS access credentials. Keep the secret out of committed environment-specific config.
accessKeyId: ""
accessKeySecret: ""
# Optional public CDN/custom domain prefix for object URLs, for example https://files.example.com.
# If empty, public buckets use the default bucket endpoint URL; private buckets use signed URLs.
baseUrl: ""
# Set to true for private buckets. Private buckets return temporary signed URLs for reads.
private: false
# Expiration for generated OSS signed GET URLs, in seconds. Values <= 0 fall back to 600.
signedUrlExpireSeconds: 600
vectorDB:
type: qdrant # qdrant, lancedb
qdrant:
host: 127.0.0.1
grpcPort: 6334
apiKey: ""
useTls: false
# LanceDB requires building the backend with -tags lancedb and LanceDB native libraries.
lancedb:
path: data/lancedb
mcp:
# Global switch for MCP tool integration.
# When false, MCP tool catalog, debug endpoints, and runtime tool calls are disabled.
enabled: true
# MCP server registry. Each map key is the serverCode used by toolCode values like "system/tool_name".
servers:
system:
# Whether this MCP server is available for catalog listing, debug calls, and agent runtime calls.
enabled: true
# Streamable HTTP MCP endpoint. The built-in system server is exposed by this backend at /api/mcp.
endpoint: "http://127.0.0.1:8083/api/mcp"
# Connection and request timeout in milliseconds. Values <= 0 fall back to 15000.
timeoutMs: 15000
# Extra HTTP headers sent to this MCP server on every request, for example Authorization or tenant headers.
headers: {}
wxWork:
# Whether to enable WeCom features.
# When set to false, the WeCom SDK is not initialized, and customer service callbacks and app notifications are unavailable.
enabled: false
# WeCom corporate ID.
# Example: wwxxxxxxxxxxxxxxxx, from the WeCom admin console.
corpId:
# WeCom app secret.
# Used by the backend to obtain access tokens and user identities. Keep it confidential.
corpSecret: ""
# AgentID of the WeCom custom app, used for app notifications.
agentId:
# Private key for decrypting WeCom callbacks.
rsaPrivateKey: ""
# WeCom callback token.
token: ""
# WeCom message encryption/decryption EncodingAESKey.
encodingAESKey: ""
notify:
# Whether to enable WeCom app message notifications.
enabled: false
# Default list of system user IDs to receive notifications. If the target business user has a bound WeCom identity, that user is preferred.
# System user IDs are mapped to WeCom member IDs through identity bindings before messages are sent.
toUsers: []
# Whether to send confidential messages.
safe: false
# Whether to enable duplicate message checks.
enableDuplicateCheck: true
# Duplicate message check window, in seconds.
duplicateCheckInterval: 1800