Configuration
The service
| Variable | What it is |
|---|---|
OBRAZ_SECRET | The shared secret every caller sends in x-obraz-secret; the deployment injects it. |
OBRAZ_COMFYUI_URL | The renderer's address, http:// or https://. Checked when the service starts, not when a render fails. A deployment that only edits names none: every render is then refused with 503 this Obraz has no renderer: its deployment sets OBRAZ_COMFYUI_URL, and GET /readyz says so under renderer.absent. |
OBRAZ_COMFYUI_TOKEN | Optional; sent to the renderer as Authorization: Bearer when the renderer wants one. |
OBRAZ_FRAME | The frame, WIDTHxHEIGHT in pixels, a render request gets when it names no width and height: the size the deployment's creator pipeline renders at. Without it, a request that names no size is refused with 400. A value that is not two whole numbers above zero stops the service at startup. |
OBRAZ_IMAGE_MODEL_URL | The image-model service the model steps of an edit go to: any service that speaks the OpenAI Images API, http:// or https://. In a Wisent deployment it is Brama, at the address stado service directory connect brama --consumer obraz names on the machine Obraz runs on; outside one it can be https://api.openai.com. Checked when the service starts. |
OBRAZ_IMAGE_MODEL_TOKEN_FILE | The file holding the bearer for that service. In a Wisent deployment, Obraz's release manifest grants the service call:brama#image-model (runtime.grants), Stado delivers that bearer to every host Obraz rolls out to as ~/.stado/obraz-skarbiec-token, and the deployment's environment names that file here. Outside one it is a file holding an API key, readable by the service's user only. The file is read at startup and at every model step, so a bearer minted again is used without a restart. |
OBRAZ_IMAGE_MODEL | The model a model step asks when it names none: image-model for Brama's alias, or a provider's own model name such as gpt-image-1. |
Without all three the service edits pictures and refuses every model
step by name; GET /readyz says so under
image_models.absent, and with all three it reports
image_models.address and image_models.model.
The caller
| Variable | What it is |
|---|---|
OBRAZ_URL | Where the service is. |
OBRAZ_SECRET_ROLE | ROLE#FIELD: the vault role whose item holds the caller secret, and its field, read with stado credentials get --role ROLE --field FIELD. No item is named, so replacing the item changes nothing here. The CLI never takes the secret itself from the environment. |
STADO_BIN | Another Stado executable than stado. |
OBRAZ_CREDENTIALS_FILE | Without Stado: an owner-only (mode 600) JSON file of role → field → value that answers OBRAZ_SECRET_ROLE in Stado's place. |
Refusals
Exit 1 from serve, nothing
served:
OBRAZ_SECRET is not set
the ComfyUI address is empty
the ComfyUI address contains <character>, so it cannot address a host: "<address>"
OBRAZ_FRAME must be WIDTHxHEIGHT in whole pixels above zero, not "<value>"
the ComfyUI address must be http or https: "<address>"
<the variables given> given and <the variables missing> missing: the model steps need all three
OBRAZ_IMAGE_MODEL_URL contains <character>, so it cannot address a host: "<address>"
OBRAZ_IMAGE_MODEL_URL must be http or https: "<address>"
OBRAZ_IMAGE_MODEL_TOKEN_FILE <path> cannot be read: <cause>
OBRAZ_IMAGE_MODEL_TOKEN_FILE <path> is empty
Exit 1 from render, nothing
sent:
OBRAZ_URL is not set
OBRAZ_SECRET_ROLE is not set: name the vault role holding the Obraz caller secret and its field as ROLE#FIELD
OBRAZ_SECRET_ROLE must be a role reference ROLE#FIELD, not "<value>"
OBRAZ_SECRET_ROLE: <binary> could not be run: <cause>; without Stado set OBRAZ_CREDENTIALS_FILE to an owner-only JSON file of role -> field -> value
OBRAZ_SECRET_ROLE: <binary> credentials get --role <role> --field <field> failed: <what Stado said>
OBRAZ_SECRET_ROLE: the item playing role <role> holds no value in field <field>
OBRAZ_CREDENTIALS_FILE <path> must be readable by its owner only (mode <mode>)
OBRAZ_CREDENTIALS_FILE <path> cannot be read: <cause>
OBRAZ_CREDENTIALS_FILE <path> is not a JSON object of role -> field -> value
OBRAZ_CREDENTIALS_FILE <path> has no non-empty <role>#<field>