Enterprise Server

Configuration reference

The settings an Enterprise Server reads, grouped by what they govern: the ones an operator is likely to change. The server declares every KNWLGE_* variable in one typed schema, and Settings → Configuration lists all of them with their current state.

How settings are read

  • The native server (knwlge-enterprise start) builds its environment from config.json, which setup wrote, plus any value saved in the console. A value set in the process's own environment wins over both.
  • Docker Compose and Helm read the environment of their definitions; the console shows the values but cannot change them.
  • Unknown, invalid or retired settings are logged as warnings by name and the server starts anyway; KNWLGE_CONFIG_STRICT=true makes them fail the start instead. Values are never logged.

In the tables, Console says whether an admin can change a setting in Settings → Configuration (taking effect at the next restart), or why not.

Knwlge Global

SettingDefaultConsoleWhat it does
KNWLGE_GLOBAL_URL—No — setupKnwlge Global's address, https://api.knwlge.com. Turns on enrollment, Global sign-in, the heartbeat and usage export.
KNWLGE_GLOBAL_SERVER_URL—No — setupThis server's canonical public address. Sent at enrollment; every token the server accepts must be for it.
KNWLGE_GLOBAL_ENROLLMENT_TOKEN—No — secretAn enrollment key. Enrolls the first start; left set, it re-enrolls the server on its own if Global refuses it while the key is still active.
KNWLGE_GLOBAL_STATUS_INTERVAL_SECONDS90No — setupSeconds between status reports to Global, 60 to 300, with a little jitter.
KNWLGE_GLOBAL_STATUS_DRY_RUNfalseNo — setupLog each status report instead of sending it — to see exactly what would leave.
KNWLGE_GLOBAL_HTTP_TIMEOUT_MS10000No — setupTimeout for every call from this server to Global.

Clients and sign-in

SettingDefaultConsoleWhat it does
KNWLGE_ALLOWED_CLIENTScodex,claude,copilot,cursorSettings → Enterprise ServerThe AI clients people may use: codex, claude, copilot, cursor, grok. A list saved in the console wins until it is reset.
KNWLGE_AUTH_PROVIDERSknwlgeSettings → Sign-inSign-in methods accepted: knwlge, microsoft, github (knwlge is always included). The console's settings, with email domains, win until reset.
KNWLGE_MULTI_TEAM_READStrueYesSomeone in several teams reads team memories across all of them. Writes always go to the active team.
KNWLGE_CONTEXT_KILL_SWITCH—Yestrue stops serving context to every assistant, at once. The server keeps running.

Memory and review

SettingDefaultConsoleWhat it does
KNWLGE_MEMORY_ACTIVATION_POLICYimmediateYesHow shared memories take effect: immediate (with history), tiered (needs verified provenance, else review), review_all.
KNWLGE_MEMORY_ADMIN_SELF_APPROVALfalseYesLets an admin approve a candidate or upload they added themselves. Each one is audited.
KNWLGE_MEMORY_REVIEW_SEPARATIONnoneYesHow broadly the rule that someone else reviews applies: none, broad or all.
KNWLGE_MEMORY_CANDIDATE_EXPIRY_DAYS30YesDays an unreviewed candidate waits before it lapses.
KNWLGE_MEMORY_EXTRACTION_CONFIDENCE_FLOOR0.5YesThe least confidence, 0 to 1, for a memory extracted from a session to be kept.
KNWLGE_MEMORY_CONFLICT_SIMILARITY0.92YesAbove this similarity a new memory is treated as conflicting with an existing one.
KNWLGE_MEMORY_RETENTION_DAYS_PERSONAL365YesDays personal memories are kept.
KNWLGE_MEMORY_RETENTION_DAYS_REPO0YesDays repository memories are kept; 0 keeps them until superseded.

Capture and privacy

The capture policy itself is set in Settings → Session capture, not in the environment.

SettingDefaultConsoleWhat it does
KNWLGE_PII_MODE—YesHow personal data in captured content is handled on the server: off, mask or block.
KNWLGE_LLM_REQUIRE_REDACTIONtrueNo — deploymentRedaction must run before any LLM call. A data-protection guard; only the deployment can turn it off.
KNWLGE_RETENTION_PURGE_SCHEDULED_ENABLEDfalseYesRuns the retention purge on a schedule: old session digests and personal memories past their retention.
KNWLGE_RETENTION_PURGE_DRY_RUNtrueYesReport what the retention purge would remove, without removing it.

LLM assistance

Off by default: a default install makes no LLM calls. With a provider key saved in Settings → Provider keys and a call limit above 0, the server's jobs use the LLM for summaries, catalog descriptions and extraction — each call redacted first.

SettingDefaultConsoleWhat it does
KNWLGE_LLM_PROVIDER—Yesanthropic or openai-compatible.
KNWLGE_LLM_MODEL—YesThe model id for extraction and summaries.
KNWLGE_LLM_MAX_CALLS_PER_JOB—YesLLM calls a job may make; unset or 0 keeps LLM assistance off.
KNWLGE_LLM_TIMEOUT_MS15000YesTimeout for each LLM call.
KNWLGE_CATALOG_SUMMARY_MAX_PER_RUN25YesCatalog entries the LLM describes after each index; 0 turns it off.
KNWLGE_CATALOG_SESSION_SUMMARY_MAX5YesCatalog entries re-described from what one session said about them; 0 turns it off.
KNWLGE_ENGINE_INDEX_LLM_BUDGET200YesLLM calls an index pass may make.

Embeddings

A configuration saved in Settings → Embedding provider is authoritative; these are the environment's fallback. The index was built with them, so most are fixed at setup.

SettingDefaultConsoleWhat it does
KNWLGE_EMBEDDING_PROVIDER—No — setupopenai or http (any OpenAI-compatible or self-hosted endpoint).
KNWLGE_EMBEDDING_MODEL—No — setupThe embedding model id.
KNWLGE_EMBEDDING_DIMENSIONS—No — setupVector dimensions, for http providers.
KNWLGE_EMBEDDING_ENDPOINT—No — setupThe endpoint, for http providers.
KNWLGE_EMBEDDING_API_KEY—No — secretThe provider's key.
KNWLGE_EMBEDDING_TIMEOUT_MS—YesTimeout for each embedding request.

GitHub and Azure DevOps

Saving the App or the organization in Settings wins over these; container installs may keep provisioning them this way.

SettingDefaultConsoleWhat it does
KNWLGE_GITHUB_APP_ID—Settings → GitHub AppThe GitHub App the server verifies installations and repositories with.
KNWLGE_GITHUB_PRIVATE_KEY_PATH—No — deploymentPath to the App's private key (PEM), readable by the server.
KNWLGE_GITHUB_WEBHOOK_SECRET—No — secretVerifies GitHub's webhook signatures.
KNWLGE_GITHUB_SYNC_DAEMON_ENABLEDfalseYesRuns the GitHub sync loop inside the worker.
KNWLGE_ADO_ORG_URL—Settings → Azure DevOpshttps://dev.azure.com/<organization>; turns on Azure DevOps.
KNWLGE_ADO_AUTH_MODE—Settings → Azure DevOpspat or service_principal.
KNWLGE_ADO_SYNC_DAEMON_ENABLEDfalseYesRuns the Azure DevOps sync loop inside the worker.
KNWLGE_CONNECTOR_SYNC_MAX_PAGES20YesPages a connector sync pulls per pass.

Limits and network

SettingDefaultConsoleWhat it does
KNWLGE_IDENTITY_RATE_LIMIT_PER_MINUTE240YesRequests a minute from one person.
KNWLGE_ORG_RATE_LIMIT_PER_MINUTE20000YesRequests a minute from the whole organization.
KNWLGE_PROVIDER_ALLOWED_HOSTS—No — setupThe embedding and LLM hosts the server may call; nothing else is reached.
KNWLGE_PROVIDER_MAX_CALLS_PER_JOB10000YesProvider calls a job may make.
KNWLGE_TRUSTED_PROXY_HOPS—No — deploymentProxies in front of the server whose forwarded headers are trusted, 1 to 4 (or KNWLGE_TRUSTED_PROXY_CIDRS).
KNWLGE_API_INSTANCE_COUNT1No — deploymentAPI instances; more than one needs Redis for rate limits.
KNWLGE_METRICS_TOKEN—No — secretBearer token required on /metrics; unset leaves it open.

Audit, alerts and retention

SettingDefaultConsoleWhat it does
KNWLGE_AUDIT_RETENTION_DAYS365YesDays audit events are kept, 30 to 3650.
KNWLGE_AUDIT_RETENTION_SCHEDULED_ENABLEDfalseYesPrunes audit events older than that on a schedule.
KNWLGE_AUDIT_SIEM_SHIP_ENABLEDfalseYesShips audit events to your SIEM continuously.
KNWLGE_AUDIT_SIEM_ENDPOINT—YesWhere they go; the bearer token and signing secret are set in the deployment.
KNWLGE_ALERT_WEBHOOK_URL—YesWhere the Alerts page sends alerts, signed with KNWLGE_ALERT_WEBHOOK_SECRET. Unset: alerts can be acknowledged but not sent.
KNWLGE_OTEL_ENABLEDfalseYesOpenTelemetry traces and metrics.
KNWLGE_CONFIG_STRICTfalseNo — deploymentFail the start on unknown, invalid or retired settings, instead of warning.