cfg

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 28, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Index

Constants

View Source
const DefaultLibvirtURI = "qemu+tcp://host.docker.internal/session"

DefaultLibvirtURI targets the macOS host's session libvirtd as seen from inside a Docker cell (CELL-372).

View Source
const DefaultNixImage = "nixos/nix:2.34.7"

DefaultNixImage is the pinned nixos/nix image for thin builds. Pinned because nixos/nix symlinks /etc files into /nix/store; upgrading changes the store hash and breaks when a shared volume is mounted over /nix.

View Source
const DefaultRegistry = "ghcr.io/devcell-sh/devcell"

DefaultRegistry is the default container registry for devcell images. Must match runner.DefaultRegistry.

View Source
const DefaultTartOCIImage = "ghcr.io/cirruslabs/macos-sequoia-base:latest"

DefaultTartOCIImage is the default macOS base image for tart VMs.

Variables

This section is empty.

Functions

func ApplyEnv

func ApplyEnv(c *CellConfig, getenv func(string) string)

ApplyEnv overrides scalar fields from environment variables.

func FormatNixCollisionHint added in v0.9.0

func FormatNixCollisionHint(pkg string, tiers []string) string

FormatNixCollisionHint returns a user-friendly hint when home-manager reports a package collision during build. Callers match the home-manager error output and call this to augment the message.

func HMOptionsNix added in v0.9.0

func HMOptionsNix() string

HMOptionsNix renders the home-manager option declarations for the devcell.toml schema by reflecting over CellConfig. The generated file (nix/home-manager/options.nix, written by `task hm:generate`) is what keeps `devcell.*` options in lockstep with the Go schema — hand-editing it would reintroduce drift, hence the DO NOT EDIT header.

Mapping rules:

  • string → types.str, int → types.int, bool / *bool → types.bool
  • []string → listOf str, map[string]string → attrsOf str
  • struct field → plain nested attrset (a TOML table the user sets directly: devcell.llm.system_prompt = "...")
  • []struct / map[string]struct → listOf/attrsOf (submodule { ... })

Every leaf is nullOr with default null: unset options never reach the rendered TOML, so absence semantics (e.g. modules unset vs modules = []) match a hand-written devcell.toml.

func KnownDefaultCommands added in v0.9.0

func KnownDefaultCommands() []string

KnownDefaultCommands returns the list of valid default_command values.

func KnownStacks added in v0.4.0

func KnownStacks() []string

KnownStacks returns the list of valid stack names.

func StackSize added in v0.4.0

func StackSize(stack string) (string, bool)

StackSize returns the approximate download size for the given stack.

func ValidateDefaultCommand added in v0.9.0

func ValidateDefaultCommand(cmd string) error

ValidateDefaultCommand checks that default_command is a known subcommand name. Empty is valid (no default, shows help).

func ValidateModulesAgainstCatalog added in v0.8.0

func ValidateModulesAgainstCatalog(userModules, catalogNames []string) error

ValidateModulesAgainstCatalog checks that every name in `userModules` exists in `catalogNames`. Returns nil on success, or a user-friendly error listing all unknown names and the available catalog for hinting.

Used by the CLI at TOML-parse time to catch typos like `yahoo-finanace` before the nix subprocess gets invoked.

func ValidateNixPackageDups added in v0.9.0

func ValidateNixPackageDups(np NixPackages) error

ValidateNixPackageDups checks that no package appears in more than one tier. Two tiers providing the same package would both get lib.hiPri, causing a home-manager collision.

func ValidateNixPackageNames added in v0.9.0

func ValidateNixPackageNames(np NixPackages) error

ValidateNixPackageNames checks that every package name in every tier is a syntactically valid nix attribute name. Returns nil if all names are valid.

func ValidateNixPackages added in v0.9.0

func ValidateNixPackages(np NixPackages) error

ValidateNixPackages runs all [packages.nix] validations: name syntax and cross-tier duplicates.

func ValidateStack added in v0.4.0

func ValidateStack(stack string) error

ValidateStack checks that stack is a known stack name. Empty is valid (defaults to ultimate).

func ValidateWireguard added in v0.9.0

func ValidateWireguard(c CellConfig) error

ValidateWireguard checks that every enabled [[wireguard]] entry has a non-empty name, config, valid WireGuard syntax, at least one peer with a valid PublicKey, and an interface Address.

func WireguardEnabled added in v0.9.0

func WireguardEnabled(c CellConfig) bool

WireguardEnabled reports whether any [[wireguard]] entry is enabled.

Types

type AwsSection added in v0.4.0

type AwsSection struct {
	ReadOnly *bool `toml:"read_only"` // default: true (nil = not set → true)
}

AwsSection holds [aws] config for AWS credential scoping.

func (AwsSection) ResolvedReadOnly added in v0.4.0

func (a AwsSection) ResolvedReadOnly() bool

ResolvedReadOnly returns false unless explicitly set to true.

type BuildSection added in v0.9.0

type BuildSection struct {
	Memory  string `toml:"memory"`   // docker --memory ceiling (e.g. "16g"); "0" = uncapped; env: DEVCELL_BUILD_MEMORY
	CPUs    string `toml:"cpus"`     // docker --cpus quota (e.g. "8"); "0" = no quota; env: DEVCELL_BUILD_CPUS
	MaxJobs int    `toml:"max_jobs"` // nix max-jobs; 0 = derived from ceiling; env: DEVCELL_NIX_MAX_JOBS
	Cores   int    `toml:"cores"`    // nix cores (make -j per job); 0 = derived; env: DEVCELL_NIX_CORES
}

BuildSection holds [build] config for thin-build resource ceilings. Values feed the same resolution chain as the env vars; an explicit env var always wins over TOML (env > toml > derived default).

type CellConfig

type CellConfig struct {
	Cell      CellSection
	Docker    DockerSection  `toml:"docker"`
	Build     BuildSection   `toml:"build"`
	Nix       NixSection     `toml:"nix"`
	LLM       LLMSection     `toml:"llm"`
	Git       GitSection     `toml:"git"`
	Ports     PortsSection   `toml:"ports"`
	Op        OpSection      `toml:"op"`
	Aws       AwsSection     `toml:"aws"`
	Stealth   StealthSection `toml:"stealth"`
	GUI       GUISection     `toml:"gui"`
	Env       map[string]string
	Mise      map[string]string `toml:"mise"` // [mise] — keys map to MISE_<UPPER_KEY> env vars
	Volumes   []VolumeMount
	Packages  PackagesSection
	Wireguard []WireguardEntry `toml:"wireguard"`
}

CellConfig is the merged configuration from all TOML layers.

func LoadFile

func LoadFile(path string) (CellConfig, error)

LoadFile parses a TOML file into CellConfig. Returns zero value + nil error if the file does not exist.

func LoadFromOS

func LoadFromOS(configDir, cwd string) CellConfig

LoadFromOS loads the layered config using real XDG paths and os.Getenv. Parse errors are logged to stderr and the file is skipped.

func LoadFromOSWithDirs added in v0.9.0

func LoadFromOSWithDirs(configDir, cwd string) (CellConfig, error)

LoadFromOSWithDirs loads the layered config using explicit directories and os.Getenv. Returns an error if a config file exists but has a parse error.

func LoadLayered

func LoadLayered(globalPath, projectPath string, getenv func(string) string) (CellConfig, error)

LoadLayered loads global + project files, merges them, then applies env overrides. Returns an error if either file exists but has a parse error (missing files are fine).

func Merge

func Merge(global, project CellConfig) CellConfig

Merge returns a new CellConfig with project overriding global for scalars; slices accumulate (Volumes, Ports.Forward, Op documents, [cell].modules). For [cell].modules: explicit empty list in project ([]) clears global as escape hatch; otherwise project values are unioned with global, deduped.

type CellSection

type CellSection struct {
	ImageTag        string            `toml:"image_tag"`
	Registry        string            `toml:"registry"`          // container registry; default: DefaultRegistry; env: DEVCELL_REGISTRY
	GUI             *bool             `toml:"gui"`               // default: true (nil = not set → true)
	Timezone        string            `toml:"timezone"`          // IANA tz (e.g. "Europe/Prague"); default: host $TZ
	Locale          string            `toml:"locale"`            // POSIX locale (e.g. "en_US.UTF-8"); default: "en_US.UTF-8"
	Stack           string            `toml:"stack"`             // nix stack name (e.g. "go", "python"); default: "base" (see ResolvedStack)
	Modules         []string          `toml:"modules"`           // extra nix modules to compose on top of stack
	NixhomePath     string            `toml:"nixhome"`           // deprecated: use [nix] nixhome instead
	Engine          string            `toml:"engine"`            // execution engine: "docker" (default) or "vagrant"
	VagrantProvider string            `toml:"vagrant_provider"`  // vagrant provider: "utm" (default) or "libvirt"
	VagrantBox      string            `toml:"vagrant_box"`       // vagrant box name override (default: "utm/bookworm")
	KVM             *bool             `toml:"kvm"`               // pass the daemon host's /dev/kvm into the container so QEMU gets hardware accel instead of TCG; default: false; env: DEVCELL_KVM
	PerCellImage    *bool             `toml:"per_cell_image"`    // tag user image per cell instead of per stack; default: false
	Hostname        string            `toml:"hostname"`          // override container hostname; default: computed "cell-<basename>-<bunk>"; env: DEVCELL_HOSTNAME
	MacAddress      string            `toml:"mac_address"`       // MAC for the container's NIC (XX:XX:XX:XX:XX:XX); pinned across restarts for infra-side identity persistence. Honored on user-defined bridge networks (devcell uses --network devcell-network). Empty → docker auto-assigns a random MAC per launch.
	Thin            *bool             `toml:"thin"`              // thin image mode; default: true; disable with thin=false or DEVCELL_THIN=0
	StaleWarning    *bool             `toml:"stale_warning"`     // CELL-391 "cell is behind — parallel reality" nudge at start; default: true; env: DEVCELL_STALE_WARN
	Background      *bool             `toml:"background"`        // keep VM/container running after shell exit; default: false; env: DEVCELL_BACKGROUND
	TartSSHPort     int               `toml:"tart_ssh_port"`     // SSH port for tart engine; default: 22; env: DEVCELL_TART_SSH_PORT
	TartSSHHost     string            `toml:"tart_ssh_host"`     // SSH host for tart engine; default: "localhost"; env: DEVCELL_TART_SSH_HOST
	TartSSHUser     string            `toml:"tart_ssh_user"`     // SSH user for tart engine; default: "admin"; env: DEVCELL_TART_SSH_USER
	TartSSHKey      string            `toml:"tart_ssh_key"`      // path to SSH private key for tart; env: DEVCELL_TART_SSH_KEY
	TartOCIImage    string            `toml:"tart_oci_image"`    // OCI base image for tart VMs; default: DefaultTartOCIImage; env: DEVCELL_TART_OCI_IMAGE
	QemuSSHPort     int               `toml:"qemu_ssh_port"`     // SSH port for QEMU engine; default: 2222; env: DEVCELL_QEMU_SSH_PORT
	QemuSSHHost     string            `toml:"qemu_ssh_host"`     // SSH host for QEMU engine; default: "127.0.0.1"; env: DEVCELL_QEMU_SSH_HOST
	QemuWindowsISO  string            `toml:"qemu_windows_iso"`  // path to Windows ARM64 ISO; env: DEVCELL_QEMU_WINDOWS_ISO
	QemuCPUs        int               `toml:"qemu_cpus"`         // QEMU vCPUs; default: 4; env: DEVCELL_QEMU_CPUS
	QemuMemoryGB    int               `toml:"qemu_memory_gb"`    // QEMU RAM in GB; default: 4; env: DEVCELL_QEMU_MEMORY_GB
	QemuDiskSizeGB  int               `toml:"qemu_disk_size_gb"` // QEMU disk size in GB; default: 64; env: DEVCELL_QEMU_DISK_SIZE_GB
	QemuDisplay     string            `toml:"qemu_display"`      // QEMU display: "none", "cocoa", "sdl"; default: "none"; env: DEVCELL_QEMU_DISPLAY
	LibvirtURI      string            `toml:"libvirt_uri"`       // libvirtd connection URI for the libvirt engine; default: DefaultLibvirtURI; env: DEVCELL_LIBVIRT_URI
	LibvirtPathMap  map[string]string `toml:"libvirt_path_map"`  // container prefix -> host prefix rewrites for domain XML paths (CELL-375); empty = CLI runs on the host
	QemuProjectSync string            `toml:"qemu_project_sync"` // project sync for qemu/libvirt engines: "push" (default), "two-way", "off"; env: DEVCELL_QEMU_PROJECT_SYNC (CELL-383)
	DefaultCommand  string            `toml:"default_command"`   // subcommand to run when `cell` is invoked with no args; env: DEVCELL_DEFAULT_COMMAND
}

CellSection holds [cell] config.

func (CellSection) DescribeModulesSource added in v0.8.0

func (c CellSection) DescribeModulesSource() string

DescribeModulesSource classifies how the effective module set is sourced — stack-only, explicit-modules-only, both merged, or default — so the cell startup banner can tell the user at a glance what's about to load (CELL-48).

default (base stack, no extra modules)  // neither set
stack=<name>                            // only stack
modules=[a,b,c]                         // only explicit modules
stack=<name> + modules=[a,b,c] (merged) // both

func (CellSection) ResolvedBackground added in v0.9.0

func (c CellSection) ResolvedBackground() bool

ResolvedBackground returns the effective background setting: default OFF, enabled by env/toml.

func (CellSection) ResolvedDefaultCommand added in v0.9.0

func (c CellSection) ResolvedDefaultCommand() string

ResolvedDefaultCommand returns the effective default command: env > toml > "".

func (CellSection) ResolvedGUI added in v0.4.0

func (c CellSection) ResolvedGUI() bool

ResolvedGUI returns the effective GUI setting: true unless explicitly set to false.

func (CellSection) ResolvedHostname added in v0.7.0

func (c CellSection) ResolvedHostname(computed string) string

ResolvedHostname returns the effective container hostname. Precedence: DEVCELL_HOSTNAME env > [cell] hostname in TOML > computed default (typically "cell-<basename>-<bunk>" assembled by config.Load).

func (CellSection) ResolvedKVM added in v0.9.0

func (c CellSection) ResolvedKVM() bool

ResolvedKVM returns the effective KVM passthrough setting: env > toml > default OFF. It is opt-in because the device lives on the docker daemon host (e.g. the Colima VM), which the CLI cannot stat — a wrong guess either breaks `docker run` outright or silently drops the guest back to TCG.

func (CellSection) ResolvedLibvirtURI added in v0.9.0

func (c CellSection) ResolvedLibvirtURI() string

ResolvedLibvirtURI returns the effective libvirtd URI: env > toml > default.

func (CellSection) ResolvedPerCellImage added in v0.8.0

func (c CellSection) ResolvedPerCellImage() bool

ResolvedPerCellImage returns true only when explicitly enabled.

func (CellSection) ResolvedQemuCPUs added in v0.9.0

func (c CellSection) ResolvedQemuCPUs() int

ResolvedQemuCPUs returns the effective QEMU vCPU count: env > toml > default 4.

func (CellSection) ResolvedQemuDiskSizeGB added in v0.9.0

func (c CellSection) ResolvedQemuDiskSizeGB() int

ResolvedQemuDiskSizeGB returns the effective QEMU disk size: env > toml > default 64.

func (CellSection) ResolvedQemuDisplay added in v0.9.0

func (c CellSection) ResolvedQemuDisplay() string

ResolvedQemuDisplay returns the effective QEMU display: env > toml > default "none".

func (CellSection) ResolvedQemuMemoryGB added in v0.9.0

func (c CellSection) ResolvedQemuMemoryGB() int

ResolvedQemuMemoryGB returns the effective QEMU memory: env > toml > default 4.

func (CellSection) ResolvedQemuProjectSync added in v0.9.0

func (c CellSection) ResolvedQemuProjectSync() string

func (CellSection) ResolvedQemuSSHHost added in v0.9.0

func (c CellSection) ResolvedQemuSSHHost() string

ResolvedQemuSSHHost returns the effective QEMU SSH host: env > toml > default "127.0.0.1".

func (CellSection) ResolvedQemuSSHPort added in v0.9.0

func (c CellSection) ResolvedQemuSSHPort() int

ResolvedQemuSSHPort returns the effective QEMU SSH port: env > toml > default 2222.

func (CellSection) ResolvedQemuWindowsISO added in v0.9.0

func (c CellSection) ResolvedQemuWindowsISO() string

ResolvedQemuWindowsISO returns the Windows ISO path: env > toml > "".

func (CellSection) ResolvedRegistry added in v0.4.0

func (c CellSection) ResolvedRegistry() string

ResolvedRegistry returns the effective registry: env > toml > default.

func (CellSection) ResolvedStack added in v0.4.0

func (c CellSection) ResolvedStack() string

ResolvedStack returns Stack if set, else "base".

func (CellSection) ResolvedTartOCIImage added in v0.9.0

func (c CellSection) ResolvedTartOCIImage() string

ResolvedTartOCIImage returns the effective tart OCI base image: env > toml > default.

func (CellSection) ResolvedTartSSHHost added in v0.9.0

func (c CellSection) ResolvedTartSSHHost() string

ResolvedTartSSHHost returns the effective SSH host: env > toml > default "localhost".

func (CellSection) ResolvedTartSSHKey added in v0.9.0

func (c CellSection) ResolvedTartSSHKey() string

ResolvedTartSSHKey returns the effective SSH key path: env > toml > "".

func (CellSection) ResolvedTartSSHPort added in v0.9.0

func (c CellSection) ResolvedTartSSHPort() int

ResolvedTartSSHPort returns the effective SSH port: env > toml > default 22.

func (CellSection) ResolvedTartSSHUser added in v0.9.0

func (c CellSection) ResolvedTartSSHUser() string

ResolvedTartSSHUser returns the effective SSH user: env > toml > default "admin". Cirrus Labs OCI images ship with user "admin"; our init flow provisions into that account rather than creating a separate user.

func (CellSection) ResolvedThin added in v0.8.0

func (c CellSection) ResolvedThin() bool

ResolvedThin returns the effective thin setting: default ON, disabled by env/toml.

func (CellSection) StackExplicit added in v0.8.0

func (c CellSection) StackExplicit() bool

StackExplicit reports whether the user opted into a specific stack via TOML (`[cell] stack = "..."`). Drives the build progress label — when false, the "stack=..." qualifier is suppressed (CELL-43). CLI/env overrides are handled at the call site by OR'ing the override into this flag.

func (CellSection) StaleWarningEnabled added in v0.9.0

func (c CellSection) StaleWarningEnabled() bool

ResolvedQemuProjectSync returns the effective project sync mode: env > toml > "push". Anything but off/push/two-way resolves to "push" — the safe default (guest gets files, nothing overwritten on the host). StaleWarningEnabled reports whether the CELL-391 stale-cell nudge should fire at cell start. Default (unset) is enabled — it's a read-only nudge with a proceed-by-default prompt, so opting out is the explicit act.

type DockerSection added in v0.9.0

type DockerSection struct {
	Privileged bool     `toml:"privileged"` // run container with --privileged; default: false
	CapAdd     []string `toml:"cap_add"`    // extra Linux capabilities (e.g. ["SYS_ADMIN"]); default: none
	MemLimit   string   `toml:"mem_limit"`  // docker --memory ceiling (e.g. "4g"); "0" = uncapped; env: DEVCELL_DOCKER_MEM_LIMIT
	CPULimit   string   `toml:"cpu_limit"`  // docker --cpus quota (e.g. "2"); "0" = no quota; env: DEVCELL_DOCKER_CPU_LIMIT
	ShmSize    string   `toml:"shm_size"`   // docker --shm-size (e.g. "1g"); env: DEVCELL_DOCKER_SHM_SIZE
}

DockerSection holds [docker] config for runtime container resource limits. Values follow the same env > toml > default resolution chain as other sections.

func (DockerSection) ResolvedCPULimit added in v0.9.0

func (d DockerSection) ResolvedCPULimit() string

ResolvedCPULimit returns the effective CPU limit: env > toml > default "2".

func (DockerSection) ResolvedMemLimit added in v0.9.0

func (d DockerSection) ResolvedMemLimit() string

ResolvedMemLimit returns the effective memory limit: env > toml > default "4g".

func (DockerSection) ResolvedShmSize added in v0.9.0

func (d DockerSection) ResolvedShmSize() string

ResolvedShmSize returns the effective shm size: env > toml > default "1g".

type GUISection added in v0.9.0

type GUISection struct {
	Enabled    *bool  `toml:"enabled"`    // default: true (nil = not set → true)
	WM         string `toml:"wm"`         // "icewm" (default) or "fluxbox"
	Resolution string `toml:"resolution"` // logical resolution; default: "1920x1080x24"
	Scale      int    `toml:"scale"`      // display scale factor (1=96dpi, 2=192dpi HiDPI); default: 1
}

GUISection holds [gui] config for desktop/window-manager settings.

func (GUISection) ResolvedDPI added in v0.9.0

func (g GUISection) ResolvedDPI() int

ResolvedDPI returns the X server DPI: 96 * scale.

func (GUISection) ResolvedEnabled added in v0.9.0

func (g GUISection) ResolvedEnabled() bool

ResolvedEnabled returns the effective GUI setting: true unless explicitly set to false.

func (GUISection) ResolvedFramebufferResolution added in v0.9.0

func (g GUISection) ResolvedFramebufferResolution() string

ResolvedFramebufferResolution returns the physical Xvfb framebuffer size: logical resolution multiplied by scale factor.

func (GUISection) ResolvedResolution added in v0.9.0

func (g GUISection) ResolvedResolution() string

ResolvedResolution returns the logical resolution: "1920x1080x24" unless explicitly set.

func (GUISection) ResolvedScale added in v0.9.0

func (g GUISection) ResolvedScale() int

ResolvedScale returns the display scale factor: 1 unless explicitly set.

func (GUISection) ResolvedWM added in v0.9.0

func (g GUISection) ResolvedWM() string

ResolvedWM returns the effective window manager: "icewm" unless explicitly set.

type GitSection added in v0.3.0

type GitSection struct {
	AuthorName     string `toml:"author_name"`
	AuthorEmail    string `toml:"author_email"`
	CommitterName  string `toml:"committer_name"`
	CommitterEmail string `toml:"committer_email"`
}

GitSection holds [git] config for git identity inside the container.

func (GitSection) HasIdentity added in v0.3.0

func (g GitSection) HasIdentity() bool

HasIdentity reports whether any git identity field is set.

func (GitSection) ResolvedCommitterEmail added in v0.3.0

func (g GitSection) ResolvedCommitterEmail() string

ResolvedCommitterEmail returns CommitterEmail if set, else falls back to AuthorEmail.

func (GitSection) ResolvedCommitterName added in v0.3.0

func (g GitSection) ResolvedCommitterName() string

ResolvedCommitterName returns CommitterName if set, else falls back to AuthorName.

type LLMModelsSection added in v0.3.0

type LLMModelsSection struct {
	Default   string                 `toml:"default"`
	Providers map[string]LLMProvider `toml:"providers"`
}

LLMModelsSection holds [llm.models] config — provider/model declarations.

type LLMProvider added in v0.2.0

type LLMProvider struct {
	BaseURL string   `toml:"base_url"`
	Models  []string `toml:"models"`
}

LLMProvider holds a single provider entry under [llm.models.providers.<name>].

type LLMSection added in v0.3.0

type LLMSection struct {
	SystemPrompt           string           `toml:"system_prompt"`
	SystemPromptFile       string           `toml:"system_prompt_file"`
	AppendSystemPrompt     string           `toml:"append_system_prompt"`
	AppendSystemPromptFile string           `toml:"append_system_prompt_file"`
	UseOllama              bool             `toml:"use_ollama"`
	UseOpenRouter          bool             `toml:"use_openrouter"`
	Models                 LLMModelsSection `toml:"models"`
}

LLMSection holds [llm] config — all AI agent settings in one place.

Two independent layers, each with an inline and a file form:

  • SystemPrompt / SystemPromptFile REPLACE Claude Code's built-in prompt (claude --system-prompt-file). Setting this discards the stock tool guidance and safety instructions — you own the whole prompt.
  • AppendSystemPrompt / AppendSystemPromptFile layer on top of whichever base is in effect (claude --append-system-prompt-file), alongside the container context devcell always contributes.

Within a layer the inline and file forms are mutually exclusive — set one or neither. The resolver in internal/runner.ResolveSystemPrompt validates this and returns an error when both are set, so we don't fail config load for projects where the conflict is harmless (e.g. callers that don't read system prompts).

type MissingEnvError added in v0.8.0

type MissingEnvError struct {
	// Refs maps each missing host var name to the [env].<key> paths that
	// referenced it (the same var may be referenced from multiple [env] keys).
	Refs map[string][]string
}

MissingEnvError reports host env vars referenced from .devcell.toml [env] values that are unset (or empty) on the host. Aggregates all misses so the user fixes them in one pass rather than one boot per typo.

func ExpandEnv added in v0.8.0

func ExpandEnv(env map[string]string, lookup func(string) (string, bool)) *MissingEnvError

ExpandEnv resolves ${VAR} and $VAR in [env] values against the host environment via lookup (pass os.LookupEnv in production). Values are mutated in place. Returns a non-nil *MissingEnvError if any reference resolved to an unset or empty host var — set-but-empty is treated as a miss (almost always a config bug).

Plain values (no `$`) pass through unchanged and never allocate.

func (*MissingEnvError) Error added in v0.8.0

func (e *MissingEnvError) Error() string

type NixPackages added in v0.9.0

type NixPackages struct {
	Stable   []string `toml:"stable"`
	Unstable []string `toml:"unstable"`
	Edge     []string `toml:"edge"`
}

NixPackages holds [packages.nix] config: arbitrary nixpkgs packages from three channels matching the flake inputs in nixhome/flake.nix.

type NixSection added in v0.9.0

type NixSection struct {
	Image       string `toml:"image"`   // nix core image for thin builds; default: DefaultNixImage; env: DEVCELL_NIX_IMAGE
	NixhomePath string `toml:"nixhome"` // local nixhome path; overridden by DEVCELL_NIXHOME_PATH env
}

NixSection holds [nix] config for nix image and nixhome settings.

func (NixSection) ResolvedImage added in v0.9.0

func (n NixSection) ResolvedImage() string

ResolvedImage returns the effective nix image: env > toml > default.

type OpSection added in v0.3.0

type OpSection struct {
	Documents []string `toml:"documents"` // 1Password document names to resolve via `op item get`
	Items     []string `toml:"items"`     // deprecated: use documents (kept for backwards compat)
}

OpSection holds [op] config for 1Password secret injection.

func (OpSection) ResolvedDocuments added in v0.4.0

func (o OpSection) ResolvedDocuments() []string

ResolvedDocuments returns the merged list of documents + legacy items (deduped).

type PackagesSection

type PackagesSection struct {
	Npm    map[string]string `toml:"npm"`
	Python map[string]string `toml:"python"`
	Nix    NixPackages       `toml:"nix"`
}

PackagesSection holds [packages] config for npm, python, and nix tools.

type PortsSection added in v0.4.0

type PortsSection struct {
	Forward   []string `toml:"forward"`    // port mappings: "3000", "8080:3000"
	PublishIP string   `toml:"publish_ip"` // host interface for `docker run -p`; default "0.0.0.0". Applies to VNC, RDP, and all forward entries.
}

PortsSection holds [ports] config for port forwarding.

func (PortsSection) ResolvedPublishIP added in v0.7.0

func (p PortsSection) ResolvedPublishIP() string

ResolvedPublishIP returns the effective host IP for `docker run -p`. Defaults to "0.0.0.0" when unset so cells are reachable from other hosts regardless of dockerd's bind default (some Docker Desktop / rootless setups default to 127.0.0.1, which would silently break remote RDP/VNC). Override in TOML to bind a specific NIC or "127.0.0.1" for loopback-only.

type StealthSection added in v0.8.0

type StealthSection struct {
	Arch     string `toml:"arch"`
	Platform string `toml:"platform"`
}

StealthSection holds [stealth] config for browser fingerprint spoofing.

func (StealthSection) ResolvedArch added in v0.8.0

func (s StealthSection) ResolvedArch() string

ResolvedArch returns the stealth architecture: explicit > host-detected. Maps runtime.GOARCH to Chrome's getHighEntropyValues().architecture values.

func (StealthSection) ResolvedPlatform added in v0.8.0

func (s StealthSection) ResolvedPlatform() string

ResolvedPlatform returns the stealth platform: explicit > "Linux" default.

func (StealthSection) ResolvedUserAgent added in v0.8.0

func (s StealthSection) ResolvedUserAgent() string

ResolvedUserAgent builds a Chrome UA string matching the stealth identity.

type VolumeMount

type VolumeMount struct {
	Mount string `toml:"mount"`
}

VolumeMount holds a single [[volumes]] entry.

func (VolumeMount) ContainerPath added in v0.9.0

func (v VolumeMount) ContainerPath() string

ContainerPath returns the container-side mount point with trailing slashes stripped so path comparisons work regardless of how the user wrote the path. For "host:container" or "host:container:mode" it returns "container". For shorthand (no colon) it returns the path itself (identity mount).

func (VolumeMount) Resolved added in v0.8.1

func (v VolumeMount) Resolved() string

Resolved returns the mount string in `host:container[:mode]` form, expanding the single-path shorthand where a colonless value means "mount this path at the same path inside the container".

Examples:

"/foo/bar"          → "/foo/bar:/foo/bar"
"/foo:/bar"         → "/foo:/bar"      (unchanged)
"/foo:/bar:ro"      → "/foo:/bar:ro"   (unchanged)

type WireguardEntry added in v0.9.0

type WireguardEntry struct {
	Name    string `toml:"name"`
	Enabled bool   `toml:"enabled"`
	Config  string `toml:"config"`
}

WireguardEntry holds one [[wireguard]] table-array entry.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL