# Neo4j static configuration for the Graphiti stack (examples/neo4j/conf). # # Only settings that are NOT user-tunable via .env live here. User-facing # settings (credentials, memory sizing, bolt advertised address, CPU/RAM # limits, shm size, ulimits) are provided as NEO4J_* environment variables # from .env / .env.example and applied through docker-compose-graphiti.yml. # # Do not duplicate those here: the Neo4j Docker entrypoint always strips a # matching line from this file and re-appends the environment variable's # value, so any duplicated setting would be silently ignored anyway. # # This file is optional: docker-compose-graphiti.yml mounts this directory as # /conf via NEO4J_DIR, and Neo4j starts fine with image defaults if absent/empty. # Security: APOC needs unrestricted/allowlisted access to its own procedures; # scope this to the apoc.* namespace instead of allowing every procedure. dbms.security.procedures.unrestricted=apoc.* dbms.security.procedures.allowlist=apoc.* dbms.security.auth_enabled=true # Logging db.logs.query.enabled=INFO # Connectors bind on all interfaces inside the container; the host-side # binding/exposure is controlled by the "ports" mapping in # docker-compose-graphiti.yml, not here. server.default_listen_address=0.0.0.0 # Bolt connector (plaintext). TLS is intentionally left DISABLED because this # compose stack does not provision an SSL policy/certificates for Neo4j; # enable it only after configuring dbms.ssl.policy.bolt.* and mounting certs. server.bolt.enabled=true server.bolt.tls_level=DISABLED server.bolt.listen_address=0.0.0.0:7687 # HTTP connector server.http.enabled=true server.http.listen_address=0.0.0.0:7474 # Performance tuning independent of heap/pagecache sizing (which is set via # NEO4J_HEAP_INITIAL_SIZE / NEO4J_HEAP_MAX_SIZE / NEO4J_PAGECACHE_SIZE). server.memory.pagecache.flush.buffer.enabled=true server.memory.pagecache.flush.buffer.size_in_pages=512 # Runaway query / lock protection db.transaction.timeout=15m db.lock.acquisition.timeout=15m