Enterprise Server
Configuration reference
The settings an Enterprise Server reads, grouped by what they govern: the ones an operator is likely to change. The server declares every KNWLGE_* variable in one typed schema, and Settings → Configuration lists all of them with their current state.
How settings are read
- The native server (
knwlge-enterprise start) builds its environment from config.json, which setup wrote, plus any value saved in the console. A value set in the process's own environment wins over both. - Docker Compose and Helm read the environment of their definitions; the console shows the values but cannot change them.
- Unknown, invalid or retired settings are logged as warnings by name and the server starts anyway;
KNWLGE_CONFIG_STRICT=true makes them fail the start instead. Values are never logged.
In the tables, Console says whether an admin can change a setting in Settings → Configuration (taking effect at the next restart), or why not.
Knwlge Global
| Setting | Default | Console | What it does |
|---|
KNWLGE_GLOBAL_URL | — | No — setup | Knwlge Global's address, https://api.knwlge.com. Turns on enrollment, Global sign-in, the heartbeat and usage export. |
KNWLGE_GLOBAL_SERVER_URL | — | No — setup | This server's canonical public address. Sent at enrollment; every token the server accepts must be for it. |
KNWLGE_GLOBAL_ENROLLMENT_TOKEN | — | No — secret | An enrollment key. Enrolls the first start; left set, it re-enrolls the server on its own if Global refuses it while the key is still active. |
KNWLGE_GLOBAL_STATUS_INTERVAL_SECONDS | 90 | No — setup | Seconds between status reports to Global, 60 to 300, with a little jitter. |
KNWLGE_GLOBAL_STATUS_DRY_RUN | false | No — setup | Log each status report instead of sending it — to see exactly what would leave. |
KNWLGE_GLOBAL_HTTP_TIMEOUT_MS | 10000 | No — setup | Timeout for every call from this server to Global. |
Clients and sign-in
| Setting | Default | Console | What it does |
|---|
KNWLGE_ALLOWED_CLIENTS | codex,claude,copilot,cursor | Settings → Enterprise Server | The AI clients people may use: codex, claude, copilot, cursor, grok. A list saved in the console wins until it is reset. |
KNWLGE_AUTH_PROVIDERS | knwlge | Settings → Sign-in | Sign-in methods accepted: knwlge, microsoft, github (knwlge is always included). The console's settings, with email domains, win until reset. |
KNWLGE_MULTI_TEAM_READS | true | Yes | Someone in several teams reads team memories across all of them. Writes always go to the active team. |
KNWLGE_CONTEXT_KILL_SWITCH | — | Yes | true stops serving context to every assistant, at once. The server keeps running. |
Memory and review
| Setting | Default | Console | What it does |
|---|
KNWLGE_MEMORY_ACTIVATION_POLICY | immediate | Yes | How shared memories take effect: immediate (with history), tiered (needs verified provenance, else review), review_all. |
KNWLGE_MEMORY_ADMIN_SELF_APPROVAL | false | Yes | Lets an admin approve a candidate or upload they added themselves. Each one is audited. |
KNWLGE_MEMORY_REVIEW_SEPARATION | none | Yes | How broadly the rule that someone else reviews applies: none, broad or all. |
KNWLGE_MEMORY_CANDIDATE_EXPIRY_DAYS | 30 | Yes | Days an unreviewed candidate waits before it lapses. |
KNWLGE_MEMORY_EXTRACTION_CONFIDENCE_FLOOR | 0.5 | Yes | The least confidence, 0 to 1, for a memory extracted from a session to be kept. |
KNWLGE_MEMORY_CONFLICT_SIMILARITY | 0.92 | Yes | Above this similarity a new memory is treated as conflicting with an existing one. |
KNWLGE_MEMORY_RETENTION_DAYS_PERSONAL | 365 | Yes | Days personal memories are kept. |
KNWLGE_MEMORY_RETENTION_DAYS_REPO | 0 | Yes | Days repository memories are kept; 0 keeps them until superseded. |
Capture and privacy
The capture policy itself is set in Settings → Session capture, not in the environment.
| Setting | Default | Console | What it does |
|---|
KNWLGE_PII_MODE | — | Yes | How personal data in captured content is handled on the server: off, mask or block. |
KNWLGE_LLM_REQUIRE_REDACTION | true | No — deployment | Redaction must run before any LLM call. A data-protection guard; only the deployment can turn it off. |
KNWLGE_RETENTION_PURGE_SCHEDULED_ENABLED | false | Yes | Runs the retention purge on a schedule: old session digests and personal memories past their retention. |
KNWLGE_RETENTION_PURGE_DRY_RUN | true | Yes | Report what the retention purge would remove, without removing it. |
LLM assistance
Off by default: a default install makes no LLM calls. With a provider key saved in Settings → Provider keys and a call limit above 0, the server's jobs use the LLM for summaries, catalog descriptions and extraction — each call redacted first.
| Setting | Default | Console | What it does |
|---|
KNWLGE_LLM_PROVIDER | — | Yes | anthropic or openai-compatible. |
KNWLGE_LLM_MODEL | — | Yes | The model id for extraction and summaries. |
KNWLGE_LLM_MAX_CALLS_PER_JOB | — | Yes | LLM calls a job may make; unset or 0 keeps LLM assistance off. |
KNWLGE_LLM_TIMEOUT_MS | 15000 | Yes | Timeout for each LLM call. |
KNWLGE_CATALOG_SUMMARY_MAX_PER_RUN | 25 | Yes | Catalog entries the LLM describes after each index; 0 turns it off. |
KNWLGE_CATALOG_SESSION_SUMMARY_MAX | 5 | Yes | Catalog entries re-described from what one session said about them; 0 turns it off. |
KNWLGE_ENGINE_INDEX_LLM_BUDGET | 200 | Yes | LLM calls an index pass may make. |
Embeddings
A configuration saved in Settings → Embedding provider is authoritative; these are the environment's fallback. The index was built with them, so most are fixed at setup.
| Setting | Default | Console | What it does |
|---|
KNWLGE_EMBEDDING_PROVIDER | — | No — setup | openai or http (any OpenAI-compatible or self-hosted endpoint). |
KNWLGE_EMBEDDING_MODEL | — | No — setup | The embedding model id. |
KNWLGE_EMBEDDING_DIMENSIONS | — | No — setup | Vector dimensions, for http providers. |
KNWLGE_EMBEDDING_ENDPOINT | — | No — setup | The endpoint, for http providers. |
KNWLGE_EMBEDDING_API_KEY | — | No — secret | The provider's key. |
KNWLGE_EMBEDDING_TIMEOUT_MS | — | Yes | Timeout for each embedding request. |
GitHub and Azure DevOps
Saving the App or the organization in Settings wins over these; container installs may keep provisioning them this way.
| Setting | Default | Console | What it does |
|---|
KNWLGE_GITHUB_APP_ID | — | Settings → GitHub App | The GitHub App the server verifies installations and repositories with. |
KNWLGE_GITHUB_PRIVATE_KEY_PATH | — | No — deployment | Path to the App's private key (PEM), readable by the server. |
KNWLGE_GITHUB_WEBHOOK_SECRET | — | No — secret | Verifies GitHub's webhook signatures. |
KNWLGE_GITHUB_SYNC_DAEMON_ENABLED | false | Yes | Runs the GitHub sync loop inside the worker. |
KNWLGE_ADO_ORG_URL | — | Settings → Azure DevOps | https://dev.azure.com/<organization>; turns on Azure DevOps. |
KNWLGE_ADO_AUTH_MODE | — | Settings → Azure DevOps | pat or service_principal. |
KNWLGE_ADO_SYNC_DAEMON_ENABLED | false | Yes | Runs the Azure DevOps sync loop inside the worker. |
KNWLGE_CONNECTOR_SYNC_MAX_PAGES | 20 | Yes | Pages a connector sync pulls per pass. |
Limits and network
| Setting | Default | Console | What it does |
|---|
KNWLGE_IDENTITY_RATE_LIMIT_PER_MINUTE | 240 | Yes | Requests a minute from one person. |
KNWLGE_ORG_RATE_LIMIT_PER_MINUTE | 20000 | Yes | Requests a minute from the whole organization. |
KNWLGE_PROVIDER_ALLOWED_HOSTS | — | No — setup | The embedding and LLM hosts the server may call; nothing else is reached. |
KNWLGE_PROVIDER_MAX_CALLS_PER_JOB | 10000 | Yes | Provider calls a job may make. |
KNWLGE_TRUSTED_PROXY_HOPS | — | No — deployment | Proxies in front of the server whose forwarded headers are trusted, 1 to 4 (or KNWLGE_TRUSTED_PROXY_CIDRS). |
KNWLGE_API_INSTANCE_COUNT | 1 | No — deployment | API instances; more than one needs Redis for rate limits. |
KNWLGE_METRICS_TOKEN | — | No — secret | Bearer token required on /metrics; unset leaves it open. |
Audit, alerts and retention
| Setting | Default | Console | What it does |
|---|
KNWLGE_AUDIT_RETENTION_DAYS | 365 | Yes | Days audit events are kept, 30 to 3650. |
KNWLGE_AUDIT_RETENTION_SCHEDULED_ENABLED | false | Yes | Prunes audit events older than that on a schedule. |
KNWLGE_AUDIT_SIEM_SHIP_ENABLED | false | Yes | Ships audit events to your SIEM continuously. |
KNWLGE_AUDIT_SIEM_ENDPOINT | — | Yes | Where they go; the bearer token and signing secret are set in the deployment. |
KNWLGE_ALERT_WEBHOOK_URL | — | Yes | Where the Alerts page sends alerts, signed with KNWLGE_ALERT_WEBHOOK_SECRET. Unset: alerts can be acknowledged but not sent. |
KNWLGE_OTEL_ENABLED | false | Yes | OpenTelemetry traces and metrics. |
KNWLGE_CONFIG_STRICT | false | No — deployment | Fail the start on unknown, invalid or retired settings, instead of warning. |