# MQTT broker (usually the mosquitto container on this host) MQTT_BROKER=mosquitto MQTT_PORT=1883 # Use the c2-core credential — must match MQTT_C2_USER/MQTT_C2_PASS in the # top-level .env MQTT_USER=drb-c2-core MQTT_PASS=change-me-c2 # Same value as the top-level .env's MOSQUITTO_DYNSEC_PASSWORD — lets # c2-core log in as mosquitto's built-in dynsec "admin" client to # administer node MQTT credentials. See app/internal/dynsec.py. MQTT_DYNSEC_ADMIN_PASS=change-me-dynsec-admin-min-12-chars # GCP — path to service account JSON inside the container GCP_CREDENTIALS_PATH=/app/gcp-key.json # Firestore database name (use "(default)" if you didn't create a named database) FIRESTORE_DATABASE=c2-server # GCS bucket for audio storage GCS_BUCKET=your-bucket-name # How long (seconds) before a node is marked offline if no checkin received NODE_OFFLINE_THRESHOLD=90 # Google Maps — for geocoding location strings extracted from transcripts # Enable "Geocoding API" in Cloud Console for this key GOOGLE_MAPS_API_KEY= # OpenAI — for transcription (Whisper), intelligence extraction, embeddings, and summaries OPENAI_API_KEY= SUMMARY_INTERVAL_MINUTES=15 CORRELATION_WINDOW_HOURS=4 EMBEDDING_SIMILARITY_THRESHOLD=0.82 # Fleet-wide token edge nodes present as X-Enrollment-Token on first boot # (POST /nodes/enroll). Shared across every node — NOT a per-node secret. # Generate with: openssl rand -hex 32 ENROLLMENT_TOKEN=