Configuration
Key settings in .env: model, data sources, database, gateway authentication, reverse proxy, the rule write-back directory and optional settings.
deploy.sh writes .env (mode 600). After a change, run docker compose -f docker-compose.prod.yml up -d to recreate the containers. Data sources and models can also be changed in the UI: data sources under Settings > Data sources, models under AI settings.
Model (optional)
| Variable | Meaning |
|---|---|
LLM_API_KEY | API key for the model endpoint |
LLM_BASE_URL | OpenAI-compatible endpoint, for example Volcengine Ark https://ark.cn-beijing.volces.com/api/v3. Required when you configure a model; there is no built-in default |
LLM_MODEL | Model name or endpoint ID |
LLM_TIMEOUT_S | Per-call timeout, 180 seconds by default. Raise it for slow reasoning models |
RST_TIMEZONE | Time zone, +08:00 by default. The model relies on it to understand "today" and "yesterday" |
With none of the three set, queries fall back to keyword generation and are marked low confidence.
Data sources
| Variable | Meaning |
|---|---|
PROMETHEUS_URL | For example http://prometheus.corp.local:9090 |
PROMETHEUS_USER and PROMETHEUS_PASSWORD, or PROMETHEUS_BEARER_TOKEN | When a reverse proxy in front of Prometheus requires authentication; use one or the other |
RST_PROMETHEUS_CA_CERT | A private CA, for example /certs/ca.pem (put the file in ./certs in the install directory). Do not turn certificate checks off |
ALERTMANAGER_URL | For example http://alertmanager.corp.local:9093 |
ALERTMANAGER_USER and ALERTMANAGER_PASSWORD, or ALERTMANAGER_BEARER_TOKEN | As above |
GRAFANA_URL | The Grafana address as the browser reaches it; used for links only |
GRAFANA_DATASOURCE_UID | UID of the Prometheus data source in Grafana, prometheus by default |
RST_ALERTS_POLL_S | How often alerts are pulled from Alertmanager, 15 seconds by default; 0 turns it off |
Alert rule write-back
| Variable | Meaning |
|---|---|
RST_PROM_RULES_DIR | Directory where the gateway writes rule files (approved rules and the network rule pack). Prometheus must load the same directory (rule_files: [<dir>/*.yml]) and run with --web.enable-lifecycle so the gateway can hot-reload it. Left blank, rules can be generated and approved but not written back |
Database
| Variable | Meaning |
|---|---|
RST_DB_PASSWORD | Password of the bundled PostgreSQL |
RST_DB_URL | postgresql://rst:<password>@postgres:5432/rst, with the same password. Point it at your own PostgreSQL if you use one |
Gateway authentication (required)
| Variable | Meaning |
|---|---|
RST_GATEWAY_SHARED_SECRET | Random string of 32+ characters, generated by deploy.sh |
RST_ADMIN_TOKEN | Random string of 32+ characters; the operations token |
RST_ADMIN_PASSWORD_HASH | Hash of the admin password. Without it the gateway refuses every sign-in through the browser |
RST_SESSION_TTL_HOURS | Session lifetime, 12 hours by default |
Generate a password hash and write the output into .env, doubling every $ to $$:
docker exec rst-ai-copilot-for-prometheus-gateway python -m backend.session_auth '<new password>'
docker compose -f docker-compose.prod.yml up -d gatewayChanging the password signs out every session. With several accounts, an admin resets other people's passwords on the Users page.
Reverse proxy (required)
| Variable | Meaning |
|---|---|
CADDY_SITE_ADDRESS | Host name or IP used to reach the gateway |
CADDY_DEFAULT_SNI | When the site address lists several names, set it to one of them; needed for bare-IP access |
CADDY_TLS | Certificate source; see Requirements |
Optional
| Variable | Meaning |
|---|---|
RST_AUDIT_ENABLED | With a database, auditing is on by default; set false to turn it off |
RST_MASKING_MODE | Masking level before data reaches the model: cloud (default), private or airgapped. Also changeable in Settings |
RST_DISCOVERY_INTERVAL_SECONDS | Device auto-discovery interval, 3600 seconds by default, minimum 300; 0 turns scheduled discovery off (the button still works) |
RST_METRICS_TOKEN | When set, scraping /metrics and /metrics/inventory requires this token |
RST_CONTENT_AUTO_APPLY | Set to 0 to save new content packs without enabling them |
RST_COMMUNITY_DAILY_QUOTA | Daily model-call cap for Community, unlimited by default |
RST_GATEWAY_CPUS, RST_GATEWAY_MEM | CPU and memory limits of the gateway container, 2 CPU and 2 GB by default |
Bundle install
The one-command install, downloading the bundle by hand, installing on an offline host, and every step of deploy.sh.
Data sources
Preparing Prometheus, Alertmanager, Grafana and snmp_exporter: read-only accounts, label conventions, vendor recognition, the inventory scrape job and rule write-back.