import type { EmbeddingEndpointConfig } from "./types.js"; export type { EmbeddingEndpointConfig } from "./types.js"; import type { PoolConfig } from "pg"; export interface HorizonFactsConfig { /** PostgreSQL/HorizonDB connection string. */ connectionString: string; /** Relational schema for the facts table + procs. Default "horizon_facts". */ schema?: string; /** AGE graph name. Default "horizon_facts". */ graphName?: string; /** * Embedding endpoint (provider-neutral, see EmbeddingEndpointConfig). * Required for semantic/hybrid search and for this provider's in-DB embedding * pipeline. Lexical + graph work without it. When provided, initialize() * configures AND auto-starts the eternal in-DB embed loop (idempotent + * advisory-locked, so repeated/concurrent instantiations never duplicate it). */ embedding?: EmbeddingEndpointConfig; /** * Dimension of the vector(N) column, fixed at migration time. Defaults to * embedding?.dim ?? 1536. configureEmbedder() rejects endpoints whose dim * differs (a dim change requires a column migration + full re-embed). */ embeddingDim?: number; /** * Vector ANN index method. "diskann" uses Azure's pg_diskann (must be * allow-listed in the cluster's azure.extensions parameter group); "hnsw" * uses pgvector's built-in HNSW; "auto" (default) prefers diskann and falls * back to hnsw when pg_diskann is unavailable. */ annIndex?: "diskann" | "hnsw" | "auto"; /** * Max pool connections. Default 16. The graph layer issues several * sequential Cypher statements per upsert, and the harvester fires graph * tool calls in parallel; a small pool serializes those behind a few * connections and connection-queue wait dominates latency (a pool of 3 was * measured ~2-4x slower than 10 under concurrency=8). Override per-cluster * with HORIZON_POOL_MAX, bearing in mind the cluster's max_connections. */ poolMax?: number; /** AAD / managed-identity auth (mirrors PilotSwarm's PgFactStore). */ useManagedIdentity?: boolean; aadUser?: string; /** * Relational schema OWNED BY THE GRAPH PROVIDER for the namespace registry * sidecar (graph-fact-search enhancements). MUST differ from the AGE graph * name (`graphName`) — `create_graph()` creates a Postgres schema named after * the graph, so reusing it would put the sidecar INSIDE the AGE-managed * schema (droppable by drop_graph). Also distinct from the facts `schema`, * since the graph store may run against a database with no facts schema at * all. Defaults to `${graphName}_registry`. Override with * HORIZON_GRAPH_REGISTRY_SCHEMA. */ registrySchema?: string; /** * TTL (ms) for the in-provider namespace-list cache. The namespace set is * small and changes rarely; the provider caches a single full snapshot and * filters in memory. Writes invalidate the snapshot in-process; other * workers converge within the TTL. Default 60000 (one minute). Set 0 to * disable caching (always reload) — useful in tests. */ namespaceCacheTtlMs?: number; } export declare const DEFAULT_SCHEMA = "horizon_facts"; export declare const DEFAULT_GRAPH = "horizon_facts"; export declare const DEFAULT_POOL_MAX = 16; export declare const DEFAULT_CONNECTION_TIMEOUT_MS = 15000; export declare const DEFAULT_NAMESPACE_CACHE_TTL_MS = 60000; /** Resolve config from explicit values, falling back to HORIZON_* env vars. */ export declare function resolveConfig(partial?: Partial): HorizonFactsConfig; /** * Build a `pg.PoolConfig` from a HorizonDB connection string, normalizing TLS * the same way the PilotSwarm SDK's `pg-pool-factory` does for the CMS / facts * pools, so a HorizonDB URL behaves here exactly like `DATABASE_URL` does there. * * Why this is needed: HorizonDB requires SSL, but its certificate chain is not in * Node's default trust store, and `pg` v8 treats `sslmode=require` (and * `prefer` / `verify-ca` / `verify-full`) as `verify-full` — which rejects the * chain with `self-signed certificate in certificate chain`. The SDK factory * handles this for `DATABASE_URL` by stripping `sslmode` from the URL and setting * `ssl: { rejectUnauthorized: false }` on the pool config. This provider builds * its OWN raw pools (it keeps its runtime dep surface to `pg` only and does not * import the SDK), so without this helper a natural `?sslmode=require` URL fails * here while the identical URL works for `DATABASE_URL` — the asymmetry that * previously forced callers to hand-append `uselibpqcompat=true`. * * Encrypt-but-don't-verify matches libpq's `sslmode=require` semantics and the * SDK's existing posture (this is not a new weakening — it is the same choice the * CMS/facts pools already make). For full CA verification against a non-preview * cluster, present a trusted chain and pass a URL without an `sslmode` param. */ export declare function buildPoolConfig(connectionString: string, max: number): PoolConfig; //# sourceMappingURL=config.d.ts.map