178 lines
7.4 KiB
Text
178 lines
7.4 KiB
Text
# Optional local config file for telesrv.
|
||
# Copy to .env for local development. Do not commit real tokens or passwords.
|
||
# Complete reference / 完整参数手册:
|
||
# docs/configuration.en.md
|
||
# docs/configuration.zh-CN.md
|
||
|
||
TELESRV_LISTEN=0.0.0.0:2398
|
||
TELESRV_ADVERTISE_IP=127.0.0.1
|
||
TELESRV_DC=2
|
||
TELESRV_DEV_AUTH_CODE=12345
|
||
TELESRV_AUTH_CODE_TTL=5m
|
||
TELESRV_AUTH_CODE_MAX_ATTEMPTS=5
|
||
# Unauthenticated login-code issuance uses the same limits for existing and
|
||
# unknown phones. Phone numbers are SHA-256 digested before becoming Redis keys.
|
||
TELESRV_AUTH_CODE_PHONE_RATE_LIMIT=5
|
||
TELESRV_AUTH_CODE_AUTH_KEY_RATE_LIMIT=20
|
||
TELESRV_AUTH_CODE_RATE_WINDOW=10m
|
||
|
||
# MTProto admission and shared inbound RPC budgets. Negative connection/handshake limits disable
|
||
# that gate; non-positive RPC values fall back to the built-in safe defaults.
|
||
TELESRV_MTPROTO_MAX_CONNECTIONS=200000
|
||
TELESRV_MTPROTO_MAX_CONNECTIONS_PER_IP=4096
|
||
TELESRV_MTPROTO_MAX_CONCURRENT_HANDSHAKES=256
|
||
TELESRV_MTPROTO_RPC_MAX_INFLIGHT=32
|
||
TELESRV_MTPROTO_RPC_QUEUE_SIZE=64
|
||
TELESRV_MTPROTO_RPC_TIMEOUT=30s
|
||
TELESRV_MTPROTO_RPC_GLOBAL_WORKERS=256
|
||
TELESRV_MTPROTO_RPC_GLOBAL_MAX_TASKS=8192
|
||
TELESRV_MTPROTO_RPC_GLOBAL_MAX_BYTES=536870912
|
||
# Process-wide in-flight transport wire + decrypted plaintext reservation.
|
||
TELESRV_MTPROTO_INBOUND_FRAME_GLOBAL_MAX_BYTES=536870912
|
||
# Per-connection outbound mailboxes (normal/control) and process-wide resend pending bodies.
|
||
TELESRV_MTPROTO_OUTBOUND_QUEUE_SIZE=128
|
||
TELESRV_MTPROTO_OUTBOUND_CONTROL_QUEUE_SIZE=32
|
||
TELESRV_MTPROTO_OUTBOUND_TRACKED_GLOBAL_MAX_BYTES=536870912
|
||
# Concurrent encrypted wire/codec/obfuscation scratch (shared bounded pool, not per connection).
|
||
TELESRV_MTPROTO_OUTBOUND_WRITE_GLOBAL_MAX_BYTES=536870912
|
||
|
||
# Optional login-email verification. When enabled, accounts with a confirmed
|
||
# login email receive login codes by email; REQUIRE_SETUP also forces new/legacy
|
||
# accounts without a login email to set one during the phone login flow.
|
||
TELESRV_LOGIN_EMAIL_ENABLE=false
|
||
TELESRV_LOGIN_EMAIL_REQUIRE_SETUP=false
|
||
TELESRV_LOGIN_EMAIL_CODE_LENGTH=6
|
||
TELESRV_SMTP_HOST=
|
||
TELESRV_SMTP_PORT=587
|
||
TELESRV_SMTP_USERNAME=
|
||
TELESRV_SMTP_PASSWORD=
|
||
TELESRV_SMTP_FROM=
|
||
TELESRV_SMTP_FROM_NAME=telesrv
|
||
TELESRV_SMTP_TLS=starttls
|
||
TELESRV_SMTP_TIMEOUT=10s
|
||
|
||
# Client-visible telesrv links. This is an HTTP(S) URL, not a listen address.
|
||
# Production uses https://telesrv.net. For local link/deeplink smoke tests use
|
||
# http://127.0.0.1:2401. Invalid schemes, credentials, query strings, fragments,
|
||
# or a missing host fail startup instead of silently falling back.
|
||
TELESRV_PUBLIC_BASE_URL=https://telesrv.net
|
||
|
||
# Public landing pages auto-open this custom scheme. It must match the scheme
|
||
# registered by every patched client build; tg/http/https are rejected.
|
||
TELESRV_PUBLIC_APP_SCHEME=telesrv
|
||
|
||
# Web client target and display brand used by public landing pages.
|
||
TELESRV_PUBLIC_WEB_BASE_URL=https://web.telesrv.net
|
||
TELESRV_PUBLIC_APP_NAME=telesrv
|
||
|
||
# Product site/download page linked from the "Download" button in the public
|
||
# landing pages' header.
|
||
TELESRV_PUBLIC_DOWNLOAD_URL=https://owpengram.org
|
||
|
||
# Admin API / Admin UI 配置
|
||
#
|
||
# TELESRV_ADMIN_API_TOKEN 是主服务 (cmd/telesrv) 暴露 Admin REST API 的鉴权 token,
|
||
# 也是 Admin UI (cmd/telesrv-admin) 调用 Admin API 时使用的凭证。
|
||
# 重要:主服务与 Admin UI 必须使用完全相同的 TELESRV_ADMIN_API_TOKEN,否则管理后台无法执行写操作。
|
||
TELESRV_ADMIN_API_TOKEN=
|
||
|
||
# TELESRV_ADMIN_UI_PASSWORD 是登录管理后台的密码;
|
||
# 也可改用 TELESRV_ADMIN_UI_TOKEN,二者至少填一个。
|
||
TELESRV_ADMIN_UI_PASSWORD=
|
||
TELESRV_ADMIN_UI_TOKEN=
|
||
|
||
# TELESRV_ADMIN_SESSION_KEY 用于加密 Admin UI 的登录 session cookie。
|
||
# 生产环境请使用至少 32 字节的强随机字符串,修改后会导致已登录会话失效。
|
||
TELESRV_ADMIN_SESSION_KEY=
|
||
|
||
# 主服务 Admin API 默认关闭;Admin UI 写操作需要同时配置强 token 并显式开启该 loopback 监听地址。
|
||
TELESRV_ADMIN_API_ADDR=
|
||
|
||
# Admin UI 监听地址,默认值通常无需修改;RTMP ingest 保留 2400。
|
||
TELESRV_ADMIN_UI_ADDR=127.0.0.1:2600
|
||
|
||
TELESRV_POSTGRES_DSN=postgres://telesrv:telesrv@127.0.0.1:5432/telesrv?sslmode=disable
|
||
TELESRV_REDIS_ADDR=127.0.0.1:6399
|
||
TELESRV_REDIS_PASSWORD=
|
||
TELESRV_REDIS_DB=0
|
||
|
||
# Bounded retention/GC. User/channel update rows are only pruned behind protocol-safe floors.
|
||
TELESRV_UPDATE_EVENT_RETENTION=168h
|
||
TELESRV_BOT_API_UPDATE_RETENTION=24h
|
||
TELESRV_ORPHAN_AUTH_KEY_RETENTION=24h
|
||
# Terminal failed outbox heads are kept briefly for diagnosis, then only the online
|
||
# delivery task is removed. The durable update remains available to getDifference.
|
||
TELESRV_OUTBOX_POISON_RETENTION=1m
|
||
TELESRV_OUTBOX_POISON_CLEANUP_INTERVAL=15s
|
||
TELESRV_RETENTION_INTERVAL=1h
|
||
TELESRV_RETENTION_BATCH=10000
|
||
|
||
# PFS temp->perm binding cache; write-side revoke/rebind invalidates entries precisely.
|
||
TELESRV_TEMP_KEY_CACHE_MAX_ENTRIES=262144
|
||
TELESRV_TEMP_KEY_CACHE_TTL=30m
|
||
|
||
# Optional. Enables Mapbox-backed map previews and TDesktop map picker config.
|
||
TELESRV_MAPBOX_TOKEN=
|
||
TELESRV_MAPTILE_CACHE_DIR=data/maptiles
|
||
|
||
TELESRV_LANGPACK_SEED_DIR=data/langpack
|
||
TELESRV_BLOB_DIR=data/blobs
|
||
TELESRV_STICKER_SEED_DIR=data/sticker-seed
|
||
|
||
# Optional public-link Web listener for /<username>, profile avatars,
|
||
# sticker/custom emoji sets, and shared folders. This is a host:port bind
|
||
# address without a URL scheme. It is not replaced by TELESRV_PUBLIC_BASE_URL.
|
||
# Production should keep it on loopback and reverse-proxy the documented routes
|
||
# through nginx; public canonical URLs use TELESRV_PUBLIC_BASE_URL.
|
||
TELESRV_PUBLIC_LINK_WEB_ADDR=127.0.0.1:2401
|
||
|
||
# AI compose for TDesktop/Android input box rewrite/polish.
|
||
# The local provider is deterministic and does not call external services.
|
||
TELESRV_AI_ENABLED=true
|
||
TELESRV_AI_PROVIDERS=local
|
||
TELESRV_AI_TIMEOUT=15s
|
||
TELESRV_AI_RATE_LIMIT=20
|
||
TELESRV_AI_RATE_WINDOW=1m
|
||
TELESRV_AI_LOG_CONTENT=false
|
||
|
||
# Chat/message translation reuses the remote providers declared above. The
|
||
# deterministic "local" AI provider is excluded because it cannot translate.
|
||
# Leave TRANSLATION_PROVIDERS empty to use all configured remote AI providers,
|
||
# or provide a comma-separated subset such as "openai,gemini".
|
||
TELESRV_TRANSLATION_ENABLED=true
|
||
TELESRV_TRANSLATION_PROVIDERS=
|
||
TELESRV_TRANSLATION_TIMEOUT=15s
|
||
# Counts translated text items, not RPC envelopes (one RPC may contain 20).
|
||
TELESRV_TRANSLATION_RATE_LIMIT=60
|
||
TELESRV_TRANSLATION_RATE_WINDOW=1m
|
||
|
||
# External providers are optional. Keep API keys in TELESRV_* variables here;
|
||
# the loader rejects non-TELESRV keys from .env files by design.
|
||
# TELESRV_AI_OPENAI_KIND=openai_responses
|
||
# TELESRV_AI_OPENAI_API_KEY=
|
||
# TELESRV_AI_OPENAI_MODEL=
|
||
# TELESRV_AI_OPENAI_BASE_URL=
|
||
# TELESRV_AI_OPENAI_MAX_OUTPUT_TOKENS=1024
|
||
# TELESRV_AI_OPENAI_TEMPERATURE=0.2
|
||
# TELESRV_AI_OPENAI_OMIT_TEMPERATURE=false
|
||
# TELESRV_AI_OPENAI_THINKING=
|
||
# TELESRV_AI_GEMINI_KIND=gemini
|
||
# TELESRV_AI_GEMINI_API_KEY=
|
||
# TELESRV_AI_GEMINI_MODEL=
|
||
# TELESRV_AI_GEMINI_TEMPERATURE=0.2
|
||
# TELESRV_AI_ANTHROPIC_KIND=anthropic
|
||
# TELESRV_AI_ANTHROPIC_API_KEY=
|
||
# TELESRV_AI_ANTHROPIC_MODEL=
|
||
|
||
# Kimi/Moonshot can be used as an OpenAI-compatible Chat Completions provider.
|
||
# TELESRV_AI_PROVIDERS=kimi,local
|
||
# TELESRV_AI_KIMI_KIND=openai_chat
|
||
# TELESRV_AI_KIMI_API_KEY=
|
||
# TELESRV_AI_KIMI_BASE_URL=https://api.moonshot.cn/v1
|
||
# TELESRV_AI_KIMI_MODEL=kimi-k2.6
|
||
# TELESRV_AI_KIMI_THINKING=disabled
|
||
# TELESRV_AI_KIMI_TEMPERATURE=0.6
|
||
|
||
# Business automation reply provider:
|
||
# echo (default), template/quick_reply, or ai/compose_ai/kimi to reuse AI providers.
|
||
TELESRV_BUSINESS_AI_PROVIDER=echo
|