Configuration Reference

Complete environment variable and configuration file reference.

Core Environment Variables

VariableDefaultDescription
TARGET_LLMhttps://api.openai.comTarget AI API endpoint (OpenAI-compatible)
LISTEN_PORT9999Gateway listen port
UPSTREAM_API_KEY(empty)Upstream LLM API key
ADMIN_PASSWORD(auto-generated)Admin dashboard password
JWT_SECRET(auto-generated)JWT signing secret
VAULT_ENCRYPT_KEY(auto-generated)AES-256-GCM vault encryption key

Database Configuration

VariableDefaultDescription
DB_PATH./vault_data/privacy_vault.dbSQLite database path
DB_TYPEsqliteDatabase type (currently sqlite only)
MAPPING_TTL259200 (72h)PII mapping retention (seconds)
STATELESS_MODE0Set to 1 for memory-only mode (no disk writes)
DRY_RUN_MODE0Set to 1 for detection-only mode (no masking)

Upstream Load Balancing

VariableDefaultDescription
UPSTREAM_LLM_URLS(empty)Comma-separated upstream API URLs
UPSTREAM_LB_STRATEGYround_robinStrategy: round_robin / random / least_connections
UPSTREAM_HEALTH_CHECK_INTERVAL30Health check interval (seconds)
UPSTREAM_MODEL_MAP{}JSON model-to-upstream routing map

Performance Controls

VariableDefaultDescription
MAX_CONCURRENT_REQUESTS50Maximum concurrent requests
MAX_REQUEST_BODY_SIZE10485760 (10MB)Max request body size (bytes)
SHUTDOWN_TIMEOUT30Graceful shutdown timeout (seconds)
RATE_LIMIT_STORAGEmemory://Rate limit storage backend

Logging & TLS

VariableDefaultDescription
LOG_FORMATjsonLog format: json or text
LOG_LEVELINFOLog level: DEBUG / INFO / WARNING / ERROR
SSL_CERTFILE(empty)SSL certificate path
SSL_KEYFILE(empty)SSL private key path

Masking Rules

Custom keyword file: vault_data/keywords.txt

# Custom keywords (one per line)
# Format: sensitive_word:replacement_label
Internal Project X:PROJECT_X
Client Alpha:CLIENT_ALPHA
Secret Project Phoenix:SECRET_PHOENIX

Custom regex file: vault_data/patterns.json

{
  "custom": [
    {"name": "Employee ID", "pattern": "EMP\\d{6}"},
    {"name": "Project Code", "pattern": "PRJ-[A-Z]{3}-\\d{4}"},
    {"name": "Passport Number", "pattern": "E\\d{8}"}
  ]
}

Enable/Disable Entity Detection

Modify the enabled field in entity_catalog.json:

{
  "entities": {
    "phone": {"enabled": true},
    "email": {"enabled": true},
    "idcard": {"enabled": true},
    "bankcard": {"enabled": true},
    "ip": {"enabled": false}
  }
}

Next Steps