How to Configure derisk-proxy-aliyun.toml for Secure API Access in OpenRisk
To configure derisk-proxy-aliyun.toml for API access, copy the template to ~/.openderisk/, set the required environment variables (DASHSCOPE_API_KEY_2, OSS_ACCESS_KEY_ID, OSS_ACCESS_KEY_SECRET, and ENCRYPT_KEY), and start the server with the --config flag pointing to your configuration file.
The derisk-proxy-aliyun.toml file controls the OpenRisk server's integration with Alibaba Cloud services, including the DashScope LLM API and OSS object storage. According to the derisk-ai/openderisk source code, this TOML configuration uses environment variable substitution to keep sensitive credentials out of version control while maintaining runnable defaults.
Understanding the Configuration Structure
The configuration file in configs/derisk-proxy-aliyun.toml contains several distinct sections that define system behavior, network settings, and cloud service authentication.
System and Web Service Settings
The [system] section defines global server parameters:
language: UI locale, defaulting tozhvia${env:DERISK_LANG:-zh}log_level: Logging verbosity (e.g.,"INFO")encrypt_key: Secret key for data encryption, using${ENCRYPT_KEY:-your_secret_key}placeholder
The [service.web] section configures the HTTP endpoint:
hostandport: Bind address and port (defaults to"0.0.0.0"and7777)web_url: Public-facing URL supporting dynamic port substitution via${env:WEB_SERVER_PORT:-7777}
The [service.web.database] subsection specifies SQLite storage at "pilot/meta_data/derisk.db" for session persistence.
LLM Provider Configuration
The [[agent.llm.provider]] array configures the Alibaba Cloud DashScope endpoint:
provider: Set to"openai"for compatibility modeapi_base: Fixed at"https://dashscope.aliyuncs.com/compatible-mode/v1"api_key: Authentication token via${DASHSCOPE_API_KEY_2:-sk-...}
The [[agent.llm.provider.model]] subsections list available model identifiers such as deepseek-r1 and qwen-plus.
Object Storage Service (OSS) Backend
The [[serves.backends]] section with type = "oss" configures file storage:
endpoint: OSS URL (e.g.,"https://oss-cn-beijing.aliyuncs.com")region: Alibaba region identifier (e.g.,"oss-cn-beijing")access_key_idandaccess_key_secret: Credentials via${env:OSS_ACCESS_KEY_ID:-xxx}and${env:OSS_ACCESS_KEY_SECRET:-xxx}fixed_bucket: Default storage bucket (e.g.,"openderisk")
The [sandbox] section duplicates these OSS credentials for the isolated execution environment using the same substitution pattern.
Environment Variable Substitution
Values wrapped in ${env:VAR_NAME:-default} resolve at runtime according to the implementation in packages/derisk-app/src/derisk_app/app.py. If the environment variable exists, the server uses its value; otherwise, it falls back to the literal default. This design pattern prevents accidental credential commits while allowing immediate execution with placeholder values.
Step-by-Step Configuration
Follow these steps to prepare the derisk-proxy-aliyun.toml configuration for production use:
- Copy the template to your home directory:
mkdir -p ~/.openderisk
cp configs/derisk-proxy-aliyun.toml ~/.openderisk/derisk-proxy-aliyun.toml
- Export required environment variables:
export DASHSCOPE_API_KEY_2="sk-your-dashscope-api-key"
export OSS_ACCESS_KEY_ID="your-oss-access-key-id"
export OSS_ACCESS_KEY_SECRET="your-oss-access-key-secret"
export ENCRYPT_KEY="your-32-character-encryption-key"
- Start the server with the configuration path:
uv run python packages/derisk-app/src/derisk_app/derisk_server.py \
--config ~/.openderisk/derisk-proxy-aliyun.toml
The server loads the TOML from packages/derisk-app/src/derisk_app/app.py, resolves the environment variables, and establishes connections to DashScope and OSS.
Configuration Examples
Using a .env File (Recommended)
Create ~/.openderisk/.env to store credentials outside the TOML:
DASHSCOPE_API_KEY_2=sk-your-dashscope-key-here
OSS_ACCESS_KEY_ID=LTAI-your-access-key
OSS_ACCESS_KEY_SECRET=your-secret-key-here
ENCRYPT_KEY=super-secure-random-encryption-key
Load the variables before starting the server:
set -a && source ~/.openderisk/.env && set +a
uv run python packages/derisk-app/src/derisk_app/derisk_server.py \
--config ~/.openderisk/derisk-proxy-aliyun.toml
Hardcoding Credentials (Testing Only)
For local testing without environment variables, edit the TOML directly:
[[agent.llm.provider]]
provider = "openai"
api_base = "https://dashscope.aliyuncs.com/compatible-mode/v1"
api_key = "sk-your-dashscope-key"
[[serves.backends]]
type = "oss"
endpoint = "https://oss-cn-beijing.aliyuncs.com"
region = "oss-cn-beijing"
access_key_id = "your-oss-access-key-id"
access_key_secret = "your-oss-access-key-secret"
fixed_bucket = "openderisk"
Warning: Hardcoding credentials exposes secrets to anyone with file system access and increases the risk of accidental commits to version control.
Verifying Configuration Loading
Use this Python snippet to verify environment substitution works correctly:
from pathlib import Path
import toml
import os
# Ensure env vars are set
os.environ['DASHSCOPE_API_KEY_2'] = 'sk-test-key'
cfg_path = Path.home() / ".openderisk" / "derisk-proxy-aliyun.toml"
config = toml.load(cfg_path)
provider = config["agent"]["llm"]["provider"][0]
print(f"API Base: {provider['api_base']}")
print(f"API Key resolved: {provider['api_key'][:10]}...")
Summary
- The
derisk-proxy-aliyun.tomlfile inconfigs/serves as the template for Alibaba Cloud API integration. - Environment variable substitution using
${env:VAR:-default}syntax keeps credentials secure and out of the repository. - Required variables include
DASHSCOPE_API_KEY_2for LLM access,OSS_ACCESS_KEY_IDandOSS_ACCESS_KEY_SECRETfor storage, andENCRYPT_KEYfor data security. - The server loads configuration via
packages/derisk-app/src/derisk_app/app.pyand starts with the--configflag pointing to your TOML file.
Frequently Asked Questions
Where is the default derisk-proxy-aliyun.toml template located?
The default template resides in configs/derisk-proxy-aliyun.toml at the repository root. The install.sh script references this file during setup, and the README.md documentation directs users to copy it to ~/.openderisk/ for customization.
Can I use hardcoded credentials instead of environment variables?
Yes, but only for local testing. Replace the ${env:VAR:-default} placeholders with literal strings in the TOML file. However, this exposes secrets in plain text and risks accidental commits. Production deployments should always use environment variables or secret management systems.
What should I use for the ENCRYPT_KEY value?
Set ENCRYPT_KEY to a strong, random string of at least 32 characters. This key encrypts sensitive data stored in the SQLite database. If the key changes after data is encrypted, the server cannot decrypt existing session data, requiring database reset.
How do I verify that the configuration loaded correctly?
Check the server logs on startup for connection errors to dashscope.aliyuncs.com or OSS endpoints. You can also inspect the resolved configuration by examining the config object loaded in packages/derisk-app/src/derisk_app/app.py, or use the Python verification snippet to confirm environment variables resolve correctly before starting the server.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →