96 lines
4.0 KiB
Bash
96 lines
4.0 KiB
Bash
# Merge this section into the target environment's existing .env. No credentials are provided here.
|
|
# Only dify may reuse existing [prescription_ai] base/key. openai_audio needs MODEL; asr_then_llm needs both stage model/key/base triples.
|
|
[followup_audio]
|
|
ENABLED = false
|
|
PREVIEW_ONLY = false
|
|
# IDs only. Empty or invalid diagnosis allowlist denies preview; admin list never replaces RBAC.
|
|
TEST_DIAGNOSIS_IDS =
|
|
TEST_ADMIN_IDS =
|
|
AUDIO_VERIFIED = false
|
|
VERIFIED_PROFILES =
|
|
PROFILE = qwen
|
|
CONCURRENCY = 1
|
|
REQUEST_TIMEOUT = 240
|
|
UPSTREAM_MAX_BYTES = 20971520
|
|
NORMALIZE_TIMEOUT = 120
|
|
FFMPEG = ffmpeg
|
|
FFPROBE = ffprobe
|
|
# At least 32 characters; keep secret, stable, backed up and identical on web/worker nodes.
|
|
# Empty uses the existing prescription_analysis key; never rotate without a data re-encryption plan.
|
|
ENCRYPTION_KEY =
|
|
|
|
# Never enable HTTP for real audio. This switch applies only to the synthetic CLI probe.
|
|
ALLOW_INSECURE_SYNTHETIC = false
|
|
# Supported drivers: dify, openai_audio, asr_then_llm. openai_audio MODEL is sent in the request.
|
|
# Dify selects an application with its key; MODEL does not change the model inside that app.
|
|
QWEN_DRIVER = dify
|
|
QWEN_BASE_URL =
|
|
QWEN_API_KEY =
|
|
QWEN_MODEL =
|
|
QWEN_LABEL = qwen
|
|
QWEN_VERIFIED_FINGERPRINT =
|
|
OPENAI_DRIVER = dify
|
|
OPENAI_BASE_URL =
|
|
OPENAI_API_KEY =
|
|
OPENAI_MODEL =
|
|
OPENAI_LABEL = openai
|
|
OPENAI_VERIFIED_FINGERPRINT =
|
|
# Fingerprints must come from all three passing synthetic gates for this exact driver/URL/model/key.
|
|
# Any identity change invalidates prior verification; unknown prior requests still require reconciliation.
|
|
|
|
# Two-stage is opt-in per slot. ASR transcript is canonical; extraction uses text only.
|
|
# Mono keeps120s; stereo always isolates both channels on shared fixed windows.
|
|
ASR_STEREO_CHUNK_SECONDS = 15
|
|
ASR_CHUNK_SECONDS = 120
|
|
ASR_REQUEST_TIMEOUT = 240
|
|
EXTRACTION_REQUEST_TIMEOUT = 240
|
|
# HTTPS required. Enable this only for an operator-established SSH tunnel on literal 127.0.0.1 or [::1].
|
|
# localhost, other hosts, external HTTP and HTTP redirects are never exceptions.
|
|
QWEN_ALLOW_LOOPBACK_TUNNEL = false
|
|
QWEN_ASR_BASE_URL =
|
|
QWEN_ASR_API_KEY =
|
|
QWEN_ASR_MODEL =
|
|
QWEN_EXTRACTION_BASE_URL =
|
|
QWEN_EXTRACTION_API_KEY =
|
|
QWEN_EXTRACTION_MODEL =
|
|
OPENAI_ALLOW_LOOPBACK_TUNNEL = false
|
|
OPENAI_ASR_BASE_URL =
|
|
OPENAI_ASR_API_KEY =
|
|
OPENAI_ASR_MODEL =
|
|
OPENAI_EXTRACTION_BASE_URL =
|
|
OPENAI_EXTRACTION_API_KEY =
|
|
OPENAI_EXTRACTION_MODEL =
|
|
|
|
# V2 structured extraction; explicit json_schema/json_object/prompt_json, never automatic fallback.
|
|
QWEN_EXTRACTION_RESPONSE_FORMAT = json_schema
|
|
QWEN_EXTRACTION_MAX_TOKENS = 8192
|
|
OPENAI_EXTRACTION_RESPONSE_FORMAT = json_schema
|
|
OPENAI_EXTRACTION_MAX_TOKENS = 8192
|
|
# Optional vendor extension; leave absent for portable providers. true/false are explicit Qwen choices.
|
|
# The local Qwen run exhausted 8192 tokens with thinking=true; false produced JSON, not a quality pass.
|
|
# QWEN_EXTRACTION_ENABLE_THINKING = false
|
|
# OPENAI_EXTRACTION_ENABLE_THINKING = false
|
|
|
|
# Synthetic connection readiness only; never sets AUDIO_VERIFIED or allows clinical adoption.
|
|
QWEN_PREVIEW_VERIFIED_FINGERPRINT =
|
|
OPENAI_PREVIEW_VERIFIED_FINGERPRINT =
|
|
|
|
# Explicit per-stage protocol. No automatic fallback. Dify uses dedicated App keys only.
|
|
QWEN_ASR_PROTOCOL = openai
|
|
QWEN_ASR_BINDING_REVISION =
|
|
QWEN_EXTRACTION_PROTOCOL = openai
|
|
QWEN_EXTRACTION_BINDING_REVISION =
|
|
OPENAI_ASR_PROTOCOL = openai
|
|
OPENAI_ASR_BINDING_REVISION =
|
|
OPENAI_EXTRACTION_PROTOCOL = openai
|
|
OPENAI_EXTRACTION_BINDING_REVISION =
|
|
# For Dify: ASR_PROTOCOL=dify, EXTRACTION_PROTOCOL=dify_chat, RESPONSE_FORMAT=prompt_json.
|
|
# Every Dify stage needs a nonempty BINDING_REVISION. MODEL is expected identity, not sent.
|
|
# Dify App owns generation parameters: local max_tokens/response_format/thinking are NOT forwarded.
|
|
# Leave EXTRACTION_ENABLE_THINKING absent for Dify; set generation limits in the dedicated App.
|
|
# Changing that App requires a new binding revision and fresh preview fingerprint acceptance.
|
|
|
|
# asr_then_llm only: curl (default) or openssl_stream (explicit verified-TLS child process).
|
|
# No automatic transport fallback; changing this requires new fingerprint readiness.
|
|
HTTP_TRANSPORT = curl
|