Obraz documentation

Configuration

The service

VariableWhat it is
OBRAZ_SECRETThe shared secret every caller sends in x-obraz-secret; the deployment injects it.
OBRAZ_COMFYUI_URLThe renderer's address, http:// or https://. Checked when the service starts, not when a render fails. A deployment that only edits names none: every render is then refused with 503 this Obraz has no renderer: its deployment sets OBRAZ_COMFYUI_URL, and GET /readyz says so under renderer.absent.
OBRAZ_COMFYUI_TOKENOptional; sent to the renderer as Authorization: Bearer when the renderer wants one.
OBRAZ_FRAMEThe frame, WIDTHxHEIGHT in pixels, a render request gets when it names no width and height: the size the deployment's creator pipeline renders at. Without it, a request that names no size is refused with 400. A value that is not two whole numbers above zero stops the service at startup.
OBRAZ_IMAGE_MODEL_URLThe image-model service the model steps of an edit go to: any service that speaks the OpenAI Images API, http:// or https://. In a Wisent deployment it is Brama, at the address stado service directory connect brama --consumer obraz names on the machine Obraz runs on; outside one it can be https://api.openai.com. Checked when the service starts.
OBRAZ_IMAGE_MODEL_TOKEN_FILEThe file holding the bearer for that service. In a Wisent deployment, Obraz's release manifest grants the service call:brama#image-model (runtime.grants), Stado delivers that bearer to every host Obraz rolls out to as ~/.stado/obraz-skarbiec-token, and the deployment's environment names that file here. Outside one it is a file holding an API key, readable by the service's user only. The file is read at startup and at every model step, so a bearer minted again is used without a restart.
OBRAZ_IMAGE_MODELThe model a model step asks when it names none: image-model for Brama's alias, or a provider's own model name such as gpt-image-1.

Without all three the service edits pictures and refuses every model step by name; GET /readyz says so under image_models.absent, and with all three it reports image_models.address and image_models.model.

The caller

VariableWhat it is
OBRAZ_URLWhere the service is.
OBRAZ_SECRET_ROLEROLE#FIELD: the vault role whose item holds the caller secret, and its field, read with stado credentials get --role ROLE --field FIELD. No item is named, so replacing the item changes nothing here. The CLI never takes the secret itself from the environment.
STADO_BINAnother Stado executable than stado.
OBRAZ_CREDENTIALS_FILEWithout Stado: an owner-only (mode 600) JSON file of role → field → value that answers OBRAZ_SECRET_ROLE in Stado's place.

Refusals

Exit 1 from serve, nothing served:

OBRAZ_SECRET is not set

the ComfyUI address is empty

the ComfyUI address contains <character>, so it cannot address a host: "<address>"

OBRAZ_FRAME must be WIDTHxHEIGHT in whole pixels above zero, not "<value>"

the ComfyUI address must be http or https: "<address>"

<the variables given> given and <the variables missing> missing: the model steps need all three

OBRAZ_IMAGE_MODEL_URL contains <character>, so it cannot address a host: "<address>"

OBRAZ_IMAGE_MODEL_URL must be http or https: "<address>"

OBRAZ_IMAGE_MODEL_TOKEN_FILE <path> cannot be read: <cause>

OBRAZ_IMAGE_MODEL_TOKEN_FILE <path> is empty

Exit 1 from render, nothing sent:

OBRAZ_URL is not set

OBRAZ_SECRET_ROLE is not set: name the vault role holding the Obraz caller secret and its field as ROLE#FIELD

OBRAZ_SECRET_ROLE must be a role reference ROLE#FIELD, not "<value>"

OBRAZ_SECRET_ROLE: <binary> could not be run: <cause>; without Stado set OBRAZ_CREDENTIALS_FILE to an owner-only JSON file of role -> field -> value

OBRAZ_SECRET_ROLE: <binary> credentials get --role <role> --field <field> failed: <what Stado said>

OBRAZ_SECRET_ROLE: the item playing role <role> holds no value in field <field>

OBRAZ_CREDENTIALS_FILE <path> must be readable by its owner only (mode <mode>)

OBRAZ_CREDENTIALS_FILE <path> cannot be read: <cause>

OBRAZ_CREDENTIALS_FILE <path> is not a JSON object of role -> field -> value

OBRAZ_CREDENTIALS_FILE <path> has no non-empty <role>#<field>