config

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 10, 2026 License: MIT Imports: 8 Imported by: 0

Documentation

Overview

Package config loads and validates sim's TOML configuration.

The TOML document is decoded directly into the typed structs below, which are pre-filled with sim's defaults: BurntSushi only overwrites keys that are present, so absent keys need no presence tracking. `[systemd.limits]` uses pointers because "absent" (do not pass -p MemoryMax=...) differs from a zero value.

Wrong-type values are rejected by the decoder; everything else (port range, enum membership, env-name syntax, positive ints, non-empty strings) is checked in validate(), which reports the same messages the Python implementation did.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func FindFile

func FindFile(cwd string) string

FindFile returns the nearest .sim.toml walking up from cwd, else ~/.config/sim/sim.toml if it exists, else "".

Types

type Config

type Config struct {
	Path    string  `toml:"-"`
	Network Network `toml:"network"`
	Podman  Podman  `toml:"podman"`
	Systemd Systemd `toml:"systemd"`
	Env     Env     `toml:"env"`
	Sandbox Sandbox `toml:"sandbox"`
}

Config is the validated configuration.

func LoadAt

func LoadAt(path string) (*Config, error)

LoadAt reads and validates the config at path; an empty path means built-in defaults. Callers stage the chosen source before calling, so a validation failure still reports which file was used.

func Parse

func Parse(data []byte, path string) (*Config, error)

Parse decodes and validates a TOML document on top of the built-in defaults. path is used in messages only; pass "" (and nil data) for defaults.

type Env

type Env struct {
	Setenv []string `toml:"setenv"`
}

Env mirrors [env].

type Limits

type Limits struct {
	MemoryMax     *string `toml:"memory_max"`
	MemoryHigh    *string `toml:"memory_high"`
	MemorySwapMax *string `toml:"memory_swap_max"`
	CPUQuota      *string `toml:"cpu_quota"`
	TasksMax      *int    `toml:"tasks_max"`
}

Limits mirrors [systemd.limits]. A nil field means the key was absent.

type Network

type Network struct {
	Public bool `toml:"public"`
	// LocalPorts are host ports spliced into the sandbox by pasta (-T/-U).
	// An empty list passes "none", so no host port is reachable.
	LocalPorts []int `toml:"local_ports"`
	// AllowCIDRs are egress destinations that stay reachable when Public is
	// false (the corporate-only / "private" mode). Normalized to masked
	// prefixes by validate; empty with Public false means loopback only.
	AllowCIDRs []string `toml:"allow_cidrs"`
	ResolvConf string   `toml:"resolv_conf"`
}

Network mirrors [network].

type Podman

type Podman struct {
	Enabled     bool     `toml:"enabled"`
	Images      []string `toml:"images"`
	ChownShadow bool     `toml:"chown_shadow"`
}

Podman mirrors [podman].

type Sandbox

type Sandbox struct {
	VirtualHome  string   `toml:"virtual_home"`
	Binds        []string `toml:"binds"`
	CwdGitMode   string   `toml:"cwd_git_mode"`
	SetupScripts []string `toml:"setup_scripts"`
}

Sandbox mirrors [sandbox].

type Systemd

type Systemd struct {
	Enabled bool   `toml:"enabled"`
	Limits  Limits `toml:"limits"`
}

Systemd mirrors [systemd]. The limits live in this section because they are systemd cgroup properties (`-p MemoryMax=...`): there is nothing to apply them to without a systemd scope, so nesting keeps them from being configured where they cannot take effect.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL