Skip to content

Configuration

Muhammad amien edited this page Sep 24, 2026 · 3 revisions

Configuration

Environment Variables

Variable Required Purpose
TELEGRAM_BOT_TOKEN Yes Authenticates the Telegram bot used by aiogram.
TELEGRAM_ALLOWED_CHAT_IDS Recommended Comma-separated numeric chat IDs allowed to use the bot.
AI_PROVIDER No Provider preset. Defaults to ollama.
AI_MODEL Provider-dependent Model identifier. Defaults to qwen3:8b with Ollama.
AI_BASE_URL Provider-dependent OpenAI-compatible chat-completions endpoint.
AI_API_KEY Provider-dependent Credential for providers that require authentication.
AI_TEMPERATURE No Sampling temperature; defaults to 0.
GEMINI_API_KEY Legacy only Backward-compatible fallback when AI_PROVIDER=gemini.

Create a local configuration from the example:

cp .env.example .env

Do not commit real values. The repository .gitignore excludes .env, but contributors must still review commits and logs for accidental secrets.

AI Providers

Lophiarch uses one OpenAI-compatible provider interface across local and hosted models.

AI_PROVIDER Default endpoint Default model API key
ollama http://localhost:11434/v1/chat/completions qwen3:8b Not required
vllm http://localhost:8000/v1/chat/completions Qwen/Qwen3-8B Not required by default
lmstudio http://localhost:1234/v1/chat/completions local-model Not required by default
llamacpp http://localhost:8080/v1/chat/completions local-model Not required by default
gemini Google OpenAI-compatible endpoint gemini-3.5-flash-lite Required
openai-compatible Set with AI_BASE_URL Set with AI_MODEL Provider-dependent

A local default configuration:

AI_PROVIDER=ollama
AI_MODEL=qwen3:8b
AI_BASE_URL=http://localhost:11434/v1/chat/completions
AI_API_KEY=
AI_TEMPERATURE=0

For an unlisted service, use AI_PROVIDER=openai-compatible and supply its chat-completions URL, model identifier, and API key when required.

Worker Image Names

The current scanner modules expect these exact tags:

Capability Image
Nmap lophiarch-nmap:latest
Ffuf lophiarch-ffuf:latest
Nuclei lophiarch-nuclei:latest
Subfinder projectdiscovery/subfinder:latest
dnsx projectdiscovery/dnsx:latest

If a custom build uses different names, update the corresponding engine module or retag the image.

Nmap Modes

Mode Current behavior
quick Adds -F for the common-port set.
default Uses service detection with -sV -Pn.
deep Adds all-port scanning and default scripts with -p- -sC.

All modes request XML output for parsing.

Ffuf Modes

Mode Wordlist
quick or default /wordlists/quick.txt
deep /wordlists/deep.txt

The custom image downloads its wordlists from SecLists during image build.

Helm Values

The chart exposes provider-neutral values:

telegram:
  botToken: ""
  allowedChatIds: ""

ai:
  provider: ollama
  model: qwen3:8b
  baseUrl: http://ollama.default.svc.cluster.local:11434/v1/chat/completions
  temperature: "0"
  apiKey: ""
  geminiApiKey: "" # legacy fallback only

Override secrets at installation time or through a secure values workflow. Avoid committing plaintext production values.

Generated Reports

PDFs are created in generated_reports/. The directory is ignored by Git. Inside a disposable main container, reports disappear when the container is removed unless a volume is mounted.

Clone this wiki locally