# Arbo engine — real .env lives on irv-ml1 (gitignored), this is the template. # Copy to .env on the host and fill the secrets. See README.md for provisioning. # Image comfy-dev builds + pushes (pin a tag; bump on code/schema change only): ARBO_IMAGE=gitea.phasefinal.com/vh/arbo:0.11.0 # Published port on irv-ml1 (reachable over WireGuard at 10.100.79.3:): ARBO_PORT=8200 ARBO_BIND=0.0.0.0 # Run-as ownership — must match /worktank owner so basedir writes land clean: ARBO_UID=1000 ARBO_GID=1000 # Host path of the comfy-dev catalog checkout (the git pull target, mounted ro): ARBO_CATALOG_DIR=/worktank/arbo/repo # ── Secrets (DO NOT COMMIT REAL VALUES) ────────────────────────────── # ENGINE_TOKEN: bearer auth is intentionally OFF (operator decision 2026-06-13, # WireGuard = the boundary). Leave it UNSET — the protected-gate no-ops only # when the var is ABSENT (an empty `ENGINE_TOKEN=` still gates), and the compose # injection is commented out to match. To re-lock: un-comment the compose line # `- ENGINE_TOKEN=${ENGINE_TOKEN}`, mint a bearer (`openssl rand -hex 32`), set # it below, `compose up -d`. # ENGINE_TOKEN= # GRANITE_KEY: the LiteLLM virtual key scoped to arbo. The 'arbo-prompt-enhance' # vkey (comfy-dev, issued 2026-06-09) is extended to reach BOTH granite-4.1-8b # (gen step) AND qwen3.5-9b-fp8 (vision / hero judge step, v0.11.3+). # Reuse or rotate it; do NOT use the master sk-corvid key. GRANITE_KEY=