docs: update docs for global variables page and security (#4878)
* Added best practices document * Refactored global variables page * added category * move-security-page * link * Removed title from Security Best Practices * Avoid empty headings * Sentence case for headings * Remove general best practices not related to Langflow * Add bulleted list instead of numbered list * changed default secret locations to use the default secret key locations * Add periods on end of sentences * Changed title to be imperative --------- Co-authored-by: Mendon Kissling <59585235+mendonk@users.noreply.github.com>
This commit is contained in:
parent
19d2974904
commit
008c65b6b7
3 changed files with 183 additions and 141 deletions
|
|
@ -29,8 +29,7 @@ Langflow stores global variables in its internal database, and encrypts the valu
|
||||||
|
|
||||||
6. Enter the **Value** for your global variable.
|
6. Enter the **Value** for your global variable.
|
||||||
|
|
||||||
7. Optional: Use the **Apply To Fields** menu to select one or more fields that you want Langflow to automatically apply your global variable to.
|
7. Optional: Use the **Apply To Fields** menu to select one or more fields that you want Langflow to automatically apply your global variable to. For example, if you select **OpenAI API Key**, Langflow will automatically apply the variable to any **OpenAI API Key** field.
|
||||||
For example, if you select **OpenAI API Key**, Langflow will automatically apply the variable to any **OpenAI API Key** field.
|
|
||||||
|
|
||||||
8. Click **Save Variable**.
|
8. Click **Save Variable**.
|
||||||
|
|
||||||
|
|
@ -71,6 +70,8 @@ The global variable, and any existing references to it, are deleted.
|
||||||
|
|
||||||
## Add global variables from the environment {#76844a93dbbc4d1ba551ea1a4a89ccdd}
|
## Add global variables from the environment {#76844a93dbbc4d1ba551ea1a4a89ccdd}
|
||||||
|
|
||||||
|
### Custom environment variables
|
||||||
|
|
||||||
You can use the `LANGFLOW_VARIABLES_TO_GET_FROM_ENVIRONMENT` environment variable to source global variables from your runtime environment.
|
You can use the `LANGFLOW_VARIABLES_TO_GET_FROM_ENVIRONMENT` environment variable to source global variables from your runtime environment.
|
||||||
|
|
||||||
<Tabs>
|
<Tabs>
|
||||||
|
|
@ -150,8 +151,8 @@ When adding global variables from the environment, the following limitations app
|
||||||
- You can only source the **Name** and **Value** from the environment.
|
- You can only source the **Name** and **Value** from the environment.
|
||||||
To add additional parameters, such as the **Apply To Fields** parameter, you must edit the global variables in the Langflow UI.
|
To add additional parameters, such as the **Apply To Fields** parameter, you must edit the global variables in the Langflow UI.
|
||||||
|
|
||||||
- Global variables that you add from the the environment always have the **Credential** type.
|
- Global variables that you add from the environment always have the **Credential** type.
|
||||||
:::
|
:::
|
||||||
|
|
||||||
:::tip
|
:::tip
|
||||||
If you want to explicitly prevent Langflow from sourcing global variables from the environment, set `LANGFLOW_STORE_ENVIRONMENT_VARIABLES` to `false` in your `.env` file:
|
If you want to explicitly prevent Langflow from sourcing global variables from the environment, set `LANGFLOW_STORE_ENVIRONMENT_VARIABLES` to `false` in your `.env` file:
|
||||||
|
|
@ -162,46 +163,36 @@ LANGFLOW_STORE_ENVIRONMENT_VARIABLES=false
|
||||||
|
|
||||||
:::
|
:::
|
||||||
|
|
||||||
<!-- TODO: Most of the information in this section should be documented on other pages dedicated to environment variables and best practices. However, until those pages exist, we'll just have to keep this information here. Once those pages are added, we can reduce this section to a bulleted list with cross references. -->
|
### Default environment variables
|
||||||
## Precautions
|
|
||||||
|
|
||||||
Even though Langflow stores global variables in its internal database, and encrypts the values using a secret key, you should consider taking extra precautions to ensure the database and secret key are protected.
|
Langflow automatically detects and converts some environment variables into global variables of the type **Credential**, which are applied to the specific fields in components that require them. Currently, the following variables are supported:
|
||||||
|
|
||||||
### Use a custom secret key
|
- `OPENAI_API_KEY`
|
||||||
|
- `ANTHROPIC_API_KEY`
|
||||||
|
- `GOOGLE_API_KEY`
|
||||||
|
- `COHERE_API_KEY`
|
||||||
|
- `GROQ_API_KEY`
|
||||||
|
- `HUGGINGFACEHUB_API_TOKEN`
|
||||||
|
- `SEARCHAPI_API_KEY`
|
||||||
|
- `SERPAPI_API_KEY`
|
||||||
|
- `AZURE_OPENAI_API_KEY`
|
||||||
|
- `AZURE_OPENAI_API_VERSION`
|
||||||
|
- `AZURE_OPENAI_API_INSTANCE_NAME`
|
||||||
|
- `AZURE_OPENAI_API_DEPLOYMENT_NAME`
|
||||||
|
- `AZURE_OPENAI_API_EMBEDDINGS_DEPLOYMENT_NAME`
|
||||||
|
- `PINECONE_API_KEY`
|
||||||
|
- `ASTRA_DB_APPLICATION_TOKEN`
|
||||||
|
- `ASTRA_DB_API_ENDPOINT`
|
||||||
|
- `UPSTASH_VECTOR_REST_URL`
|
||||||
|
- `UPSTASH_VECTOR_REST_TOKEN`
|
||||||
|
- `VECTARA_CUSTOMER_ID`
|
||||||
|
- `VECTARA_CORPUS_ID`
|
||||||
|
- `VECTARA_API_KEY`
|
||||||
|
- `AWS_ACCESS_KEY_ID`
|
||||||
|
- `AWS_SECRET_ACCESS_KEY`
|
||||||
|
|
||||||
By default, Langflow generates a random secret key.
|
For information about other environment variables and their usage, see [Environment Variables](/environment-variables).
|
||||||
However, you should provide your own secret key, as it's more secure to use a key that is already known to you.
|
|
||||||
|
|
||||||
Use the `LANGFLOW_SECRET_KEY` environment variable to provide a custom value for the secret key when you start Langflow.
|
## Security best practices
|
||||||
|
|
||||||
### Protect the secret key
|
For information about securing your global variables and other sensitive data, see [Security best practices](/configuration-security-best-practices).
|
||||||
|
|
||||||
Make sure to store the secret key in a secure location.
|
|
||||||
|
|
||||||
By default, Langflow stores the secret key in its configuration directory.
|
|
||||||
The location of the configuration directory depends on your operating system:
|
|
||||||
|
|
||||||
- macOS: `~/Library/Caches/langflow/secret_key`
|
|
||||||
- Linux: `~/.cache/langflow/secret_key`
|
|
||||||
- Windows: `%USERPROFILE%\AppData\Local\langflow\secret_key`
|
|
||||||
|
|
||||||
To change the location of the the configuration directory, and thus the location of the secret key, set the `LANGFLOW_CONFIG_DIR` environment variable to your preferred storage directory.
|
|
||||||
|
|
||||||
### Protect the database
|
|
||||||
|
|
||||||
Make sure to store Langflow's internal database file in a secure location, and take regular backups to prevent accidental data loss.
|
|
||||||
|
|
||||||
By default, Langflow stores the database file in its installation directory.
|
|
||||||
The location of the file depends on your operating system and installation method:
|
|
||||||
|
|
||||||
- macOS: `PYTHON_LOCATION/site-packages/langflow/langflow.db`
|
|
||||||
- Linux: `PYTHON_LOCATION/site-packages/langflow/langflow.db`
|
|
||||||
- Windows: `PYTHON_LOCATION\Lib\site-packages\langflow\langflow.db`
|
|
||||||
|
|
||||||
To change the location of the database file, follow these steps:
|
|
||||||
|
|
||||||
1. Set the `LANGFLOW_SAVE_DB_IN_CONFIG_DIR` environment variable to `true`.
|
|
||||||
2. Set the `LANGFLOW_CONFIG_DIR` environment variable to your preferred storage directory.
|
|
||||||
|
|
||||||
<!-- TODO: Add documentation for external database support. -->
|
|
||||||
<!-- Alternatively, you can configure Langflow to store data in an *external* database, such as PostgreSQL, instead of its own internal database. -->
|
|
||||||
|
|
@ -0,0 +1,48 @@
|
||||||
|
---
|
||||||
|
title: Security best practices
|
||||||
|
sidebar_position: 1
|
||||||
|
slug: /configuration-security-best-practices
|
||||||
|
---
|
||||||
|
|
||||||
|
This guide outlines security best practices for deploying and managing Langflow.
|
||||||
|
|
||||||
|
## Secret key protection
|
||||||
|
|
||||||
|
The secret key is critical for encrypting sensitive data in Langflow. Follow these guidelines:
|
||||||
|
|
||||||
|
- Always use a custom secret key in production:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
LANGFLOW_SECRET_KEY=your-secure-secret-key
|
||||||
|
```
|
||||||
|
|
||||||
|
- Store the secret key securely:
|
||||||
|
|
||||||
|
- Use environment variables or secure secret management systems.
|
||||||
|
- Never commit the secret key to version control.
|
||||||
|
- Regularly rotate the secret key.
|
||||||
|
|
||||||
|
- Use the default secret key locations:
|
||||||
|
- macOS: `~/Library/Caches/langflow/secret_key`
|
||||||
|
- Linux: `~/.cache/langflow/secret_key`
|
||||||
|
- Windows: `%USERPROFILE%\AppData\Local\langflow\secret_key`
|
||||||
|
|
||||||
|
## API keys and credentials
|
||||||
|
|
||||||
|
- Store API keys and credentials as encrypted global variables.
|
||||||
|
- Use the Credential type for sensitive information.
|
||||||
|
- Implement proper access controls for users who can view/edit credentials.
|
||||||
|
- Regularly audit and rotate API keys.
|
||||||
|
|
||||||
|
## Database file protection
|
||||||
|
|
||||||
|
- Store the database in a secure location:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
LANGFLOW_SAVE_DB_IN_CONFIG_DIR=true
|
||||||
|
LANGFLOW_CONFIG_DIR=/secure/path/to/config
|
||||||
|
```
|
||||||
|
|
||||||
|
- Use the default database locations:
|
||||||
|
- macOS/Linux: `PYTHON_LOCATION/site-packages/langflow/langflow.db`
|
||||||
|
- Windows: `PYTHON_LOCATION\Lib\site-packages\langflow\langflow.db`
|
||||||
169
docs/sidebars.js
169
docs/sidebars.js
|
|
@ -1,17 +1,17 @@
|
||||||
module.exports = {
|
module.exports = {
|
||||||
docs: [
|
docs: [
|
||||||
'Get-Started/welcome-to-langflow',
|
"Get-Started/welcome-to-langflow",
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Get Started',
|
label: "Get Started",
|
||||||
items: [
|
items: [
|
||||||
'Get-Started/get-started-installation',
|
"Get-Started/get-started-installation",
|
||||||
'Get-Started/get-started-quickstart',
|
"Get-Started/get-started-quickstart",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Starter Projects',
|
label: "Starter Projects",
|
||||||
items: [
|
items: [
|
||||||
'Starter-Projects/starter-projects-basic-prompting',
|
'Starter-Projects/starter-projects-basic-prompting',
|
||||||
'Starter-Projects/starter-projects-blog-writer',
|
'Starter-Projects/starter-projects-blog-writer',
|
||||||
|
|
@ -24,122 +24,125 @@ module.exports = {
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Workspace',
|
label: "Workspace",
|
||||||
items: [
|
items: [
|
||||||
'Workspace/workspace-overview',
|
"Workspace/workspace-overview",
|
||||||
'Workspace/workspace-api',
|
"Workspace/workspace-api",
|
||||||
'Workspace/workspace-logs',
|
"Workspace/workspace-logs",
|
||||||
'Workspace/workspace-playground',
|
"Workspace/workspace-playground",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Agents',
|
label: "Agents",
|
||||||
items: [
|
items: [
|
||||||
'Agents/agents-overview',
|
"Agents/agents-overview",
|
||||||
'Agents/agent-tool-calling-agent-component',
|
"Agents/agent-tool-calling-agent-component",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Configuration',
|
label: "Configuration",
|
||||||
items: [
|
items: [
|
||||||
'Configuration/configuration-api-keys',
|
"Configuration/configuration-api-keys",
|
||||||
'Configuration/configuration-authentication',
|
"Configuration/configuration-authentication",
|
||||||
'Configuration/configuration-auto-saving',
|
"Configuration/configuration-auto-saving",
|
||||||
'Configuration/configuration-backend-only',
|
"Configuration/configuration-backend-only",
|
||||||
'Configuration/configuration-cli',
|
"Configuration/configuration-cli",
|
||||||
'Configuration/configuration-global-variables',
|
"Configuration/configuration-global-variables",
|
||||||
'Configuration/environment-variables',
|
"Configuration/environment-variables",
|
||||||
|
"Configuration/configuration-security-best-practices"
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Components',
|
label: "Components",
|
||||||
items: [
|
items: [
|
||||||
'Components/components-overview',
|
"Components/components-overview",
|
||||||
'Components/components-agents',
|
"Components/components-agents",
|
||||||
'Components/components-custom-components',
|
"Components/components-custom-components",
|
||||||
'Components/components-data',
|
"Components/components-data",
|
||||||
'Components/components-embedding-models',
|
"Components/components-embedding-models",
|
||||||
'Components/components-helpers',
|
"Components/components-helpers",
|
||||||
'Components/components-io',
|
"Components/components-io",
|
||||||
'Components/components-loaders',
|
"Components/components-loaders",
|
||||||
'Components/components-logic',
|
"Components/components-logic",
|
||||||
'Components/components-memories',
|
"Components/components-memories",
|
||||||
'Components/components-models',
|
"Components/components-models",
|
||||||
'Components/components-prompts',
|
"Components/components-prompts",
|
||||||
'Components/components-rag',
|
"Components/components-rag",
|
||||||
'Components/components-tools',
|
"Components/components-tools",
|
||||||
'Components/components-vector-stores',
|
"Components/components-vector-stores",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Guides',
|
label: "Guides",
|
||||||
items: [
|
items: [
|
||||||
'Guides/guides-chat-memory',
|
"Guides/guides-chat-memory",
|
||||||
'Guides/guides-data-message',
|
"Guides/guides-data-message",
|
||||||
'Guides/guides-new-to-llms',
|
"Guides/guides-new-to-llms",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Deployment',
|
label: "Deployment",
|
||||||
items: [
|
items: [
|
||||||
'Deployment/deployment-docker',
|
"Deployment/deployment-docker",
|
||||||
'Deployment/deployment-gcp',
|
"Deployment/deployment-gcp",
|
||||||
'Deployment/deployment-hugging-face-spaces',
|
"Deployment/deployment-hugging-face-spaces",
|
||||||
'Deployment/deployment-kubernetes',
|
"Deployment/deployment-kubernetes",
|
||||||
'Deployment/deployment-railway',
|
"Deployment/deployment-railway",
|
||||||
'Deployment/deployment-render',
|
"Deployment/deployment-render",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Integrations',
|
label: "Integrations",
|
||||||
items: [
|
items: [
|
||||||
'Integrations/integrations-assemblyai',
|
"Integrations/integrations-assemblyai",
|
||||||
'Integrations/integrations-langfuse',
|
"Integrations/integrations-langfuse",
|
||||||
'Integrations/integrations-langsmith',
|
"Integrations/integrations-langsmith",
|
||||||
'Integrations/integrations-langwatch',
|
"Integrations/integrations-langwatch",
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Google',
|
label: "Google",
|
||||||
items: ['Integrations/Google/integrations-setup-google-oauth-langflow'],
|
items: [
|
||||||
|
"Integrations/Google/integrations-setup-google-oauth-langflow",
|
||||||
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Notion',
|
label: "Notion",
|
||||||
items: [
|
items: [
|
||||||
'Integrations/Notion/integrations-notion',
|
"Integrations/Notion/integrations-notion",
|
||||||
'Integrations/Notion/notion-agent-conversational',
|
"Integrations/Notion/notion-agent-conversational",
|
||||||
'Integrations/Notion/notion-agent-meeting-notes',
|
"Integrations/Notion/notion-agent-meeting-notes",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'Contributing',
|
label: "Contributing",
|
||||||
items: [
|
items: [
|
||||||
'Contributing/contributing-community',
|
"Contributing/contributing-community",
|
||||||
'Contributing/contributing-components',
|
"Contributing/contributing-components",
|
||||||
'Contributing/contributing-github-discussion-board',
|
"Contributing/contributing-github-discussion-board",
|
||||||
'Contributing/contributing-github-issues',
|
"Contributing/contributing-github-issues",
|
||||||
'Contributing/contributing-how-to-contribute',
|
"Contributing/contributing-how-to-contribute",
|
||||||
'Contributing/contributing-telemetry',
|
"Contributing/contributing-telemetry",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
type: 'category',
|
type: "category",
|
||||||
label: 'API Reference',
|
label: "API Reference",
|
||||||
items: [
|
items: [
|
||||||
{
|
{
|
||||||
type: 'link',
|
type: "link",
|
||||||
label: 'API Documentation',
|
label: "API Documentation",
|
||||||
href: '/api',
|
href: "/api",
|
||||||
},
|
},
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue