Documentation
¶
Index ¶
- Constants
- func BridgeServerName(instanceID string) string
- func BridgeServerSPIFFE(instanceID string) string
- func NormalizeImageRef(ref string) string
- func ServerClientSPIFFE(instanceID string) string
- func WorkspaceImagePullCandidates(ref string) []string
- type AdminConfig
- type AgentConfig
- type AppleConfig
- type AuthConfig
- type BridgeTLSConfig
- type ChannelConfig
- type Config
- type ConnectItConfig
- type ContainerConfig
- type ContainerdConfig
- type DatabaseConfig
- type DockerConfig
- type InternalRPCConfig
- type LogConfig
- type OAuthClientsConfig
- type PGVectorConfig
- type PostgresConfig
- type RegistryConfig
- type ServerConfig
- type SessionRuntimeConfig
- func (c SessionRuntimeConfig) BackendLossGraceDuration() (time.Duration, error)
- func (c SessionRuntimeConfig) BackendOrDefault() string
- func (c SessionRuntimeConfig) OwnerLeaseTTLDuration() (time.Duration, error)
- func (c SessionRuntimeConfig) OwnerLeaseTTLOrDefault() string
- func (c SessionRuntimeConfig) StateTTLOrDefault() string
- func (c SessionRuntimeConfig) Validate() error
- type SessionRuntimeRedisConfig
- type SupermarketConfig
- type TelemetryConfig
- type WebhookTunnelConfig
- type WorkspaceConfig
- type WorkspaceDependenciesConfig
Constants ¶
const ( DefaultConfigPath = "config.toml" DefaultHTTPAddr = ":8080" DefaultChannelHTTPAddr = ":8081" // The internal RPC is plaintext; default to loopback so bare-metal // split deployments never expose it on all interfaces by accident. // Container deployments override this in their config template. DefaultServerRPCListenAddr = "127.0.0.1:9090" DefaultChannelRPCListenAddr = "127.0.0.1:9091" DefaultServerRPCTarget = "127.0.0.1:9090" DefaultChannelRPCTarget = "127.0.0.1:9091" DefaultNamespace = "default" DefaultSocketPath = "/run/containerd/containerd.sock" DefaultDataRoot = "data" DefaultDataMount = "/data" DefaultCNIBinaryDir = "/opt/cni/bin" DefaultCNIConfigDir = "/etc/cni/net.d" DefaultJWTExpiresIn = "24h" DefaultDatabaseDriver = "postgres" DefaultPGHost = "127.0.0.1" DefaultPGPort = 5432 DefaultPGUser = "postgres" DefaultPGDatabase = "memoh" DefaultPGSSLMode = "disable" DefaultPGVectorHost = "127.0.0.1" DefaultPGVectorPort = 5432 DefaultPGVectorUser = "memoh" DefaultPGVectorDatabase = "memoh_vector" DefaultPGVectorSSLMode = "disable" DefaultRuntimeDir = "/opt/memoh/runtime" DefaultBridgePath = DefaultRuntimeDir + "/bridge" DefaultWorkspaceImage = "memohai/workspace:debian-latest" DefaultBaseImage = DefaultWorkspaceImage DefaultWorkspaceMirrorImage = "memoh.cn/memohai/workspace:debian-latest" DefaultTimezone = "UTC" DefaultAgentToolOutputBytes = 64 * 1024 DefaultAgentToolOutputLines = 2000 DefaultAgentSystemFilesBytes = 32 * 1024 ImagePullPolicyIfNotPresent = "if_not_present" ImagePullPolicyAlways = "always" ImagePullPolicyNever = "never" )
const ( TelemetryProtocolGRPC = "grpc" TelemetryProtocolHTTP = "http" )
OTLP transports for TelemetryConfig.Protocol.
const ( BridgeTLSModeDisabled = "disabled" BridgeTLSModeStrict = "strict" )
const ( WebhookTunnelModeDisabled = "disabled" WebhookTunnelModeManaged = "managed" WebhookTunnelModeExternal = "external" )
const ( ContextLoopReselectModeActive = "active" ContextLoopReselectModeShadow = "shadow" ContextLoopReselectModeOff = "off" )
const ( SyncCompactionModeActive = "active" SyncCompactionModeShadow = "shadow" SyncCompactionModeOff = "off" )
const ( SessionRuntimeBackendMemory = "memory" SessionRuntimeBackendRedis = "redis" DefaultSessionRuntimeStateTTL = "24h" DefaultSessionRuntimeOwnerLeaseTTL = "30s" DefaultSessionRuntimeRedisURL = "redis://127.0.0.1:6379/0" DefaultSessionRuntimeRedisKeyPrefix = "memoh:session_runtime:" MinSessionRuntimeOwnerLeaseTTL = time.Second // SessionRuntimeBackendLossGraceFactor derives the default fail-closed // grace from owner_lease_ttl. Three lease periods absorbs a short blip // without letting a genuinely lost backend hold runs open indefinitely. SessionRuntimeBackendLossGraceFactor = 3 )
const ( DefaultSupermarketBaseURL = "https://supermarket.memoh.ai" DefaultOAuthClientsConfigPath = "conf/oauth-clients.toml" )
const DefaultProvidersDir = "conf/providers"
Variables ¶
This section is empty.
Functions ¶
func BridgeServerName ¶
func BridgeServerSPIFFE ¶
func NormalizeImageRef ¶
NormalizeImageRef ensures an image reference is fully qualified for containerd.
func ServerClientSPIFFE ¶
Types ¶
type AdminConfig ¶
type AgentConfig ¶
type AgentConfig struct {
ToolOutputMaxBytes int `toml:"tool_output_max_bytes"`
ToolOutputMaxLines int `toml:"tool_output_max_lines"`
SystemFilesMaxBytes int `toml:"system_files_max_bytes"`
ContextLoopReselect string `toml:"context_loop_reselect"`
// ContextAbsoluteMaxTokens is the server-wide context admission cap
// (CM-ADM-001): the effective per-turn budget is
// min(model context window − reserve, this cap), and the cap alone when
// the model has no configured window. Zero or negative selects the
// built-in default; the cap can be raised but never disabled.
ContextAbsoluteMaxTokens int `toml:"context_absolute_max_tokens"`
// SyncCompaction gates the pre-turn synchronous compaction backstop on
// the discuss and pipeline-chat paths (CM-CMP-001/003): "shadow"
// (default) logs would-have-fired decisions without blocking, "active"
// compacts synchronously before the model call at the hard threshold,
// "off" disables the backstop. The legacy history chat path keeps its
// existing always-on synchronous backstop regardless of this setting.
SyncCompaction string `toml:"sync_compaction"`
}
func (AgentConfig) EffectiveContextAbsoluteMaxTokens ¶
func (c AgentConfig) EffectiveContextAbsoluteMaxTokens() int
EffectiveContextAbsoluteMaxTokens resolves the server-wide context admission cap, falling back to the shared default when unset.
func (AgentConfig) EffectiveContextLoopReselectMode ¶
func (c AgentConfig) EffectiveContextLoopReselectMode() (mode string, recognized bool)
EffectiveContextLoopReselectMode normalizes the configured in-loop context step reselector rollout mode. Empty defaults to active. recognized is false when a non-empty value does not match active/shadow/off.
func (AgentConfig) EffectiveSyncCompactionMode ¶ added in v0.20.0
func (c AgentConfig) EffectiveSyncCompactionMode() (mode string, recognized bool)
EffectiveSyncCompactionMode normalizes the pre-turn synchronous compaction rollout mode. Empty defaults to shadow (observe before enforcing, per the CM-CMP-003 rollout gate). recognized is false when a non-empty value does not match active/shadow/off.
type AppleConfig ¶
type AuthConfig ¶
type BridgeTLSConfig ¶
type BridgeTLSConfig struct {
Mode string `toml:"mode"`
ServerDir string `toml:"server_dir"`
BridgeDir string `toml:"bridge_dir"`
ServerName string `toml:"server_name"`
}
BridgeTLSConfig controls mTLS for Memoh server -> workspace bridge TCP gRPC. Strict mode never falls back to plaintext. UDS/local targets are unaffected.
func (BridgeTLSConfig) EffectiveMode ¶
func (c BridgeTLSConfig) EffectiveMode() string
func (BridgeTLSConfig) Strict ¶
func (c BridgeTLSConfig) Strict() bool
type ChannelConfig ¶
type Config ¶
type Config struct {
Log LogConfig `toml:"log"`
Server ServerConfig `toml:"server"`
Channel ChannelConfig `toml:"channel"`
InternalRPC InternalRPCConfig `toml:"internal_rpc"`
Admin AdminConfig `toml:"admin"`
Auth AuthConfig `toml:"auth"`
Agent AgentConfig `toml:"agent"`
Timezone string `toml:"timezone"`
Database DatabaseConfig `toml:"database"`
Container ContainerConfig `toml:"container"`
Containerd ContainerdConfig `toml:"containerd"`
Docker DockerConfig `toml:"docker"`
Apple AppleConfig `toml:"apple"`
Workspace WorkspaceConfig `toml:"workspace"`
Postgres PostgresConfig `toml:"postgres"`
PGVector PGVectorConfig `toml:"pgvector"`
Registry RegistryConfig `toml:"registry"`
Supermarket SupermarketConfig `toml:"supermarket"`
WorkspaceDependencies WorkspaceDependenciesConfig `toml:"workspace_dependencies"`
OAuthClients OAuthClientsConfig `toml:"oauth_clients"`
SessionRuntime SessionRuntimeConfig `toml:"session_runtime"`
InstanceID string `toml:"instance_id"`
BridgeTLS BridgeTLSConfig `toml:"bridge_tls"`
WebhookTunnel WebhookTunnelConfig `toml:"webhook_tunnel"`
ConnectIt ConnectItConfig `toml:"connect_it"`
Telemetry TelemetryConfig `toml:"telemetry"`
}
func (Config) SplitChannelRuntime ¶
SplitChannelRuntime reports whether the channel runtime runs as a separate process reached over the internal RPC. Setting the shared secret opts into split mode (docker compose does); without it the server embeds the full channel runtime, preserving the pre-split all-in-one deployment for existing configs.
func (Config) ValidateChannelRuntime ¶
ValidateChannelRuntime validates the settings required by the Channel process.
func (Config) ValidateServerRuntime ¶
ValidateServerRuntime validates the settings required by the Server process. It is intentionally separate from Load so migration commands do not require runtime-to-runtime credentials.
type ConnectItConfig ¶
type ConnectItConfig struct {
BaseURL string `toml:"base_url"`
APIToken string `toml:"api_token" json:"-"`
}
ConnectItConfig is the deployment-level credential Memoh uses to call its trusted Connect-It instance. It is never persisted in bot configuration.
func (ConnectItConfig) Configured ¶
func (c ConnectItConfig) Configured() bool
func (ConnectItConfig) Validate ¶
func (c ConnectItConfig) Validate() error
type ContainerConfig ¶
type ContainerConfig struct {
Backend string `toml:"backend"`
WorkspaceConfig
}
type ContainerdConfig ¶
type DatabaseConfig ¶
type DatabaseConfig struct {
Driver string `toml:"driver"`
}
func (DatabaseConfig) DriverOrDefault ¶
func (c DatabaseConfig) DriverOrDefault() string
type DockerConfig ¶
type InternalRPCConfig ¶
type InternalRPCConfig struct {
ServerTarget string `toml:"server_target"`
ChannelTarget string `toml:"channel_target"`
}
func (InternalRPCConfig) Validate ¶
func (c InternalRPCConfig) Validate() error
type OAuthClientsConfig ¶
type OAuthClientsConfig struct {
ConfigPath string `toml:"config_path"`
}
func (OAuthClientsConfig) Path ¶
func (c OAuthClientsConfig) Path() string
type PGVectorConfig ¶
type PGVectorConfig struct {
Enabled bool `toml:"enabled"`
Host string `toml:"host"`
Port int `toml:"port"`
User string `toml:"user"`
Password string `toml:"password" json:"-"`
Database string `toml:"database"`
SSLMode string `toml:"sslmode"`
}
func (PGVectorConfig) PostgresConfig ¶
func (c PGVectorConfig) PostgresConfig() PostgresConfig
type PostgresConfig ¶
type RegistryConfig ¶
type RegistryConfig struct {
ProvidersDir string `toml:"providers_dir"`
}
func (RegistryConfig) ProvidersPath ¶
func (c RegistryConfig) ProvidersPath() string
ProvidersPath returns the configured providers directory or the default.
type ServerConfig ¶
type SessionRuntimeConfig ¶
type SessionRuntimeConfig struct {
Backend string `toml:"backend"`
// Cluster declares that more than one server instance shares this
// deployment. It is a topology statement rather than a tuning value: no
// process can infer how many peers it has, and SR-DEP-001 requires
// refusing multi-instance mode without a shared live backend.
Cluster bool `toml:"cluster"`
StateTTL string `toml:"state_ttl"`
OwnerLeaseTTL string `toml:"owner_lease_ttl"`
// BackendLossGrace is how long to wait after observing a new live backend
// generation before the fail-closed sweep marks stale runs lost. This is
// the budget for a Redis restart or failover, which varies by deployment
// and cannot be derived from anything the server knows. Empty derives
// SessionRuntimeBackendLossGraceFactor x OwnerLeaseTTL.
BackendLossGrace string `toml:"backend_loss_grace"`
Redis SessionRuntimeRedisConfig `toml:"redis"`
}
SessionRuntimeConfig exposes only the values that depend on something the process cannot observe. Every other timing in the session runtime is derived from OwnerLeaseTTL or is a package constant in the sessionruntime package; see docs and internal/agent/runtime/session/tuning.go.
func (SessionRuntimeConfig) BackendLossGraceDuration ¶
func (c SessionRuntimeConfig) BackendLossGraceDuration() (time.Duration, error)
BackendLossGraceDuration returns the configured grace, or the derived default when unset. A grace shorter than one lease period would start the sweep while a healthy owner could still be renewing, so it is rejected.
func (SessionRuntimeConfig) BackendOrDefault ¶
func (c SessionRuntimeConfig) BackendOrDefault() string
func (SessionRuntimeConfig) OwnerLeaseTTLDuration ¶
func (c SessionRuntimeConfig) OwnerLeaseTTLDuration() (time.Duration, error)
OwnerLeaseTTLDuration is the single tuning dial for the session runtime. It paces owner lease renewal, the reaper tick, the reaper leader lease and the orphan grace, so it matters on both backends: with a memory backend there is no cross-process lease, but the reaper still runs.
func (SessionRuntimeConfig) OwnerLeaseTTLOrDefault ¶
func (c SessionRuntimeConfig) OwnerLeaseTTLOrDefault() string
func (SessionRuntimeConfig) StateTTLOrDefault ¶
func (c SessionRuntimeConfig) StateTTLOrDefault() string
func (SessionRuntimeConfig) Validate ¶
func (c SessionRuntimeConfig) Validate() error
type SessionRuntimeRedisConfig ¶
type SessionRuntimeRedisConfig struct {
URL string `toml:"url"`
KeyPrefix string `toml:"key_prefix"`
}
func (SessionRuntimeRedisConfig) KeyPrefixOrDefault ¶
func (c SessionRuntimeRedisConfig) KeyPrefixOrDefault() string
func (SessionRuntimeRedisConfig) URLOrDefault ¶
func (c SessionRuntimeRedisConfig) URLOrDefault() string
type SupermarketConfig ¶
type SupermarketConfig struct {
BaseURL string `toml:"base_url"`
}
func (SupermarketConfig) GetBaseURL ¶
func (c SupermarketConfig) GetBaseURL() string
type TelemetryConfig ¶ added in v0.21.0
type TelemetryConfig struct {
// Endpoint is an OTLP collector address: host:port for grpc, or a URL for
// http. Empty disables export.
Endpoint string `toml:"endpoint"`
// Protocol is "grpc" (default) or "http".
Protocol string `toml:"protocol"`
// Insecure sends over plaintext. Required for an http:// endpoint or a
// grpc collector without TLS.
Insecure bool `toml:"insecure"`
// Headers are sent with every export, for collectors that authenticate.
Headers map[string]string `toml:"headers"`
// SampleRatio is the fraction of traces started here that are recorded,
// between 0 and 1; 1 records every trace. A sampling decision already made
// upstream is always respected, so this applies to traces this process
// starts. Defaults to 1: a self-hosted deployment small enough to need no
// collector tuning should not have to discover why its traces are missing.
SampleRatio float64 `toml:"sample_ratio"`
// ServiceName overrides the reported service.name. Empty uses the name the
// binary registers at startup.
ServiceName string `toml:"service_name"`
}
TelemetryConfig configures OpenTelemetry trace and metric export. It is off unless an endpoint is set, here or through the standard OTEL_EXPORTER_OTLP_ENDPOINT / OTEL_EXPORTER_OTLP_TRACES_ENDPOINT variables. Metrics go to the same collector; OTEL_METRICS_EXPORTER=none turns them off and leaves traces on.
"Off" has to mean no exporter at all rather than an exporter pointed somewhere harmless: the OTLP SDK defaults an unset endpoint to localhost:4317, so a build that always constructs one would spend every deployment without a collector retrying a connection that cannot succeed.
func (TelemetryConfig) Enabled ¶ added in v0.21.0
func (c TelemetryConfig) Enabled() bool
Enabled reports whether OTLP export should be configured.
type WebhookTunnelConfig ¶
type WebhookTunnelConfig struct {
Mode string `toml:"mode"`
PublicBaseURL string `toml:"public_base_url"`
ListenAddr string `toml:"listen_addr"`
CloudflaredPath string `toml:"cloudflared_path"`
TargetURL string `toml:"target_url"`
MetricsAddr string `toml:"metrics_addr"`
MetricsURL string `toml:"metrics_url"`
}
func (WebhookTunnelConfig) EffectiveMode ¶
func (c WebhookTunnelConfig) EffectiveMode() string
func (WebhookTunnelConfig) Validate ¶
func (c WebhookTunnelConfig) Validate() error
type WorkspaceConfig ¶
type WorkspaceConfig struct {
Registry string `toml:"registry"`
DefaultImage string `toml:"default_image"`
ImagePullPolicy string `toml:"image_pull_policy"`
Snapshotter string `toml:"snapshotter"`
DataRoot string `toml:"data_root"`
CNIBinaryDir string `toml:"cni_bin_dir"`
CNIConfigDir string `toml:"cni_conf_dir"`
BridgePath string `toml:"bridge_path"`
// RuntimeDir is accepted for one compatibility release. New deployments
// should configure bridge_path because the Server no longer owns a toolkit
// or workspace templates directory.
RuntimeDir string `toml:"runtime_dir"`
}
func (WorkspaceConfig) BridgeBinaryPath ¶
func (c WorkspaceConfig) BridgeBinaryPath() string
BridgeBinaryPath returns the host path mounted read-only into native workspace containers. runtime_dir remains a compatibility fallback.
func (WorkspaceConfig) DataRootPath ¶
func (c WorkspaceConfig) DataRootPath() string
func (WorkspaceConfig) EffectiveImagePullPolicy ¶
func (c WorkspaceConfig) EffectiveImagePullPolicy() string
func (WorkspaceConfig) ImageRef ¶
func (c WorkspaceConfig) ImageRef() string
ImageRef returns the fully qualified image reference for the base image, prepending the registry mirror when configured and normalizing for containerd compatibility.
func (WorkspaceConfig) RuntimePath ¶
func (c WorkspaceConfig) RuntimePath() string
RuntimePath returns the path to the workspace runtime directory.
type WorkspaceDependenciesConfig ¶ added in v0.20.0
type WorkspaceDependenciesConfig struct {
Offline bool `toml:"offline"`
CatalogRefreshIntervalSeconds int `toml:"catalog_refresh_interval_seconds"`
UpdateCheckIntervalSeconds int `toml:"update_check_interval_seconds"`
ReapIntervalSeconds int `toml:"reap_interval_seconds"`
DiscoveryCacheTTLSeconds int `toml:"discovery_cache_ttl_seconds"`
// ScriptEnv overrides recipe download mirrors. Only NODEJS_MIRROR,
// UV_RELEASES_URL, NPM_MIRROR, and UV_PYTHON_INSTALL_MIRROR are accepted.
ScriptEnv map[string]string `toml:"script_env"`
}
WorkspaceDependenciesConfig controls maintenance of the persisted dependency catalog and workspace observations. Offline disables automatic upstream work; cached definitions and installed workspace commands remain available.
func (WorkspaceDependenciesConfig) CatalogRefreshInterval ¶ added in v0.20.0
func (c WorkspaceDependenciesConfig) CatalogRefreshInterval() time.Duration
func (WorkspaceDependenciesConfig) DiscoveryCacheTTL ¶ added in v0.20.0
func (c WorkspaceDependenciesConfig) DiscoveryCacheTTL() time.Duration
func (WorkspaceDependenciesConfig) ReapInterval ¶ added in v0.20.0
func (c WorkspaceDependenciesConfig) ReapInterval() time.Duration
func (WorkspaceDependenciesConfig) UpdateCheckInterval ¶ added in v0.20.0
func (c WorkspaceDependenciesConfig) UpdateCheckInterval() time.Duration