How to Configure derisk-proxy-aliyun.toml for Secure API Access in OpenRisk

To configure derisk-proxy-aliyun.toml for API access, copy the template to ~/.openderisk/, set the required environment variables (DASHSCOPE_API_KEY_2, OSS_ACCESS_KEY_ID, OSS_ACCESS_KEY_SECRET, and ENCRYPT_KEY), and start the server with the --config flag pointing to your configuration file.

The derisk-proxy-aliyun.toml file controls the OpenRisk server's integration with Alibaba Cloud services, including the DashScope LLM API and OSS object storage. According to the derisk-ai/openderisk source code, this TOML configuration uses environment variable substitution to keep sensitive credentials out of version control while maintaining runnable defaults.

Understanding the Configuration Structure

The configuration file in configs/derisk-proxy-aliyun.toml contains several distinct sections that define system behavior, network settings, and cloud service authentication.

System and Web Service Settings

The [system] section defines global server parameters:

  • language: UI locale, defaulting to zh via ${env:DERISK_LANG:-zh}
  • log_level: Logging verbosity (e.g., "INFO")
  • encrypt_key: Secret key for data encryption, using ${ENCRYPT_KEY:-your_secret_key} placeholder

The [service.web] section configures the HTTP endpoint:

  • host and port: Bind address and port (defaults to "0.0.0.0" and 7777)
  • web_url: Public-facing URL supporting dynamic port substitution via ${env:WEB_SERVER_PORT:-7777}

The [service.web.database] subsection specifies SQLite storage at "pilot/meta_data/derisk.db" for session persistence.

LLM Provider Configuration

The [[agent.llm.provider]] array configures the Alibaba Cloud DashScope endpoint:

  • provider: Set to "openai" for compatibility mode
  • api_base: Fixed at "https://dashscope.aliyuncs.com/compatible-mode/v1"
  • api_key: Authentication token via ${DASHSCOPE_API_KEY_2:-sk-...}

The [[agent.llm.provider.model]] subsections list available model identifiers such as deepseek-r1 and qwen-plus.

Object Storage Service (OSS) Backend

The [[serves.backends]] section with type = "oss" configures file storage:

  • endpoint: OSS URL (e.g., "https://oss-cn-beijing.aliyuncs.com")
  • region: Alibaba region identifier (e.g., "oss-cn-beijing")
  • access_key_id and access_key_secret: Credentials via ${env:OSS_ACCESS_KEY_ID:-xxx} and ${env:OSS_ACCESS_KEY_SECRET:-xxx}
  • fixed_bucket: Default storage bucket (e.g., "openderisk")

The [sandbox] section duplicates these OSS credentials for the isolated execution environment using the same substitution pattern.

Environment Variable Substitution

Values wrapped in ${env:VAR_NAME:-default} resolve at runtime according to the implementation in packages/derisk-app/src/derisk_app/app.py. If the environment variable exists, the server uses its value; otherwise, it falls back to the literal default. This design pattern prevents accidental credential commits while allowing immediate execution with placeholder values.

Step-by-Step Configuration

Follow these steps to prepare the derisk-proxy-aliyun.toml configuration for production use:

  1. Copy the template to your home directory:
mkdir -p ~/.openderisk
cp configs/derisk-proxy-aliyun.toml ~/.openderisk/derisk-proxy-aliyun.toml
  1. Export required environment variables:
export DASHSCOPE_API_KEY_2="sk-your-dashscope-api-key"
export OSS_ACCESS_KEY_ID="your-oss-access-key-id"
export OSS_ACCESS_KEY_SECRET="your-oss-access-key-secret"
export ENCRYPT_KEY="your-32-character-encryption-key"
  1. Start the server with the configuration path:
uv run python packages/derisk-app/src/derisk_app/derisk_server.py \
    --config ~/.openderisk/derisk-proxy-aliyun.toml

The server loads the TOML from packages/derisk-app/src/derisk_app/app.py, resolves the environment variables, and establishes connections to DashScope and OSS.

Configuration Examples

Create ~/.openderisk/.env to store credentials outside the TOML:

DASHSCOPE_API_KEY_2=sk-your-dashscope-key-here
OSS_ACCESS_KEY_ID=LTAI-your-access-key
OSS_ACCESS_KEY_SECRET=your-secret-key-here
ENCRYPT_KEY=super-secure-random-encryption-key

Load the variables before starting the server:

set -a && source ~/.openderisk/.env && set +a
uv run python packages/derisk-app/src/derisk_app/derisk_server.py \
    --config ~/.openderisk/derisk-proxy-aliyun.toml

Hardcoding Credentials (Testing Only)

For local testing without environment variables, edit the TOML directly:

[[agent.llm.provider]]
provider = "openai"
api_base = "https://dashscope.aliyuncs.com/compatible-mode/v1"
api_key = "sk-your-dashscope-key"

[[serves.backends]]
type = "oss"
endpoint = "https://oss-cn-beijing.aliyuncs.com"
region = "oss-cn-beijing"
access_key_id = "your-oss-access-key-id"
access_key_secret = "your-oss-access-key-secret"
fixed_bucket = "openderisk"

Warning: Hardcoding credentials exposes secrets to anyone with file system access and increases the risk of accidental commits to version control.

Verifying Configuration Loading

Use this Python snippet to verify environment substitution works correctly:

from pathlib import Path
import toml
import os

# Ensure env vars are set

os.environ['DASHSCOPE_API_KEY_2'] = 'sk-test-key'

cfg_path = Path.home() / ".openderisk" / "derisk-proxy-aliyun.toml"
config = toml.load(cfg_path)

provider = config["agent"]["llm"]["provider"][0]
print(f"API Base: {provider['api_base']}")
print(f"API Key resolved: {provider['api_key'][:10]}...")

Summary

  • The derisk-proxy-aliyun.toml file in configs/ serves as the template for Alibaba Cloud API integration.
  • Environment variable substitution using ${env:VAR:-default} syntax keeps credentials secure and out of the repository.
  • Required variables include DASHSCOPE_API_KEY_2 for LLM access, OSS_ACCESS_KEY_ID and OSS_ACCESS_KEY_SECRET for storage, and ENCRYPT_KEY for data security.
  • The server loads configuration via packages/derisk-app/src/derisk_app/app.py and starts with the --config flag pointing to your TOML file.

Frequently Asked Questions

Where is the default derisk-proxy-aliyun.toml template located?

The default template resides in configs/derisk-proxy-aliyun.toml at the repository root. The install.sh script references this file during setup, and the README.md documentation directs users to copy it to ~/.openderisk/ for customization.

Can I use hardcoded credentials instead of environment variables?

Yes, but only for local testing. Replace the ${env:VAR:-default} placeholders with literal strings in the TOML file. However, this exposes secrets in plain text and risks accidental commits. Production deployments should always use environment variables or secret management systems.

What should I use for the ENCRYPT_KEY value?

Set ENCRYPT_KEY to a strong, random string of at least 32 characters. This key encrypts sensitive data stored in the SQLite database. If the key changes after data is encrypted, the server cannot decrypt existing session data, requiring database reset.

How do I verify that the configuration loaded correctly?

Check the server logs on startup for connection errors to dashscope.aliyuncs.com or OSS endpoints. You can also inspect the resolved configuration by examining the config object loaded in packages/derisk-app/src/derisk_app/app.py, or use the Python verification snippet to confirm environment variables resolve correctly before starting the server.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →