# kb-query secrets + host-local binds — copy to .env (gitignored) next to # docker-compose.yml and fill in real values. Never commit .env. # LAN IP of PIHA. The published port (8230) binds ONLY to this interface — # never 0.0.0.0. Verify after host rebuilds: ip -4 addr. LAN_BIND_IP=192.168.31.5 # asyncpg DSN for kb-postgres@PIHA. kb-query runs in its own Docker network # (separate compose project from kb-postgres), so it reaches kb-postgres's # published port over the host's LAN interface, not "localhost" — same # reasoning as paperless-worker@SOLARIA reaching paperless@PIHA over LAN. KB_DSN=postgresql://kb:CHANGE-ME@192.168.31.5:5433/kb # Ollama upstream (SOLARIA, over Tailscale MagicDNS — same trick as # llm-gateway's OLLAMA_URL). Optional: defaults to this value if unset. # OLLAMA_URL=http://solaria:11434 # Local fallback Ollama (ollama-piha@PIHA, plan §2 decision 2 / §5) — used only when SOLARIA # is unreachable/times out. kb-query runs in its own Docker network (separate compose project # from ollama-piha), so this must be PIHA's LAN IP + published port, not "localhost" — same # reasoning as KB_DSN above. Optional: defaults to http://localhost:11434, which fails closed # (nothing listens there in this container) until you set the real value below. # OLLAMA_PIHA_URL=http://192.168.31.5:11434 # Embedding model kb-query enforces as a startup invariant (plan §2 decision # 2) against document_chunk.model / document_summary.embedding_model. # Optional: defaults to bge-m3. # EMBED_MODEL=bge-m3 # document_summary.model kb-query's cascade path pre-filters on (the # compilation track, plan §2 D3). Optional: defaults to claude-haiku-4-5. # SUMMARY_MODEL=claude-haiku-4-5