{
  "manifest_version": "1.0.0",
  "template": {
    "id": "1bb77bcd-3591-4b31-a9ee-019bdb1866e1",
    "slug": "dify-v1-ai-app-studio",
    "name": "Dify v1 AI App Studio",
    "description": "Visual agent & RAG builder with plugins, sandbox, workers and a vector DB.",
    "url": "https://railway.com/deploy/dify-v1-ai-app-studio",
    "upstream": {
      "repo_url": "https://github.com/baranberkay96/dify-railway"
    }
  },
  "services": [
    {
      "name": "API",
      "source": {
        "image": "langgenius/dify-api:1.17.1"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Worker",
      "source": {
        "image": "langgenius/dify-api:1.17.1"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "SSRF Proxy",
      "source": {
        "repo": "https://github.com/baranberkay96/dify-railway"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Web",
      "source": {
        "image": "langgenius/dify-web:1.17.1"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Agent SSRF Proxy",
      "source": {
        "repo": "https://github.com/baranberkay96/dify-railway"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Postgres",
      "source": {
        "image": "ghcr.io/railwayapp-templates/postgres-ssl:18"
      },
      "needs_volume": true,
      "volume_mount_path": "/var/lib/postgresql/data",
      "http": false
    },
    {
      "name": "API WebSocket",
      "source": {
        "image": "langgenius/dify-api:1.17.1"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Redis",
      "source": {
        "image": "redis:8.2"
      },
      "needs_volume": true,
      "volume_mount_path": "/data",
      "http": false
    },
    {
      "name": "Weaviate",
      "source": {
        "image": "semitechnologies/weaviate:1.39.11"
      },
      "needs_volume": true,
      "volume_mount_path": "/var/lib/weaviate",
      "http": false
    },
    {
      "name": "Sandbox",
      "source": {
        "image": "langgenius/dify-sandbox:0.2.15"
      },
      "needs_volume": true,
      "volume_mount_path": "/dependencies",
      "http": false
    },
    {
      "name": "Worker Beat",
      "source": {
        "image": "langgenius/dify-api:1.17.1"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Agent Sandbox",
      "source": {
        "repo": "https://github.com/baranberkay96/dify-railway"
      },
      "needs_volume": true,
      "volume_mount_path": "/home/dify",
      "http": false
    },
    {
      "name": "Plugin Daemon",
      "source": {
        "image": "langgenius/dify-plugin-daemon:0.6.10-local"
      },
      "needs_volume": true,
      "volume_mount_path": "/app/storage",
      "http": false
    },
    {
      "name": "Agent Backend",
      "source": {
        "image": "langgenius/dify-agent-backend:1.17.1"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Gateway",
      "source": {
        "repo": "https://github.com/baranberkay96/dify-railway"
      },
      "needs_volume": false,
      "http": true
    }
  ],
  "required_inputs": [
    {
      "key": "MODE",
      "service": "API",
      "description": "dify-api run mode.",
      "secret": false,
      "strategy": "default",
      "default": "api"
    },
    {
      "key": "PORT",
      "service": "API",
      "description": "Port Railway health-checks and routes to.",
      "secret": false,
      "strategy": "default",
      "default": "5001"
    },
    {
      "key": "DB_HOST",
      "service": "API",
      "description": "Postgres private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PORT",
      "service": "API",
      "description": "Postgres port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_TYPE",
      "service": "API",
      "description": "Metadata database type.",
      "secret": false,
      "strategy": "default",
      "default": "postgresql"
    },
    {
      "key": "REDIS_DB",
      "service": "API",
      "description": "Redis DB index for cache/locks.",
      "secret": false,
      "strategy": "default",
      "default": "0"
    },
    {
      "key": "DIFY_PORT",
      "service": "API",
      "description": "Gunicorn listen port.",
      "secret": false,
      "strategy": "default",
      "default": "5001"
    },
    {
      "key": "FILES_URL",
      "service": "API",
      "description": "Public prefix for signed file preview/download links.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "LOG_LEVEL",
      "service": "API",
      "description": "Log verbosity (DEBUG, INFO, WARNING, ERROR).",
      "secret": false,
      "strategy": "default",
      "default": "INFO"
    },
    {
      "key": "S3_REGION",
      "service": "API",
      "description": "Railway Bucket region.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DEPLOY_ENV",
      "service": "API",
      "description": "Deployment environment flag.",
      "secret": false,
      "strategy": "default",
      "default": "PRODUCTION"
    },
    {
      "key": "REDIS_HOST",
      "service": "API",
      "description": "Redis private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PORT",
      "service": "API",
      "description": "Redis port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SECRET_KEY",
      "service": "API",
      "description": "Flask signing/encryption key. Shared by API, WebSocket, Worker and Beat. Never change after first boot.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "APP_API_URL",
      "service": "API",
      "description": "Public URL of the web-app API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "APP_WEB_URL",
      "service": "API",
      "description": "Public URL of published web apps.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_DATABASE",
      "service": "API",
      "description": "Dify metadata database.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PASSWORD",
      "service": "API",
      "description": "Postgres password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_USERNAME",
      "service": "API",
      "description": "Postgres user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ENDPOINT",
      "service": "API",
      "description": "Railway Bucket S3 endpoint.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "TRIGGER_URL",
      "service": "API",
      "description": "Public prefix for workflow trigger webhooks.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "STORAGE_TYPE",
      "service": "API",
      "description": "File storage backend: Railway Bucket via the S3 API.",
      "secret": false,
      "strategy": "default",
      "default": "s3"
    },
    {
      "key": "VECTOR_STORE",
      "service": "API",
      "description": "Vector database used for knowledge bases.",
      "secret": false,
      "strategy": "default",
      "default": "weaviate"
    },
    {
      "key": "INIT_PASSWORD",
      "service": "API",
      "description": "Password required on /install before the first admin account can be created. Read it from this variable.",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    },
    {
      "key": "S3_ACCESS_KEY",
      "service": "API",
      "description": "Railway Bucket access key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_SECRET_KEY",
      "service": "API",
      "description": "Railway Bucket secret key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_BACKEND",
      "service": "API",
      "description": "Celery result backend.",
      "secret": false,
      "strategy": "default",
      "default": "redis"
    },
    {
      "key": "REDIS_PASSWORD",
      "service": "API",
      "description": "Redis password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_USERNAME",
      "service": "API",
      "description": "Redis user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_BUCKET_NAME",
      "service": "API",
      "description": "Railway Bucket name (S3 API name).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_API_URL",
      "service": "API",
      "description": "Public URL of the console API (same origin via Gateway).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_WEB_URL",
      "service": "API",
      "description": "Public URL of the console web UI.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_PUBLIC_URL",
      "service": "API",
      "description": "Public base URL of this Dify instance (the Gateway). Change here when you add a custom domain.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_domain"
    },
    {
      "key": "SERVICE_API_URL",
      "service": "API",
      "description": "Base URL shown for the Service API (/v1).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "GUNICORN_TIMEOUT",
      "service": "API",
      "description": "Request timeout in seconds (long streaming responses).",
      "secret": false,
      "strategy": "default",
      "default": "360"
    },
    {
      "key": "S3_ADDRESS_STYLE",
      "service": "API",
      "description": "S3 addressing style. Railway Buckets use virtual-hosted style; set 'path' only if the bucket's Credentials tab says so.",
      "secret": false,
      "strategy": "default",
      "default": "virtual"
    },
    {
      "key": "WEAVIATE_API_KEY",
      "service": "API",
      "description": "Weaviate API key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_BROKER_URL",
      "service": "API",
      "description": "Celery broker (Redis DB 1).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_BIND_ADDRESS",
      "service": "API",
      "description": "Bind on IPv4+IPv6 so the private network can reach it.",
      "secret": false,
      "strategy": "default",
      "default": "[::]"
    },
    {
      "key": "MIGRATION_ENABLED",
      "service": "API",
      "description": "Run database migrations on boot (only this service migrates).",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "PLUGIN_DAEMON_KEY",
      "service": "API",
      "description": "Key the API uses to call Plugin Daemon.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_DAEMON_URL",
      "service": "API",
      "description": "Plugin Daemon endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "WEAVIATE_ENDPOINT",
      "service": "API",
      "description": "Weaviate REST endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "INTERNAL_FILES_URL",
      "service": "API",
      "description": "Private URL used by Plugin Daemon and Agent services to fetch files.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "MARKETPLACE_API_URL",
      "service": "API",
      "description": "Plugin marketplace API.",
      "secret": false,
      "strategy": "default",
      "default": "https://marketplace.dify.ai"
    },
    {
      "key": "MARKETPLACE_ENABLED",
      "service": "API",
      "description": "Enable the Dify plugin marketplace.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "SERVER_WORKER_CLASS",
      "service": "API",
      "description": "Gunicorn worker class.",
      "secret": false,
      "strategy": "default",
      "default": "gevent"
    },
    {
      "key": "SSRF_PROXY_HTTP_URL",
      "service": "API",
      "description": "SSRF proxy for outbound HTTP from workflows/tools.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "SERVER_WORKER_AMOUNT",
      "service": "API",
      "description": "Gunicorn worker processes (raise with more RAM/CPU).",
      "secret": false,
      "strategy": "default",
      "default": "1"
    },
    {
      "key": "SQLALCHEMY_POOL_SIZE",
      "service": "API",
      "description": "DB pool size per process (kept below Postgres' default 100 connections across all services).",
      "secret": false,
      "strategy": "default",
      "default": "10"
    },
    {
      "key": "SSRF_PROXY_HTTPS_URL",
      "service": "API",
      "description": "SSRF proxy for outbound HTTPS from workflows/tools.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "ENDPOINT_URL_TEMPLATE",
      "service": "API",
      "description": "Public URL template for plugin endpoints (routed by the Gateway to Plugin Daemon).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_DAEMON_TIMEOUT",
      "service": "API",
      "description": "Timeout (s) for plugin invocations.",
      "secret": false,
      "strategy": "default",
      "default": "600.0"
    },
    {
      "key": "AGENT_BACKEND_BASE_URL",
      "service": "API",
      "description": "Dify Agent backend endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "CODE_EXECUTION_API_KEY",
      "service": "API",
      "description": "Code sandbox API key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_USE_AWS_MANAGED_IAM",
      "service": "API",
      "description": "Use static keys, not AWS IAM roles.",
      "secret": false,
      "strategy": "default",
      "default": "false"
    },
    {
      "key": "WEAVIATE_GRPC_ENDPOINT",
      "service": "API",
      "description": "Weaviate gRPC endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "AGENT_BACKEND_API_TOKEN",
      "service": "API",
      "description": "Bearer token for the Agent backend control plane.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CODE_EXECUTION_ENDPOINT",
      "service": "API",
      "description": "Code sandbox endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "PLUGIN_MAX_PACKAGE_SIZE",
      "service": "API",
      "description": "Max plugin package size in bytes.",
      "secret": false,
      "strategy": "default",
      "default": "52428800"
    },
    {
      "key": "SQLALCHEMY_MAX_OVERFLOW",
      "service": "API",
      "description": "Extra DB connections allowed above the pool size.",
      "secret": false,
      "strategy": "default",
      "default": "5"
    },
    {
      "key": "SQLALCHEMY_POOL_RECYCLE",
      "service": "API",
      "description": "Recycle DB connections after N seconds.",
      "secret": false,
      "strategy": "default",
      "default": "3600"
    },
    {
      "key": "INNER_API_KEY_FOR_PLUGIN",
      "service": "API",
      "description": "Key Plugin Daemon / Agent Backend use to call the API's inner endpoints.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_POOL_PRE_PING",
      "service": "API",
      "description": "Validate pooled connections before use (survives idle network resets).",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "ENABLE_COLLABORATION_MODE",
      "service": "API",
      "description": "Real-time collaborative workflow editing via the API WebSocket service.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "SERVER_WORKER_CONNECTIONS",
      "service": "API",
      "description": "Concurrent connections per worker.",
      "secret": false,
      "strategy": "default",
      "default": "10"
    },
    {
      "key": "CONSOLE_CORS_ALLOW_ORIGINS",
      "service": "API",
      "description": "Allowed origins for the console API (same origin by default).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEB_API_CORS_ALLOW_ORIGINS",
      "service": "API",
      "description": "Allowed origins for the public web-app API (embeds need *).",
      "secret": false,
      "strategy": "default",
      "default": "*"
    },
    {
      "key": "MODE",
      "service": "Worker",
      "description": "dify-api run mode: Celery worker for all queues.",
      "secret": false,
      "strategy": "default",
      "default": "worker"
    },
    {
      "key": "DB_HOST",
      "service": "Worker",
      "description": "Postgres private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PORT",
      "service": "Worker",
      "description": "Postgres port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_TYPE",
      "service": "Worker",
      "description": "Metadata database type.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_DB",
      "service": "Worker",
      "description": "Redis DB index for cache/locks.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "FILES_URL",
      "service": "Worker",
      "description": "Public prefix for signed file preview/download links.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "LOG_LEVEL",
      "service": "Worker",
      "description": "Log verbosity (DEBUG, INFO, WARNING, ERROR).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_REGION",
      "service": "Worker",
      "description": "Railway Bucket region.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DEPLOY_ENV",
      "service": "Worker",
      "description": "Deployment environment flag.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_HOST",
      "service": "Worker",
      "description": "Redis private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PORT",
      "service": "Worker",
      "description": "Redis port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SECRET_KEY",
      "service": "Worker",
      "description": "Flask signing/encryption key. Shared by API, WebSocket, Worker and Beat. Never change after first boot.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "APP_API_URL",
      "service": "Worker",
      "description": "Public URL of the web-app API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "APP_WEB_URL",
      "service": "Worker",
      "description": "Public URL of published web apps.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_DATABASE",
      "service": "Worker",
      "description": "Dify metadata database.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PASSWORD",
      "service": "Worker",
      "description": "Postgres password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_USERNAME",
      "service": "Worker",
      "description": "Postgres user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ENDPOINT",
      "service": "Worker",
      "description": "Railway Bucket S3 endpoint.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "TRIGGER_URL",
      "service": "Worker",
      "description": "Public prefix for workflow trigger webhooks.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "STORAGE_TYPE",
      "service": "Worker",
      "description": "File storage backend: Railway Bucket via the S3 API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "VECTOR_STORE",
      "service": "Worker",
      "description": "Vector database used for knowledge bases.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ACCESS_KEY",
      "service": "Worker",
      "description": "Railway Bucket access key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_SECRET_KEY",
      "service": "Worker",
      "description": "Railway Bucket secret key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_BACKEND",
      "service": "Worker",
      "description": "Celery result backend.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PASSWORD",
      "service": "Worker",
      "description": "Redis password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_USERNAME",
      "service": "Worker",
      "description": "Redis user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_BUCKET_NAME",
      "service": "Worker",
      "description": "Railway Bucket name (S3 API name).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_API_URL",
      "service": "Worker",
      "description": "Public URL of the console API (same origin via Gateway).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_WEB_URL",
      "service": "Worker",
      "description": "Public URL of the console web UI.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_PUBLIC_URL",
      "service": "Worker",
      "description": "Public base URL of this Dify instance (the Gateway). Change here when you add a custom domain.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SERVICE_API_URL",
      "service": "Worker",
      "description": "Base URL shown for the Service API (/v1).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ADDRESS_STYLE",
      "service": "Worker",
      "description": "S3 addressing style. Railway Buckets use virtual-hosted style; set 'path' only if the bucket's Credentials tab says so.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_API_KEY",
      "service": "Worker",
      "description": "Weaviate API key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_AUTO_SCALE",
      "service": "Worker",
      "description": "Autoscale Celery concurrency by CPU count.",
      "secret": false,
      "strategy": "default",
      "default": "false"
    },
    {
      "key": "CELERY_BROKER_URL",
      "service": "Worker",
      "description": "Celery broker (Redis DB 1).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MIGRATION_ENABLED",
      "service": "Worker",
      "description": "Migrations are run by the API service only.",
      "secret": false,
      "strategy": "default",
      "default": "false"
    },
    {
      "key": "PLUGIN_DAEMON_KEY",
      "service": "Worker",
      "description": "Key the API uses to call Plugin Daemon.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_DAEMON_URL",
      "service": "Worker",
      "description": "Plugin Daemon endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_ENDPOINT",
      "service": "Worker",
      "description": "Weaviate REST endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "INTERNAL_FILES_URL",
      "service": "Worker",
      "description": "Private URL used by Plugin Daemon and Agent services to fetch files.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MARKETPLACE_API_URL",
      "service": "Worker",
      "description": "Plugin marketplace API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MARKETPLACE_ENABLED",
      "service": "Worker",
      "description": "Enable the Dify plugin marketplace.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SSRF_PROXY_HTTP_URL",
      "service": "Worker",
      "description": "SSRF proxy for outbound HTTP from workflows/tools.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_WORKER_AMOUNT",
      "service": "Worker",
      "description": "Celery concurrency (gevent greenlets) per replica.",
      "secret": false,
      "strategy": "default",
      "default": "4"
    },
    {
      "key": "SQLALCHEMY_POOL_SIZE",
      "service": "Worker",
      "description": "DB pool size per process (kept below Postgres' default 100 connections across all services).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SSRF_PROXY_HTTPS_URL",
      "service": "Worker",
      "description": "SSRF proxy for outbound HTTPS from workflows/tools.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "ENDPOINT_URL_TEMPLATE",
      "service": "Worker",
      "description": "Public URL template for plugin endpoints (routed by the Gateway to Plugin Daemon).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_DAEMON_TIMEOUT",
      "service": "Worker",
      "description": "Timeout (s) for plugin invocations.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "AGENT_BACKEND_BASE_URL",
      "service": "Worker",
      "description": "Dify Agent backend endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CODE_EXECUTION_API_KEY",
      "service": "Worker",
      "description": "Code sandbox API key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_USE_AWS_MANAGED_IAM",
      "service": "Worker",
      "description": "Use static keys, not AWS IAM roles.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_GRPC_ENDPOINT",
      "service": "Worker",
      "description": "Weaviate gRPC endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "AGENT_BACKEND_API_TOKEN",
      "service": "Worker",
      "description": "Bearer token for the Agent backend control plane.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CODE_EXECUTION_ENDPOINT",
      "service": "Worker",
      "description": "Code sandbox endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_MAX_PACKAGE_SIZE",
      "service": "Worker",
      "description": "Max plugin package size in bytes.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_MAX_OVERFLOW",
      "service": "Worker",
      "description": "Extra DB connections allowed above the pool size.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_POOL_RECYCLE",
      "service": "Worker",
      "description": "Recycle DB connections after N seconds.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "INNER_API_KEY_FOR_PLUGIN",
      "service": "Worker",
      "description": "Key Plugin Daemon / Agent Backend use to call the API's inner endpoints.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_POOL_PRE_PING",
      "service": "Worker",
      "description": "Validate pooled connections before use (survives idle network resets).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "ENABLE_COLLABORATION_MODE",
      "service": "Worker",
      "description": "Real-time collaborative workflow editing via the API WebSocket service.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_CORS_ALLOW_ORIGINS",
      "service": "Worker",
      "description": "Allowed origins for the console API (same origin by default).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEB_API_CORS_ALLOW_ORIGINS",
      "service": "Worker",
      "description": "Allowed origins for the public web-app API (embeds need *).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "HTTP_PORT",
      "service": "SSRF Proxy",
      "description": "Squid listen port.",
      "secret": false,
      "strategy": "default",
      "default": "3128"
    },
    {
      "key": "SSRF_PROXY_MODE",
      "service": "SSRF Proxy",
      "description": "Policy: default = Dify egress proxy.",
      "secret": false,
      "strategy": "default",
      "default": "default"
    },
    {
      "key": "PORT",
      "service": "Web",
      "description": "Next.js listen port.",
      "secret": false,
      "strategy": "default",
      "default": "3000"
    },
    {
      "key": "HOSTNAME",
      "service": "Web",
      "description": "Listen on IPv4+IPv6.",
      "secret": false,
      "strategy": "default",
      "default": "::"
    },
    {
      "key": "DEPLOY_ENV",
      "service": "Web",
      "description": "Deployment environment flag.",
      "secret": false,
      "strategy": "default",
      "default": "PRODUCTION"
    },
    {
      "key": "ALLOW_EMBED",
      "service": "Web",
      "description": "Allow embedding the console in iframes (published apps are always embeddable).",
      "secret": false,
      "strategy": "default",
      "default": "false"
    },
    {
      "key": "MAX_TOOLS_NUM",
      "service": "Web",
      "description": "Max tools per agent.",
      "secret": false,
      "strategy": "default",
      "default": "10"
    },
    {
      "key": "MAX_TREE_DEPTH",
      "service": "Web",
      "description": "Max workflow nesting depth.",
      "secret": false,
      "strategy": "default",
      "default": "50"
    },
    {
      "key": "CONSOLE_WEB_URL",
      "service": "Web",
      "description": "Public console URL (web prefix).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MARKETPLACE_URL",
      "service": "Web",
      "description": "Plugin marketplace site.",
      "secret": false,
      "strategy": "default",
      "default": "https://marketplace.dify.ai"
    },
    {
      "key": "TOP_K_MAX_VALUE",
      "service": "Web",
      "description": "Max retrieval top-k in the UI.",
      "secret": false,
      "strategy": "default",
      "default": "10"
    },
    {
      "key": "MAX_ITERATIONS_NUM",
      "service": "Web",
      "description": "Max iteration-node items.",
      "secret": false,
      "strategy": "default",
      "default": "99"
    },
    {
      "key": "MAX_PARALLEL_LIMIT",
      "service": "Web",
      "description": "Max parallel branches.",
      "secret": false,
      "strategy": "default",
      "default": "10"
    },
    {
      "key": "LOOP_NODE_MAX_COUNT",
      "service": "Web",
      "description": "Max loop iterations in workflows.",
      "secret": false,
      "strategy": "default",
      "default": "100"
    },
    {
      "key": "MARKETPLACE_API_URL",
      "service": "Web",
      "description": "Plugin marketplace API.",
      "secret": false,
      "strategy": "default",
      "default": "https://marketplace.dify.ai"
    },
    {
      "key": "NEXT_PUBLIC_SOCKET_URL",
      "service": "Web",
      "description": "Public WebSocket origin for collaboration (update with a custom domain).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_domain"
    },
    {
      "key": "SERVER_CONSOLE_API_URL",
      "service": "Web",
      "description": "Private API URL for server-side rendering requests.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "NEXT_TELEMETRY_DISABLED",
      "service": "Web",
      "description": "Disable Next.js telemetry.",
      "secret": false,
      "strategy": "default",
      "default": "1"
    },
    {
      "key": "TEXT_GENERATION_TIMEOUT_MS",
      "service": "Web",
      "description": "Client timeout for text generation (ms).",
      "secret": false,
      "strategy": "default",
      "default": "60000"
    },
    {
      "key": "NEXT_PUBLIC_ENABLE_AGENT_V2",
      "service": "Web",
      "description": "Show the Agent (v2) builder, backed by Agent Backend + Agent Sandbox.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH",
      "service": "Web",
      "description": "Max chunk length for knowledge indexing.",
      "secret": true,
      "strategy": "default",
      "default": "4000"
    },
    {
      "key": "HTTP_PORT",
      "service": "Agent SSRF Proxy",
      "description": "Squid listen port.",
      "secret": false,
      "strategy": "default",
      "default": "3128"
    },
    {
      "key": "DIFY_API_HOST",
      "service": "Agent SSRF Proxy",
      "description": "API private hostname (allowed for /files/).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "SSRF_PROXY_MODE",
      "service": "Agent SSRF Proxy",
      "description": "Policy: agent = only Agent Stub + API /files/* on the private network, internet otherwise.",
      "secret": false,
      "strategy": "default",
      "default": "agent"
    },
    {
      "key": "DIFY_AGENT_BACKEND_HOST",
      "service": "Agent SSRF Proxy",
      "description": "Agent Backend private hostname (allowed for /agent-stub/).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "PGDATA",
      "service": "Postgres",
      "description": "Location where the database will be initialized",
      "secret": false,
      "strategy": "default",
      "default": "/var/lib/postgresql/data/pgdata"
    },
    {
      "key": "PGHOST",
      "service": "Postgres",
      "description": "Railway Private Domain Name.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "PGPORT",
      "service": "Postgres",
      "description": "Port to connect to Postgres.",
      "secret": false,
      "strategy": "default",
      "default": "5432"
    },
    {
      "key": "PGUSER",
      "service": "Postgres",
      "description": "Required variable for Data panel",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PGDATABASE",
      "service": "Postgres",
      "description": "Required variable for the data panel.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PGPASSWORD",
      "service": "Postgres",
      "description": "Required variable for Data panel",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "POSTGRES_DB",
      "service": "Postgres",
      "description": "Default database created when image is started.",
      "secret": false,
      "strategy": "default",
      "default": "railway"
    },
    {
      "key": "DATABASE_URL",
      "service": "Postgres",
      "description": "URL to connect to Postgres database.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "POSTGRES_USER",
      "service": "Postgres",
      "description": "User to connect to Postgres DB",
      "secret": false,
      "strategy": "default",
      "default": "postgres"
    },
    {
      "key": "SSL_CERT_DAYS",
      "service": "Postgres",
      "description": "SSL certificate expiry in days.",
      "secret": false,
      "strategy": "default",
      "default": "820"
    },
    {
      "key": "POSTGRES_PASSWORD",
      "service": "Postgres",
      "description": "Password to connect to DB",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    },
    {
      "key": "RAILWAY_DEPLOYMENT_DRAINING_SECONDS",
      "service": "Postgres",
      "description": "Allow Postgres to cleanly shut down",
      "secret": false,
      "strategy": "default",
      "default": "60"
    },
    {
      "key": "MODE",
      "service": "API WebSocket",
      "description": "dify-api run mode.",
      "secret": false,
      "strategy": "default",
      "default": "api"
    },
    {
      "key": "PORT",
      "service": "API WebSocket",
      "description": "Port Railway health-checks and routes to.",
      "secret": false,
      "strategy": "default",
      "default": "5001"
    },
    {
      "key": "DB_HOST",
      "service": "API WebSocket",
      "description": "Postgres private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PORT",
      "service": "API WebSocket",
      "description": "Postgres port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_TYPE",
      "service": "API WebSocket",
      "description": "Metadata database type.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_DB",
      "service": "API WebSocket",
      "description": "Redis DB index for cache/locks.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_PORT",
      "service": "API WebSocket",
      "description": "Gunicorn listen port.",
      "secret": false,
      "strategy": "default",
      "default": "5001"
    },
    {
      "key": "FILES_URL",
      "service": "API WebSocket",
      "description": "Public prefix for signed file preview/download links.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "LOG_LEVEL",
      "service": "API WebSocket",
      "description": "Log verbosity (DEBUG, INFO, WARNING, ERROR).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_REGION",
      "service": "API WebSocket",
      "description": "Railway Bucket region.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DEPLOY_ENV",
      "service": "API WebSocket",
      "description": "Deployment environment flag.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_HOST",
      "service": "API WebSocket",
      "description": "Redis private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PORT",
      "service": "API WebSocket",
      "description": "Redis port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SECRET_KEY",
      "service": "API WebSocket",
      "description": "Flask signing/encryption key. Shared by API, WebSocket, Worker and Beat. Never change after first boot.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "APP_API_URL",
      "service": "API WebSocket",
      "description": "Public URL of the web-app API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "APP_WEB_URL",
      "service": "API WebSocket",
      "description": "Public URL of published web apps.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_DATABASE",
      "service": "API WebSocket",
      "description": "Dify metadata database.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PASSWORD",
      "service": "API WebSocket",
      "description": "Postgres password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_USERNAME",
      "service": "API WebSocket",
      "description": "Postgres user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ENDPOINT",
      "service": "API WebSocket",
      "description": "Railway Bucket S3 endpoint.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "TRIGGER_URL",
      "service": "API WebSocket",
      "description": "Public prefix for workflow trigger webhooks.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "STORAGE_TYPE",
      "service": "API WebSocket",
      "description": "File storage backend: Railway Bucket via the S3 API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "VECTOR_STORE",
      "service": "API WebSocket",
      "description": "Vector database used for knowledge bases.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ACCESS_KEY",
      "service": "API WebSocket",
      "description": "Railway Bucket access key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_SECRET_KEY",
      "service": "API WebSocket",
      "description": "Railway Bucket secret key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_BACKEND",
      "service": "API WebSocket",
      "description": "Celery result backend.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PASSWORD",
      "service": "API WebSocket",
      "description": "Redis password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_USERNAME",
      "service": "API WebSocket",
      "description": "Redis user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_BUCKET_NAME",
      "service": "API WebSocket",
      "description": "Railway Bucket name (S3 API name).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_API_URL",
      "service": "API WebSocket",
      "description": "Public URL of the console API (same origin via Gateway).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_WEB_URL",
      "service": "API WebSocket",
      "description": "Public URL of the console web UI.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_PUBLIC_URL",
      "service": "API WebSocket",
      "description": "Public base URL of this Dify instance (the Gateway). Change here when you add a custom domain.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SERVICE_API_URL",
      "service": "API WebSocket",
      "description": "Base URL shown for the Service API (/v1).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "GUNICORN_TIMEOUT",
      "service": "API WebSocket",
      "description": "Request timeout in seconds (long streaming responses).",
      "secret": false,
      "strategy": "default",
      "default": "360"
    },
    {
      "key": "S3_ADDRESS_STYLE",
      "service": "API WebSocket",
      "description": "S3 addressing style. Railway Buckets use virtual-hosted style; set 'path' only if the bucket's Credentials tab says so.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_API_KEY",
      "service": "API WebSocket",
      "description": "Weaviate API key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_BROKER_URL",
      "service": "API WebSocket",
      "description": "Celery broker (Redis DB 1).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_BIND_ADDRESS",
      "service": "API WebSocket",
      "description": "Bind on IPv4+IPv6 so the private network can reach it.",
      "secret": false,
      "strategy": "default",
      "default": "[::]"
    },
    {
      "key": "MIGRATION_ENABLED",
      "service": "API WebSocket",
      "description": "Migrations are run by the API service only.",
      "secret": false,
      "strategy": "default",
      "default": "false"
    },
    {
      "key": "PLUGIN_DAEMON_KEY",
      "service": "API WebSocket",
      "description": "Key the API uses to call Plugin Daemon.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_DAEMON_URL",
      "service": "API WebSocket",
      "description": "Plugin Daemon endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_ENDPOINT",
      "service": "API WebSocket",
      "description": "Weaviate REST endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "INTERNAL_FILES_URL",
      "service": "API WebSocket",
      "description": "Private URL used by Plugin Daemon and Agent services to fetch files.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MARKETPLACE_API_URL",
      "service": "API WebSocket",
      "description": "Plugin marketplace API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MARKETPLACE_ENABLED",
      "service": "API WebSocket",
      "description": "Enable the Dify plugin marketplace.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SERVER_WORKER_CLASS",
      "service": "API WebSocket",
      "description": "Gunicorn worker class.",
      "secret": false,
      "strategy": "default",
      "default": "geventwebsocket.gunicorn.workers.GeventWebSocketWorker"
    },
    {
      "key": "SSRF_PROXY_HTTP_URL",
      "service": "API WebSocket",
      "description": "SSRF proxy for outbound HTTP from workflows/tools.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SERVER_WORKER_AMOUNT",
      "service": "API WebSocket",
      "description": "Gunicorn worker processes (raise with more RAM/CPU).",
      "secret": false,
      "strategy": "default",
      "default": "1"
    },
    {
      "key": "SQLALCHEMY_POOL_SIZE",
      "service": "API WebSocket",
      "description": "DB pool size per process (kept below Postgres' default 100 connections across all services).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SSRF_PROXY_HTTPS_URL",
      "service": "API WebSocket",
      "description": "SSRF proxy for outbound HTTPS from workflows/tools.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "ENDPOINT_URL_TEMPLATE",
      "service": "API WebSocket",
      "description": "Public URL template for plugin endpoints (routed by the Gateway to Plugin Daemon).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_DAEMON_TIMEOUT",
      "service": "API WebSocket",
      "description": "Timeout (s) for plugin invocations.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "AGENT_BACKEND_BASE_URL",
      "service": "API WebSocket",
      "description": "Dify Agent backend endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CODE_EXECUTION_API_KEY",
      "service": "API WebSocket",
      "description": "Code sandbox API key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_USE_AWS_MANAGED_IAM",
      "service": "API WebSocket",
      "description": "Use static keys, not AWS IAM roles.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_GRPC_ENDPOINT",
      "service": "API WebSocket",
      "description": "Weaviate gRPC endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "AGENT_BACKEND_API_TOKEN",
      "service": "API WebSocket",
      "description": "Bearer token for the Agent backend control plane.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CODE_EXECUTION_ENDPOINT",
      "service": "API WebSocket",
      "description": "Code sandbox endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_MAX_PACKAGE_SIZE",
      "service": "API WebSocket",
      "description": "Max plugin package size in bytes.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_MAX_OVERFLOW",
      "service": "API WebSocket",
      "description": "Extra DB connections allowed above the pool size.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_POOL_RECYCLE",
      "service": "API WebSocket",
      "description": "Recycle DB connections after N seconds.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "INNER_API_KEY_FOR_PLUGIN",
      "service": "API WebSocket",
      "description": "Key Plugin Daemon / Agent Backend use to call the API's inner endpoints.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_POOL_PRE_PING",
      "service": "API WebSocket",
      "description": "Validate pooled connections before use (survives idle network resets).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "ENABLE_COLLABORATION_MODE",
      "service": "API WebSocket",
      "description": "Real-time collaborative workflow editing via the API WebSocket service.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SERVER_WORKER_CONNECTIONS",
      "service": "API WebSocket",
      "description": "Concurrent connections per worker.",
      "secret": false,
      "strategy": "default",
      "default": "1000"
    },
    {
      "key": "CONSOLE_CORS_ALLOW_ORIGINS",
      "service": "API WebSocket",
      "description": "Allowed origins for the console API (same origin by default).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEB_API_CORS_ALLOW_ORIGINS",
      "service": "API WebSocket",
      "description": "Allowed origins for the public web-app API (embeds need *).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDISHOST",
      "service": "Redis",
      "description": "Private network hostname of the Redis service, only resolvable from services in the same environment",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "REDISPORT",
      "service": "Redis",
      "description": "Port that Redis listens on",
      "secret": false,
      "strategy": "default",
      "default": "6379"
    },
    {
      "key": "REDISUSER",
      "service": "Redis",
      "description": "Username for authenticating with Redis",
      "secret": false,
      "strategy": "default",
      "default": "default"
    },
    {
      "key": "REDIS_URL",
      "service": "Redis",
      "description": "Connection string for connecting to Redis using the private network",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDISPASSWORD",
      "service": "Redis",
      "description": "Alias of REDIS_PASSWORD for clients that expect the unseparated name",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PASSWORD",
      "service": "Redis",
      "description": "Randomly generated password for authenticating with Redis",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    },
    {
      "key": "PORT",
      "service": "Weaviate",
      "description": "REST port (gRPC is 50051).",
      "secret": false,
      "strategy": "default",
      "default": "8080"
    },
    {
      "key": "CLUSTER_HOSTNAME",
      "service": "Weaviate",
      "description": "Stable node name; do not change after first boot.",
      "secret": false,
      "strategy": "default",
      "default": "node1"
    },
    {
      "key": "DISABLE_TELEMETRY",
      "service": "Weaviate",
      "description": "Disable Weaviate telemetry.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "QUERY_DEFAULTS_LIMIT",
      "service": "Weaviate",
      "description": "Default query limit.",
      "secret": false,
      "strategy": "default",
      "default": "25"
    },
    {
      "key": "PERSISTENCE_DATA_PATH",
      "service": "Weaviate",
      "description": "Data directory (the volume).",
      "secret": false,
      "strategy": "default",
      "default": "/var/lib/weaviate"
    },
    {
      "key": "DEFAULT_VECTORIZER_MODULE",
      "service": "Weaviate",
      "description": "Dify sends its own embeddings.",
      "secret": false,
      "strategy": "default",
      "default": "none"
    },
    {
      "key": "AUTHENTICATION_APIKEY_USERS",
      "service": "Weaviate",
      "description": "User mapped to the API key.",
      "secret": true,
      "strategy": "default",
      "default": "dify"
    },
    {
      "key": "AUTHENTICATION_APIKEY_ENABLED",
      "service": "Weaviate",
      "description": "Enable API-key auth.",
      "secret": true,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "AUTHORIZATION_ADMINLIST_USERS",
      "service": "Weaviate",
      "description": "Admin users.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "AUTHORIZATION_ADMINLIST_ENABLED",
      "service": "Weaviate",
      "description": "Admin-list authorization.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "AUTHENTICATION_APIKEY_ALLOWED_KEYS",
      "service": "Weaviate",
      "description": "API key Dify uses.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED",
      "service": "Weaviate",
      "description": "Require an API key.",
      "secret": false,
      "strategy": "default",
      "default": "false"
    },
    {
      "key": "PORT",
      "service": "Sandbox",
      "description": "Port Railway health-checks.",
      "secret": false,
      "strategy": "default",
      "default": "8194"
    },
    {
      "key": "API_KEY",
      "service": "Sandbox",
      "description": "Key the API uses to call the code sandbox.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "GIN_MODE",
      "service": "Sandbox",
      "description": "Go web framework mode.",
      "secret": false,
      "strategy": "default",
      "default": "release"
    },
    {
      "key": "HTTP_PROXY",
      "service": "Sandbox",
      "description": "Egress via SSRF proxy.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "HTTPS_PROXY",
      "service": "Sandbox",
      "description": "Egress via SSRF proxy.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "SANDBOX_PORT",
      "service": "Sandbox",
      "description": "Sandbox listen port.",
      "secret": false,
      "strategy": "default",
      "default": "8194"
    },
    {
      "key": "ENABLE_NETWORK",
      "service": "Sandbox",
      "description": "Allow sandboxed code to make network calls (through the SSRF proxy).",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "WORKER_TIMEOUT",
      "service": "Sandbox",
      "description": "Max code execution time (s).",
      "secret": false,
      "strategy": "default",
      "default": "15"
    },
    {
      "key": "MODE",
      "service": "Worker Beat",
      "description": "dify-api run mode: Celery beat scheduler (run exactly one).",
      "secret": false,
      "strategy": "default",
      "default": "beat"
    },
    {
      "key": "DB_HOST",
      "service": "Worker Beat",
      "description": "Postgres private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PORT",
      "service": "Worker Beat",
      "description": "Postgres port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_TYPE",
      "service": "Worker Beat",
      "description": "Metadata database type.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_DB",
      "service": "Worker Beat",
      "description": "Redis DB index for cache/locks.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "FILES_URL",
      "service": "Worker Beat",
      "description": "Public prefix for signed file preview/download links.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "LOG_LEVEL",
      "service": "Worker Beat",
      "description": "Log verbosity (DEBUG, INFO, WARNING, ERROR).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_REGION",
      "service": "Worker Beat",
      "description": "Railway Bucket region.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DEPLOY_ENV",
      "service": "Worker Beat",
      "description": "Deployment environment flag.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_HOST",
      "service": "Worker Beat",
      "description": "Redis private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PORT",
      "service": "Worker Beat",
      "description": "Redis port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SECRET_KEY",
      "service": "Worker Beat",
      "description": "Flask signing/encryption key. Shared by API, WebSocket, Worker and Beat. Never change after first boot.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "APP_API_URL",
      "service": "Worker Beat",
      "description": "Public URL of the web-app API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "APP_WEB_URL",
      "service": "Worker Beat",
      "description": "Public URL of published web apps.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_DATABASE",
      "service": "Worker Beat",
      "description": "Dify metadata database.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PASSWORD",
      "service": "Worker Beat",
      "description": "Postgres password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_USERNAME",
      "service": "Worker Beat",
      "description": "Postgres user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ENDPOINT",
      "service": "Worker Beat",
      "description": "Railway Bucket S3 endpoint.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "TRIGGER_URL",
      "service": "Worker Beat",
      "description": "Public prefix for workflow trigger webhooks.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "STORAGE_TYPE",
      "service": "Worker Beat",
      "description": "File storage backend: Railway Bucket via the S3 API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "VECTOR_STORE",
      "service": "Worker Beat",
      "description": "Vector database used for knowledge bases.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ACCESS_KEY",
      "service": "Worker Beat",
      "description": "Railway Bucket access key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_SECRET_KEY",
      "service": "Worker Beat",
      "description": "Railway Bucket secret key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_BACKEND",
      "service": "Worker Beat",
      "description": "Celery result backend.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PASSWORD",
      "service": "Worker Beat",
      "description": "Redis password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_USERNAME",
      "service": "Worker Beat",
      "description": "Redis user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_BUCKET_NAME",
      "service": "Worker Beat",
      "description": "Railway Bucket name (S3 API name).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_API_URL",
      "service": "Worker Beat",
      "description": "Public URL of the console API (same origin via Gateway).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_WEB_URL",
      "service": "Worker Beat",
      "description": "Public URL of the console web UI.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_PUBLIC_URL",
      "service": "Worker Beat",
      "description": "Public base URL of this Dify instance (the Gateway). Change here when you add a custom domain.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SERVICE_API_URL",
      "service": "Worker Beat",
      "description": "Base URL shown for the Service API (/v1).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ADDRESS_STYLE",
      "service": "Worker Beat",
      "description": "S3 addressing style. Railway Buckets use virtual-hosted style; set 'path' only if the bucket's Credentials tab says so.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_API_KEY",
      "service": "Worker Beat",
      "description": "Weaviate API key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CELERY_BROKER_URL",
      "service": "Worker Beat",
      "description": "Celery broker (Redis DB 1).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MIGRATION_ENABLED",
      "service": "Worker Beat",
      "description": "Migrations are run by the API service only.",
      "secret": false,
      "strategy": "default",
      "default": "false"
    },
    {
      "key": "PLUGIN_DAEMON_KEY",
      "service": "Worker Beat",
      "description": "Key the API uses to call Plugin Daemon.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_DAEMON_URL",
      "service": "Worker Beat",
      "description": "Plugin Daemon endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_ENDPOINT",
      "service": "Worker Beat",
      "description": "Weaviate REST endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "INTERNAL_FILES_URL",
      "service": "Worker Beat",
      "description": "Private URL used by Plugin Daemon and Agent services to fetch files.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MARKETPLACE_API_URL",
      "service": "Worker Beat",
      "description": "Plugin marketplace API.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MARKETPLACE_ENABLED",
      "service": "Worker Beat",
      "description": "Enable the Dify plugin marketplace.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SSRF_PROXY_HTTP_URL",
      "service": "Worker Beat",
      "description": "SSRF proxy for outbound HTTP from workflows/tools.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_POOL_SIZE",
      "service": "Worker Beat",
      "description": "DB pool size per process (kept below Postgres' default 100 connections across all services).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SSRF_PROXY_HTTPS_URL",
      "service": "Worker Beat",
      "description": "SSRF proxy for outbound HTTPS from workflows/tools.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "ENDPOINT_URL_TEMPLATE",
      "service": "Worker Beat",
      "description": "Public URL template for plugin endpoints (routed by the Gateway to Plugin Daemon).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_DAEMON_TIMEOUT",
      "service": "Worker Beat",
      "description": "Timeout (s) for plugin invocations.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "AGENT_BACKEND_BASE_URL",
      "service": "Worker Beat",
      "description": "Dify Agent backend endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CODE_EXECUTION_API_KEY",
      "service": "Worker Beat",
      "description": "Code sandbox API key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_USE_AWS_MANAGED_IAM",
      "service": "Worker Beat",
      "description": "Use static keys, not AWS IAM roles.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEAVIATE_GRPC_ENDPOINT",
      "service": "Worker Beat",
      "description": "Weaviate gRPC endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "AGENT_BACKEND_API_TOKEN",
      "service": "Worker Beat",
      "description": "Bearer token for the Agent backend control plane.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CODE_EXECUTION_ENDPOINT",
      "service": "Worker Beat",
      "description": "Code sandbox endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PLUGIN_MAX_PACKAGE_SIZE",
      "service": "Worker Beat",
      "description": "Max plugin package size in bytes.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_MAX_OVERFLOW",
      "service": "Worker Beat",
      "description": "Extra DB connections allowed above the pool size.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_POOL_RECYCLE",
      "service": "Worker Beat",
      "description": "Recycle DB connections after N seconds.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "INNER_API_KEY_FOR_PLUGIN",
      "service": "Worker Beat",
      "description": "Key Plugin Daemon / Agent Backend use to call the API's inner endpoints.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SQLALCHEMY_POOL_PRE_PING",
      "service": "Worker Beat",
      "description": "Validate pooled connections before use (survives idle network resets).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "ENABLE_COLLABORATION_MODE",
      "service": "Worker Beat",
      "description": "Real-time collaborative workflow editing via the API WebSocket service.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CONSOLE_CORS_ALLOW_ORIGINS",
      "service": "Worker Beat",
      "description": "Allowed origins for the console API (same origin by default).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "WEB_API_CORS_ALLOW_ORIGINS",
      "service": "Worker Beat",
      "description": "Allowed origins for the public web-app API (embeds need *).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PORT",
      "service": "Agent Sandbox",
      "description": "Port Railway health-checks.",
      "secret": false,
      "strategy": "default",
      "default": "5004"
    },
    {
      "key": "NO_PROXY",
      "service": "Agent Sandbox",
      "description": "Hosts that bypass the proxy.",
      "secret": false,
      "strategy": "default",
      "default": "localhost,127.0.0.1"
    },
    {
      "key": "HTTP_PROXY",
      "service": "Agent Sandbox",
      "description": "Egress via the agent SSRF proxy.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "HTTPS_PROXY",
      "service": "Agent Sandbox",
      "description": "Egress via the agent SSRF proxy.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "SHELLCTL_AUTH_TOKEN",
      "service": "Agent Sandbox",
      "description": "Token the Agent Backend presents.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SHELLCTL_ENABLE_PATH_ISOLATION",
      "service": "Agent Sandbox",
      "description": "Landlock path isolation for agent shell jobs. Set false only if jobs fail with Landlock errors.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "PORT",
      "service": "Plugin Daemon",
      "description": "Port Railway health-checks.",
      "secret": false,
      "strategy": "default",
      "default": "5002"
    },
    {
      "key": "DB_HOST",
      "service": "Plugin Daemon",
      "description": "Postgres private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_PORT",
      "service": "Plugin Daemon",
      "description": "Postgres port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_TYPE",
      "service": "Plugin Daemon",
      "description": "Database type.",
      "secret": false,
      "strategy": "default",
      "default": "postgresql"
    },
    {
      "key": "REDIS_DB",
      "service": "Plugin Daemon",
      "description": "Redis DB index (keys are prefixed).",
      "secret": false,
      "strategy": "default",
      "default": "0"
    },
    {
      "key": "REDIS_HOST",
      "service": "Plugin Daemon",
      "description": "Redis private host.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_PORT",
      "service": "Plugin Daemon",
      "description": "Redis port.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SERVER_KEY",
      "service": "Plugin Daemon",
      "description": "Key the API presents to Plugin Daemon.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "DB_DATABASE",
      "service": "Plugin Daemon",
      "description": "Plugin database (created automatically on first boot).",
      "secret": false,
      "strategy": "default",
      "default": "dify_plugin"
    },
    {
      "key": "DB_PASSWORD",
      "service": "Plugin Daemon",
      "description": "Postgres password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_SSL_MODE",
      "service": "Plugin Daemon",
      "description": "Private network; TLS not required.",
      "secret": false,
      "strategy": "default",
      "default": "disable"
    },
    {
      "key": "DB_USERNAME",
      "service": "Plugin Daemon",
      "description": "Postgres user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "SERVER_HOST",
      "service": "Plugin Daemon",
      "description": "Listen on IPv4+IPv6.",
      "secret": false,
      "strategy": "default",
      "default": "[::]"
    },
    {
      "key": "SERVER_PORT",
      "service": "Plugin Daemon",
      "description": "Plugin Daemon HTTP port.",
      "secret": false,
      "strategy": "default",
      "default": "5002"
    },
    {
      "key": "PPROF_ENABLED",
      "service": "Plugin Daemon",
      "description": "Go profiler endpoint.",
      "secret": false,
      "strategy": "default",
      "default": "false"
    },
    {
      "key": "REDIS_PASSWORD",
      "service": "Plugin Daemon",
      "description": "Redis password.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "REDIS_USERNAME",
      "service": "Plugin Daemon",
      "description": "Redis user.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DB_MAX_IDLE_CONNS",
      "service": "Plugin Daemon",
      "description": "Idle DB connections kept open.",
      "secret": false,
      "strategy": "default",
      "default": "5"
    },
    {
      "key": "DB_MAX_OPEN_CONNS",
      "service": "Plugin Daemon",
      "description": "Max DB connections.",
      "secret": false,
      "strategy": "default",
      "default": "20"
    },
    {
      "key": "DIFY_INNER_API_KEY",
      "service": "Plugin Daemon",
      "description": "Key Plugin Daemon presents to the API inner endpoints.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "DIFY_INNER_API_URL",
      "service": "Plugin Daemon",
      "description": "API inner endpoint (private).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "PLUGIN_STORAGE_TYPE",
      "service": "Plugin Daemon",
      "description": "Plugin packages are kept on this service's volume.",
      "secret": false,
      "strategy": "default",
      "default": "local"
    },
    {
      "key": "PLUGIN_WORKING_PATH",
      "service": "Plugin Daemon",
      "description": "Where installed plugins run (Python envs).",
      "secret": false,
      "strategy": "default",
      "default": "/app/storage/cwd"
    },
    {
      "key": "PLUGIN_INSTALLED_PATH",
      "service": "Plugin Daemon",
      "description": "Installed plugins sub-directory.",
      "secret": false,
      "strategy": "default",
      "default": "plugin"
    },
    {
      "key": "MAX_PLUGIN_PACKAGE_SIZE",
      "service": "Plugin Daemon",
      "description": "Max plugin package size in bytes.",
      "secret": false,
      "strategy": "default",
      "default": "52428800"
    },
    {
      "key": "PLUGIN_MEDIA_CACHE_PATH",
      "service": "Plugin Daemon",
      "description": "Plugin asset cache sub-directory.",
      "secret": false,
      "strategy": "default",
      "default": "assets"
    },
    {
      "key": "PYTHON_ENV_INIT_TIMEOUT",
      "service": "Plugin Daemon",
      "description": "Timeout (s) to build a plugin's Python environment.",
      "secret": false,
      "strategy": "default",
      "default": "120"
    },
    {
      "key": "FORCE_VERIFYING_SIGNATURE",
      "service": "Plugin Daemon",
      "description": "Only allow signed marketplace plugins.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "PLUGIN_PACKAGE_CACHE_PATH",
      "service": "Plugin Daemon",
      "description": "Package cache sub-directory.",
      "secret": false,
      "strategy": "default",
      "default": "plugin_packages"
    },
    {
      "key": "PLUGIN_STORAGE_LOCAL_ROOT",
      "service": "Plugin Daemon",
      "description": "Storage root (the volume).",
      "secret": false,
      "strategy": "default",
      "default": "/app/storage"
    },
    {
      "key": "PLUGIN_MAX_EXECUTION_TIMEOUT",
      "service": "Plugin Daemon",
      "description": "Max plugin execution time (s).",
      "secret": false,
      "strategy": "default",
      "default": "600"
    },
    {
      "key": "PLUGIN_REMOTE_INSTALLING_HOST",
      "service": "Plugin Daemon",
      "description": "Remote plugin-debugging listener (needs a TCP proxy on 5003 to be used).",
      "secret": false,
      "strategy": "default",
      "default": "0.0.0.0"
    },
    {
      "key": "PLUGIN_REMOTE_INSTALLING_PORT",
      "service": "Plugin Daemon",
      "description": "Remote plugin-debugging port.",
      "secret": false,
      "strategy": "default",
      "default": "5003"
    },
    {
      "key": "PORT",
      "service": "Agent Backend",
      "description": "Port Railway health-checks.",
      "secret": false,
      "strategy": "default",
      "default": "5050"
    },
    {
      "key": "DIFY_AGENT_API_TOKEN",
      "service": "Agent Backend",
      "description": "Bearer token the API uses for the Agent control plane.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "DIFY_AGENT_REDIS_URL",
      "service": "Agent Backend",
      "description": "Agent run store (Redis DB 2).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_AGENT_INNER_API_KEY",
      "service": "Agent Backend",
      "description": "Must equal the API's INNER_API_KEY_FOR_PLUGIN.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_AGENT_INNER_API_URL",
      "service": "Agent Backend",
      "description": "API inner endpoint.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DIFY_AGENT_RUNTIME_BACKEND",
      "service": "Agent Backend",
      "description": "Sandbox backend: local (Agent Sandbox service) or e2b.",
      "secret": false,
      "strategy": "default",
      "default": "local"
    },
    {
      "key": "DIFY_AGENT_PLUGIN_DAEMON_URL",
      "service": "Agent Backend",
      "description": "Plugin Daemon endpoint.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DIFY_AGENT_SERVER_SECRET_KEY",
      "service": "Agent Backend",
      "description": "Root secret (43-char base64url = 32 bytes) for Agent Stub token encryption.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "DIFY_AGENT_STUB_API_BASE_URL",
      "service": "Agent Backend",
      "description": "Agent Stub URL the sandbox calls (through Agent SSRF Proxy).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DIFY_AGENT_RUN_TIMEOUT_SECONDS",
      "service": "Agent Backend",
      "description": "Max agent run time (s).",
      "secret": false,
      "strategy": "default",
      "default": "3600"
    },
    {
      "key": "DIFY_AGENT_PLUGIN_DAEMON_API_KEY",
      "service": "Agent Backend",
      "description": "Plugin Daemon key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DIFY_AGENT_LOCAL_SANDBOX_ENDPOINT",
      "service": "Agent Backend",
      "description": "Agent Sandbox (shellctl) endpoint.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DIFY_AGENT_SANDBOX_FILES_BASE_URL",
      "service": "Agent Backend",
      "description": "API base for sandbox file transfers (/files/*).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DIFY_AGENT_LOCAL_SANDBOX_AUTH_TOKEN",
      "service": "Agent Backend",
      "description": "Token shared with the Agent Sandbox.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "PORT",
      "service": "Gateway",
      "description": "Port nginx listens on (public domain target).",
      "secret": false,
      "strategy": "default",
      "default": "8080"
    },
    {
      "key": "DIFY_API_UPSTREAM",
      "service": "Gateway",
      "description": "API private address.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DIFY_WEB_UPSTREAM",
      "service": "Gateway",
      "description": "Web (Next.js) private address.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "NGINX_PROXY_TIMEOUT",
      "service": "Gateway",
      "description": "Proxy read/send timeout (long-running streams).",
      "secret": false,
      "strategy": "default",
      "default": "3600s"
    },
    {
      "key": "DIFY_SOCKET_UPSTREAM",
      "service": "Gateway",
      "description": "API WebSocket private address (/socket.io).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "NGINX_CLIENT_MAX_BODY_SIZE",
      "service": "Gateway",
      "description": "Max upload size through the gateway.",
      "secret": false,
      "strategy": "default",
      "default": "100M"
    },
    {
      "key": "DIFY_PLUGIN_DAEMON_UPSTREAM",
      "service": "Gateway",
      "description": "Plugin Daemon private address (/e/ plugin endpoints).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    }
  ],
  "deploy": {
    "mcp": {
      "server": "railway",
      "tool": "deploy_template",
      "args": {
        "template_code": "dify-v1-ai-app-studio"
      }
    },
    "cli": "railway deploy --template dify-v1-ai-app-studio",
    "api": {
      "method": "POST",
      "path": "/graphql/v2",
      "body": {
        "query": "mutation templateDeploy($input: TemplateDeployV2Input!) { templateDeployV2(input: $input) { projectId workflowId } }",
        "variables": {
          "input": {
            "templateId": "1bb77bcd-3591-4b31-a9ee-019bdb1866e1",
            "serializedConfig": {
              "buckets": {
                "c1b51481-97a8-5df4-8b7f-f9d346ceee56": {
                  "name": "Bucket"
                }
              },
              "services": {
                "0a487fed-e2b2-5bc7-ba61-1c58aa310efc": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "API",
                  "deploy": {
                    "healthcheckPath": "/health",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 600,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "langgenius/dify-api:1.17.1"
                  },
                  "variables": {
                    "MODE": {
                      "isOptional": true,
                      "description": "dify-api run mode.",
                      "defaultValue": "api"
                    },
                    "PORT": {
                      "isOptional": true,
                      "description": "Port Railway health-checks and routes to.",
                      "defaultValue": "5001"
                    },
                    "DB_HOST": {
                      "isOptional": true,
                      "description": "Postgres private host.",
                      "defaultValue": "${{Postgres.PGHOST}}"
                    },
                    "DB_PORT": {
                      "isOptional": true,
                      "description": "Postgres port.",
                      "defaultValue": "${{Postgres.PGPORT}}"
                    },
                    "DB_TYPE": {
                      "isOptional": true,
                      "description": "Metadata database type.",
                      "defaultValue": "postgresql"
                    },
                    "REDIS_DB": {
                      "isOptional": true,
                      "description": "Redis DB index for cache/locks.",
                      "defaultValue": "0"
                    },
                    "DIFY_PORT": {
                      "isOptional": true,
                      "description": "Gunicorn listen port.",
                      "defaultValue": "5001"
                    },
                    "FILES_URL": {
                      "isOptional": true,
                      "description": "Public prefix for signed file preview/download links.",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}"
                    },
                    "LOG_LEVEL": {
                      "isOptional": true,
                      "description": "Log verbosity (DEBUG, INFO, WARNING, ERROR).",
                      "defaultValue": "INFO"
                    },
                    "S3_REGION": {
                      "isOptional": true,
                      "description": "Railway Bucket region.",
                      "defaultValue": "${{Bucket.REGION}}"
                    },
                    "DEPLOY_ENV": {
                      "isOptional": true,
                      "description": "Deployment environment flag.",
                      "defaultValue": "PRODUCTION"
                    },
                    "REDIS_HOST": {
                      "isOptional": true,
                      "description": "Redis private host.",
                      "defaultValue": "${{Redis.REDISHOST}}"
                    },
                    "REDIS_PORT": {
                      "isOptional": true,
                      "description": "Redis port.",
                      "defaultValue": "${{Redis.REDISPORT}}"
                    },
                    "SECRET_KEY": {
                      "isOptional": true,
                      "description": "Flask signing/encryption key. Shared by API, WebSocket, Worker and Beat. Never change after first boot.",
                      "defaultValue": "{{SECRET_KEY}}"
                    },
                    "APP_API_URL": {
                      "isOptional": true,
                      "description": "Public URL of the web-app API.",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}"
                    },
                    "APP_WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of published web apps.",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}"
                    },
                    "DB_DATABASE": {
                      "isOptional": true,
                      "description": "Dify metadata database.",
                      "defaultValue": "${{Postgres.PGDATABASE}}"
                    },
                    "DB_PASSWORD": {
                      "isOptional": true,
                      "description": "Postgres password.",
                      "defaultValue": "${{Postgres.PGPASSWORD}}"
                    },
                    "DB_USERNAME": {
                      "isOptional": true,
                      "description": "Postgres user.",
                      "defaultValue": "${{Postgres.PGUSER}}"
                    },
                    "S3_ENDPOINT": {
                      "isOptional": true,
                      "description": "Railway Bucket S3 endpoint.",
                      "defaultValue": "${{Bucket.ENDPOINT}}"
                    },
                    "TRIGGER_URL": {
                      "isOptional": true,
                      "description": "Public prefix for workflow trigger webhooks.",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}"
                    },
                    "STORAGE_TYPE": {
                      "isOptional": true,
                      "description": "File storage backend: Railway Bucket via the S3 API.",
                      "defaultValue": "s3"
                    },
                    "VECTOR_STORE": {
                      "isOptional": true,
                      "description": "Vector database used for knowledge bases.",
                      "defaultValue": "weaviate"
                    },
                    "INIT_PASSWORD": {
                      "isOptional": true,
                      "description": "Password required on /install before the first admin account can be created. Read it from this variable.",
                      "defaultValue": "{{INIT_PASSWORD}}"
                    },
                    "S3_ACCESS_KEY": {
                      "isOptional": true,
                      "description": "Railway Bucket access key.",
                      "defaultValue": "${{Bucket.ACCESS_KEY_ID}}"
                    },
                    "S3_SECRET_KEY": {
                      "isOptional": true,
                      "description": "Railway Bucket secret key.",
                      "defaultValue": "${{Bucket.SECRET_ACCESS_KEY}}"
                    },
                    "CELERY_BACKEND": {
                      "isOptional": true,
                      "description": "Celery result backend.",
                      "defaultValue": "redis"
                    },
                    "REDIS_PASSWORD": {
                      "isOptional": true,
                      "description": "Redis password.",
                      "defaultValue": "${{Redis.REDIS_PASSWORD}}"
                    },
                    "REDIS_USERNAME": {
                      "isOptional": true,
                      "description": "Redis user.",
                      "defaultValue": "${{Redis.REDISUSER}}"
                    },
                    "S3_BUCKET_NAME": {
                      "isOptional": true,
                      "description": "Railway Bucket name (S3 API name).",
                      "defaultValue": "${{Bucket.BUCKET}}"
                    },
                    "CONSOLE_API_URL": {
                      "isOptional": true,
                      "description": "Public URL of the console API (same origin via Gateway).",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}"
                    },
                    "CONSOLE_WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of the console web UI.",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}"
                    },
                    "DIFY_PUBLIC_URL": {
                      "isOptional": true,
                      "description": "Public base URL of this Dify instance (the Gateway). Change here when you add a custom domain.",
                      "defaultValue": "https://${{Gateway.RAILWAY_PUBLIC_DOMAIN}}"
                    },
                    "SERVICE_API_URL": {
                      "isOptional": true,
                      "description": "Base URL shown for the Service API (/v1).",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}"
                    },
                    "GUNICORN_TIMEOUT": {
                      "isOptional": true,
                      "description": "Request timeout in seconds (long streaming responses).",
                      "defaultValue": "360"
                    },
                    "S3_ADDRESS_STYLE": {
                      "isOptional": true,
                      "description": "S3 addressing style. Railway Buckets use virtual-hosted style; set 'path' only if the bucket's Credentials tab says so.",
                      "defaultValue": "virtual"
                    },
                    "WEAVIATE_API_KEY": {
                      "isOptional": true,
                      "description": "Weaviate API key.",
                      "defaultValue": "${{Weaviate.AUTHENTICATION_APIKEY_ALLOWED_KEYS}}"
                    },
                    "CELERY_BROKER_URL": {
                      "isOptional": true,
                      "description": "Celery broker (Redis DB 1).",
                      "defaultValue": "redis://${{Redis.REDISUSER}}:${{Redis.REDIS_PASSWORD}}@${{Redis.REDISHOST}}:${{Redis.REDISPORT}}/1"
                    },
                    "DIFY_BIND_ADDRESS": {
                      "isOptional": true,
                      "description": "Bind on IPv4+IPv6 so the private network can reach it.",
                      "defaultValue": "[::]"
                    },
                    "MIGRATION_ENABLED": {
                      "isOptional": true,
                      "description": "Run database migrations on boot (only this service migrates).",
                      "defaultValue": "true"
                    },
                    "PLUGIN_DAEMON_KEY": {
                      "isOptional": true,
                      "description": "Key the API uses to call Plugin Daemon.",
                      "defaultValue": "${{Plugin Daemon.SERVER_KEY}}"
                    },
                    "PLUGIN_DAEMON_URL": {
                      "isOptional": true,
                      "description": "Plugin Daemon endpoint (private).",
                      "defaultValue": "http://${{Plugin Daemon.RAILWAY_PRIVATE_DOMAIN}}:5002"
                    },
                    "WEAVIATE_ENDPOINT": {
                      "isOptional": true,
                      "description": "Weaviate REST endpoint (private).",
                      "defaultValue": "http://${{Weaviate.RAILWAY_PRIVATE_DOMAIN}}:8080"
                    },
                    "INTERNAL_FILES_URL": {
                      "isOptional": true,
                      "description": "Private URL used by Plugin Daemon and Agent services to fetch files.",
                      "defaultValue": "http://${{API.RAILWAY_PRIVATE_DOMAIN}}:5001"
                    },
                    "MARKETPLACE_API_URL": {
                      "isOptional": true,
                      "description": "Plugin marketplace API.",
                      "defaultValue": "https://marketplace.dify.ai"
                    },
                    "MARKETPLACE_ENABLED": {
                      "isOptional": true,
                      "description": "Enable the Dify plugin marketplace.",
                      "defaultValue": "true"
                    },
                    "SERVER_WORKER_CLASS": {
                      "isOptional": true,
                      "description": "Gunicorn worker class.",
                      "defaultValue": "gevent"
                    },
                    "SSRF_PROXY_HTTP_URL": {
                      "isOptional": true,
                      "description": "SSRF proxy for outbound HTTP from workflows/tools.",
                      "defaultValue": "http://${{SSRF Proxy.RAILWAY_PRIVATE_DOMAIN}}:3128"
                    },
                    "SERVER_WORKER_AMOUNT": {
                      "isOptional": true,
                      "description": "Gunicorn worker processes (raise with more RAM/CPU).",
                      "defaultValue": "1"
                    },
                    "SQLALCHEMY_POOL_SIZE": {
                      "isOptional": true,
                      "description": "DB pool size per process (kept below Postgres' default 100 connections across all services).",
                      "defaultValue": "10"
                    },
                    "SSRF_PROXY_HTTPS_URL": {
                      "isOptional": true,
                      "description": "SSRF proxy for outbound HTTPS from workflows/tools.",
                      "defaultValue": "http://${{SSRF Proxy.RAILWAY_PRIVATE_DOMAIN}}:3128"
                    },
                    "ENDPOINT_URL_TEMPLATE": {
                      "isOptional": true,
                      "description": "Public URL template for plugin endpoints (routed by the Gateway to Plugin Daemon).",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}/e/{hook_id}"
                    },
                    "PLUGIN_DAEMON_TIMEOUT": {
                      "isOptional": true,
                      "description": "Timeout (s) for plugin invocations.",
                      "defaultValue": "600.0"
                    },
                    "AGENT_BACKEND_BASE_URL": {
                      "isOptional": true,
                      "description": "Dify Agent backend endpoint (private).",
                      "defaultValue": "http://${{Agent Backend.RAILWAY_PRIVATE_DOMAIN}}:5050"
                    },
                    "CODE_EXECUTION_API_KEY": {
                      "isOptional": true,
                      "description": "Code sandbox API key.",
                      "defaultValue": "${{Sandbox.API_KEY}}"
                    },
                    "S3_USE_AWS_MANAGED_IAM": {
                      "isOptional": true,
                      "description": "Use static keys, not AWS IAM roles.",
                      "defaultValue": "false"
                    },
                    "WEAVIATE_GRPC_ENDPOINT": {
                      "isOptional": true,
                      "description": "Weaviate gRPC endpoint (private).",
                      "defaultValue": "grpc://${{Weaviate.RAILWAY_PRIVATE_DOMAIN}}:50051"
                    },
                    "AGENT_BACKEND_API_TOKEN": {
                      "isOptional": true,
                      "description": "Bearer token for the Agent backend control plane.",
                      "defaultValue": "${{Agent Backend.DIFY_AGENT_API_TOKEN}}"
                    },
                    "CODE_EXECUTION_ENDPOINT": {
                      "isOptional": true,
                      "description": "Code sandbox endpoint (private).",
                      "defaultValue": "http://${{Sandbox.RAILWAY_PRIVATE_DOMAIN}}:8194"
                    },
                    "PLUGIN_MAX_PACKAGE_SIZE": {
                      "isOptional": true,
                      "description": "Max plugin package size in bytes.",
                      "defaultValue": "52428800"
                    },
                    "SQLALCHEMY_MAX_OVERFLOW": {
                      "isOptional": true,
                      "description": "Extra DB connections allowed above the pool size.",
                      "defaultValue": "5"
                    },
                    "SQLALCHEMY_POOL_RECYCLE": {
                      "isOptional": true,
                      "description": "Recycle DB connections after N seconds.",
                      "defaultValue": "3600"
                    },
                    "INNER_API_KEY_FOR_PLUGIN": {
                      "isOptional": true,
                      "description": "Key Plugin Daemon / Agent Backend use to call the API's inner endpoints.",
                      "defaultValue": "${{Plugin Daemon.DIFY_INNER_API_KEY}}"
                    },
                    "SQLALCHEMY_POOL_PRE_PING": {
                      "isOptional": true,
                      "description": "Validate pooled connections before use (survives idle network resets).",
                      "defaultValue": "true"
                    },
                    "ENABLE_COLLABORATION_MODE": {
                      "isOptional": true,
                      "description": "Real-time collaborative workflow editing via the API WebSocket service.",
                      "defaultValue": "true"
                    },
                    "SERVER_WORKER_CONNECTIONS": {
                      "isOptional": true,
                      "description": "Concurrent connections per worker.",
                      "defaultValue": "10"
                    },
                    "CONSOLE_CORS_ALLOW_ORIGINS": {
                      "isOptional": true,
                      "description": "Allowed origins for the console API (same origin by default).",
                      "defaultValue": "${{DIFY_PUBLIC_URL}}"
                    },
                    "WEB_API_CORS_ALLOW_ORIGINS": {
                      "isOptional": true,
                      "description": "Allowed origins for the public web-app API (embeds need *).",
                      "defaultValue": "*"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "2b56caed-83f2-588d-95c8-74a437ceeba3": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "Worker",
                  "deploy": {
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "langgenius/dify-api:1.17.1"
                  },
                  "variables": {
                    "MODE": {
                      "isOptional": true,
                      "description": "dify-api run mode: Celery worker for all queues.",
                      "defaultValue": "worker"
                    },
                    "DB_HOST": {
                      "isOptional": true,
                      "description": "Postgres private host.",
                      "defaultValue": "${{API.DB_HOST}}"
                    },
                    "DB_PORT": {
                      "isOptional": true,
                      "description": "Postgres port.",
                      "defaultValue": "${{API.DB_PORT}}"
                    },
                    "DB_TYPE": {
                      "isOptional": true,
                      "description": "Metadata database type.",
                      "defaultValue": "${{API.DB_TYPE}}"
                    },
                    "REDIS_DB": {
                      "isOptional": true,
                      "description": "Redis DB index for cache/locks.",
                      "defaultValue": "${{API.REDIS_DB}}"
                    },
                    "FILES_URL": {
                      "isOptional": true,
                      "description": "Public prefix for signed file preview/download links.",
                      "defaultValue": "${{API.FILES_URL}}"
                    },
                    "LOG_LEVEL": {
                      "isOptional": true,
                      "description": "Log verbosity (DEBUG, INFO, WARNING, ERROR).",
                      "defaultValue": "${{API.LOG_LEVEL}}"
                    },
                    "S3_REGION": {
                      "isOptional": true,
                      "description": "Railway Bucket region.",
                      "defaultValue": "${{API.S3_REGION}}"
                    },
                    "DEPLOY_ENV": {
                      "isOptional": true,
                      "description": "Deployment environment flag.",
                      "defaultValue": "${{API.DEPLOY_ENV}}"
                    },
                    "REDIS_HOST": {
                      "isOptional": true,
                      "description": "Redis private host.",
                      "defaultValue": "${{API.REDIS_HOST}}"
                    },
                    "REDIS_PORT": {
                      "isOptional": true,
                      "description": "Redis port.",
                      "defaultValue": "${{API.REDIS_PORT}}"
                    },
                    "SECRET_KEY": {
                      "isOptional": true,
                      "description": "Flask signing/encryption key. Shared by API, WebSocket, Worker and Beat. Never change after first boot.",
                      "defaultValue": "${{API.SECRET_KEY}}"
                    },
                    "APP_API_URL": {
                      "isOptional": true,
                      "description": "Public URL of the web-app API.",
                      "defaultValue": "${{API.APP_API_URL}}"
                    },
                    "APP_WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of published web apps.",
                      "defaultValue": "${{API.APP_WEB_URL}}"
                    },
                    "DB_DATABASE": {
                      "isOptional": true,
                      "description": "Dify metadata database.",
                      "defaultValue": "${{API.DB_DATABASE}}"
                    },
                    "DB_PASSWORD": {
                      "isOptional": true,
                      "description": "Postgres password.",
                      "defaultValue": "${{API.DB_PASSWORD}}"
                    },
                    "DB_USERNAME": {
                      "isOptional": true,
                      "description": "Postgres user.",
                      "defaultValue": "${{API.DB_USERNAME}}"
                    },
                    "S3_ENDPOINT": {
                      "isOptional": true,
                      "description": "Railway Bucket S3 endpoint.",
                      "defaultValue": "${{API.S3_ENDPOINT}}"
                    },
                    "TRIGGER_URL": {
                      "isOptional": true,
                      "description": "Public prefix for workflow trigger webhooks.",
                      "defaultValue": "${{API.TRIGGER_URL}}"
                    },
                    "STORAGE_TYPE": {
                      "isOptional": true,
                      "description": "File storage backend: Railway Bucket via the S3 API.",
                      "defaultValue": "${{API.STORAGE_TYPE}}"
                    },
                    "VECTOR_STORE": {
                      "isOptional": true,
                      "description": "Vector database used for knowledge bases.",
                      "defaultValue": "${{API.VECTOR_STORE}}"
                    },
                    "S3_ACCESS_KEY": {
                      "isOptional": true,
                      "description": "Railway Bucket access key.",
                      "defaultValue": "${{API.S3_ACCESS_KEY}}"
                    },
                    "S3_SECRET_KEY": {
                      "isOptional": true,
                      "description": "Railway Bucket secret key.",
                      "defaultValue": "${{API.S3_SECRET_KEY}}"
                    },
                    "CELERY_BACKEND": {
                      "isOptional": true,
                      "description": "Celery result backend.",
                      "defaultValue": "${{API.CELERY_BACKEND}}"
                    },
                    "REDIS_PASSWORD": {
                      "isOptional": true,
                      "description": "Redis password.",
                      "defaultValue": "${{API.REDIS_PASSWORD}}"
                    },
                    "REDIS_USERNAME": {
                      "isOptional": true,
                      "description": "Redis user.",
                      "defaultValue": "${{API.REDIS_USERNAME}}"
                    },
                    "S3_BUCKET_NAME": {
                      "isOptional": true,
                      "description": "Railway Bucket name (S3 API name).",
                      "defaultValue": "${{API.S3_BUCKET_NAME}}"
                    },
                    "CONSOLE_API_URL": {
                      "isOptional": true,
                      "description": "Public URL of the console API (same origin via Gateway).",
                      "defaultValue": "${{API.CONSOLE_API_URL}}"
                    },
                    "CONSOLE_WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of the console web UI.",
                      "defaultValue": "${{API.CONSOLE_WEB_URL}}"
                    },
                    "DIFY_PUBLIC_URL": {
                      "isOptional": true,
                      "description": "Public base URL of this Dify instance (the Gateway). Change here when you add a custom domain.",
                      "defaultValue": "${{API.DIFY_PUBLIC_URL}}"
                    },
                    "SERVICE_API_URL": {
                      "isOptional": true,
                      "description": "Base URL shown for the Service API (/v1).",
                      "defaultValue": "${{API.SERVICE_API_URL}}"
                    },
                    "S3_ADDRESS_STYLE": {
                      "isOptional": true,
                      "description": "S3 addressing style. Railway Buckets use virtual-hosted style; set 'path' only if the bucket's Credentials tab says so.",
                      "defaultValue": "${{API.S3_ADDRESS_STYLE}}"
                    },
                    "WEAVIATE_API_KEY": {
                      "isOptional": true,
                      "description": "Weaviate API key.",
                      "defaultValue": "${{API.WEAVIATE_API_KEY}}"
                    },
                    "CELERY_AUTO_SCALE": {
                      "isOptional": true,
                      "description": "Autoscale Celery concurrency by CPU count.",
                      "defaultValue": "false"
                    },
                    "CELERY_BROKER_URL": {
                      "isOptional": true,
                      "description": "Celery broker (Redis DB 1).",
                      "defaultValue": "${{API.CELERY_BROKER_URL}}"
                    },
                    "MIGRATION_ENABLED": {
                      "isOptional": true,
                      "description": "Migrations are run by the API service only.",
                      "defaultValue": "false"
                    },
                    "PLUGIN_DAEMON_KEY": {
                      "isOptional": true,
                      "description": "Key the API uses to call Plugin Daemon.",
                      "defaultValue": "${{API.PLUGIN_DAEMON_KEY}}"
                    },
                    "PLUGIN_DAEMON_URL": {
                      "isOptional": true,
                      "description": "Plugin Daemon endpoint (private).",
                      "defaultValue": "${{API.PLUGIN_DAEMON_URL}}"
                    },
                    "WEAVIATE_ENDPOINT": {
                      "isOptional": true,
                      "description": "Weaviate REST endpoint (private).",
                      "defaultValue": "${{API.WEAVIATE_ENDPOINT}}"
                    },
                    "INTERNAL_FILES_URL": {
                      "isOptional": true,
                      "description": "Private URL used by Plugin Daemon and Agent services to fetch files.",
                      "defaultValue": "${{API.INTERNAL_FILES_URL}}"
                    },
                    "MARKETPLACE_API_URL": {
                      "isOptional": true,
                      "description": "Plugin marketplace API.",
                      "defaultValue": "${{API.MARKETPLACE_API_URL}}"
                    },
                    "MARKETPLACE_ENABLED": {
                      "isOptional": true,
                      "description": "Enable the Dify plugin marketplace.",
                      "defaultValue": "${{API.MARKETPLACE_ENABLED}}"
                    },
                    "SSRF_PROXY_HTTP_URL": {
                      "isOptional": true,
                      "description": "SSRF proxy for outbound HTTP from workflows/tools.",
                      "defaultValue": "${{API.SSRF_PROXY_HTTP_URL}}"
                    },
                    "CELERY_WORKER_AMOUNT": {
                      "isOptional": true,
                      "description": "Celery concurrency (gevent greenlets) per replica.",
                      "defaultValue": "4"
                    },
                    "SQLALCHEMY_POOL_SIZE": {
                      "isOptional": true,
                      "description": "DB pool size per process (kept below Postgres' default 100 connections across all services).",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_SIZE}}"
                    },
                    "SSRF_PROXY_HTTPS_URL": {
                      "isOptional": true,
                      "description": "SSRF proxy for outbound HTTPS from workflows/tools.",
                      "defaultValue": "${{API.SSRF_PROXY_HTTPS_URL}}"
                    },
                    "ENDPOINT_URL_TEMPLATE": {
                      "isOptional": true,
                      "description": "Public URL template for plugin endpoints (routed by the Gateway to Plugin Daemon).",
                      "defaultValue": "${{API.ENDPOINT_URL_TEMPLATE}}"
                    },
                    "PLUGIN_DAEMON_TIMEOUT": {
                      "isOptional": true,
                      "description": "Timeout (s) for plugin invocations.",
                      "defaultValue": "${{API.PLUGIN_DAEMON_TIMEOUT}}"
                    },
                    "AGENT_BACKEND_BASE_URL": {
                      "isOptional": true,
                      "description": "Dify Agent backend endpoint (private).",
                      "defaultValue": "${{API.AGENT_BACKEND_BASE_URL}}"
                    },
                    "CODE_EXECUTION_API_KEY": {
                      "isOptional": true,
                      "description": "Code sandbox API key.",
                      "defaultValue": "${{API.CODE_EXECUTION_API_KEY}}"
                    },
                    "S3_USE_AWS_MANAGED_IAM": {
                      "isOptional": true,
                      "description": "Use static keys, not AWS IAM roles.",
                      "defaultValue": "${{API.S3_USE_AWS_MANAGED_IAM}}"
                    },
                    "WEAVIATE_GRPC_ENDPOINT": {
                      "isOptional": true,
                      "description": "Weaviate gRPC endpoint (private).",
                      "defaultValue": "${{API.WEAVIATE_GRPC_ENDPOINT}}"
                    },
                    "AGENT_BACKEND_API_TOKEN": {
                      "isOptional": true,
                      "description": "Bearer token for the Agent backend control plane.",
                      "defaultValue": "${{API.AGENT_BACKEND_API_TOKEN}}"
                    },
                    "CODE_EXECUTION_ENDPOINT": {
                      "isOptional": true,
                      "description": "Code sandbox endpoint (private).",
                      "defaultValue": "${{API.CODE_EXECUTION_ENDPOINT}}"
                    },
                    "PLUGIN_MAX_PACKAGE_SIZE": {
                      "isOptional": true,
                      "description": "Max plugin package size in bytes.",
                      "defaultValue": "${{API.PLUGIN_MAX_PACKAGE_SIZE}}"
                    },
                    "SQLALCHEMY_MAX_OVERFLOW": {
                      "isOptional": true,
                      "description": "Extra DB connections allowed above the pool size.",
                      "defaultValue": "${{API.SQLALCHEMY_MAX_OVERFLOW}}"
                    },
                    "SQLALCHEMY_POOL_RECYCLE": {
                      "isOptional": true,
                      "description": "Recycle DB connections after N seconds.",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_RECYCLE}}"
                    },
                    "INNER_API_KEY_FOR_PLUGIN": {
                      "isOptional": true,
                      "description": "Key Plugin Daemon / Agent Backend use to call the API's inner endpoints.",
                      "defaultValue": "${{API.INNER_API_KEY_FOR_PLUGIN}}"
                    },
                    "SQLALCHEMY_POOL_PRE_PING": {
                      "isOptional": true,
                      "description": "Validate pooled connections before use (survives idle network resets).",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_PRE_PING}}"
                    },
                    "ENABLE_COLLABORATION_MODE": {
                      "isOptional": true,
                      "description": "Real-time collaborative workflow editing via the API WebSocket service.",
                      "defaultValue": "${{API.ENABLE_COLLABORATION_MODE}}"
                    },
                    "CONSOLE_CORS_ALLOW_ORIGINS": {
                      "isOptional": true,
                      "description": "Allowed origins for the console API (same origin by default).",
                      "defaultValue": "${{API.CONSOLE_CORS_ALLOW_ORIGINS}}"
                    },
                    "WEB_API_CORS_ALLOW_ORIGINS": {
                      "isOptional": true,
                      "description": "Allowed origins for the public web-app API (embeds need *).",
                      "defaultValue": "${{API.WEB_API_CORS_ALLOW_ORIGINS}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "54748cda-c7d6-56de-896b-b09954e5a1dd": {
                  "icon": "https://avatars.githubusercontent.com/u/363029?v=4",
                  "name": "SSRF Proxy",
                  "build": {
                    "builder": "DOCKERFILE"
                  },
                  "deploy": {
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "repo": "baranberkay96/dify-railway",
                    "branch": "main",
                    "rootDirectory": "/services/ssrf-proxy"
                  },
                  "variables": {
                    "HTTP_PORT": {
                      "isOptional": true,
                      "description": "Squid listen port.",
                      "defaultValue": "3128"
                    },
                    "SSRF_PROXY_MODE": {
                      "isOptional": true,
                      "description": "Policy: default = Dify egress proxy.",
                      "defaultValue": "default"
                    },
                    "SSRF_PROXY_ALLOW_PRIVATE_IPS": {
                      "isOptional": true,
                      "description": "Optional comma-separated CIDRs that workflows may reach despite the private-network block.",
                      "defaultValue": ""
                    },
                    "SSRF_PROXY_ALLOW_PRIVATE_DOMAINS": {
                      "isOptional": true,
                      "description": "Optional comma-separated domains (e.g. .railway.internal) that workflows may reach.",
                      "defaultValue": ""
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "5ee55463-7567-5115-95f1-4790e2562990": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "Web",
                  "deploy": {
                    "healthcheckPath": "/signin",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 300,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "langgenius/dify-web:1.17.1"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "Next.js listen port.",
                      "defaultValue": "3000"
                    },
                    "HOSTNAME": {
                      "isOptional": true,
                      "description": "Listen on IPv4+IPv6.",
                      "defaultValue": "::"
                    },
                    "DEPLOY_ENV": {
                      "isOptional": true,
                      "description": "Deployment environment flag.",
                      "defaultValue": "PRODUCTION"
                    },
                    "ALLOW_EMBED": {
                      "isOptional": true,
                      "description": "Allow embedding the console in iframes (published apps are always embeddable).",
                      "defaultValue": "false"
                    },
                    "MAX_TOOLS_NUM": {
                      "isOptional": true,
                      "description": "Max tools per agent.",
                      "defaultValue": "10"
                    },
                    "MAX_TREE_DEPTH": {
                      "isOptional": true,
                      "description": "Max workflow nesting depth.",
                      "defaultValue": "50"
                    },
                    "CONSOLE_WEB_URL": {
                      "isOptional": true,
                      "description": "Public console URL (web prefix).",
                      "defaultValue": "${{API.CONSOLE_WEB_URL}}"
                    },
                    "MARKETPLACE_URL": {
                      "isOptional": true,
                      "description": "Plugin marketplace site.",
                      "defaultValue": "https://marketplace.dify.ai"
                    },
                    "TOP_K_MAX_VALUE": {
                      "isOptional": true,
                      "description": "Max retrieval top-k in the UI.",
                      "defaultValue": "10"
                    },
                    "MAX_ITERATIONS_NUM": {
                      "isOptional": true,
                      "description": "Max iteration-node items.",
                      "defaultValue": "99"
                    },
                    "MAX_PARALLEL_LIMIT": {
                      "isOptional": true,
                      "description": "Max parallel branches.",
                      "defaultValue": "10"
                    },
                    "LOOP_NODE_MAX_COUNT": {
                      "isOptional": true,
                      "description": "Max loop iterations in workflows.",
                      "defaultValue": "100"
                    },
                    "MARKETPLACE_API_URL": {
                      "isOptional": true,
                      "description": "Plugin marketplace API.",
                      "defaultValue": "https://marketplace.dify.ai"
                    },
                    "NEXT_PUBLIC_SOCKET_URL": {
                      "isOptional": true,
                      "description": "Public WebSocket origin for collaboration (update with a custom domain).",
                      "defaultValue": "wss://${{Gateway.RAILWAY_PUBLIC_DOMAIN}}"
                    },
                    "SERVER_CONSOLE_API_URL": {
                      "isOptional": true,
                      "description": "Private API URL for server-side rendering requests.",
                      "defaultValue": "http://${{API.RAILWAY_PRIVATE_DOMAIN}}:5001"
                    },
                    "NEXT_TELEMETRY_DISABLED": {
                      "isOptional": true,
                      "description": "Disable Next.js telemetry.",
                      "defaultValue": "1"
                    },
                    "TEXT_GENERATION_TIMEOUT_MS": {
                      "isOptional": true,
                      "description": "Client timeout for text generation (ms).",
                      "defaultValue": "60000"
                    },
                    "NEXT_PUBLIC_ENABLE_AGENT_V2": {
                      "isOptional": true,
                      "description": "Show the Agent (v2) builder, backed by Agent Backend + Agent Sandbox.",
                      "defaultValue": "true"
                    },
                    "INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH": {
                      "isOptional": true,
                      "description": "Max chunk length for knowledge indexing.",
                      "defaultValue": "4000"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "99c56b0a-b3ae-50dc-9c5c-da76e49beba8": {
                  "icon": "https://avatars.githubusercontent.com/u/363029?v=4",
                  "name": "Agent SSRF Proxy",
                  "build": {
                    "builder": "DOCKERFILE"
                  },
                  "deploy": {
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "repo": "baranberkay96/dify-railway",
                    "branch": "main",
                    "rootDirectory": "/services/ssrf-proxy"
                  },
                  "variables": {
                    "HTTP_PORT": {
                      "isOptional": true,
                      "description": "Squid listen port.",
                      "defaultValue": "3128"
                    },
                    "DIFY_API_HOST": {
                      "isOptional": true,
                      "description": "API private hostname (allowed for /files/).",
                      "defaultValue": "${{API.RAILWAY_PRIVATE_DOMAIN}}"
                    },
                    "SSRF_PROXY_MODE": {
                      "isOptional": true,
                      "description": "Policy: agent = only Agent Stub + API /files/* on the private network, internet otherwise.",
                      "defaultValue": "agent"
                    },
                    "DIFY_AGENT_BACKEND_HOST": {
                      "isOptional": true,
                      "description": "Agent Backend private hostname (allowed for /agent-stub/).",
                      "defaultValue": "${{Agent Backend.RAILWAY_PRIVATE_DOMAIN}}"
                    },
                    "SSRF_PROXY_ALLOW_PRIVATE_IPS": {
                      "isOptional": true,
                      "description": "Optional extra private CIDRs the agent may reach.",
                      "defaultValue": ""
                    },
                    "SSRF_PROXY_ALLOW_PRIVATE_DOMAINS": {
                      "isOptional": true,
                      "description": "Optional extra private domains the agent may reach.",
                      "defaultValue": ""
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "aa1443ad-83a4-5886-b84d-c9f4787b7c7c": {
                  "icon": "https://devicons.railway.app/i/postgresql.svg",
                  "name": "Postgres",
                  "deploy": {
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "ghcr.io/railwayapp-templates/postgres-ssl:18"
                  },
                  "variables": {
                    "PGDATA": {
                      "isOptional": true,
                      "description": "Location where the database will be initialized",
                      "defaultValue": "/var/lib/postgresql/data/pgdata"
                    },
                    "PGHOST": {
                      "isOptional": true,
                      "description": "Railway Private Domain Name.",
                      "defaultValue": "${{RAILWAY_PRIVATE_DOMAIN}}"
                    },
                    "PGPORT": {
                      "isOptional": true,
                      "description": "Port to connect to Postgres.",
                      "defaultValue": "5432"
                    },
                    "PGUSER": {
                      "isOptional": true,
                      "description": "Required variable for Data panel",
                      "defaultValue": "${{ POSTGRES_USER }}"
                    },
                    "PGDATABASE": {
                      "isOptional": true,
                      "description": "Required variable for the data panel.",
                      "defaultValue": "${{POSTGRES_DB}}"
                    },
                    "PGPASSWORD": {
                      "isOptional": true,
                      "description": "Required variable for Data panel",
                      "defaultValue": "${{POSTGRES_PASSWORD}}"
                    },
                    "POSTGRES_DB": {
                      "isOptional": true,
                      "description": "Default database created when image is started.",
                      "defaultValue": "railway"
                    },
                    "DATABASE_URL": {
                      "isOptional": true,
                      "description": "URL to connect to Postgres database.",
                      "defaultValue": "postgresql://${{PGUSER}}:${{POSTGRES_PASSWORD}}@${{RAILWAY_PRIVATE_DOMAIN}}:5432/${{PGDATABASE}}"
                    },
                    "POSTGRES_USER": {
                      "isOptional": true,
                      "description": "User to connect to Postgres DB",
                      "defaultValue": "postgres"
                    },
                    "SSL_CERT_DAYS": {
                      "isOptional": true,
                      "description": "SSL certificate expiry in days.",
                      "defaultValue": "820"
                    },
                    "POSTGRES_PASSWORD": {
                      "isOptional": true,
                      "description": "Password to connect to DB",
                      "defaultValue": "{{POSTGRES_PASSWORD}}"
                    },
                    "RAILWAY_DEPLOYMENT_DRAINING_SECONDS": {
                      "isOptional": true,
                      "description": "Allow Postgres to cleanly shut down",
                      "defaultValue": "60"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "92c0acd8-4089-5f5e-960d-6018fc3fc15d": {
                      "mountPath": "/var/lib/postgresql/data"
                    }
                  }
                },
                "ab8cb032-261b-5115-ae0e-ec6d64920799": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "API WebSocket",
                  "deploy": {
                    "healthcheckPath": "/health",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 600,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "langgenius/dify-api:1.17.1"
                  },
                  "variables": {
                    "MODE": {
                      "isOptional": true,
                      "description": "dify-api run mode.",
                      "defaultValue": "api"
                    },
                    "PORT": {
                      "isOptional": true,
                      "description": "Port Railway health-checks and routes to.",
                      "defaultValue": "5001"
                    },
                    "DB_HOST": {
                      "isOptional": true,
                      "description": "Postgres private host.",
                      "defaultValue": "${{API.DB_HOST}}"
                    },
                    "DB_PORT": {
                      "isOptional": true,
                      "description": "Postgres port.",
                      "defaultValue": "${{API.DB_PORT}}"
                    },
                    "DB_TYPE": {
                      "isOptional": true,
                      "description": "Metadata database type.",
                      "defaultValue": "${{API.DB_TYPE}}"
                    },
                    "REDIS_DB": {
                      "isOptional": true,
                      "description": "Redis DB index for cache/locks.",
                      "defaultValue": "${{API.REDIS_DB}}"
                    },
                    "DIFY_PORT": {
                      "isOptional": true,
                      "description": "Gunicorn listen port.",
                      "defaultValue": "5001"
                    },
                    "FILES_URL": {
                      "isOptional": true,
                      "description": "Public prefix for signed file preview/download links.",
                      "defaultValue": "${{API.FILES_URL}}"
                    },
                    "LOG_LEVEL": {
                      "isOptional": true,
                      "description": "Log verbosity (DEBUG, INFO, WARNING, ERROR).",
                      "defaultValue": "${{API.LOG_LEVEL}}"
                    },
                    "S3_REGION": {
                      "isOptional": true,
                      "description": "Railway Bucket region.",
                      "defaultValue": "${{API.S3_REGION}}"
                    },
                    "DEPLOY_ENV": {
                      "isOptional": true,
                      "description": "Deployment environment flag.",
                      "defaultValue": "${{API.DEPLOY_ENV}}"
                    },
                    "REDIS_HOST": {
                      "isOptional": true,
                      "description": "Redis private host.",
                      "defaultValue": "${{API.REDIS_HOST}}"
                    },
                    "REDIS_PORT": {
                      "isOptional": true,
                      "description": "Redis port.",
                      "defaultValue": "${{API.REDIS_PORT}}"
                    },
                    "SECRET_KEY": {
                      "isOptional": true,
                      "description": "Flask signing/encryption key. Shared by API, WebSocket, Worker and Beat. Never change after first boot.",
                      "defaultValue": "${{API.SECRET_KEY}}"
                    },
                    "APP_API_URL": {
                      "isOptional": true,
                      "description": "Public URL of the web-app API.",
                      "defaultValue": "${{API.APP_API_URL}}"
                    },
                    "APP_WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of published web apps.",
                      "defaultValue": "${{API.APP_WEB_URL}}"
                    },
                    "DB_DATABASE": {
                      "isOptional": true,
                      "description": "Dify metadata database.",
                      "defaultValue": "${{API.DB_DATABASE}}"
                    },
                    "DB_PASSWORD": {
                      "isOptional": true,
                      "description": "Postgres password.",
                      "defaultValue": "${{API.DB_PASSWORD}}"
                    },
                    "DB_USERNAME": {
                      "isOptional": true,
                      "description": "Postgres user.",
                      "defaultValue": "${{API.DB_USERNAME}}"
                    },
                    "S3_ENDPOINT": {
                      "isOptional": true,
                      "description": "Railway Bucket S3 endpoint.",
                      "defaultValue": "${{API.S3_ENDPOINT}}"
                    },
                    "TRIGGER_URL": {
                      "isOptional": true,
                      "description": "Public prefix for workflow trigger webhooks.",
                      "defaultValue": "${{API.TRIGGER_URL}}"
                    },
                    "STORAGE_TYPE": {
                      "isOptional": true,
                      "description": "File storage backend: Railway Bucket via the S3 API.",
                      "defaultValue": "${{API.STORAGE_TYPE}}"
                    },
                    "VECTOR_STORE": {
                      "isOptional": true,
                      "description": "Vector database used for knowledge bases.",
                      "defaultValue": "${{API.VECTOR_STORE}}"
                    },
                    "S3_ACCESS_KEY": {
                      "isOptional": true,
                      "description": "Railway Bucket access key.",
                      "defaultValue": "${{API.S3_ACCESS_KEY}}"
                    },
                    "S3_SECRET_KEY": {
                      "isOptional": true,
                      "description": "Railway Bucket secret key.",
                      "defaultValue": "${{API.S3_SECRET_KEY}}"
                    },
                    "CELERY_BACKEND": {
                      "isOptional": true,
                      "description": "Celery result backend.",
                      "defaultValue": "${{API.CELERY_BACKEND}}"
                    },
                    "REDIS_PASSWORD": {
                      "isOptional": true,
                      "description": "Redis password.",
                      "defaultValue": "${{API.REDIS_PASSWORD}}"
                    },
                    "REDIS_USERNAME": {
                      "isOptional": true,
                      "description": "Redis user.",
                      "defaultValue": "${{API.REDIS_USERNAME}}"
                    },
                    "S3_BUCKET_NAME": {
                      "isOptional": true,
                      "description": "Railway Bucket name (S3 API name).",
                      "defaultValue": "${{API.S3_BUCKET_NAME}}"
                    },
                    "CONSOLE_API_URL": {
                      "isOptional": true,
                      "description": "Public URL of the console API (same origin via Gateway).",
                      "defaultValue": "${{API.CONSOLE_API_URL}}"
                    },
                    "CONSOLE_WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of the console web UI.",
                      "defaultValue": "${{API.CONSOLE_WEB_URL}}"
                    },
                    "DIFY_PUBLIC_URL": {
                      "isOptional": true,
                      "description": "Public base URL of this Dify instance (the Gateway). Change here when you add a custom domain.",
                      "defaultValue": "${{API.DIFY_PUBLIC_URL}}"
                    },
                    "SERVICE_API_URL": {
                      "isOptional": true,
                      "description": "Base URL shown for the Service API (/v1).",
                      "defaultValue": "${{API.SERVICE_API_URL}}"
                    },
                    "GUNICORN_TIMEOUT": {
                      "isOptional": true,
                      "description": "Request timeout in seconds (long streaming responses).",
                      "defaultValue": "360"
                    },
                    "S3_ADDRESS_STYLE": {
                      "isOptional": true,
                      "description": "S3 addressing style. Railway Buckets use virtual-hosted style; set 'path' only if the bucket's Credentials tab says so.",
                      "defaultValue": "${{API.S3_ADDRESS_STYLE}}"
                    },
                    "WEAVIATE_API_KEY": {
                      "isOptional": true,
                      "description": "Weaviate API key.",
                      "defaultValue": "${{API.WEAVIATE_API_KEY}}"
                    },
                    "CELERY_BROKER_URL": {
                      "isOptional": true,
                      "description": "Celery broker (Redis DB 1).",
                      "defaultValue": "${{API.CELERY_BROKER_URL}}"
                    },
                    "DIFY_BIND_ADDRESS": {
                      "isOptional": true,
                      "description": "Bind on IPv4+IPv6 so the private network can reach it.",
                      "defaultValue": "[::]"
                    },
                    "MIGRATION_ENABLED": {
                      "isOptional": true,
                      "description": "Migrations are run by the API service only.",
                      "defaultValue": "false"
                    },
                    "PLUGIN_DAEMON_KEY": {
                      "isOptional": true,
                      "description": "Key the API uses to call Plugin Daemon.",
                      "defaultValue": "${{API.PLUGIN_DAEMON_KEY}}"
                    },
                    "PLUGIN_DAEMON_URL": {
                      "isOptional": true,
                      "description": "Plugin Daemon endpoint (private).",
                      "defaultValue": "${{API.PLUGIN_DAEMON_URL}}"
                    },
                    "WEAVIATE_ENDPOINT": {
                      "isOptional": true,
                      "description": "Weaviate REST endpoint (private).",
                      "defaultValue": "${{API.WEAVIATE_ENDPOINT}}"
                    },
                    "INTERNAL_FILES_URL": {
                      "isOptional": true,
                      "description": "Private URL used by Plugin Daemon and Agent services to fetch files.",
                      "defaultValue": "${{API.INTERNAL_FILES_URL}}"
                    },
                    "MARKETPLACE_API_URL": {
                      "isOptional": true,
                      "description": "Plugin marketplace API.",
                      "defaultValue": "${{API.MARKETPLACE_API_URL}}"
                    },
                    "MARKETPLACE_ENABLED": {
                      "isOptional": true,
                      "description": "Enable the Dify plugin marketplace.",
                      "defaultValue": "${{API.MARKETPLACE_ENABLED}}"
                    },
                    "SERVER_WORKER_CLASS": {
                      "isOptional": true,
                      "description": "Gunicorn worker class.",
                      "defaultValue": "geventwebsocket.gunicorn.workers.GeventWebSocketWorker"
                    },
                    "SSRF_PROXY_HTTP_URL": {
                      "isOptional": true,
                      "description": "SSRF proxy for outbound HTTP from workflows/tools.",
                      "defaultValue": "${{API.SSRF_PROXY_HTTP_URL}}"
                    },
                    "SERVER_WORKER_AMOUNT": {
                      "isOptional": true,
                      "description": "Gunicorn worker processes (raise with more RAM/CPU).",
                      "defaultValue": "1"
                    },
                    "SQLALCHEMY_POOL_SIZE": {
                      "isOptional": true,
                      "description": "DB pool size per process (kept below Postgres' default 100 connections across all services).",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_SIZE}}"
                    },
                    "SSRF_PROXY_HTTPS_URL": {
                      "isOptional": true,
                      "description": "SSRF proxy for outbound HTTPS from workflows/tools.",
                      "defaultValue": "${{API.SSRF_PROXY_HTTPS_URL}}"
                    },
                    "ENDPOINT_URL_TEMPLATE": {
                      "isOptional": true,
                      "description": "Public URL template for plugin endpoints (routed by the Gateway to Plugin Daemon).",
                      "defaultValue": "${{API.ENDPOINT_URL_TEMPLATE}}"
                    },
                    "PLUGIN_DAEMON_TIMEOUT": {
                      "isOptional": true,
                      "description": "Timeout (s) for plugin invocations.",
                      "defaultValue": "${{API.PLUGIN_DAEMON_TIMEOUT}}"
                    },
                    "AGENT_BACKEND_BASE_URL": {
                      "isOptional": true,
                      "description": "Dify Agent backend endpoint (private).",
                      "defaultValue": "${{API.AGENT_BACKEND_BASE_URL}}"
                    },
                    "CODE_EXECUTION_API_KEY": {
                      "isOptional": true,
                      "description": "Code sandbox API key.",
                      "defaultValue": "${{API.CODE_EXECUTION_API_KEY}}"
                    },
                    "S3_USE_AWS_MANAGED_IAM": {
                      "isOptional": true,
                      "description": "Use static keys, not AWS IAM roles.",
                      "defaultValue": "${{API.S3_USE_AWS_MANAGED_IAM}}"
                    },
                    "WEAVIATE_GRPC_ENDPOINT": {
                      "isOptional": true,
                      "description": "Weaviate gRPC endpoint (private).",
                      "defaultValue": "${{API.WEAVIATE_GRPC_ENDPOINT}}"
                    },
                    "AGENT_BACKEND_API_TOKEN": {
                      "isOptional": true,
                      "description": "Bearer token for the Agent backend control plane.",
                      "defaultValue": "${{API.AGENT_BACKEND_API_TOKEN}}"
                    },
                    "CODE_EXECUTION_ENDPOINT": {
                      "isOptional": true,
                      "description": "Code sandbox endpoint (private).",
                      "defaultValue": "${{API.CODE_EXECUTION_ENDPOINT}}"
                    },
                    "PLUGIN_MAX_PACKAGE_SIZE": {
                      "isOptional": true,
                      "description": "Max plugin package size in bytes.",
                      "defaultValue": "${{API.PLUGIN_MAX_PACKAGE_SIZE}}"
                    },
                    "SQLALCHEMY_MAX_OVERFLOW": {
                      "isOptional": true,
                      "description": "Extra DB connections allowed above the pool size.",
                      "defaultValue": "${{API.SQLALCHEMY_MAX_OVERFLOW}}"
                    },
                    "SQLALCHEMY_POOL_RECYCLE": {
                      "isOptional": true,
                      "description": "Recycle DB connections after N seconds.",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_RECYCLE}}"
                    },
                    "INNER_API_KEY_FOR_PLUGIN": {
                      "isOptional": true,
                      "description": "Key Plugin Daemon / Agent Backend use to call the API's inner endpoints.",
                      "defaultValue": "${{API.INNER_API_KEY_FOR_PLUGIN}}"
                    },
                    "SQLALCHEMY_POOL_PRE_PING": {
                      "isOptional": true,
                      "description": "Validate pooled connections before use (survives idle network resets).",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_PRE_PING}}"
                    },
                    "ENABLE_COLLABORATION_MODE": {
                      "isOptional": true,
                      "description": "Real-time collaborative workflow editing via the API WebSocket service.",
                      "defaultValue": "${{API.ENABLE_COLLABORATION_MODE}}"
                    },
                    "SERVER_WORKER_CONNECTIONS": {
                      "isOptional": true,
                      "description": "Concurrent connections per worker.",
                      "defaultValue": "1000"
                    },
                    "CONSOLE_CORS_ALLOW_ORIGINS": {
                      "isOptional": true,
                      "description": "Allowed origins for the console API (same origin by default).",
                      "defaultValue": "${{API.CONSOLE_CORS_ALLOW_ORIGINS}}"
                    },
                    "WEB_API_CORS_ALLOW_ORIGINS": {
                      "isOptional": true,
                      "description": "Allowed origins for the public web-app API (embeds need *).",
                      "defaultValue": "${{API.WEB_API_CORS_ALLOW_ORIGINS}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "b6effee2-281c-59dc-ab19-4ae451868ccc": {
                  "icon": "https://cdn.sanity.io/images/sy1jschh/production/0ce0bfdcfbdbf69662b1116671f97c2dd788b655-157x157.svg",
                  "name": "Redis",
                  "deploy": {
                    "startCommand": "/bin/sh -c \"rm -rf $RAILWAY_VOLUME_MOUNT_PATH/lost+found/ && exec docker-entrypoint.sh redis-server --requirepass $REDIS_PASSWORD --save 60 1 --dir $RAILWAY_VOLUME_MOUNT_PATH\"",
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "redis:8.2"
                  },
                  "variables": {
                    "REDISHOST": {
                      "isOptional": true,
                      "description": "Private network hostname of the Redis service, only resolvable from services in the same environment",
                      "defaultValue": "${{RAILWAY_PRIVATE_DOMAIN}}"
                    },
                    "REDISPORT": {
                      "isOptional": true,
                      "description": "Port that Redis listens on",
                      "defaultValue": "6379"
                    },
                    "REDISUSER": {
                      "isOptional": true,
                      "description": "Username for authenticating with Redis",
                      "defaultValue": "default"
                    },
                    "REDIS_URL": {
                      "isOptional": true,
                      "description": "Connection string for connecting to Redis using the private network",
                      "defaultValue": "redis://${{ REDISUSER }}:${{ REDIS_PASSWORD }}@${{ REDISHOST }}:${{ REDISPORT }}"
                    },
                    "REDISPASSWORD": {
                      "isOptional": true,
                      "description": "Alias of REDIS_PASSWORD for clients that expect the unseparated name",
                      "defaultValue": "${{REDIS_PASSWORD}}"
                    },
                    "REDIS_PASSWORD": {
                      "isOptional": true,
                      "description": "Randomly generated password for authenticating with Redis",
                      "defaultValue": "{{REDIS_PASSWORD}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "77c4a7ed-0995-57f0-a47b-8d4c493b61ce": {
                      "mountPath": "/data"
                    }
                  }
                },
                "dac3423f-6eee-57ce-9456-1abcd68a5269": {
                  "icon": "https://avatars.githubusercontent.com/u/37794290?v=4",
                  "name": "Weaviate",
                  "deploy": {
                    "startCommand": "/bin/weaviate --host :: --port 8080 --scheme http",
                    "healthcheckPath": "/v1/.well-known/ready",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 300,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "semitechnologies/weaviate:1.39.11"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "REST port (gRPC is 50051).",
                      "defaultValue": "8080"
                    },
                    "CLUSTER_HOSTNAME": {
                      "isOptional": true,
                      "description": "Stable node name; do not change after first boot.",
                      "defaultValue": "node1"
                    },
                    "DISABLE_TELEMETRY": {
                      "isOptional": true,
                      "description": "Disable Weaviate telemetry.",
                      "defaultValue": "true"
                    },
                    "QUERY_DEFAULTS_LIMIT": {
                      "isOptional": true,
                      "description": "Default query limit.",
                      "defaultValue": "25"
                    },
                    "PERSISTENCE_DATA_PATH": {
                      "isOptional": true,
                      "description": "Data directory (the volume).",
                      "defaultValue": "/var/lib/weaviate"
                    },
                    "DEFAULT_VECTORIZER_MODULE": {
                      "isOptional": true,
                      "description": "Dify sends its own embeddings.",
                      "defaultValue": "none"
                    },
                    "AUTHENTICATION_APIKEY_USERS": {
                      "isOptional": true,
                      "description": "User mapped to the API key.",
                      "defaultValue": "dify"
                    },
                    "AUTHENTICATION_APIKEY_ENABLED": {
                      "isOptional": true,
                      "description": "Enable API-key auth.",
                      "defaultValue": "true"
                    },
                    "AUTHORIZATION_ADMINLIST_USERS": {
                      "isOptional": true,
                      "description": "Admin users.",
                      "defaultValue": "${{AUTHENTICATION_APIKEY_USERS}}"
                    },
                    "AUTHORIZATION_ADMINLIST_ENABLED": {
                      "isOptional": true,
                      "description": "Admin-list authorization.",
                      "defaultValue": "true"
                    },
                    "AUTHENTICATION_APIKEY_ALLOWED_KEYS": {
                      "isOptional": true,
                      "description": "API key Dify uses.",
                      "defaultValue": "{{AUTHENTICATION_APIKEY_ALLOWED_KEYS}}"
                    },
                    "AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED": {
                      "isOptional": true,
                      "description": "Require an API key.",
                      "defaultValue": "false"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "a72f5231-26c9-5dfd-977a-1be0752b0221": {
                      "mountPath": "/var/lib/weaviate"
                    }
                  }
                },
                "db367364-77dd-50fd-9d89-3e0eb8ac1130": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "Sandbox",
                  "deploy": {
                    "healthcheckPath": "/health",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 300,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "langgenius/dify-sandbox:0.2.15"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "Port Railway health-checks.",
                      "defaultValue": "8194"
                    },
                    "API_KEY": {
                      "isOptional": true,
                      "description": "Key the API uses to call the code sandbox.",
                      "defaultValue": "{{API_KEY}}"
                    },
                    "GIN_MODE": {
                      "isOptional": true,
                      "description": "Go web framework mode.",
                      "defaultValue": "release"
                    },
                    "HTTP_PROXY": {
                      "isOptional": true,
                      "description": "Egress via SSRF proxy.",
                      "defaultValue": "http://${{SSRF Proxy.RAILWAY_PRIVATE_DOMAIN}}:3128"
                    },
                    "HTTPS_PROXY": {
                      "isOptional": true,
                      "description": "Egress via SSRF proxy.",
                      "defaultValue": "http://${{SSRF Proxy.RAILWAY_PRIVATE_DOMAIN}}:3128"
                    },
                    "SANDBOX_PORT": {
                      "isOptional": true,
                      "description": "Sandbox listen port.",
                      "defaultValue": "8194"
                    },
                    "ENABLE_NETWORK": {
                      "isOptional": true,
                      "description": "Allow sandboxed code to make network calls (through the SSRF proxy).",
                      "defaultValue": "true"
                    },
                    "PIP_MIRROR_URL": {
                      "isOptional": true,
                      "description": "Optional PyPI mirror for extra Python packages.",
                      "defaultValue": ""
                    },
                    "WORKER_TIMEOUT": {
                      "isOptional": true,
                      "description": "Max code execution time (s).",
                      "defaultValue": "15"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "3680446b-6e8f-5bc4-b11c-9c8bdfb08d55": {
                      "mountPath": "/dependencies"
                    }
                  }
                },
                "e07284af-b174-5b95-8604-60e03fd361aa": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "Worker Beat",
                  "deploy": {
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "langgenius/dify-api:1.17.1"
                  },
                  "variables": {
                    "MODE": {
                      "isOptional": true,
                      "description": "dify-api run mode: Celery beat scheduler (run exactly one).",
                      "defaultValue": "beat"
                    },
                    "DB_HOST": {
                      "isOptional": true,
                      "description": "Postgres private host.",
                      "defaultValue": "${{API.DB_HOST}}"
                    },
                    "DB_PORT": {
                      "isOptional": true,
                      "description": "Postgres port.",
                      "defaultValue": "${{API.DB_PORT}}"
                    },
                    "DB_TYPE": {
                      "isOptional": true,
                      "description": "Metadata database type.",
                      "defaultValue": "${{API.DB_TYPE}}"
                    },
                    "REDIS_DB": {
                      "isOptional": true,
                      "description": "Redis DB index for cache/locks.",
                      "defaultValue": "${{API.REDIS_DB}}"
                    },
                    "FILES_URL": {
                      "isOptional": true,
                      "description": "Public prefix for signed file preview/download links.",
                      "defaultValue": "${{API.FILES_URL}}"
                    },
                    "LOG_LEVEL": {
                      "isOptional": true,
                      "description": "Log verbosity (DEBUG, INFO, WARNING, ERROR).",
                      "defaultValue": "${{API.LOG_LEVEL}}"
                    },
                    "S3_REGION": {
                      "isOptional": true,
                      "description": "Railway Bucket region.",
                      "defaultValue": "${{API.S3_REGION}}"
                    },
                    "DEPLOY_ENV": {
                      "isOptional": true,
                      "description": "Deployment environment flag.",
                      "defaultValue": "${{API.DEPLOY_ENV}}"
                    },
                    "REDIS_HOST": {
                      "isOptional": true,
                      "description": "Redis private host.",
                      "defaultValue": "${{API.REDIS_HOST}}"
                    },
                    "REDIS_PORT": {
                      "isOptional": true,
                      "description": "Redis port.",
                      "defaultValue": "${{API.REDIS_PORT}}"
                    },
                    "SECRET_KEY": {
                      "isOptional": true,
                      "description": "Flask signing/encryption key. Shared by API, WebSocket, Worker and Beat. Never change after first boot.",
                      "defaultValue": "${{API.SECRET_KEY}}"
                    },
                    "APP_API_URL": {
                      "isOptional": true,
                      "description": "Public URL of the web-app API.",
                      "defaultValue": "${{API.APP_API_URL}}"
                    },
                    "APP_WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of published web apps.",
                      "defaultValue": "${{API.APP_WEB_URL}}"
                    },
                    "DB_DATABASE": {
                      "isOptional": true,
                      "description": "Dify metadata database.",
                      "defaultValue": "${{API.DB_DATABASE}}"
                    },
                    "DB_PASSWORD": {
                      "isOptional": true,
                      "description": "Postgres password.",
                      "defaultValue": "${{API.DB_PASSWORD}}"
                    },
                    "DB_USERNAME": {
                      "isOptional": true,
                      "description": "Postgres user.",
                      "defaultValue": "${{API.DB_USERNAME}}"
                    },
                    "S3_ENDPOINT": {
                      "isOptional": true,
                      "description": "Railway Bucket S3 endpoint.",
                      "defaultValue": "${{API.S3_ENDPOINT}}"
                    },
                    "TRIGGER_URL": {
                      "isOptional": true,
                      "description": "Public prefix for workflow trigger webhooks.",
                      "defaultValue": "${{API.TRIGGER_URL}}"
                    },
                    "STORAGE_TYPE": {
                      "isOptional": true,
                      "description": "File storage backend: Railway Bucket via the S3 API.",
                      "defaultValue": "${{API.STORAGE_TYPE}}"
                    },
                    "VECTOR_STORE": {
                      "isOptional": true,
                      "description": "Vector database used for knowledge bases.",
                      "defaultValue": "${{API.VECTOR_STORE}}"
                    },
                    "S3_ACCESS_KEY": {
                      "isOptional": true,
                      "description": "Railway Bucket access key.",
                      "defaultValue": "${{API.S3_ACCESS_KEY}}"
                    },
                    "S3_SECRET_KEY": {
                      "isOptional": true,
                      "description": "Railway Bucket secret key.",
                      "defaultValue": "${{API.S3_SECRET_KEY}}"
                    },
                    "CELERY_BACKEND": {
                      "isOptional": true,
                      "description": "Celery result backend.",
                      "defaultValue": "${{API.CELERY_BACKEND}}"
                    },
                    "REDIS_PASSWORD": {
                      "isOptional": true,
                      "description": "Redis password.",
                      "defaultValue": "${{API.REDIS_PASSWORD}}"
                    },
                    "REDIS_USERNAME": {
                      "isOptional": true,
                      "description": "Redis user.",
                      "defaultValue": "${{API.REDIS_USERNAME}}"
                    },
                    "S3_BUCKET_NAME": {
                      "isOptional": true,
                      "description": "Railway Bucket name (S3 API name).",
                      "defaultValue": "${{API.S3_BUCKET_NAME}}"
                    },
                    "CONSOLE_API_URL": {
                      "isOptional": true,
                      "description": "Public URL of the console API (same origin via Gateway).",
                      "defaultValue": "${{API.CONSOLE_API_URL}}"
                    },
                    "CONSOLE_WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of the console web UI.",
                      "defaultValue": "${{API.CONSOLE_WEB_URL}}"
                    },
                    "DIFY_PUBLIC_URL": {
                      "isOptional": true,
                      "description": "Public base URL of this Dify instance (the Gateway). Change here when you add a custom domain.",
                      "defaultValue": "${{API.DIFY_PUBLIC_URL}}"
                    },
                    "SERVICE_API_URL": {
                      "isOptional": true,
                      "description": "Base URL shown for the Service API (/v1).",
                      "defaultValue": "${{API.SERVICE_API_URL}}"
                    },
                    "S3_ADDRESS_STYLE": {
                      "isOptional": true,
                      "description": "S3 addressing style. Railway Buckets use virtual-hosted style; set 'path' only if the bucket's Credentials tab says so.",
                      "defaultValue": "${{API.S3_ADDRESS_STYLE}}"
                    },
                    "WEAVIATE_API_KEY": {
                      "isOptional": true,
                      "description": "Weaviate API key.",
                      "defaultValue": "${{API.WEAVIATE_API_KEY}}"
                    },
                    "CELERY_BROKER_URL": {
                      "isOptional": true,
                      "description": "Celery broker (Redis DB 1).",
                      "defaultValue": "${{API.CELERY_BROKER_URL}}"
                    },
                    "MIGRATION_ENABLED": {
                      "isOptional": true,
                      "description": "Migrations are run by the API service only.",
                      "defaultValue": "false"
                    },
                    "PLUGIN_DAEMON_KEY": {
                      "isOptional": true,
                      "description": "Key the API uses to call Plugin Daemon.",
                      "defaultValue": "${{API.PLUGIN_DAEMON_KEY}}"
                    },
                    "PLUGIN_DAEMON_URL": {
                      "isOptional": true,
                      "description": "Plugin Daemon endpoint (private).",
                      "defaultValue": "${{API.PLUGIN_DAEMON_URL}}"
                    },
                    "WEAVIATE_ENDPOINT": {
                      "isOptional": true,
                      "description": "Weaviate REST endpoint (private).",
                      "defaultValue": "${{API.WEAVIATE_ENDPOINT}}"
                    },
                    "INTERNAL_FILES_URL": {
                      "isOptional": true,
                      "description": "Private URL used by Plugin Daemon and Agent services to fetch files.",
                      "defaultValue": "${{API.INTERNAL_FILES_URL}}"
                    },
                    "MARKETPLACE_API_URL": {
                      "isOptional": true,
                      "description": "Plugin marketplace API.",
                      "defaultValue": "${{API.MARKETPLACE_API_URL}}"
                    },
                    "MARKETPLACE_ENABLED": {
                      "isOptional": true,
                      "description": "Enable the Dify plugin marketplace.",
                      "defaultValue": "${{API.MARKETPLACE_ENABLED}}"
                    },
                    "SSRF_PROXY_HTTP_URL": {
                      "isOptional": true,
                      "description": "SSRF proxy for outbound HTTP from workflows/tools.",
                      "defaultValue": "${{API.SSRF_PROXY_HTTP_URL}}"
                    },
                    "SQLALCHEMY_POOL_SIZE": {
                      "isOptional": true,
                      "description": "DB pool size per process (kept below Postgres' default 100 connections across all services).",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_SIZE}}"
                    },
                    "SSRF_PROXY_HTTPS_URL": {
                      "isOptional": true,
                      "description": "SSRF proxy for outbound HTTPS from workflows/tools.",
                      "defaultValue": "${{API.SSRF_PROXY_HTTPS_URL}}"
                    },
                    "ENDPOINT_URL_TEMPLATE": {
                      "isOptional": true,
                      "description": "Public URL template for plugin endpoints (routed by the Gateway to Plugin Daemon).",
                      "defaultValue": "${{API.ENDPOINT_URL_TEMPLATE}}"
                    },
                    "PLUGIN_DAEMON_TIMEOUT": {
                      "isOptional": true,
                      "description": "Timeout (s) for plugin invocations.",
                      "defaultValue": "${{API.PLUGIN_DAEMON_TIMEOUT}}"
                    },
                    "AGENT_BACKEND_BASE_URL": {
                      "isOptional": true,
                      "description": "Dify Agent backend endpoint (private).",
                      "defaultValue": "${{API.AGENT_BACKEND_BASE_URL}}"
                    },
                    "CODE_EXECUTION_API_KEY": {
                      "isOptional": true,
                      "description": "Code sandbox API key.",
                      "defaultValue": "${{API.CODE_EXECUTION_API_KEY}}"
                    },
                    "S3_USE_AWS_MANAGED_IAM": {
                      "isOptional": true,
                      "description": "Use static keys, not AWS IAM roles.",
                      "defaultValue": "${{API.S3_USE_AWS_MANAGED_IAM}}"
                    },
                    "WEAVIATE_GRPC_ENDPOINT": {
                      "isOptional": true,
                      "description": "Weaviate gRPC endpoint (private).",
                      "defaultValue": "${{API.WEAVIATE_GRPC_ENDPOINT}}"
                    },
                    "AGENT_BACKEND_API_TOKEN": {
                      "isOptional": true,
                      "description": "Bearer token for the Agent backend control plane.",
                      "defaultValue": "${{API.AGENT_BACKEND_API_TOKEN}}"
                    },
                    "CODE_EXECUTION_ENDPOINT": {
                      "isOptional": true,
                      "description": "Code sandbox endpoint (private).",
                      "defaultValue": "${{API.CODE_EXECUTION_ENDPOINT}}"
                    },
                    "PLUGIN_MAX_PACKAGE_SIZE": {
                      "isOptional": true,
                      "description": "Max plugin package size in bytes.",
                      "defaultValue": "${{API.PLUGIN_MAX_PACKAGE_SIZE}}"
                    },
                    "SQLALCHEMY_MAX_OVERFLOW": {
                      "isOptional": true,
                      "description": "Extra DB connections allowed above the pool size.",
                      "defaultValue": "${{API.SQLALCHEMY_MAX_OVERFLOW}}"
                    },
                    "SQLALCHEMY_POOL_RECYCLE": {
                      "isOptional": true,
                      "description": "Recycle DB connections after N seconds.",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_RECYCLE}}"
                    },
                    "INNER_API_KEY_FOR_PLUGIN": {
                      "isOptional": true,
                      "description": "Key Plugin Daemon / Agent Backend use to call the API's inner endpoints.",
                      "defaultValue": "${{API.INNER_API_KEY_FOR_PLUGIN}}"
                    },
                    "SQLALCHEMY_POOL_PRE_PING": {
                      "isOptional": true,
                      "description": "Validate pooled connections before use (survives idle network resets).",
                      "defaultValue": "${{API.SQLALCHEMY_POOL_PRE_PING}}"
                    },
                    "ENABLE_COLLABORATION_MODE": {
                      "isOptional": true,
                      "description": "Real-time collaborative workflow editing via the API WebSocket service.",
                      "defaultValue": "${{API.ENABLE_COLLABORATION_MODE}}"
                    },
                    "CONSOLE_CORS_ALLOW_ORIGINS": {
                      "isOptional": true,
                      "description": "Allowed origins for the console API (same origin by default).",
                      "defaultValue": "${{API.CONSOLE_CORS_ALLOW_ORIGINS}}"
                    },
                    "WEB_API_CORS_ALLOW_ORIGINS": {
                      "isOptional": true,
                      "description": "Allowed origins for the public web-app API (embeds need *).",
                      "defaultValue": "${{API.WEB_API_CORS_ALLOW_ORIGINS}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "e3ca6478-3ca9-58b9-8e10-db9b0c41e179": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "Agent Sandbox",
                  "build": {
                    "builder": "DOCKERFILE"
                  },
                  "deploy": {
                    "healthcheckPath": "/healthz",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 300,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "repo": "baranberkay96/dify-railway",
                    "branch": "main",
                    "rootDirectory": "/services/agent-sandbox"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "Port Railway health-checks.",
                      "defaultValue": "5004"
                    },
                    "NO_PROXY": {
                      "isOptional": true,
                      "description": "Hosts that bypass the proxy.",
                      "defaultValue": "localhost,127.0.0.1"
                    },
                    "HTTP_PROXY": {
                      "isOptional": true,
                      "description": "Egress via the agent SSRF proxy.",
                      "defaultValue": "http://${{Agent SSRF Proxy.RAILWAY_PRIVATE_DOMAIN}}:3128"
                    },
                    "HTTPS_PROXY": {
                      "isOptional": true,
                      "description": "Egress via the agent SSRF proxy.",
                      "defaultValue": "http://${{Agent SSRF Proxy.RAILWAY_PRIVATE_DOMAIN}}:3128"
                    },
                    "SHELLCTL_AUTH_TOKEN": {
                      "isOptional": true,
                      "description": "Token the Agent Backend presents.",
                      "defaultValue": "${{Agent Backend.DIFY_AGENT_LOCAL_SANDBOX_AUTH_TOKEN}}"
                    },
                    "SHELLCTL_ENABLE_PATH_ISOLATION": {
                      "isOptional": true,
                      "description": "Landlock path isolation for agent shell jobs. Set false only if jobs fail with Landlock errors.",
                      "defaultValue": "true"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "049d9342-575d-504d-9017-b359f7375bc0": {
                      "mountPath": "/home/dify"
                    }
                  }
                },
                "f1b0ba67-cdd3-5e19-a838-233f8048c834": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "Plugin Daemon",
                  "deploy": {
                    "healthcheckPath": "/health/check",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 300,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "langgenius/dify-plugin-daemon:0.6.10-local"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "Port Railway health-checks.",
                      "defaultValue": "5002"
                    },
                    "DB_HOST": {
                      "isOptional": true,
                      "description": "Postgres private host.",
                      "defaultValue": "${{Postgres.PGHOST}}"
                    },
                    "DB_PORT": {
                      "isOptional": true,
                      "description": "Postgres port.",
                      "defaultValue": "${{Postgres.PGPORT}}"
                    },
                    "DB_TYPE": {
                      "isOptional": true,
                      "description": "Database type.",
                      "defaultValue": "postgresql"
                    },
                    "REDIS_DB": {
                      "isOptional": true,
                      "description": "Redis DB index (keys are prefixed).",
                      "defaultValue": "0"
                    },
                    "REDIS_HOST": {
                      "isOptional": true,
                      "description": "Redis private host.",
                      "defaultValue": "${{Redis.REDISHOST}}"
                    },
                    "REDIS_PORT": {
                      "isOptional": true,
                      "description": "Redis port.",
                      "defaultValue": "${{Redis.REDISPORT}}"
                    },
                    "SERVER_KEY": {
                      "isOptional": true,
                      "description": "Key the API presents to Plugin Daemon.",
                      "defaultValue": "{{SERVER_KEY}}"
                    },
                    "DB_DATABASE": {
                      "isOptional": true,
                      "description": "Plugin database (created automatically on first boot).",
                      "defaultValue": "dify_plugin"
                    },
                    "DB_PASSWORD": {
                      "isOptional": true,
                      "description": "Postgres password.",
                      "defaultValue": "${{Postgres.PGPASSWORD}}"
                    },
                    "DB_SSL_MODE": {
                      "isOptional": true,
                      "description": "Private network; TLS not required.",
                      "defaultValue": "disable"
                    },
                    "DB_USERNAME": {
                      "isOptional": true,
                      "description": "Postgres user.",
                      "defaultValue": "${{Postgres.PGUSER}}"
                    },
                    "SERVER_HOST": {
                      "isOptional": true,
                      "description": "Listen on IPv4+IPv6.",
                      "defaultValue": "[::]"
                    },
                    "SERVER_PORT": {
                      "isOptional": true,
                      "description": "Plugin Daemon HTTP port.",
                      "defaultValue": "5002"
                    },
                    "PPROF_ENABLED": {
                      "isOptional": true,
                      "description": "Go profiler endpoint.",
                      "defaultValue": "false"
                    },
                    "PIP_MIRROR_URL": {
                      "isOptional": true,
                      "description": "Optional PyPI mirror for plugin installs.",
                      "defaultValue": ""
                    },
                    "REDIS_PASSWORD": {
                      "isOptional": true,
                      "description": "Redis password.",
                      "defaultValue": "${{Redis.REDIS_PASSWORD}}"
                    },
                    "REDIS_USERNAME": {
                      "isOptional": true,
                      "description": "Redis user.",
                      "defaultValue": "${{Redis.REDISUSER}}"
                    },
                    "DB_MAX_IDLE_CONNS": {
                      "isOptional": true,
                      "description": "Idle DB connections kept open.",
                      "defaultValue": "5"
                    },
                    "DB_MAX_OPEN_CONNS": {
                      "isOptional": true,
                      "description": "Max DB connections.",
                      "defaultValue": "20"
                    },
                    "DIFY_INNER_API_KEY": {
                      "isOptional": true,
                      "description": "Key Plugin Daemon presents to the API inner endpoints.",
                      "defaultValue": "{{DIFY_INNER_API_KEY}}"
                    },
                    "DIFY_INNER_API_URL": {
                      "isOptional": true,
                      "description": "API inner endpoint (private).",
                      "defaultValue": "http://${{API.RAILWAY_PRIVATE_DOMAIN}}:5001"
                    },
                    "PLUGIN_STORAGE_TYPE": {
                      "isOptional": true,
                      "description": "Plugin packages are kept on this service's volume.",
                      "defaultValue": "local"
                    },
                    "PLUGIN_WORKING_PATH": {
                      "isOptional": true,
                      "description": "Where installed plugins run (Python envs).",
                      "defaultValue": "/app/storage/cwd"
                    },
                    "PLUGIN_INSTALLED_PATH": {
                      "isOptional": true,
                      "description": "Installed plugins sub-directory.",
                      "defaultValue": "plugin"
                    },
                    "MAX_PLUGIN_PACKAGE_SIZE": {
                      "isOptional": true,
                      "description": "Max plugin package size in bytes.",
                      "defaultValue": "52428800"
                    },
                    "PLUGIN_MEDIA_CACHE_PATH": {
                      "isOptional": true,
                      "description": "Plugin asset cache sub-directory.",
                      "defaultValue": "assets"
                    },
                    "PYTHON_ENV_INIT_TIMEOUT": {
                      "isOptional": true,
                      "description": "Timeout (s) to build a plugin's Python environment.",
                      "defaultValue": "120"
                    },
                    "FORCE_VERIFYING_SIGNATURE": {
                      "isOptional": true,
                      "description": "Only allow signed marketplace plugins.",
                      "defaultValue": "true"
                    },
                    "PLUGIN_PACKAGE_CACHE_PATH": {
                      "isOptional": true,
                      "description": "Package cache sub-directory.",
                      "defaultValue": "plugin_packages"
                    },
                    "PLUGIN_STORAGE_LOCAL_ROOT": {
                      "isOptional": true,
                      "description": "Storage root (the volume).",
                      "defaultValue": "/app/storage"
                    },
                    "PLUGIN_MAX_EXECUTION_TIMEOUT": {
                      "isOptional": true,
                      "description": "Max plugin execution time (s).",
                      "defaultValue": "600"
                    },
                    "PLUGIN_REMOTE_INSTALLING_HOST": {
                      "isOptional": true,
                      "description": "Remote plugin-debugging listener (needs a TCP proxy on 5003 to be used).",
                      "defaultValue": "0.0.0.0"
                    },
                    "PLUGIN_REMOTE_INSTALLING_PORT": {
                      "isOptional": true,
                      "description": "Remote plugin-debugging port.",
                      "defaultValue": "5003"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "ab521ea0-946a-5edc-8a66-cb7b01a19904": {
                      "mountPath": "/app/storage"
                    }
                  }
                },
                "fbed3118-fbb3-5ea7-bcb9-148c62f2facf": {
                  "icon": "https://avatars.githubusercontent.com/u/127165244?v=4",
                  "name": "Agent Backend",
                  "deploy": {
                    "startCommand": "uvicorn dify_agent.server.app:app --host 0.0.0.0 --port 5050",
                    "healthcheckPath": "/docs",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 300,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "langgenius/dify-agent-backend:1.17.1"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "Port Railway health-checks.",
                      "defaultValue": "5050"
                    },
                    "DIFY_AGENT_API_TOKEN": {
                      "isOptional": true,
                      "description": "Bearer token the API uses for the Agent control plane.",
                      "defaultValue": "{{DIFY_AGENT_API_TOKEN}}"
                    },
                    "DIFY_AGENT_REDIS_URL": {
                      "isOptional": true,
                      "description": "Agent run store (Redis DB 2).",
                      "defaultValue": "redis://${{Redis.REDISUSER}}:${{Redis.REDIS_PASSWORD}}@${{Redis.REDISHOST}}:${{Redis.REDISPORT}}/2"
                    },
                    "DIFY_AGENT_INNER_API_KEY": {
                      "isOptional": true,
                      "description": "Must equal the API's INNER_API_KEY_FOR_PLUGIN.",
                      "defaultValue": "${{Plugin Daemon.DIFY_INNER_API_KEY}}"
                    },
                    "DIFY_AGENT_INNER_API_URL": {
                      "isOptional": true,
                      "description": "API inner endpoint.",
                      "defaultValue": "http://${{API.RAILWAY_PRIVATE_DOMAIN}}:5001"
                    },
                    "DIFY_AGENT_RUNTIME_BACKEND": {
                      "isOptional": true,
                      "description": "Sandbox backend: local (Agent Sandbox service) or e2b.",
                      "defaultValue": "local"
                    },
                    "DIFY_AGENT_PLUGIN_DAEMON_URL": {
                      "isOptional": true,
                      "description": "Plugin Daemon endpoint.",
                      "defaultValue": "http://${{Plugin Daemon.RAILWAY_PRIVATE_DOMAIN}}:5002"
                    },
                    "DIFY_AGENT_SERVER_SECRET_KEY": {
                      "isOptional": true,
                      "description": "Root secret (43-char base64url = 32 bytes) for Agent Stub token encryption.",
                      "defaultValue": "{{DIFY_AGENT_SERVER_SECRET_KEY}}"
                    },
                    "DIFY_AGENT_STUB_API_BASE_URL": {
                      "isOptional": true,
                      "description": "Agent Stub URL the sandbox calls (through Agent SSRF Proxy).",
                      "defaultValue": "http://${{RAILWAY_PRIVATE_DOMAIN}}:5050/agent-stub"
                    },
                    "DIFY_AGENT_RUN_TIMEOUT_SECONDS": {
                      "isOptional": true,
                      "description": "Max agent run time (s).",
                      "defaultValue": "3600"
                    },
                    "DIFY_AGENT_PLUGIN_DAEMON_API_KEY": {
                      "isOptional": true,
                      "description": "Plugin Daemon key.",
                      "defaultValue": "${{Plugin Daemon.SERVER_KEY}}"
                    },
                    "DIFY_AGENT_LOCAL_SANDBOX_ENDPOINT": {
                      "isOptional": true,
                      "description": "Agent Sandbox (shellctl) endpoint.",
                      "defaultValue": "http://${{Agent Sandbox.RAILWAY_PRIVATE_DOMAIN}}:5004"
                    },
                    "DIFY_AGENT_SANDBOX_FILES_BASE_URL": {
                      "isOptional": true,
                      "description": "API base for sandbox file transfers (/files/*).",
                      "defaultValue": "http://${{API.RAILWAY_PRIVATE_DOMAIN}}:5001"
                    },
                    "DIFY_AGENT_LOCAL_SANDBOX_AUTH_TOKEN": {
                      "isOptional": true,
                      "description": "Token shared with the Agent Sandbox.",
                      "defaultValue": "{{DIFY_AGENT_LOCAL_SANDBOX_AUTH_TOKEN}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "fc808785-e889-5887-b2b2-07311fcfe676": {
                  "icon": "https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/nginx.svg",
                  "name": "Gateway",
                  "build": {
                    "builder": "DOCKERFILE"
                  },
                  "deploy": {
                    "healthcheckPath": "/healthz",
                    "restartPolicyType": "ON_FAILURE",
                    "healthcheckTimeout": 120,
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "repo": "baranberkay96/dify-railway",
                    "branch": "main",
                    "rootDirectory": "/services/gateway"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "Port nginx listens on (public domain target).",
                      "defaultValue": "8080"
                    },
                    "DIFY_API_UPSTREAM": {
                      "isOptional": true,
                      "description": "API private address.",
                      "defaultValue": "${{API.RAILWAY_PRIVATE_DOMAIN}}:5001"
                    },
                    "DIFY_WEB_UPSTREAM": {
                      "isOptional": true,
                      "description": "Web (Next.js) private address.",
                      "defaultValue": "${{Web.RAILWAY_PRIVATE_DOMAIN}}:3000"
                    },
                    "NGINX_PROXY_TIMEOUT": {
                      "isOptional": true,
                      "description": "Proxy read/send timeout (long-running streams).",
                      "defaultValue": "3600s"
                    },
                    "DIFY_SOCKET_UPSTREAM": {
                      "isOptional": true,
                      "description": "API WebSocket private address (/socket.io).",
                      "defaultValue": "${{API WebSocket.RAILWAY_PRIVATE_DOMAIN}}:5001"
                    },
                    "NGINX_CLIENT_MAX_BODY_SIZE": {
                      "isOptional": true,
                      "description": "Max upload size through the gateway.",
                      "defaultValue": "100M"
                    },
                    "DIFY_PLUGIN_DAEMON_UPSTREAM": {
                      "isOptional": true,
                      "description": "Plugin Daemon private address (/e/ plugin endpoints).",
                      "defaultValue": "${{Plugin Daemon.RAILWAY_PRIVATE_DOMAIN}}:5002"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {
                      "<hasDomain>:8080": {
                        "port": 8080
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "post_deploy": {
    "healthcheck": {
      "service": "Gateway",
      "method": "GET",
      "path": "/healthz",
      "expect_status": 200
    }
  },
  "resources": {
    "expected_services": 15,
    "needs_volume": true
  },
  "generated_at": "2026-10-11T16:14:40.554Z",
  "generator_version": "0.1.0",
  "status": "degraded",
  "validated_at": "2026-10-11T14:21:38.017Z",
  "success_rate_30d": 0,
  "validation": {
    "last_run_id": "run_c7d911040e5449a79b74",
    "checks": [
      {
        "name": "workflow_completed",
        "passed": false,
        "detail": "Your workspace has been restricted. Please contact support to resolve this."
      }
    ]
  }
}
