Skip to content

History of Vault Cortex

io.github.aliasunder/vault-cortex · Registry status: active

Report data on this entry

Every published change to this entry, most recent first.

Changes
2026-09-24Last changed in the registry (raw): 2026-09-21 → 2026-09-23
2026-09-24First listed in the registry (raw): 2026-09-21 → 2026-09-23
2026-09-24Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.54.1","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.54.2","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
2026-09-24Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.54.1 → ghcr.io/aliasunder/vault-cortex:0.54.2
2026-09-24Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.54.1 → oci:ghcr.io/aliasunder/vault-cortex:0.54.2
2026-09-22Declared version: 0.54.0 → 0.54.1
2026-09-22Last changed in the registry (raw): 2026-09-19 → 2026-09-21
2026-09-22First listed in the registry (raw): 2026-09-19 → 2026-09-21
2026-09-22Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.54.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.54.1","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
2026-09-22Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.54.0 → ghcr.io/aliasunder/vault-cortex:0.54.1
2026-09-22Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.54.0 → oci:ghcr.io/aliasunder/vault-cortex:0.54.1
2026-09-20Declared version: 0.53.0 → 0.54.0
2026-09-20Last changed in the registry (raw): 2026-09-18 → 2026-09-19
2026-09-20First listed in the registry (raw): 2026-09-18 → 2026-09-19
2026-09-20Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.53.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.54.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
2026-09-20Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.53.0 → ghcr.io/aliasunder/vault-cortex:0.54.0
2026-09-20Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.53.0 → oci:ghcr.io/aliasunder/vault-cortex:0.54.0
2026-09-19Declared version: 0.52.1 → 0.53.0
2026-09-19Last changed in the registry (raw): 2026-09-17 → 2026-09-18
2026-09-19First listed in the registry (raw): 2026-09-17 → 2026-09-18
2026-09-19Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.52.1","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.53.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
2026-09-19Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.52.1 → ghcr.io/aliasunder/vault-cortex:0.53.0
2026-09-19Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.52.1 → oci:ghcr.io/aliasunder/vault-cortex:0.53.0
2026-09-18Declared version: 0.52.0 → 0.52.1
2026-09-18Last changed in the registry (raw): 2026-09-16 → 2026-09-17
2026-09-18First listed in the registry (raw): 2026-09-16 → 2026-09-17
2026-09-18Environment variable descriptions (raw): DAILY_NOTES_FOLDER=Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. · DAILY_NOTES_FORMAT=Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. · DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: "Daily Notes", "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely. · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HOPS=How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it. · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. → DAILY_NOTES_FOLDER=Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "Daily Notes". · DAILY_NOTES_FORMAT=Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "YYYY-MM-DD". · DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else "Daily Notes"), "Templates", MEMORY_DIR. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely. · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HOPS=How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it. · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.
2026-09-18Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.52.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.52.1","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
2026-09-18Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.52.0 → ghcr.io/aliasunder/vault-cortex:0.52.1
2026-09-18Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.52.0 → oci:ghcr.io/aliasunder/vault-cortex:0.52.1
2026-09-17Declared version: 0.51.0 → 0.52.0
2026-09-17Last changed in the registry (raw): 2026-09-15 → 2026-09-16
2026-09-17First listed in the registry (raw): 2026-09-15 → 2026-09-16
2026-09-17Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.51.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.52.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
2026-09-17Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.51.0 → ghcr.io/aliasunder/vault-cortex:0.52.0
2026-09-17Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.51.0 → oci:ghcr.io/aliasunder/vault-cortex:0.52.0
2026-09-16Declared version: 0.50.4 → 0.51.0
2026-09-16Last changed in the registry (raw): 2026-09-13 → 2026-09-15
2026-09-16First listed in the registry (raw): 2026-09-13 → 2026-09-15
2026-09-16Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.50.4","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.51.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
2026-09-16Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.50.4 → ghcr.io/aliasunder/vault-cortex:0.51.0
2026-09-16Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.50.4 → oci:ghcr.io/aliasunder/vault-cortex:0.51.0
2026-09-14Declared version: 0.50.3 → 0.50.4
2026-09-14Last changed in the registry (raw): 2026-09-12 → 2026-09-13
2026-09-14First listed in the registry (raw): 2026-09-12 → 2026-09-13
2026-09-14Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.50.3","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.50.4","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin.","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
2026-09-14Package identifiers (raw): ghcr.io/aliasunder/vault-cortex:0.50.3 → ghcr.io/aliasunder/vault-cortex:0.50.4
2026-09-14Package coordinate: oci:ghcr.io/aliasunder/vault-cortex:0.50.3 → oci:ghcr.io/aliasunder/vault-cortex:0.50.4
2026-09-13Declared version: 0.50.2 → 0.50.3
2026-09-13Last changed in the registry (raw): 2026-09-11 → 2026-09-12

This view pages forward and states no total: individual rows are dropped only at output time when their evidence is missing. A counted total would be larger than what is shown.

tracevero · https://tracevero.com/mcp/io-github-aliasunder-vault-cortex/aenderungen