Required configuration
This page covers the options every deployment needs: the secret keys, the SQL database, Redis, and file storage. Feature options such as LLM providers, moderation, or hooks have their own pages, linked at the end.
CKEditor AI On-Premises reads every option from one of two sources:
- Environment variables – the default. The service reads each option from the environment variable that has the option name in upper case, for example
LICENSE_KEYorDATABASE_HOST. - A JSON configuration file – read when the
CS_CONFIG_PATHenvironment variable points to a file. The file holds a flat JSON object whose keys are the option names, for example{ "license_key": "...", "database_host": "..." }.
The two sources are mutually exclusive. When you set CS_CONFIG_PATH, the service reads options only from the file and ignores the environment variables that hold options. There is no default file path. Without CS_CONFIG_PATH, the service reads environment variables.
To configure the service with a file, mount the file into the container and point CS_CONFIG_PATH at it:
docker run --init -p 8000:8000 \
-v [PATH_TO_LOCAL_CONFIG_FILE]:/app/config.json \
-e CS_CONFIG_PATH=/app/config.json \
docker.cke-cs.com/ai-service:[version]Copy codeThis page shows every option in both forms. The JSON tab shows the entry for the configuration file, and the Environment variable tab shows the same option as a variable. Option names are case-insensitive, so license_key and LICENSE_KEY name the same option.
Telemetry variables prefixed with OTEL_ and LANGFUSE_ are an exception. The service reads them from the process environment when it starts. Pass them as environment variables even when the rest of the configuration is in a file. See Observability for details.
The service needs a license_key option. The key confirms that you have the rights to run the service. To get a key, contact us. The service does not start with an empty or invalid key.
The environments_management_secret_key option grants access to the Cloud Services Management Panel. Set it to a string from a password generator.
{
"license_key": "[LICENSE_KEY]",
"environments_management_secret_key": "[ENVIRONMENTS_MANAGEMENT_SECRET_KEY]"
}Copy codeSet the database_driver option to postgres.
Then provide:
database_hostanddatabase_portto set the database address.database_useranddatabase_passwordto set the database credentials.database_databaseanddatabase_schemato set the database and schema the service uses.
To encrypt the connection, set the database_ssl_ca, database_ssl_key, and database_ssl_cert options.
{
"database_driver": "postgres",
"database_host": "[DATABASE_HOST]",
"database_port": 5432,
"database_user": "[DATABASE_USER]",
"database_password": "[DATABASE_PASSWORD]",
"database_database": "[DATABASE_NAME]",
"database_schema": "[DATABASE_SCHEMA]"
}Copy codeTo use MySQL instead of PostgreSQL, set the database_driver option to mysql. The service uses MySQL when the option is not set.
Then provide:
database_hostanddatabase_portto set the database address.database_useranddatabase_passwordto set the database credentials.database_databaseto set the database the service uses.
To encrypt the connection, set the database_ssl_ca, database_ssl_key, and database_ssl_cert options.
{
"database_driver": "mysql",
"database_host": "[DATABASE_HOST]",
"database_port": 3306,
"database_user": "[DATABASE_USER]",
"database_password": "[DATABASE_PASSWORD]",
"database_database": "[DATABASE_NAME]"
}Copy codeThe service needs Redis in addition to the SQL database. Configure it with:
redis_hostandredis_portto set the Redis address.redis_userandredis_passwordto set the Redis credentials. Both are optional.
Set redis_db to use a database number other than the default 1.
If the Redis address is an IPv6 address or an IPv6 domain name, set redis_ip_family to 6. The service uses IPv4 by default.
To encrypt the connection, set the redis_tls_ca, redis_tls_key, and redis_tls_cert options. If you do not have a custom certificate, set redis_tls_enable to true instead.
{
"redis_host": "[REDIS_HOST]",
"redis_port": 6379,
"redis_user": "[REDIS_USER]",
"redis_password": "[REDIS_PASSWORD]",
"redis_db": 1
}Copy codeTo connect to a Redis Cluster, set:
redis_cluster_nodes– required for a Redis Cluster connection.redis_ip_family– optional. Set it to6whenredis_cluster_nodesholds IPv6 addresses or IPv6 domain names.
The value is a comma-separated list of nodes in this format:
"IP:PORT:[optional PASSWORD],IP:PORT:[optional PASSWORD]"Copy codeFor example:
# IPv6
[0:0:0:0:0:0:0:1]:7000,[0:0:0:0:0:0:0:1]:7001,[0:0:0:0:0:0:0:1]:7002
# IPv6 with a password
[0:0:0:0:0:0:0:1]:7000:password1,[0:0:0:0:0:0:0:1]:7001:password2,[0:0:0:0:0:0:0:1]:7002:password3
# Domain name
example.redis.server.com:7000,example.redis.server.com:7001,example.redis.server.com:7002
# Domain name with a password
example.redis.server.com:7000:password1,example.redis.server.com:7001:password2,example.redis.server.com:7002:password3Copy codeThe example below shows a cluster of domain-name nodes with IPv6 support enabled:
{
"redis_cluster_nodes": "example.ipv6.redis.server.com:7000,example.ipv6.redis.server.com:7001,example.ipv6.redis.server.com:7002",
"redis_ip_family": 6
}Copy codeTo store files in S3, set the storage_driver option to s3.
Then provide:
storage_access_key_idandstorage_secret_access_keyto authorize the service.storage_bucketto set the bucket the service writes the files to.
For an S3-compatible server, set its address with the storage_endpoint option.
{
"storage_driver": "s3",
"storage_region": "[AWS_REGION]",
"storage_access_key_id": "[AWS_ACCESS_KEY_ID]",
"storage_secret_access_key": "[AWS_SECRET_ACCESS_KEY]",
"storage_bucket": "[AWS_S3_BUCKET]",
"storage_endpoint": "[AWS_S3_ENDPOINT]"
}Copy codeTo store files in Azure Blob Storage, set the storage_driver option to azure.
Then provide:
storage_account_nameandstorage_account_keyto authorize the service.storage_containerto set the container the service writes the files to.
By default, the service builds the endpoint from the account name: https://[AZURE_ACCOUNT_NAME].blob.core.windows.net. To use another address, set the storage_endpoint option.
{
"storage_driver": "azure",
"storage_account_name": "[AZURE_ACCOUNT_NAME]",
"storage_account_key": "[AZURE_ACCOUNT_KEY]",
"storage_container": "[AZURE_CONTAINER]",
"storage_endpoint": "[AZURE_ENDPOINT]"
}Copy codeTo store files on a local filesystem, set the storage_driver option to filesystem.
Then set the path to the directory for the files with the storage_location option.
{
"storage_driver": "filesystem",
"storage_location": "/var/storage/location"
}Copy codeTo store files in PostgreSQL or MySQL, set the storage_driver option to database. The service then uses the connection that the database_* options define.
{
"storage_driver": "database"
}Copy codeSee LLM providers for the providers and models options.
See Observability for the telemetry options.
See Moderation for the moderation option.
See Web resources for the webresources_* options.
See Web search for the websearch_* options.