Environment variables¶
Kosmos is configured through config/.env, the only file it reads.
This page lists every variable. How to create the file is covered in
Configuration.
Required means there is no default and the application will not start without a value. A default of empty means the feature the variable belongs to stays off or falls back until it is set.
Core¶
| Variable | Default | Description |
|---|---|---|
SECRET_KEY |
Required | Django's secret key. Generate one with: python3 -c 'import secrets; print(secrets.token_urlsafe(50))' |
DEBUG |
False |
Django debug mode. Always False in production. (boolean) |
ENV |
Required | Name of this environment: prod or dev. dev keeps login sessions in files under .dev-sessions/ and marks the interface as a development instance. |
ALLOWED_HOSTS |
Required | Comma-separated host names the application answers to. (comma-separated list) |
CSRF_TRUSTED_ORIGINS |
empty | Comma-separated full origins (scheme, host and port when not the default) trusted for form posts. Needed behind a reverse proxy. (comma-separated list) |
PUBLIC_BASE_URL |
empty | Scheme and host used to build absolute links outside a web request, such as payment links in emails sent by the background worker. Blank falls back to the host of the request that triggered the send, when there is one. |
TIME_ZONE |
America/New_York |
The firm's time zone, as a tz database name (for example America/Chicago). Dates shown in the app, the times scheduled jobs run, and the zone events are written to Google Calendar in all follow it. |
Database¶
| Variable | Default | Description |
|---|---|---|
DB_NAME |
Required | PostgreSQL database name. |
DB_USER |
Required | PostgreSQL role. It must own the database. |
DB_PASSWORD |
Required | Password for that role. |
DB_HOST |
localhost |
Database host. |
DB_PORT |
5432 |
Database port. |
Email¶
| Variable | Default | Description |
|---|---|---|
EMAIL_BACKEND |
'console' if DEBUG else 'smtp' |
How outgoing mail is delivered: console (print to the process log, no credentials needed), smtp, or locmem (tests). Defaults to console when DEBUG is on and smtp when it is off. |
EMAIL_HOST |
empty | SMTP server host. |
EMAIL_PORT |
587 |
SMTP server port. (integer) |
EMAIL_USE_TLS |
True |
Use STARTTLS on the SMTP connection. (boolean) |
EMAIL_TIMEOUT |
10 |
Seconds before a stalled SMTP connection is abandoned. Login codes are sent during the request, so a hung connection would otherwise hang the login page. (integer) |
EMAIL_HOST_USER |
empty | SMTP user name. |
EMAIL_HOST_PASSWORD |
empty | SMTP password. |
SERVER_EMAIL |
webmaster@localhost |
From address for error reports sent to ADMINS. |
DEFAULT_FROM_EMAIL |
the value of SERVER_EMAIL |
From address for mail the application sends. Defaults to SERVER_EMAIL. |
BILLING_FROM_EMAIL |
the value of DEFAULT_FROM_EMAIL |
From address for client-facing billing mail (invoices and payment requests). Defaults to DEFAULT_FROM_EMAIL. |
ADMINS |
empty | People who receive error emails, as a Python list of (name, address) tuples. |
File storage¶
| Variable | Default | Description |
|---|---|---|
STORAGE_BACKEND |
local |
Where uploaded files are kept: local (the media/ directory) or s3 (an S3-compatible object store). With local storage, never serve media/ directly from the web server: it holds confidential client documents, and the application streams them only to signed-in users. |
DIGITAL_OCEAN_REGION_NAME |
Required when STORAGE_BACKEND == 's3' |
Object store region. Required when STORAGE_BACKEND=s3, as are the four settings below. The names say DigitalOcean; any S3-compatible store works. |
DIGITAL_OCEAN_ENDPOINT_URL |
Required when STORAGE_BACKEND == 's3' |
Object store endpoint URL. |
DIGITAL_OCEAN_BUCKET_NAME |
Required when STORAGE_BACKEND == 's3' |
Bucket name. |
DIGITAL_OCEAN_ACCESS_KEY_ID |
Required when STORAGE_BACKEND == 's3' |
Access key id. |
DIGITAL_OCEAN_SECRET_ACCESS_KEY |
Required when STORAGE_BACKEND == 's3' |
Secret access key. |
Google Workspace¶
| Variable | Default | Description |
|---|---|---|
GOOGLE_DATA_DIR |
google/ in the repository |
Directory holding the Google OAuth client file (google_tokens.json) and the tokens generated when an integration is connected. A relative path is resolved from the repository root. |
CALENDAR_ID |
empty | Id of the Google Calendar that events sync with. |
DRIVE_NOTES_ROOT |
Matters - Open |
Name of the Drive folder that holds one subfolder per matter. |
DRIVE_SHARED_DRIVE_ID |
empty | Shared Drive id. Set only when the root folder lives in a Shared Drive. |
GMAIL_LABEL_ROOT |
Matters - Open |
Parent Gmail label whose child labels can be linked to matters. Blank offers every user label in the mailbox. |
Drafting (LibreOffice)¶
| Variable | Default | Description |
|---|---|---|
SOFFICE_BIN |
soffice |
Headless LibreOffice binary for the server-side redline module (apps/drive/redline.py). Drafting does not currently use that module: edits are applied by the companion extension in the user's LibreOffice. |
UNO_PYTHON |
/usr/bin/python3 |
A Python interpreter that has the UNO bindings (the system python3 with the python3-uno package), not the project virtualenv. Used only by the same server-side redline module. |
AI and research¶
| Variable | Default | Description |
|---|---|---|
ANTHROPIC_API_KEY |
empty | Anthropic API key, for the Claude models. |
GEMINI_API_KEY |
empty | Google Gemini API key, for the Gemini models and for the embeddings behind semantic search (the one feature only Gemini provides). |
SEMANTIC_AUTO_INDEX |
True |
Re-embed a record for semantic search whenever it is saved. The built-in default is True; nothing is queued while no Gemini key is set. After setting one, run manage.py build_semantic_index once. (boolean) |
COURTLISTENER_API_KEY |
empty | CourtListener API token, for case law search and citation checking. While it is blank, the AI is not offered the case law search tools. |
CHAT_RETENTION_DAYS |
180 |
Days after a matter closes before the weekly purge deletes its AI chats. 0 keeps them indefinitely. (integer) |
Intakes¶
| Variable | Default | Description |
|---|---|---|
KOSMOS_SEAM_KEY |
empty | Shared secret for the intake API used by a connected website or intake application (the X-Seam-Key header). While blank, that API refuses every request. |
MAILGUN_WEBHOOK_SIGNING_KEY |
empty | Mailgun HTTP webhook signing key, verifying inbound mail posted to /api/inbound-email/. While blank, that webhook refuses every request. |
INTAKE_INBOUND_RECIPIENT |
kosmos-intakes |
The part before the @ of the address this instance accepts forwarded intake mail on. Mail for any other address is dropped, which lets several instances share one Mailgun route. |
INTAKE_FORM_LINK_MAX_AGE |
2592000 |
Seconds a client intake-form link stays valid. Defaults to 30 days. (integer) |
Billing and payments¶
| Variable | Default | Description |
|---|---|---|
LAW_FIRM_ID |
empty | The firm's id in LEDES invoice exports. While it is blank, the Download Ledes action is hidden. |
PAYMENT_PROCESSOR |
fake |
Which processor collects online payments: none (online payment off; the emailed link still shows the invoice), lawpay, stripe, confido, or fake. fake is for development: it records a payment although no money moves, so never run it where real clients receive invoices. The built-in default is fake; the installer sets none for a production install. |
INVOICE_PAY_LINK_MAX_AGE |
7776000 |
Seconds an emailed payment link stays valid. Defaults to 90 days. Resending the invoice issues a fresh link. (integer) |
LAWPAY_PUBLIC_KEY |
empty | LawPay (AffiniPay) public key, used in the browser by the hosted card fields. Test keys reach only test accounts. |
LAWPAY_SECRET_KEY |
empty | LawPay secret key, used by the server. |
LAWPAY_OPERATING_CARD_ACCOUNT_ID |
empty | LawPay deposit account for card payments to the operating account. List the account ids with manage.py lawpay_accounts. Blank lets the gateway pick its primary account; the same applies to the three settings below. |
LAWPAY_OPERATING_ECHECK_ACCOUNT_ID |
empty | LawPay deposit account for eCheck payments to the operating account. |
LAWPAY_TRUST_CARD_ACCOUNT_ID |
empty | LawPay deposit account for card payments to the trust account. Required before a trust deposit request can be sent: a trust charge is never left to the gateway's choice of account. |
LAWPAY_TRUST_ECHECK_ACCOUNT_ID |
empty | LawPay deposit account for eCheck payments to the trust account. |
LAWPAY_API_BASE |
https://api.8am.com |
LawPay API host. Change only if AffiniPay moves it. |
STRIPE_PUBLISHABLE_KEY |
empty | Stripe publishable key, used in the browser. The firm supplies keys for its own Stripe account. |
STRIPE_SECRET_KEY |
empty | Stripe secret key, used by the server. |
STRIPE_WEBHOOK_SECRET |
empty | Stripe webhook signing secret for the /webhooks/stripe/ endpoint. |
CONFIDO_API_KEY |
empty | Confido Legal (Gravity Legal) API key. |
CONFIDO_WEBHOOK_SECRET |
empty | Confido webhook signing secret for the /webhooks/confido/ endpoint. |
CONFIDO_OPERATING_BANK_ACCOUNT_ID |
empty | Confido bank account id that invoice payments are deposited to. Confido has no default account, so both account ids are required. |
CONFIDO_TRUST_BANK_ACCOUNT_ID |
empty | Confido bank account id that trust deposits go to. |
CONFIDO_API_BASE |
https://api.sandbox.gravity-legal.com/v2 |
Confido API endpoint. The default is the sandbox; for live payments set https://api.gravity-legal.com/v2 |
CONFIDO_HOSTED_FIELDS_URL |
https://js.sandbox.gravity-legal.com/hosted-fields.js |
Confido hosted-fields script. The default is the sandbox; for live payments set https://js.gravity-legal.com/hosted-fields.js |