Skip to content

DocsUse

Configuration

Every setting is an environment variable starting with BBM_ATLAS_, also read from a .env file, with credentials readable from files.

How settings are read

  • Each setting is an environment variable named BBM_ATLAS_ plus the setting in capitals: api_port is BBM_ATLAS_API_PORT.
  • A .env file in the directory BBM-Atlas starts in is read too. A variable already in the environment wins over the file.
  • A list (API_KEYS, INDEX_ROOTS, MCP_ALLOWED_HOSTS, FORWARDED_ALLOW_IPS) is a JSON array, a comma-separated string, or a single value.
  • Settings are read when a process starts: restart BBM-Atlas after changing one.
.env
BBM_ATLAS_API_KEYS=["a-long-random-key"]BBM_ATLAS_INDEX_ROOTS=/srv/repos,/home/dev/workBBM_ATLAS_LOG_LEVEL=INFO

Credentials from files

Any credential can be read from a file instead, which keeps it out of the process environment: set BBM_ATLAS_<NAME>_FILE to its path. This is how Docker and Kubernetes secrets are mounted.

terminal
BBM_ATLAS_API_KEYS_FILE=/run/secrets/api_keysBBM_ATLAS_POSTGRES_DSN_FILE=/run/secrets/postgres_dsn

It works for API_KEYS, ADMIN_API_KEYS, POSTGRES_DSN, NEO4J_PASSWORD, QDRANT_API_KEY and REDIS_URL. The file's trailing newline is ignored, setting both forms of one credential is refused, and an unreadable file stops start-up with its path and the reason. The Enterprise Edition reads its licence key, OIDC client secret and SAML certificate from files too (BBM_ATLAS_EE_LICENSE_KEY_FILE, BBM_ATLAS_EE_OIDC_CLIENT_SECRET_FILE, BBM_ATLAS_EE_SAML_IDP_CERTIFICATE_FILE); for those, the file wins when both are set.

Server

VariableDefaultWhat it does
BBM_ATLAS_API_HOST127.0.0.1Where bbm-atlas serve listens. Set 0.0.0.0 only to expose it, with keys set (Security)
BBM_ATLAS_API_PORT8000Its port
BBM_ATLAS_ENVIRONMENTdevelopmentdevelopment, testing, staging or production. Production refuses to start without API keys
BBM_ATLAS_CONSOLE_ENABLEDtrueThe web console at /console/
BBM_ATLAS_MCP_HTTP_ENABLEDtrueMCP over HTTP at /mcp
BBM_ATLAS_MCP_ALLOWED_HOSTSemptyThe host names clients use for /mcp, when it is exposed beyond this machine
BBM_ATLAS_FORWARDED_ALLOW_IPS127.0.0.1The reverse proxies trusted to report the client's address and scheme
BBM_ATLAS_DATA_DIRyour user data folderWhere BBM-Atlas keeps its own files - logs, the local store - when their paths are relative

Access and limits

VariableDefaultWhat it does
BBM_ATLAS_API_KEYSemptyThe keys a request must carry (as X-API-Key or a bearer token). Empty: no key needed
BBM_ATLAS_ADMIN_API_KEYSemptyKeys allowed to change feature flags. Empty: any key may
BBM_ATLAS_INDEX_ROOTSemptyThe directories repositories may be indexed from. Empty: anywhere the server can read
BBM_ATLAS_RATE_LIMIT_ENABLEDfalseA budget of requests per minute for each caller
BBM_ATLAS_RATE_LIMIT_REQUESTS_PER_MINUTE120The budget: per API key, per signed-in account, else per address
BBM_ATLAS_RATE_LIMIT_BACKENDmemorymemory (each process counts alone) or redis (one budget across replicas)
BBM_ATLAS_MAX_REQUEST_BODY_BYTES10485760The largest request body accepted (10 MiB)

Storage

VariableDefaultWhat it does
BBM_ATLAS_STORAGE_BACKENDlocal with servelocal (one SQLite file, one process), memory (nothing kept) or all (Postgres, Neo4j, Qdrant and Redis)
BBM_ATLAS_LOCAL_STORE_PATHstore/bbm-atlas.sqlite3The local store's file, under the data folder when relative
BBM_ATLAS_MEMORY_FACTS_BACKENDlocal with serveWhere remembered facts live: memory, local or redis
BBM_ATLAS_POSTGRES_DSNa local databaseRepository metadata, memory and chunks
BBM_ATLAS_NEO4J_URI, _USER, _PASSWORDbolt://localhost:7687The knowledge graph. The password is required with all
BBM_ATLAS_QDRANT_URL, _API_KEYhttp://localhost:6333Vectors for semantic search
BBM_ATLAS_REDIS_URLredis://localhost:6379/0The cache, and shared rate limits and facts

Models

VariableDefaultWhat it does
BBM_ATLAS_EMBEDDING_PROVIDERhashsentence_transformers loads a real embedding model (the embeddings extra)
BBM_ATLAS_EMBEDDING_MODEL_NAMEBAAI/bge-m3Which model
BBM_ATLAS_LLM_PROVIDERtemplateThe agents' language model: template (deterministic, no model), llamacpp (in-process, the llm extra) or llamacpp_server
BBM_ATLAS_LLM_MODEL_PATHa GGUF fileThe model llamacpp loads
BBM_ATLAS_LLM_DEVICE, BBM_ATLAS_EMBEDDING_DEVICEcpugpu offloads to a GPU build

Logging and tracing

VariableDefaultWhat it does
BBM_ATLAS_LOG_LEVELINFODEBUG, INFO, WARNING or ERROR
BBM_ATLAS_LOG_FORMATjsonjson lines, or console for people
BBM_ATLAS_LOG_TO_FILEtrueAlso write log files under the data folder
BBM_ATLAS_OTEL_ENABLEDfalseOpenTelemetry traces (the otel extra), sent where the standard OTEL_EXPORTER_OTLP_ENDPOINT says

The Enterprise Edition's settings start with BBM_ATLAS_EE_; see Licence and set-up.