# ── Bring your own key ──────────────────────────────────────────────────────── # Provider credentials are read from the environment at start-up and are NEVER written to # the image or to git. The secret store reads env before disk, so a key exported here is # used but not persisted. # # A connection is one JSON value naming a provider and its credential. Define at least one. # Anthropic — for the claude-code backend HR_SECRET_GLOBAL_HARNESS_CONN_ANTHROPIC={"name":"anthropic","provider":"anthropic","api_key":"sk-ant-REPLACE_ME"} # OpenAI — for the codex backend # HR_SECRET_GLOBAL_HARNESS_CONN_OPENAI={"name":"openai","provider":"openai","api_key":"sk-REPLACE_ME"} # Any OpenAI-compatible endpoint (aggregators, local models, self-hosted inference) # HR_SECRET_GLOBAL_HARNESS_CONN_CUSTOM={"name":"custom","provider":"openai-api","api_key":"REPLACE_ME","base_url":"https://api.example.com/v1"} # Google AI Studio — for the gemini backend. A free-tier key's content may be reviewed/used # for training; use a billing-linked key for anything private. # HR_SECRET_GLOBAL_HARNESS_CONN_GOOGLE={"name":"google","provider":"google","api_key":"AIza-REPLACE_ME"} # Which connection each backend uses by default. HR_SECRET_GLOBAL_HARNESS_POLICY_CLAUDE={"chain":["anthropic"]} # HR_SECRET_GLOBAL_HARNESS_POLICY_CODEX={"chain":["openai"]} # HR_SECRET_GLOBAL_HARNESS_POLICY_HERMES={"chain":["openai"]} # HR_SECRET_GLOBAL_HARNESS_POLICY_GEMINI={"chain":["google"]} # ── Optional ────────────────────────────────────────────────────────────────── # PORT=3000 # HR_DATA_DIR=/data # Required only to connect a database to an agent. Connection strings are encrypted at rest # under a key derived from this passphrase; without it the server refuses to store one rather # than writing your database credential to disk in plaintext. Keep it — changing it means # reconnecting every database. # HR_SECRET_KEY=a-long-random-passphrase # Everything else is configured for self-hosting by the entrypoint: local SQLite storage, # no auth, no metering, a loopback runner, and direct key hand-off to the agent. You should # not need to set them, and they are documented in the README if you want to. # ── console login ───────────────────────────────────────────────────────────── # The console creates harnesses, reads every transcript, and runs agents with your provider key. # These defaults are published in the README, so CHANGE THEM before the instance is reachable by # anyone but you. HR_AUTH_USER=harnessrouter HR_AUTH_PASSWORD=harnessrouter # HR_AUTH_DISABLED=1 # no gate at all — only for a box nobody else can reach