Documentation
¶
Index ¶
- func FindConfigPath(providedPath string) string
- func Save(cfg *Config, path string) error
- func Set(cfg *Config, key string, raw interface{}) error
- type AIConfig
- type APIConfig
- type AuditConfig
- type AuthConfig
- type BackupConfig
- type BackupDestination
- type CapacityConfig
- type CertbotConfig
- type CleanupConfig
- type ClusterConfig
- type Config
- type DomainConfig
- type Entry
- type FilesConfig
- type HealthConfig
- type InfrastructureConfig
- type K3sConfig
- type LoggingConfig
- type MCPConfig
- type NginxConfig
- type PlansConfig
- type PowerDNSConfig
- type SecurityConfig
- type ServiceExecConfig
- type SharedDatabaseConfig
- type SharedRedisConfig
- type SystemTerminalConfig
- type TemplatesConfig
- type TemplatesGitHubConfig
- type TemplatesMarketplaceConfig
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func FindConfigPath ¶ added in v0.1.5
Types ¶
type AIConfig ¶ added in v0.3.0
type AIConfig struct {
Enabled bool `yaml:"enabled" json:"enabled"`
BaseURL string `yaml:"base_url" json:"base_url"`
APIKey string `yaml:"api_key" json:"api_key"`
Model string `yaml:"model" json:"model"`
Timeout time.Duration `yaml:"timeout" json:"timeout"`
DocsURL string `yaml:"docs_url" json:"docs_url"`
// TriageDailyCap bounds the log incidents a day the assistant may be asked to explain.
// Triage runs unattended, so it gets a ceiling that operator-initiated chat does not need.
TriageDailyCap int `yaml:"triage_daily_cap" json:"triage_daily_cap"`
}
type AuditConfig ¶ added in v0.1.5
type AuditConfig struct {
Enabled bool `yaml:"enabled" json:"enabled"`
RetentionDays int `yaml:"retention_days" json:"retention_days"`
CaptureRequestBody bool `yaml:"capture_request_body" json:"capture_request_body"`
ExcludedPaths []string `yaml:"excluded_paths" json:"excluded_paths"`
SensitiveFields []string `yaml:"sensitive_fields" json:"sensitive_fields"`
CleanupInterval time.Duration `yaml:"cleanup_interval" json:"cleanup_interval"`
}
type AuthConfig ¶
type BackupConfig ¶
type BackupConfig struct {
Destinations []BackupDestination `yaml:"destinations" json:"destinations"`
}
type BackupDestination ¶
type BackupDestination struct {
Name string `yaml:"name" json:"name"`
Type string `yaml:"type" json:"type"`
Kind string `yaml:"kind" json:"kind"`
Deployment string `yaml:"deployment,omitempty" json:"deployment,omitempty"`
Endpoint string `yaml:"endpoint" json:"endpoint"`
Region string `yaml:"region" json:"region"`
Bucket string `yaml:"bucket" json:"bucket"`
Prefix string `yaml:"prefix" json:"prefix"`
CredentialID string `yaml:"credential_id" json:"credential_id"`
UsePathStyle bool `yaml:"use_path_style" json:"use_path_style"`
// Pointer so an explicit false survives reloads; nil means enabled.
Enabled *bool `yaml:"enabled" json:"enabled"`
}
BackupDestination is an object store that backups are mirrored to after the local copy is written. Secrets are never stored here: CredentialID references an S3 credential held by the credential manager.
Kind records who runs the store: "external" (a store FlatRun only connects to) or "managed" (a store FlatRun runs itself, deployed from a template). For a managed store, Deployment names the deployment that runs the container. See docs/OBJECT_STORES.md.
func (BackupDestination) IsEnabled ¶
func (d BackupDestination) IsEnabled() bool
func (BackupDestination) StoreKind ¶
func (d BackupDestination) StoreKind() string
StoreKind returns the store kind, defaulting to "external" when unset.
type CapacityConfig ¶
type CapacityConfig struct {
AllocationThresholdPercent float64 `yaml:"allocation_threshold_percent" json:"allocation_threshold_percent"`
HostThresholdPercent float64 `yaml:"host_threshold_percent" json:"host_threshold_percent"`
HostMemoryReserve uint64 `yaml:"host_memory_reserve" json:"host_memory_reserve"`
HostCPUReserve float64 `yaml:"host_cpu_reserve" json:"host_cpu_reserve"`
MemoryStepPercent float64 `yaml:"memory_step_percent" json:"memory_step_percent"`
CPUStepPercent float64 `yaml:"cpu_step_percent" json:"cpu_step_percent"`
MaxMemory uint64 `yaml:"max_memory" json:"max_memory"`
MaxCPU float64 `yaml:"max_cpu" json:"max_cpu"`
AllowVertical *bool `yaml:"allow_vertical" json:"allow_vertical"`
AllowHorizontal *bool `yaml:"allow_horizontal" json:"allow_horizontal"`
OfferToFleet bool `yaml:"offer_to_fleet" json:"offer_to_fleet"`
}
type CertbotConfig ¶
type CertbotConfig struct {
Enabled bool `yaml:"enabled" json:"enabled"`
Image string `yaml:"image" json:"image"`
Email string `yaml:"email" json:"email"`
Staging bool `yaml:"staging" json:"staging"`
CertsPath string `yaml:"certs_path" json:"certs_path"`
WebrootPath string `yaml:"webroot_path" json:"webroot_path"`
ContainerWebrootPath string `yaml:"container_webroot_path" json:"container_webroot_path"`
DNSProvider string `yaml:"dns_provider" json:"dns_provider"`
AutoRenewalEnabled *bool `yaml:"auto_renewal_enabled" json:"auto_renewal_enabled"`
RenewalThresholdDays int `yaml:"renewal_threshold_days" json:"renewal_threshold_days"`
RenewalCheckInterval time.Duration `yaml:"renewal_check_interval" json:"renewal_check_interval"`
}
type CleanupConfig ¶ added in v0.3.0
type ClusterConfig ¶ added in v0.1.5
type ClusterConfig struct {
Enabled bool `yaml:"enabled"`
ServerName string `yaml:"server_name"`
AdvertiseURL string `yaml:"advertise_url"`
HealthInterval string `yaml:"health_interval"`
RequestTimeout string `yaml:"request_timeout"`
Orchestrator string `yaml:"orchestrator" json:"orchestrator"`
Routing string `yaml:"routing" json:"routing"`
K3s K3sConfig `yaml:"k3s" json:"k3s"`
}
type Config ¶
type Config struct {
DeploymentsPath string `yaml:"deployments_path"`
SystemFilesRoot string `yaml:"system_files_root"`
DockerSocket string `yaml:"docker_socket"`
DefaultTimeout time.Duration `yaml:"default_timeout"`
API APIConfig `yaml:"api"`
Auth AuthConfig `yaml:"auth"`
Domain DomainConfig `yaml:"domain"`
Nginx NginxConfig `yaml:"nginx"`
Certbot CertbotConfig `yaml:"certbot"`
Logging LoggingConfig `yaml:"logging"`
Health HealthConfig `yaml:"health"`
Infrastructure InfrastructureConfig `yaml:"infrastructure"`
Security SecurityConfig `yaml:"security"`
Audit AuditConfig `yaml:"audit"`
Cluster ClusterConfig `yaml:"cluster"`
Capacity CapacityConfig `yaml:"capacity"`
SystemTerminal SystemTerminalConfig `yaml:"system_terminal"`
Cleanup CleanupConfig `yaml:"cleanup"`
Plans PlansConfig `yaml:"plans"`
AI AIConfig `yaml:"ai"`
MCP MCPConfig `yaml:"mcp"`
Files FilesConfig `yaml:"files"`
Backup BackupConfig `yaml:"backup"`
Templates TemplatesConfig `yaml:"templates"`
}
type DomainConfig ¶
type Entry ¶ added in v0.3.0
type FilesConfig ¶ added in v0.3.0
type FilesConfig struct {
// Pointer so an explicit false survives reloads; nil means "use default" (true).
ShowHidden *bool `yaml:"show_hidden" json:"show_hidden"`
}
type HealthConfig ¶
type InfrastructureConfig ¶ added in v0.1.3
type InfrastructureConfig struct {
DefaultProxyNetwork string `yaml:"default_proxy_network" json:"default_proxy_network"`
DefaultDatabaseNetwork string `yaml:"default_database_network" json:"default_database_network"`
// DefaultObjectStorageNetwork is the shared network self-hosted object
// stores join so apps can reach them by name. Empty reuses the database
// network (object storage is a data backend like a database); set it to run
// object stores on a dedicated network instead.
DefaultObjectStorageNetwork string `yaml:"default_object_storage_network" json:"default_object_storage_network"`
Database SharedDatabaseConfig `yaml:"database" json:"database"`
Redis SharedRedisConfig `yaml:"redis" json:"redis"`
PowerDNS PowerDNSConfig `yaml:"powerdns" json:"powerdns"`
}
type LoggingConfig ¶
type MCPConfig ¶
type MCPConfig struct {
Enabled bool `yaml:"enabled" json:"enabled"`
}
MCPConfig controls the built-in MCP server that exposes the assistant's tool set to external MCP clients. Every call is authenticated and permission-gated exactly as the assistant is, so it is off unless deliberately enabled.
type NginxConfig ¶
type NginxConfig struct {
Enabled bool `yaml:"enabled" json:"enabled"`
Image string `yaml:"image" json:"image"`
ContainerName string `yaml:"container_name" json:"container_name"`
ConfigPath string `yaml:"config_path" json:"config_path"`
ReloadCommand string `yaml:"reload_command" json:"reload_command"`
External bool `yaml:"external" json:"external"`
ContainerWebrootPath string `yaml:"container_webroot_path" json:"container_webroot_path"`
RejectUnknownDomains bool `yaml:"reject_unknown_domains" json:"reject_unknown_domains"`
}
type PlansConfig ¶ added in v0.3.0
type PowerDNSConfig ¶ added in v0.1.5
type PowerDNSConfig struct {
Enabled bool `yaml:"enabled" json:"enabled"`
Container string `yaml:"container" json:"container"`
Image string `yaml:"image" json:"image"`
APIPort int `yaml:"api_port" json:"api_port"`
DNSPort int `yaml:"dns_port" json:"dns_port"`
APIKey string `yaml:"api_key" json:"api_key"`
DataPath string `yaml:"data_path" json:"data_path"`
DefaultSOA string `yaml:"default_soa" json:"default_soa"`
Nameservers string `yaml:"nameservers" json:"nameservers"`
}
type SecurityConfig ¶ added in v0.1.5
type SecurityConfig struct {
Enabled bool `yaml:"enabled" json:"enabled"`
RealtimeCapture bool `yaml:"realtime_capture" json:"realtime_capture"`
ScanInterval time.Duration `yaml:"scan_interval" json:"scan_interval"`
RetentionDays int `yaml:"retention_days" json:"retention_days"`
RateThreshold int `yaml:"rate_threshold" json:"rate_threshold"`
AutoBlockEnabled bool `yaml:"auto_block_enabled" json:"auto_block_enabled"`
AutoBlockThreshold int `yaml:"auto_block_threshold" json:"auto_block_threshold"`
AutoBlockDuration time.Duration `yaml:"auto_block_duration" json:"auto_block_duration"`
// Detection thresholds for autoblock
DetectionWindow time.Duration `yaml:"detection_window" json:"detection_window"`
NotFoundThreshold int `yaml:"not_found_threshold" json:"not_found_threshold"`
AuthFailureThreshold int `yaml:"auth_failure_threshold" json:"auth_failure_threshold"`
UniquePathsThreshold int `yaml:"unique_paths_threshold" json:"unique_paths_threshold"`
RepeatedHitsThreshold int `yaml:"repeated_hits_threshold" json:"repeated_hits_threshold"`
// Internal API token for nginx-to-agent communication (auto-generated if empty)
InternalAPIToken string `yaml:"internal_api_token" json:"-"`
TrustedProxies []string `yaml:"trusted_proxies" json:"trusted_proxies"`
TrustCFHeader bool `yaml:"trust_cf_header" json:"trust_cf_header"`
}
type ServiceExecConfig ¶ added in v0.1.5
type ServiceExecConfig struct {
Image string `yaml:"image" json:"image"`
Container string `yaml:"container" json:"container"`
KeepAlive bool `yaml:"keep_alive" json:"keep_alive"`
RunOnRequest bool `yaml:"run_on_request" json:"run_on_request"`
Volumes []string `yaml:"volumes" json:"volumes"`
Networks []string `yaml:"networks" json:"networks"`
}
func (*ServiceExecConfig) ShouldUseDockerRun ¶ added in v0.1.5
func (c *ServiceExecConfig) ShouldUseDockerRun() bool
type SharedDatabaseConfig ¶ added in v0.1.3
type SharedDatabaseConfig struct {
}
type SharedRedisConfig ¶ added in v0.1.3
type SharedRedisConfig struct {
}
type SystemTerminalConfig ¶ added in v0.2.0
type SystemTerminalConfig struct {
ProtectedMode models.ProtectedModeConfig `yaml:"protected_mode" json:"protected_mode"`
}
type TemplatesConfig ¶
type TemplatesConfig struct {
// SyncInterval is the background resync period in seconds. A pointer so an
// explicit 0, which disables the resync loop, is distinct from unset.
SyncInterval *int `yaml:"sync_interval" json:"sync_interval"`
GitHub TemplatesGitHubConfig `yaml:"github" json:"github"`
Marketplace TemplatesMarketplaceConfig `yaml:"marketplace" json:"marketplace"`
}
TemplatesConfig controls where the app template catalog is fetched from. The catalog lives outside the binary: it is synced from a source into an on-disk cache that the deploy and listing paths read. Infra and welcome content stay embedded and are unaffected.
type TemplatesGitHubConfig ¶
type TemplatesGitHubConfig struct {
// Enabled defaults to true when unset; an explicit false is honored.
Enabled *bool `yaml:"enabled" json:"enabled"`
Repo string `yaml:"repo" json:"repo"`
Ref string `yaml:"ref" json:"ref"`
}
TemplatesGitHubConfig is the GitHub-repo source, the working default today.
type TemplatesMarketplaceConfig ¶
type TemplatesMarketplaceConfig struct {
Enabled bool `yaml:"enabled" json:"enabled"`
// URL is the marketplace API root; empty falls back to the agent's default
// marketplace endpoint.
URL string `yaml:"url" json:"url"`
}
TemplatesMarketplaceConfig is the marketplace-API source. Disabled by default until the API is declared ready; enabling it makes the marketplace authoritative ahead of GitHub with no code change.