Skip to main content
Installation

Configuration

Key settings in .env: model, data sources, database, gateway authentication, reverse proxy, the rule write-back directory and optional settings.

deploy.sh writes .env (mode 600). After a change, run docker compose -f docker-compose.prod.yml up -d to recreate the containers. Data sources and models can also be changed in the UI: data sources under Settings > Data sources, models under AI settings.

Model (optional)

VariableMeaning
LLM_API_KEYAPI key for the model endpoint
LLM_BASE_URLOpenAI-compatible endpoint, for example Volcengine Ark https://ark.cn-beijing.volces.com/api/v3. Required when you configure a model; there is no built-in default
LLM_MODELModel name or endpoint ID
LLM_TIMEOUT_SPer-call timeout, 180 seconds by default. Raise it for slow reasoning models
RST_TIMEZONETime zone, +08:00 by default. The model relies on it to understand "today" and "yesterday"

With none of the three set, queries fall back to keyword generation and are marked low confidence.

Data sources

VariableMeaning
PROMETHEUS_URLFor example http://prometheus.corp.local:9090
PROMETHEUS_USER and PROMETHEUS_PASSWORD, or PROMETHEUS_BEARER_TOKENWhen a reverse proxy in front of Prometheus requires authentication; use one or the other
RST_PROMETHEUS_CA_CERTA private CA, for example /certs/ca.pem (put the file in ./certs in the install directory). Do not turn certificate checks off
ALERTMANAGER_URLFor example http://alertmanager.corp.local:9093
ALERTMANAGER_USER and ALERTMANAGER_PASSWORD, or ALERTMANAGER_BEARER_TOKENAs above
GRAFANA_URLThe Grafana address as the browser reaches it; used for links only
GRAFANA_DATASOURCE_UIDUID of the Prometheus data source in Grafana, prometheus by default
RST_ALERTS_POLL_SHow often alerts are pulled from Alertmanager, 15 seconds by default; 0 turns it off

Alert rule write-back

VariableMeaning
RST_PROM_RULES_DIRDirectory where the gateway writes rule files (approved rules and the network rule pack). Prometheus must load the same directory (rule_files: [<dir>/*.yml]) and run with --web.enable-lifecycle so the gateway can hot-reload it. Left blank, rules can be generated and approved but not written back

Database

VariableMeaning
RST_DB_PASSWORDPassword of the bundled PostgreSQL
RST_DB_URLpostgresql://rst:<password>@postgres:5432/rst, with the same password. Point it at your own PostgreSQL if you use one

Gateway authentication (required)

VariableMeaning
RST_GATEWAY_SHARED_SECRETRandom string of 32+ characters, generated by deploy.sh
RST_ADMIN_TOKENRandom string of 32+ characters; the operations token
RST_ADMIN_PASSWORD_HASHHash of the admin password. Without it the gateway refuses every sign-in through the browser
RST_SESSION_TTL_HOURSSession lifetime, 12 hours by default

Generate a password hash and write the output into .env, doubling every $ to $$:

docker exec rst-ai-copilot-for-prometheus-gateway python -m backend.session_auth '<new password>'
docker compose -f docker-compose.prod.yml up -d gateway

Changing the password signs out every session. With several accounts, an admin resets other people's passwords on the Users page.

Reverse proxy (required)

VariableMeaning
CADDY_SITE_ADDRESSHost name or IP used to reach the gateway
CADDY_DEFAULT_SNIWhen the site address lists several names, set it to one of them; needed for bare-IP access
CADDY_TLSCertificate source; see Requirements

Optional

VariableMeaning
RST_AUDIT_ENABLEDWith a database, auditing is on by default; set false to turn it off
RST_MASKING_MODEMasking level before data reaches the model: cloud (default), private or airgapped. Also changeable in Settings
RST_DISCOVERY_INTERVAL_SECONDSDevice auto-discovery interval, 3600 seconds by default, minimum 300; 0 turns scheduled discovery off (the button still works)
RST_METRICS_TOKENWhen set, scraping /metrics and /metrics/inventory requires this token
RST_CONTENT_AUTO_APPLYSet to 0 to save new content packs without enabling them
RST_COMMUNITY_DAILY_QUOTADaily model-call cap for Community, unlimited by default
RST_GATEWAY_CPUS, RST_GATEWAY_MEMCPU and memory limits of the gateway container, 2 CPU and 2 GB by default

On this page