config

package
v0.21.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: AGPL-3.0 Imports: 10 Imported by: 0

Documentation

Index

Constants

View Source
const (
	DefaultConfigPath      = "config.toml"
	DefaultHTTPAddr        = ":8080"
	DefaultChannelHTTPAddr = ":8081"
	// The internal RPC is plaintext; default to loopback so bare-metal
	// split deployments never expose it on all interfaces by accident.
	// Container deployments override this in their config template.
	DefaultServerRPCListenAddr   = "127.0.0.1:9090"
	DefaultChannelRPCListenAddr  = "127.0.0.1:9091"
	DefaultServerRPCTarget       = "127.0.0.1:9090"
	DefaultChannelRPCTarget      = "127.0.0.1:9091"
	DefaultNamespace             = "default"
	DefaultSocketPath            = "/run/containerd/containerd.sock"
	DefaultDataRoot              = "data"
	DefaultDataMount             = "/data"
	DefaultCNIBinaryDir          = "/opt/cni/bin"
	DefaultCNIConfigDir          = "/etc/cni/net.d"
	DefaultJWTExpiresIn          = "24h"
	DefaultDatabaseDriver        = "postgres"
	DefaultPGHost                = "127.0.0.1"
	DefaultPGPort                = 5432
	DefaultPGUser                = "postgres"
	DefaultPGDatabase            = "memoh"
	DefaultPGSSLMode             = "disable"
	DefaultPGVectorHost          = "127.0.0.1"
	DefaultPGVectorPort          = 5432
	DefaultPGVectorUser          = "memoh"
	DefaultPGVectorDatabase      = "memoh_vector"
	DefaultPGVectorSSLMode       = "disable"
	DefaultRuntimeDir            = "/opt/memoh/runtime"
	DefaultBridgePath            = DefaultRuntimeDir + "/bridge"
	DefaultWorkspaceImage        = "memohai/workspace:debian-latest"
	DefaultBaseImage             = DefaultWorkspaceImage
	DefaultWorkspaceMirrorImage  = "memoh.cn/memohai/workspace:debian-latest"
	DefaultTimezone              = "UTC"
	DefaultAgentToolOutputBytes  = 64 * 1024
	DefaultAgentToolOutputLines  = 2000
	DefaultAgentSystemFilesBytes = 32 * 1024

	ImagePullPolicyIfNotPresent = "if_not_present"
	ImagePullPolicyAlways       = "always"
	ImagePullPolicyNever        = "never"
)
View Source
const (
	TelemetryProtocolGRPC = "grpc"
	TelemetryProtocolHTTP = "http"
)

OTLP transports for TelemetryConfig.Protocol.

View Source
const (
	BridgeTLSModeDisabled = "disabled"
	BridgeTLSModeStrict   = "strict"
)
View Source
const (
	WebhookTunnelModeDisabled = "disabled"
	WebhookTunnelModeManaged  = "managed"
	WebhookTunnelModeExternal = "external"
)
View Source
const (
	ContextLoopReselectModeActive = "active"
	ContextLoopReselectModeShadow = "shadow"
	ContextLoopReselectModeOff    = "off"
)
View Source
const (
	SyncCompactionModeActive = "active"
	SyncCompactionModeShadow = "shadow"
	SyncCompactionModeOff    = "off"
)
View Source
const (
	SessionRuntimeBackendMemory = "memory"
	SessionRuntimeBackendRedis  = "redis"

	DefaultSessionRuntimeStateTTL       = "24h"
	DefaultSessionRuntimeOwnerLeaseTTL  = "30s"
	DefaultSessionRuntimeRedisURL       = "redis://127.0.0.1:6379/0"
	DefaultSessionRuntimeRedisKeyPrefix = "memoh:session_runtime:"
	MinSessionRuntimeOwnerLeaseTTL      = time.Second

	// SessionRuntimeBackendLossGraceFactor derives the default fail-closed
	// grace from owner_lease_ttl. Three lease periods absorbs a short blip
	// without letting a genuinely lost backend hold runs open indefinitely.
	SessionRuntimeBackendLossGraceFactor = 3
)
View Source
const (
	DefaultSupermarketBaseURL     = "https://supermarket.memoh.ai"
	DefaultOAuthClientsConfigPath = "conf/oauth-clients.toml"
)
View Source
const DefaultProvidersDir = "conf/providers"

Variables

This section is empty.

Functions

func BridgeServerName

func BridgeServerName(instanceID string) string

func BridgeServerSPIFFE

func BridgeServerSPIFFE(instanceID string) string

func NormalizeImageRef

func NormalizeImageRef(ref string) string

NormalizeImageRef ensures an image reference is fully qualified for containerd.

func ServerClientSPIFFE

func ServerClientSPIFFE(instanceID string) string

func WorkspaceImagePullCandidates

func WorkspaceImagePullCandidates(ref string) []string

Types

type AdminConfig

type AdminConfig struct {
	Username string `toml:"username"`
	Password string `toml:"password" json:"-"`
	Email    string `toml:"email"`
}

type AgentConfig

type AgentConfig struct {
	ToolOutputMaxBytes  int    `toml:"tool_output_max_bytes"`
	ToolOutputMaxLines  int    `toml:"tool_output_max_lines"`
	SystemFilesMaxBytes int    `toml:"system_files_max_bytes"`
	ContextLoopReselect string `toml:"context_loop_reselect"`
	// ContextAbsoluteMaxTokens is the server-wide context admission cap
	// (CM-ADM-001): the effective per-turn budget is
	// min(model context window − reserve, this cap), and the cap alone when
	// the model has no configured window. Zero or negative selects the
	// built-in default; the cap can be raised but never disabled.
	ContextAbsoluteMaxTokens int `toml:"context_absolute_max_tokens"`
	// SyncCompaction gates the pre-turn synchronous compaction backstop on
	// the discuss and pipeline-chat paths (CM-CMP-001/003): "shadow"
	// (default) logs would-have-fired decisions without blocking, "active"
	// compacts synchronously before the model call at the hard threshold,
	// "off" disables the backstop. The legacy history chat path keeps its
	// existing always-on synchronous backstop regardless of this setting.
	SyncCompaction string `toml:"sync_compaction"`
}

func (AgentConfig) EffectiveContextAbsoluteMaxTokens

func (c AgentConfig) EffectiveContextAbsoluteMaxTokens() int

EffectiveContextAbsoluteMaxTokens resolves the server-wide context admission cap, falling back to the shared default when unset.

func (AgentConfig) EffectiveContextLoopReselectMode

func (c AgentConfig) EffectiveContextLoopReselectMode() (mode string, recognized bool)

EffectiveContextLoopReselectMode normalizes the configured in-loop context step reselector rollout mode. Empty defaults to active. recognized is false when a non-empty value does not match active/shadow/off.

func (AgentConfig) EffectiveSyncCompactionMode added in v0.20.0

func (c AgentConfig) EffectiveSyncCompactionMode() (mode string, recognized bool)

EffectiveSyncCompactionMode normalizes the pre-turn synchronous compaction rollout mode. Empty defaults to shadow (observe before enforcing, per the CM-CMP-003 rollout gate). recognized is false when a non-empty value does not match active/shadow/off.

type AppleConfig

type AppleConfig struct {
	SocketPath string `toml:"socket_path"`
	BinaryPath string `toml:"binary_path"`
}

type AuthConfig

type AuthConfig struct {
	JWTSecret                     string `toml:"jwt_secret"                       json:"-"`
	JWTExpiresIn                  string `toml:"jwt_expires_in"`
	AgentCredentialsEncryptionKey string `toml:"agent_credentials_encryption_key" json:"-"`
}

type BridgeTLSConfig

type BridgeTLSConfig struct {
	Mode       string `toml:"mode"`
	ServerDir  string `toml:"server_dir"`
	BridgeDir  string `toml:"bridge_dir"`
	ServerName string `toml:"server_name"`
}

BridgeTLSConfig controls mTLS for Memoh server -> workspace bridge TCP gRPC. Strict mode never falls back to plaintext. UDS/local targets are unaffected.

func (BridgeTLSConfig) EffectiveMode

func (c BridgeTLSConfig) EffectiveMode() string

func (BridgeTLSConfig) Strict

func (c BridgeTLSConfig) Strict() bool

type ChannelConfig

type ChannelConfig struct {
	Addr          string `toml:"addr"`
	RPCListenAddr string `toml:"rpc_listen_addr"`
}

type Config

type Config struct {
	Log                   LogConfig                   `toml:"log"`
	Server                ServerConfig                `toml:"server"`
	Channel               ChannelConfig               `toml:"channel"`
	InternalRPC           InternalRPCConfig           `toml:"internal_rpc"`
	Admin                 AdminConfig                 `toml:"admin"`
	Auth                  AuthConfig                  `toml:"auth"`
	Agent                 AgentConfig                 `toml:"agent"`
	Timezone              string                      `toml:"timezone"`
	Database              DatabaseConfig              `toml:"database"`
	Container             ContainerConfig             `toml:"container"`
	Containerd            ContainerdConfig            `toml:"containerd"`
	Docker                DockerConfig                `toml:"docker"`
	Apple                 AppleConfig                 `toml:"apple"`
	Workspace             WorkspaceConfig             `toml:"workspace"`
	Postgres              PostgresConfig              `toml:"postgres"`
	PGVector              PGVectorConfig              `toml:"pgvector"`
	Registry              RegistryConfig              `toml:"registry"`
	Supermarket           SupermarketConfig           `toml:"supermarket"`
	WorkspaceDependencies WorkspaceDependenciesConfig `toml:"workspace_dependencies"`
	OAuthClients          OAuthClientsConfig          `toml:"oauth_clients"`
	SessionRuntime        SessionRuntimeConfig        `toml:"session_runtime"`
	InstanceID            string                      `toml:"instance_id"`
	BridgeTLS             BridgeTLSConfig             `toml:"bridge_tls"`
	WebhookTunnel         WebhookTunnelConfig         `toml:"webhook_tunnel"`
	ConnectIt             ConnectItConfig             `toml:"connect_it"`
	Telemetry             TelemetryConfig             `toml:"telemetry"`
}

func Load

func Load(path string) (Config, error)

func (Config) SplitChannelRuntime

func (cfg Config) SplitChannelRuntime() bool

SplitChannelRuntime reports whether the channel runtime runs as a separate process reached over the internal RPC. Setting the shared secret opts into split mode (docker compose does); without it the server embeds the full channel runtime, preserving the pre-split all-in-one deployment for existing configs.

func (Config) ValidateChannelRuntime

func (cfg Config) ValidateChannelRuntime() error

ValidateChannelRuntime validates the settings required by the Channel process.

func (Config) ValidateServerRuntime

func (cfg Config) ValidateServerRuntime() error

ValidateServerRuntime validates the settings required by the Server process. It is intentionally separate from Load so migration commands do not require runtime-to-runtime credentials.

type ConnectItConfig

type ConnectItConfig struct {
	BaseURL  string `toml:"base_url"`
	APIToken string `toml:"api_token" json:"-"`
}

ConnectItConfig is the deployment-level credential Memoh uses to call its trusted Connect-It instance. It is never persisted in bot configuration.

func (ConnectItConfig) Configured

func (c ConnectItConfig) Configured() bool

func (ConnectItConfig) Validate

func (c ConnectItConfig) Validate() error

type ContainerConfig

type ContainerConfig struct {
	Backend string `toml:"backend"`
	WorkspaceConfig
}

type ContainerdConfig

type ContainerdConfig struct {
	SocketPath string `toml:"socket_path"`
	Namespace  string `toml:"namespace"`
}

type DatabaseConfig

type DatabaseConfig struct {
	Driver string `toml:"driver"`
}

func (DatabaseConfig) DriverOrDefault

func (c DatabaseConfig) DriverOrDefault() string

type DockerConfig

type DockerConfig struct {
	Host            string `toml:"host"`
	Network         string `toml:"network"`
	ServerContainer string `toml:"server_container"`
}

type InternalRPCConfig

type InternalRPCConfig struct {
	ServerTarget  string `toml:"server_target"`
	ChannelTarget string `toml:"channel_target"`
	SharedSecret  string `toml:"shared_secret" json:"-"`
}

func (InternalRPCConfig) Validate

func (c InternalRPCConfig) Validate() error

type LogConfig

type LogConfig struct {
	Level  string `toml:"level"`
	Format string `toml:"format"`
}

type OAuthClientsConfig

type OAuthClientsConfig struct {
	ConfigPath string `toml:"config_path"`
}

func (OAuthClientsConfig) Path

func (c OAuthClientsConfig) Path() string

type PGVectorConfig

type PGVectorConfig struct {
	Enabled  bool   `toml:"enabled"`
	Host     string `toml:"host"`
	Port     int    `toml:"port"`
	User     string `toml:"user"`
	Password string `toml:"password" json:"-"`
	Database string `toml:"database"`
	SSLMode  string `toml:"sslmode"`
}

func (PGVectorConfig) PostgresConfig

func (c PGVectorConfig) PostgresConfig() PostgresConfig

type PostgresConfig

type PostgresConfig struct {
	Host     string `toml:"host"`
	Port     int    `toml:"port"`
	User     string `toml:"user"`
	Password string `toml:"password" json:"-"`
	Database string `toml:"database"`
	SSLMode  string `toml:"sslmode"`
}

type RegistryConfig

type RegistryConfig struct {
	ProvidersDir string `toml:"providers_dir"`
}

func (RegistryConfig) ProvidersPath

func (c RegistryConfig) ProvidersPath() string

ProvidersPath returns the configured providers directory or the default.

type ServerConfig

type ServerConfig struct {
	PublicURL     string `toml:"public_url"`
	Addr          string `toml:"addr"`
	RPCListenAddr string `toml:"rpc_listen_addr"`
}

type SessionRuntimeConfig

type SessionRuntimeConfig struct {
	Backend string `toml:"backend"`
	// Cluster declares that more than one server instance shares this
	// deployment. It is a topology statement rather than a tuning value: no
	// process can infer how many peers it has, and SR-DEP-001 requires
	// refusing multi-instance mode without a shared live backend.
	Cluster       bool   `toml:"cluster"`
	StateTTL      string `toml:"state_ttl"`
	OwnerLeaseTTL string `toml:"owner_lease_ttl"`
	// BackendLossGrace is how long to wait after observing a new live backend
	// generation before the fail-closed sweep marks stale runs lost. This is
	// the budget for a Redis restart or failover, which varies by deployment
	// and cannot be derived from anything the server knows. Empty derives
	// SessionRuntimeBackendLossGraceFactor x OwnerLeaseTTL.
	BackendLossGrace string                    `toml:"backend_loss_grace"`
	Redis            SessionRuntimeRedisConfig `toml:"redis"`
}

SessionRuntimeConfig exposes only the values that depend on something the process cannot observe. Every other timing in the session runtime is derived from OwnerLeaseTTL or is a package constant in the sessionruntime package; see docs and internal/agent/runtime/session/tuning.go.

func (SessionRuntimeConfig) BackendLossGraceDuration

func (c SessionRuntimeConfig) BackendLossGraceDuration() (time.Duration, error)

BackendLossGraceDuration returns the configured grace, or the derived default when unset. A grace shorter than one lease period would start the sweep while a healthy owner could still be renewing, so it is rejected.

func (SessionRuntimeConfig) BackendOrDefault

func (c SessionRuntimeConfig) BackendOrDefault() string

func (SessionRuntimeConfig) OwnerLeaseTTLDuration

func (c SessionRuntimeConfig) OwnerLeaseTTLDuration() (time.Duration, error)

OwnerLeaseTTLDuration is the single tuning dial for the session runtime. It paces owner lease renewal, the reaper tick, the reaper leader lease and the orphan grace, so it matters on both backends: with a memory backend there is no cross-process lease, but the reaper still runs.

func (SessionRuntimeConfig) OwnerLeaseTTLOrDefault

func (c SessionRuntimeConfig) OwnerLeaseTTLOrDefault() string

func (SessionRuntimeConfig) StateTTLOrDefault

func (c SessionRuntimeConfig) StateTTLOrDefault() string

func (SessionRuntimeConfig) Validate

func (c SessionRuntimeConfig) Validate() error

type SessionRuntimeRedisConfig

type SessionRuntimeRedisConfig struct {
	URL       string `toml:"url"`
	KeyPrefix string `toml:"key_prefix"`
}

func (SessionRuntimeRedisConfig) KeyPrefixOrDefault

func (c SessionRuntimeRedisConfig) KeyPrefixOrDefault() string

func (SessionRuntimeRedisConfig) URLOrDefault

func (c SessionRuntimeRedisConfig) URLOrDefault() string

type SupermarketConfig

type SupermarketConfig struct {
	BaseURL string `toml:"base_url"`
}

func (SupermarketConfig) GetBaseURL

func (c SupermarketConfig) GetBaseURL() string

type TelemetryConfig added in v0.21.0

type TelemetryConfig struct {
	// Endpoint is an OTLP collector address: host:port for grpc, or a URL for
	// http. Empty disables export.
	Endpoint string `toml:"endpoint"`
	// Protocol is "grpc" (default) or "http".
	Protocol string `toml:"protocol"`
	// Insecure sends over plaintext. Required for an http:// endpoint or a
	// grpc collector without TLS.
	Insecure bool `toml:"insecure"`
	// Headers are sent with every export, for collectors that authenticate.
	Headers map[string]string `toml:"headers"`
	// SampleRatio is the fraction of traces started here that are recorded,
	// between 0 and 1; 1 records every trace. A sampling decision already made
	// upstream is always respected, so this applies to traces this process
	// starts. Defaults to 1: a self-hosted deployment small enough to need no
	// collector tuning should not have to discover why its traces are missing.
	SampleRatio float64 `toml:"sample_ratio"`
	// ServiceName overrides the reported service.name. Empty uses the name the
	// binary registers at startup.
	ServiceName string `toml:"service_name"`
}

TelemetryConfig configures OpenTelemetry trace and metric export. It is off unless an endpoint is set, here or through the standard OTEL_EXPORTER_OTLP_ENDPOINT / OTEL_EXPORTER_OTLP_TRACES_ENDPOINT variables. Metrics go to the same collector; OTEL_METRICS_EXPORTER=none turns them off and leaves traces on.

"Off" has to mean no exporter at all rather than an exporter pointed somewhere harmless: the OTLP SDK defaults an unset endpoint to localhost:4317, so a build that always constructs one would spend every deployment without a collector retrying a connection that cannot succeed.

func (TelemetryConfig) Enabled added in v0.21.0

func (c TelemetryConfig) Enabled() bool

Enabled reports whether OTLP export should be configured.

type WebhookTunnelConfig

type WebhookTunnelConfig struct {
	Mode            string `toml:"mode"`
	PublicBaseURL   string `toml:"public_base_url"`
	ListenAddr      string `toml:"listen_addr"`
	CloudflaredPath string `toml:"cloudflared_path"`
	TargetURL       string `toml:"target_url"`
	MetricsAddr     string `toml:"metrics_addr"`
	MetricsURL      string `toml:"metrics_url"`
}

func (WebhookTunnelConfig) EffectiveMode

func (c WebhookTunnelConfig) EffectiveMode() string

func (WebhookTunnelConfig) Validate

func (c WebhookTunnelConfig) Validate() error

type WorkspaceConfig

type WorkspaceConfig struct {
	Registry        string `toml:"registry"`
	DefaultImage    string `toml:"default_image"`
	ImagePullPolicy string `toml:"image_pull_policy"`
	Snapshotter     string `toml:"snapshotter"`
	DataRoot        string `toml:"data_root"`
	CNIBinaryDir    string `toml:"cni_bin_dir"`
	CNIConfigDir    string `toml:"cni_conf_dir"`
	BridgePath      string `toml:"bridge_path"`
	// RuntimeDir is accepted for one compatibility release. New deployments
	// should configure bridge_path because the Server no longer owns a toolkit
	// or workspace templates directory.
	RuntimeDir string `toml:"runtime_dir"`
}

func (WorkspaceConfig) BridgeBinaryPath

func (c WorkspaceConfig) BridgeBinaryPath() string

BridgeBinaryPath returns the host path mounted read-only into native workspace containers. runtime_dir remains a compatibility fallback.

func (WorkspaceConfig) DataRootPath

func (c WorkspaceConfig) DataRootPath() string

func (WorkspaceConfig) EffectiveImagePullPolicy

func (c WorkspaceConfig) EffectiveImagePullPolicy() string

func (WorkspaceConfig) ImageRef

func (c WorkspaceConfig) ImageRef() string

ImageRef returns the fully qualified image reference for the base image, prepending the registry mirror when configured and normalizing for containerd compatibility.

func (WorkspaceConfig) RuntimePath

func (c WorkspaceConfig) RuntimePath() string

RuntimePath returns the path to the workspace runtime directory.

type WorkspaceDependenciesConfig added in v0.20.0

type WorkspaceDependenciesConfig struct {
	Offline                       bool `toml:"offline"`
	CatalogRefreshIntervalSeconds int  `toml:"catalog_refresh_interval_seconds"`
	UpdateCheckIntervalSeconds    int  `toml:"update_check_interval_seconds"`
	ReapIntervalSeconds           int  `toml:"reap_interval_seconds"`
	DiscoveryCacheTTLSeconds      int  `toml:"discovery_cache_ttl_seconds"`
	// ScriptEnv overrides recipe download mirrors. Only NODEJS_MIRROR,
	// UV_RELEASES_URL, NPM_MIRROR, and UV_PYTHON_INSTALL_MIRROR are accepted.
	ScriptEnv map[string]string `toml:"script_env"`
}

WorkspaceDependenciesConfig controls maintenance of the persisted dependency catalog and workspace observations. Offline disables automatic upstream work; cached definitions and installed workspace commands remain available.

func (WorkspaceDependenciesConfig) CatalogRefreshInterval added in v0.20.0

func (c WorkspaceDependenciesConfig) CatalogRefreshInterval() time.Duration

func (WorkspaceDependenciesConfig) DiscoveryCacheTTL added in v0.20.0

func (c WorkspaceDependenciesConfig) DiscoveryCacheTTL() time.Duration

func (WorkspaceDependenciesConfig) ReapInterval added in v0.20.0

func (c WorkspaceDependenciesConfig) ReapInterval() time.Duration

func (WorkspaceDependenciesConfig) UpdateCheckInterval added in v0.20.0

func (c WorkspaceDependenciesConfig) UpdateCheckInterval() time.Duration

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL