History of Vault Cortex
io.github.aliasunder/vault-cortex · Status: active
If you find your own account name here: write informally to German.saas@web.de, stating the identifier concerned. No reason has to be given. How to object
Every published change to this entry, most recent first.
| 2026-08-26 | Version: 0.42.0 → 0.42.1 |
|---|---|
| 2026-08-26 | Last changed in the registry (raw): 2026-08-24 → 2026-08-25 |
| 2026-08-26 | First listed in the registry (raw): 2026-08-24 → 2026-08-25 |
| 2026-08-26 | Environment variable descriptions (raw): DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HOPS=How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it. · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. → DAILY_NOTES_FOLDER=Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. · DAILY_NOTES_FORMAT=Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. · DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HOPS=How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it. · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. |
| 2026-08-26 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.42.0 → ghcr.io/aliasunder/vault-cortex:0.42.1 |
| 2026-08-26 | Environment variables (raw): MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, TRUST_PROXY_HOPS, TRUST_FORWARDED_HOPS, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES → MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, DAILY_NOTES_FOLDER, DAILY_NOTES_FORMAT, TRUST_PROXY_HOPS, TRUST_FORWARDED_HOPS, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES |
| 2026-08-26 | Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.42.0 → oci:ghcr.io/aliasunder/vault-cortex:0.42.1 |
| 2026-08-25 | Version: 0.41.0 → 0.42.0 |
| 2026-08-25 | Last changed in the registry (raw): 2026-08-23 → 2026-08-24 |
| 2026-08-25 | First listed in the registry (raw): 2026-08-23 → 2026-08-24 |
| 2026-08-25 | Environment variable descriptions (raw): DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HEADER=Trust the RFC 7239 Forwarded header as the client identity for OAuth rate limiting and request logs. Enable only when the proxy in front sets it (e.g. AWS API Gateway). · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. → DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HOPS=How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it. · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. |
| 2026-08-25 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.41.0 → ghcr.io/aliasunder/vault-cortex:0.42.0 |
| 2026-08-25 | Environment variables (raw): MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, TRUST_PROXY_HOPS, TRUST_FORWARDED_HEADER, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES → MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, TRUST_PROXY_HOPS, TRUST_FORWARDED_HOPS, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES |
| 2026-08-25 | Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.41.0 → oci:ghcr.io/aliasunder/vault-cortex:0.42.0 |
| 2026-08-24 | Version: 0.40.1 → 0.41.0 |
| 2026-08-24 | Last changed in the registry (raw): 2026-08-22 → 2026-08-23 |
| 2026-08-24 | First listed in the registry (raw): 2026-08-22 → 2026-08-23 |
| 2026-08-24 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.40.1 → ghcr.io/aliasunder/vault-cortex:0.41.0 |
| 2026-08-24 | Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.40.1 → oci:ghcr.io/aliasunder/vault-cortex:0.41.0 |
| 2026-08-23 | Version: 0.39.0 → 0.40.1 |
| 2026-08-23 | Last changed in the registry (raw): 2026-08-21 → 2026-08-22 |
| 2026-08-23 | First listed in the registry (raw): 2026-08-21 → 2026-08-22 |
| 2026-08-23 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.39.0 → ghcr.io/aliasunder/vault-cortex:0.40.1 |
| 2026-08-23 | Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.39.0 → oci:ghcr.io/aliasunder/vault-cortex:0.40.1 |
| 2026-08-22 | Version: 0.38.2 → 0.39.0 |
| 2026-08-22 | Last changed in the registry (raw): 2026-08-20 → 2026-08-21 |
| 2026-08-22 | First listed in the registry (raw): 2026-08-20 → 2026-08-21 |
| 2026-08-22 | Environment variable descriptions (raw): DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for persistent log files. Unset by default — logs go to stdout only. Set to /data/logs to also write date-stamped .log files to the persistent volume. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to retain persistent log files before cleanup. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HEADER=Trust the RFC 7239 Forwarded header as the client identity for OAuth rate limiting and request logs. Enable only when the proxy in front sets it (e.g. AWS API Gateway). · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. → DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HEADER=Trust the RFC 7239 Forwarded header as the client identity for OAuth rate limiting and request logs. Enable only when the proxy in front sets it (e.g. AWS API Gateway). · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. |
| 2026-08-22 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.38.2 → ghcr.io/aliasunder/vault-cortex:0.39.0 |
| 2026-08-22 | Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.38.2 → oci:ghcr.io/aliasunder/vault-cortex:0.39.0 |
| 2026-08-21 | Version: 0.37.4 → 0.38.2 |
| 2026-08-21 | Last changed in the registry (raw): 2026-08-19 → 2026-08-20 |
| 2026-08-21 | First listed in the registry (raw): 2026-08-19 → 2026-08-20 |
| 2026-08-21 | Environment variable descriptions (raw): DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for persistent log files. Unset by default — logs go to stdout only. Set to /data/logs to also write date-stamped .log files to the persistent volume. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to retain persistent log files before cleanup. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. → DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for persistent log files. Unset by default — logs go to stdout only. Set to /data/logs to also write date-stamped .log files to the persistent volume. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to retain persistent log files before cleanup. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HEADER=Trust the RFC 7239 Forwarded header as the client identity for OAuth rate limiting and request logs. Enable only when the proxy in front sets it (e.g. AWS API Gateway). · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. |
| 2026-08-21 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.37.4 → ghcr.io/aliasunder/vault-cortex:0.38.2 |
| 2026-08-21 | Environment variables (raw): MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES → MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, TRUST_PROXY_HOPS, TRUST_FORWARDED_HEADER, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES |
| 2026-08-21 | Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.37.4 → oci:ghcr.io/aliasunder/vault-cortex:0.38.2 |
| 2026-08-20 | Version: 0.37.3 → 0.37.4 |
| 2026-08-20 | Last changed in the registry (raw): 2026-08-18 → 2026-08-19 |
| 2026-08-20 | First listed in the registry (raw): 2026-08-18 → 2026-08-19 |
| 2026-08-20 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.37.3 → ghcr.io/aliasunder/vault-cortex:0.37.4 |
| 2026-08-20 | Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.37.3 → oci:ghcr.io/aliasunder/vault-cortex:0.37.4 |
| 2026-08-19 | Version: 0.37.1 → 0.37.3 |
| 2026-08-19 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.37.1 → ghcr.io/aliasunder/vault-cortex:0.37.3 |
| 2026-08-19 | Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.37.1 → oci:ghcr.io/aliasunder/vault-cortex:0.37.3 |
| 2026-08-18 | Version: 0.36.4 → 0.37.1 |
| 2026-08-18 | Last changed in the registry (raw): 2026-08-15 → 2026-08-18 |
| 2026-08-18 | First listed in the registry (raw): 2026-08-15 → 2026-08-18 |
| 2026-08-18 | Environment variable descriptions (raw): EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for persistent log files. Unset by default — logs go to stdout only. Set to /data/logs to also write date-stamped .log files to the persistent volume. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to retain persistent log files before cleanup. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. → DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for persistent log files. Unset by default — logs go to stdout only. Set to /data/logs to also write date-stamped .log files to the persistent volume. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to retain persistent log files before cleanup. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and "Daily Notes". · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. |
| 2026-08-18 | Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.36.4 → ghcr.io/aliasunder/vault-cortex:0.37.1 |
This view pages forward and states no total: individual rows are dropped only at output time when their evidence is missing. A counted total would be larger than what is shown.
tracevero · https://tracevero.com/mcp/io-github-aliasunder-vault-cortex/aenderungen