Documentation
¶
Overview ¶
Package config owns typed runtime configuration for the core only.
Index ¶
- Constants
- Variables
- func AccountingPriceCatalogConfig(cfg AccountingPricingConfig) accounting.PriceCatalogConfig
- func ApplyStreamRecoveryOverrides(cfg *Config, overrides StreamRecoveryOverrides) error
- func AuthorityQueryEffectivelyExposed(cfg *Config) bool
- func BoolPtr(v bool) *bool
- func ConfiguredDataPlanePaths(cfg *Config) []string
- func ControlPlaneQueryEffectivelyExposed(cfg *Config) bool
- func DecodeYAMLNode(n yaml.Node, into any) error
- func EffectiveContinuityStore(c ContinuityConfig) string
- func EffectiveDatabaseModes(d DatabaseConfig) (DatabaseConnectionMode, DatabaseSchemaMode, error)
- func EffectiveDefaultRouteSelector(cfg *Config, wireModel WireModelForBackend) string
- func EffectiveSecureSessionSQLQueryCache(ss SecureSessionConfig) (ttl time.Duration, maxEntries uint64, enabled bool)
- func EffectiveTransportFallbackPolicy(cfg *Config) lipapi.TransportFallbackPolicy
- func IsExplicitLoopbackListenAddress(raw string) bool
- func ParseToolReactorErrorPolicy(s string) sdk.ToolReactorErrorPolicy
- func RegistrationsFromConfig(cfg *Config) []lipsdk.Registration
- func RoutingOverrideAdminPathPrefix(cfg *Config) string
- func StrictDecode(raw []byte) (*Config, LoadCategory, error)
- func Validate(cfg *Config) error
- func ValidateAuthLocalAPIKeyRecords(records []AuthLocalAPIKeyRecord) error
- func ValidateBackendDiscovery(cfg *Config) error
- func ValidateProtectedDiagnosticsPosture(cfg *Config) error
- type AccessConfig
- type AccountingAdminConfig
- type AccountingAuthorityConfig
- type AccountingAuthorityDimensionMatcherConfig
- type AccountingAuthorityDimensionsConfig
- type AccountingAuthorityQueryConfig
- type AccountingAuthorityRuleConfig
- type AccountingAuthorityWindowConfig
- type AccountingBillingConfig
- type AccountingConfig
- type AccountingLedgerConfig
- type AccountingModelPriceConfig
- type AccountingObservabilityConfig
- type AccountingPreflightConfig
- type AccountingPricingConfig
- type AccountingQuotaConfig
- type AccountingQuotaFailureConfig
- type AccountingQuotaThresholdConfig
- type AccountingTokenizerConfig
- type AuthConfig
- type AuthLocalAPIKeyRecord
- type AuthLocalAttribution
- type AuthMode
- type AuthRemoteConfig
- type AutoResumeConfig
- type BackendDiscoveryConfig
- type CircuitBreakerConfig
- type ClientIPSource
- type CompatibleModeConfig
- type CompatibleModeModelItem
- type CompatibleModeModelsConfig
- type CompiledGeoIP
- func (c *CompiledGeoIP) ClientIPSource() ClientIPSource
- func (c *CompiledGeoIP) DatabaseSource() GeoIPDatabaseSource
- func (c *CompiledGeoIP) Enabled() bool
- func (c *CompiledGeoIP) Policy() *coregeoip.Policy
- func (c *CompiledGeoIP) TrustedProxies() []netip.Prefix
- func (c *CompiledGeoIP) UpdateInterval() time.Duration
- type CompiledSelfDefense
- func (c *CompiledSelfDefense) AdaptiveExemptCIDRs() []netip.Prefix
- func (c *CompiledSelfDefense) AuthFailures() int
- func (c *CompiledSelfDefense) Enabled() bool
- func (c *CompiledSelfDefense) FailureWindow() time.Duration
- func (c *CompiledSelfDefense) ImpossiblePaths() bool
- func (c *CompiledSelfDefense) InitialQuarantine() time.Duration
- func (c *CompiledSelfDefense) MaxEntries() int
- func (c *CompiledSelfDefense) MaxQuarantine() time.Duration
- func (c *CompiledSelfDefense) Policy() ingressdefense.Policy
- func (c *CompiledSelfDefense) StateLimits() ingressdefense.StateLimits
- func (c *CompiledSelfDefense) StateTTL() time.Duration
- type ConcurrencyAuthorityConfig
- type ConcurrencyAuthorityRuleConfig
- type Config
- func (c *Config) EffectiveAccessMode() (accessmode.Mode, error)
- func (c *Config) EffectiveAuthForAudit() (handler, requiredLevel string)
- func (c *Config) EffectiveServerAuthMode() AuthMode
- func (c *Config) EffectiveTrustEnvironmentProxy() bool
- func (c *Config) SecureSessionEffectivelyEnabled() bool
- func (c *Config) SingleUserLocalMode() bool
- type ContinuityConfig
- type ControlPlaneConfig
- type ControlPlaneQueryConfig
- type ControlPlaneRetentionConfig
- type DatabaseConfig
- type DatabaseConnectionMode
- type DatabasePoolSettings
- type DatabaseSchemaMode
- type DiagnosticsConfig
- type EffectiveAutoResumeConfig
- type EffectiveConfig
- type EffectiveIdentity
- type EffectivePreRequestKeepaliveConfig
- type ExecutionCompositionPolicy
- type GeoIPClientConfig
- type GeoIPConfig
- type GeoIPDBConfig
- type GeoIPDatabaseSource
- type GeoIPRuleConfig
- type GeoIPUpdateConfig
- type HTTPClientConfig
- type HTTPHeadersConfig
- type HooksConfig
- type InterleavedConfig
- type LargePayloadFastPathConfig
- func (c LargePayloadFastPathConfig) EffectiveMaxInflightSpoolBytes() int64
- func (c LargePayloadFastPathConfig) EffectiveMaxSemanticFactBytes() int64
- func (c LargePayloadFastPathConfig) EffectiveMemorySpoolBytes() int64
- func (c LargePayloadFastPathConfig) EffectiveSpoolDir() string
- func (c LargePayloadFastPathConfig) EffectiveThresholdBytes() int64
- type LoadCategory
- type LoadEffectiveOptions
- type LoadError
- type LoggingConfig
- type MeteringConfig
- type MeteringJournalConfig
- type MetricsConfig
- type ModelAliasConfig
- type ModelCatalogBackendModelOverrideEntry
- type ModelCatalogConfig
- type ModelCatalogModelOverrideEntry
- type ModelInventoryConfig
- type ObservabilityConfig
- type PluginConfig
- type PluginsConfig
- type PreRequestKeepaliveConfig
- type RoutingAffinityConfig
- type RoutingConfig
- type RoutingHealthConfig
- type RoutingOverrideAdminConfig
- type RoutingTransportConfig
- type SecureSessionConfig
- type SelfDefenseAdaptiveConfig
- type SelfDefenseConfig
- type ServerConfig
- func (s ServerConfig) EffectiveIdleTimeout() time.Duration
- func (s ServerConfig) EffectiveMaxConcurrentDecodes() int
- func (s ServerConfig) EffectiveMaxInflightDecodeBytes() int64
- func (s ServerConfig) EffectiveMaxPendingWireEvents() int
- func (s ServerConfig) EffectiveMaxRequestBodyBytes() int64
- func (s ServerConfig) EffectiveMaxRequestBodyBytesForBudget() int64
- func (s ServerConfig) EffectivePreRequestKeepalive() EffectivePreRequestKeepaliveConfig
- func (s ServerConfig) EffectiveReadHeaderTimeout() time.Duration
- func (s ServerConfig) EffectiveReadTimeout() time.Duration
- func (s ServerConfig) EffectiveShutdownTimeout() time.Duration
- func (s ServerConfig) EffectiveWriteTimeout() time.Duration
- type StreamRecoveryConfig
- type StreamRecoveryOverrides
- type StreamRecoveryPostOutputPolicy
- type TracingConfig
- type WireModelForBackend
Constants ¶
const ( DefaultAccountingAuthorityEvaluationTimeout = 250 * time.Millisecond DefaultAccountingAuthorityCleanupTimeout = 2 * time.Second )
const ( DefaultConcurrencyLeaseTTL = 60 * time.Second DefaultConcurrencyRenewBefore = 15 * time.Second )
const ( // DefaultLargePayloadThresholdBytes is the evidence-adjustable decoded-size // gate for fast-path consideration (design section 3, Task 19). DefaultLargePayloadThresholdBytes int64 = 1 << 20 // DefaultLargePayloadMemorySpoolBytes bounds retained request bytes in Go // heap per captured request. DefaultLargePayloadMemorySpoolBytes int64 = 64 << 10 // DefaultLargePayloadMaxInflightSpoolBytes bounds global logical spool // reservation across concurrent captures. DefaultLargePayloadMaxInflightSpoolBytes int64 = 256 << 20 // DefaultLargePayloadMaxSemanticFactBytes bounds profile-derived metadata // such as normalized part shapes. DefaultLargePayloadMaxSemanticFactBytes int64 = 256 << 10 )
const ( DefaultShutdownTimeout = 15 * time.Second DefaultMaxConcurrentDecodes = 32 DefaultMaxInflightDecodeBytes = 64 << 20 )
const ( DefaultModelInventoryRefreshInterval = time.Hour DefaultModelInventoryFetchTimeout = 30 * time.Second )
const ( // DefaultRoutingOverrideAdminPathPrefix is used when override admin is enabled // without an explicit path_prefix. DefaultRoutingOverrideAdminPathPrefix = "/admin/routing-overrides" // DefaultRoutingOverrideAdminMaxBodyBytes is MaxRouteSelectorBytes plus bounded JSON overhead. DefaultRoutingOverrideAdminMaxBodyBytes = int64(lipapi.MaxRouteSelectorBytes + 4096) )
const DefaultConfigMaxBytes int64 = 2 << 20 // 2 MiB
DefaultConfigMaxBytes is the shared upper bound for one configuration document. Filesystem adapters may apply a smaller startup-fixed limit.
const DefaultFallbackRouteSelector = "openai-responses:" + DefaultFallbackWireModel
DefaultFallbackRouteSelector is used only when wireModel is nil (tests / degenerate bootstrap).
const DefaultFallbackWireModel = "gpt-4o-mini"
DefaultFallbackWireModel is the compile-time model token used when synthesizing a default route selector and no WireModelForBackend mapping is available.
const DefaultMaxAttempts = 3
Variables ¶
var ( ErrInvalidAuthEventDelivery = errors.New("config: invalid auth.event_delivery") ErrInvalidAuthEventFailurePolicy = errors.New("config: invalid auth.event_failure_policy") ErrAuthLocalAPIKeysRequired = errors.New("config: auth.local_api_keys required for local_api_key handler") ErrAuthLocalAPIKeysRequiredForRemoteSSO = errors.New("config: auth.local_api_keys required for remote api_key_sso") )
Sentinel errors for access/auth validation. Use errors.Is after Validate or LoadFile.
Functions ¶
func AccountingPriceCatalogConfig ¶
func AccountingPriceCatalogConfig(cfg AccountingPricingConfig) accounting.PriceCatalogConfig
func ApplyStreamRecoveryOverrides ¶
func ApplyStreamRecoveryOverrides(cfg *Config, overrides StreamRecoveryOverrides) error
ApplyStreamRecoveryOverrides materializes effective auto-resume settings into cfg.
func AuthorityQueryEffectivelyExposed ¶
AuthorityQueryEffectivelyExposed reports whether the protected authority surface is configured to mount.
func ConfiguredDataPlanePaths ¶
ConfiguredDataPlanePaths returns every operator-configured data-plane path in cfg, normalized, from the same chokepoint that validates them.
It exists so a default-on request-graph layer can know which paths the operator actually published without keeping its own copy of the configurable path surface. Those values are any normalized absolute non-root path, which includes paths inside the frozen ingress impossible-path families, so a consumer that refuses requests before the router must treat a published path as authoritative.
The error is deliberately dropped: it is produced only by the same per-field checks Validate already runs, so a configuration that reached a caller has none. A caller that needs the error uses validation instead.
func ControlPlaneQueryEffectivelyExposed ¶
ControlPlaneQueryEffectivelyExposed reports whether the protected control-plane query surface is configured for exposure. Used by diagnostics posture checks and runtimebundle wiring to decide mounting and fail-closed behavior.
func DecodeYAMLNode ¶
DecodeYAMLNode decodes a YAML node into a typed struct when the node is present.
func EffectiveContinuityStore ¶
func EffectiveContinuityStore(c ContinuityConfig) string
EffectiveContinuityStore returns the continuity backing name after applying the same rules as Validate (in_memory forces memory; empty store defaults to memory).
func EffectiveDatabaseModes ¶
func EffectiveDatabaseModes(d DatabaseConfig) (DatabaseConnectionMode, DatabaseSchemaMode, error)
EffectiveDatabaseModes returns compatibility-preserving connection and schema modes for dual-plane PostgreSQL runtime paths after validating their combination.
func EffectiveDefaultRouteSelector ¶
func EffectiveDefaultRouteSelector(cfg *Config, wireModel WireModelForBackend) string
EffectiveDefaultRouteSelector returns the selector used when clients omit explicit routing (e.g. X-LIP-Route). Single implementation for the proxy; routing alias validation stays in package routing (see routing.ValidateModelAliasesConfig).
Resolution order:
- cfg.Routing.DefaultRoute when non-empty after trim
- first enabled backend row in cfg.Plugins.Backends, as "<instance_id>:<wireModel(factory_id)>"
- compile-time fallback "openai-responses:<wireModel(openai-responses)>" when wireModel is set
- literal "openai-responses:gpt-4o-mini" only if wireModel is nil (tests / degenerate bootstrap)
func EffectiveSecureSessionSQLQueryCache ¶
func EffectiveSecureSessionSQLQueryCache(ss SecureSessionConfig) (ttl time.Duration, maxEntries uint64, enabled bool)
EffectiveSecureSessionSQLQueryCache returns parsed TTL and capacity for durable secure-session SQL metadata caches. enabled is false when sql_query_cache_ttl is empty. Max entries zero coerces to defaultSecureSessionSQLQueryCacheMaxEntries.
func EffectiveTransportFallbackPolicy ¶
func EffectiveTransportFallbackPolicy(cfg *Config) lipapi.TransportFallbackPolicy
func IsExplicitLoopbackListenAddress ¶
IsExplicitLoopbackListenAddress reports whether raw is a conservative loopback bind (127/8, ::1, or localhost), not an all-interfaces or non-loopback address.
func ParseToolReactorErrorPolicy ¶
func ParseToolReactorErrorPolicy(s string) sdk.ToolReactorErrorPolicy
ParseToolReactorErrorPolicy maps YAML values to the stable hook-bus policy.
func RegistrationsFromConfig ¶
func RegistrationsFromConfig(cfg *Config) []lipsdk.Registration
RegistrationsFromConfig maps YAML plugin rows to SDK registrations. The core only forwards opaque config nodes; it does not interpret plugin-private schema.
func RoutingOverrideAdminPathPrefix ¶
RoutingOverrideAdminPathPrefix returns the configured or default admin path prefix.
func StrictDecode ¶
func StrictDecode(raw []byte) (*Config, LoadCategory, error)
StrictDecode decodes exactly one YAML document into Config with KnownFields. Plugin-private yaml.Node subtrees are preserved. Failures are secret-safe.
func Validate ¶
Validate checks plugin identity rules and continuity/store consistency after decoding. It does not validate model_aliases; call routing.ValidateModelAliasesConfig after LoadFile, or rely on runtimebundle.Build.
func ValidateAuthLocalAPIKeyRecords ¶
func ValidateAuthLocalAPIKeyRecords(records []AuthLocalAPIKeyRecord) error
ValidateAuthLocalAPIKeyRecords converts AuthLocalAPIKeyRecord values to core auth records and delegates to coreauth.ValidateLocalAPIKeyRecords (duplicates, required fields, min key runes).
func ValidateBackendDiscovery ¶
ValidateBackendDiscovery enforces path and production development_mode rules.
func ValidateProtectedDiagnosticsPosture ¶
ValidateProtectedDiagnosticsPosture rejects exposing protected operator surfaces on a non-loopback bind without diagnostics.shared_secret (minimum length enforced separately by Validate via validateDiagnosticsSecret). Health-only diagnostics never require a secret. Loopback binds may use an empty secret with protected surfaces (local trust posture).
Types ¶
type AccessConfig ¶
type AccessConfig struct {
Mode string `yaml:"mode"`
GeoIP GeoIPConfig `yaml:"geoip"`
SelfDefense SelfDefenseConfig `yaml:"self_defense"`
}
AccessConfig selects deployment access posture (single-user vs multi-user). Empty Mode is normalized to single_user during validation/load.
type AccountingAdminConfig ¶
type AccountingAuthorityConfig ¶
type AccountingAuthorityConfig struct {
Enabled bool `yaml:"enabled"`
Mode string `yaml:"mode"`
Store string `yaml:"store"`
SQLitePath string `yaml:"sqlite_path"`
PostgresDSN string `yaml:"postgres_dsn"`
StartupPosture string `yaml:"startup_posture"`
UnknownAttribution string `yaml:"unknown_attribution"`
EvaluationTimeout string `yaml:"evaluation_timeout"`
CleanupTimeout string `yaml:"cleanup_timeout"`
// SnapshotVersion is the immutable config-backed policy version (requirement 11.5).
// Empty defaults to "static" at source construction.
SnapshotVersion string `yaml:"snapshot_version"`
Query AccountingAuthorityQueryConfig `yaml:"query"`
Rules []AccountingAuthorityRuleConfig `yaml:"rules"`
// Quota is an optional provider account-window authority. Its presence is
// the explicit opt-in; no telemetry is inferred as quota authority when it
// is omitted.
Quota *AccountingQuotaConfig `yaml:"quota"`
}
AccountingAuthorityConfig controls the optional usage-authority capability. It is disabled by default and only becomes visible when explicitly enabled.
func (AccountingAuthorityConfig) CleanupTimeoutDuration ¶
func (a AccountingAuthorityConfig) CleanupTimeoutDuration() (time.Duration, error)
CleanupTimeoutDuration returns the bounded budget for detached settlement, release, reconciliation, advisory usage, and compensation work.
func (AccountingAuthorityConfig) DomainConfig ¶
func (a AccountingAuthorityConfig) DomainConfig() (authoritydomain.AuthorityConfig, error)
DomainConfig converts the validated config surface into the pure domain authority config consumed by the app layer.
func (AccountingAuthorityConfig) EvaluationTimeoutDuration ¶
func (a AccountingAuthorityConfig) EvaluationTimeoutDuration() (time.Duration, error)
EvaluationTimeoutDuration returns the bounded admission evaluation budget. The zero configuration value is deliberately normalized to the conservative default so enabling authority cannot accidentally restore unbounded waits.
type AccountingAuthorityDimensionMatcherConfig ¶
type AccountingAuthorityDimensionMatcherConfig struct {
Value scope.Value `yaml:"value"`
MatchUnknown bool `yaml:"match_unknown"`
}
AccountingAuthorityDimensionMatcherConfig preserves unknown versus known-empty attribution semantics for one dimension.
func (AccountingAuthorityDimensionMatcherConfig) DomainMatcher ¶
func (m AccountingAuthorityDimensionMatcherConfig) DomainMatcher() authoritydomain.DimensionMatcher
type AccountingAuthorityDimensionsConfig ¶
type AccountingAuthorityDimensionsConfig struct {
Principal AccountingAuthorityDimensionMatcherConfig `yaml:"principal"`
Credential AccountingAuthorityDimensionMatcherConfig `yaml:"credential"`
Tenant AccountingAuthorityDimensionMatcherConfig `yaml:"tenant"`
Organization AccountingAuthorityDimensionMatcherConfig `yaml:"organization"`
Workspace AccountingAuthorityDimensionMatcherConfig `yaml:"workspace"`
Project AccountingAuthorityDimensionMatcherConfig `yaml:"project"`
Department AccountingAuthorityDimensionMatcherConfig `yaml:"department"`
CostCenter AccountingAuthorityDimensionMatcherConfig `yaml:"cost_center"`
Backend AccountingAuthorityDimensionMatcherConfig `yaml:"backend"`
Model AccountingAuthorityDimensionMatcherConfig `yaml:"model"`
Route AccountingAuthorityDimensionMatcherConfig `yaml:"route"`
Labels map[string]AccountingAuthorityDimensionMatcherConfig `yaml:"labels"`
}
AccountingAuthorityDimensionsConfig carries all safe scope dimensions the authority may match against.
func (AccountingAuthorityDimensionsConfig) DomainMatcher ¶
func (m AccountingAuthorityDimensionsConfig) DomainMatcher() authoritydomain.DimensionsMatcher
type AccountingAuthorityQueryConfig ¶
type AccountingAuthorityQueryConfig struct {
Enabled bool `yaml:"enabled"`
PathPrefix string `yaml:"path_prefix"`
DefaultPageSize int `yaml:"default_page_size"`
MaxPageSize int `yaml:"max_page_size"`
}
AccountingAuthorityQueryConfig controls the protected status and bounded query routes for authority state.
type AccountingAuthorityRuleConfig ¶
type AccountingAuthorityRuleConfig struct {
ID string `yaml:"id"`
Kind string `yaml:"kind"`
Mode string `yaml:"mode"`
Unit string `yaml:"unit"`
Limit int64 `yaml:"limit"`
Currency string `yaml:"currency"`
AuthorityRequirement string `yaml:"authority_requirement"`
FailureBehavior string `yaml:"failure_behavior"`
Perspective string `yaml:"perspective"`
LifecycleScope string `yaml:"lifecycle_scope"`
Basis string `yaml:"basis"`
Namespace string `yaml:"namespace"`
Version string `yaml:"version"`
Window AccountingAuthorityWindowConfig `yaml:"window"`
Match AccountingAuthorityDimensionsConfig `yaml:"match"`
}
AccountingAuthorityRuleConfig mirrors the pure domain rule shape with YAML-friendly primitives.
func (AccountingAuthorityRuleConfig) DomainRule ¶
func (r AccountingAuthorityRuleConfig) DomainRule(defaultMode string) (authoritydomain.Rule, error)
type AccountingAuthorityWindowConfig ¶
type AccountingAuthorityWindowConfig struct {
Algorithm string `yaml:"algorithm"`
Size string `yaml:"size"`
Anchor string `yaml:"anchor"`
}
AccountingAuthorityWindowConfig defines a fixed window using config-native duration and timestamp strings.
func (AccountingAuthorityWindowConfig) DomainWindow ¶
func (w AccountingAuthorityWindowConfig) DomainWindow() (authoritydomain.WindowSpec, error)
type AccountingBillingConfig ¶
type AccountingBillingConfig struct {
// ReportsPath selects the protected billing report surface for an injected
// billing composition. Empty selects /admin/billing.
ReportsPath string `yaml:"reports_path"`
}
AccountingBillingConfig enables journal-backed monetary settlement and reports.
type AccountingConfig ¶
type AccountingConfig struct {
Enabled bool `yaml:"enabled"`
Mode string `yaml:"mode"`
// CountTimeout bounds provider/local count calls; empty selects the composition-root default.
CountTimeout string `yaml:"count_timeout"`
Tokenizer AccountingTokenizerConfig `yaml:"tokenizer"`
Preflight AccountingPreflightConfig `yaml:"preflight"`
Ledger AccountingLedgerConfig `yaml:"ledger"`
Admin AccountingAdminConfig `yaml:"admin"`
Observability AccountingObservabilityConfig `yaml:"observability"`
// StrictAuthoritative rejects backend wiring unless every configured backend can provide authoritative usage.
StrictAuthoritative bool `yaml:"strict_authoritative"`
Pricing AccountingPricingConfig `yaml:"pricing"`
Authority AccountingAuthorityConfig `yaml:"authority"`
Concurrency ConcurrencyAuthorityConfig `yaml:"concurrency"`
// Billing contains report-path configuration for an injected composition.
// Billing is enabled only by complete host composition.
Billing AccountingBillingConfig `yaml:"billing"`
}
type AccountingLedgerConfig ¶
type AccountingLedgerConfig struct {
// Store/SQLitePath/PostgresDSN/WritePolicy remain accepted for
// backward-compatible YAML. Phase 8 no longer opens or writes this ledger;
// Bun billingstore is the monetary journal.
Store string `yaml:"store"`
SQLitePath string `yaml:"sqlite_path"`
PostgresDSN string `yaml:"postgres_dsn"`
WritePolicy string `yaml:"write_policy"`
}
type AccountingModelPriceConfig ¶
type AccountingModelPriceConfig struct {
Backend string `yaml:"backend"`
Model string `yaml:"model"`
InputPer1M string `yaml:"input_per_1m"`
CachedInputPer1M string `yaml:"cached_input_per_1m"`
CacheWriteInputPer1M string `yaml:"cache_write_input_per_1m"`
OutputPer1M string `yaml:"output_per_1m"`
ReasoningOutputPer1M string `yaml:"reasoning_output_per_1m"`
}
type AccountingObservabilityConfig ¶
type AccountingObservabilityConfig struct {
Enabled bool `yaml:"enabled"`
}
type AccountingPreflightConfig ¶
type AccountingPreflightConfig struct {
Mode string `yaml:"mode"`
MaxInputTokens int64 `yaml:"max_input_tokens"`
MaxOutputTokens int64 `yaml:"max_output_tokens"`
MaxContextTokens int64 `yaml:"max_context_tokens"`
ClampMaxOutputTokens bool `yaml:"clamp_max_output_tokens"`
// UnknownOutputPolicy selects how to bound exposure when the client omits
// max_output_tokens: require_client_limit | configured_default |
// model_backend_maximum | clamp | deny. Empty applies the documented default.
UnknownOutputPolicy string `yaml:"unknown_output_policy"`
}
type AccountingPricingConfig ¶
type AccountingPricingConfig struct {
Currency string `yaml:"currency"`
CatalogVersion string `yaml:"catalog_version"`
Models []AccountingModelPriceConfig `yaml:"models"`
}
type AccountingQuotaConfig ¶
type AccountingQuotaConfig struct {
ID string `yaml:"id"`
Version string `yaml:"version"`
Method string `yaml:"method"`
StoreID string `yaml:"store_id"`
TenantID string `yaml:"tenant_id"`
ProviderAccountKey string `yaml:"provider_account_key"`
PoolID string `yaml:"pool_id"`
WindowID string `yaml:"window_id"`
ResetAt string `yaml:"reset_at"`
Freshness string `yaml:"freshness"`
Required []metering.ComponentKey `yaml:"required"`
Thresholds []AccountingQuotaThresholdConfig `yaml:"thresholds"`
Failures AccountingQuotaFailureConfig `yaml:"failures"`
}
AccountingQuotaConfig is the host-facing, YAML-friendly source form for one immutable provider quota policy. It contains only nonfinancial account-window identity, gauge fields, thresholds, and explicit telemetry failure actions.
func (*AccountingQuotaConfig) PolicyConfig ¶
func (q *AccountingQuotaConfig) PolicyConfig() (authority.QuotaPolicyConfig, error)
PolicyConfig parses the host-facing quota policy into the public immutable policy source form. CompileQuotaPolicy performs the final identity and nonfinancial policy validation.
type AccountingQuotaFailureConfig ¶
type AccountingQuotaFailureConfig struct {
Missing string `yaml:"missing"`
Stale string `yaml:"stale"`
Partial string `yaml:"partial"`
Mismatch string `yaml:"mismatch"`
Future string `yaml:"future"`
}
AccountingQuotaFailureConfig makes every non-complete evidence posture independently configurable. Empty actions are normalized by the policy to fail closed.
type AccountingQuotaThresholdConfig ¶
type AccountingQuotaThresholdConfig struct {
Kind string `yaml:"kind"`
Field metering.ComponentKey `yaml:"field"`
ValueKind string `yaml:"value_kind"`
Value string `yaml:"value"`
}
AccountingQuotaThresholdConfig keeps exact decimal thresholds as text so YAML never routes an allowance comparison through floating point.
type AuthConfig ¶
type AuthConfig struct {
Handler string `yaml:"handler"`
RequiredLevel string `yaml:"required_level"`
EventFailurePolicy string `yaml:"event_failure_policy"`
// EventDelivery selects how auth/session events are delivered: default (structured log sink),
// disabled (no sink; explicit no delivery), or custom (requires BuildOptions.AuthEventSink at wiring).
// Empty behaves like default.
EventDelivery string `yaml:"event_delivery"`
LocalAPIKeys []AuthLocalAPIKeyRecord `yaml:"local_api_keys"`
Remote AuthRemoteConfig `yaml:"remote"`
}
AuthConfig selects authentication handler, required level, event delivery policy, local key material, and remote delegation placeholders.
type AuthLocalAPIKeyRecord ¶
type AuthLocalAPIKeyRecord struct {
KeyID string `yaml:"key_id"`
PrincipalID string `yaml:"principal_id"`
Key string `yaml:"key"`
// Attribution carries optional operator-controlled safe attribution for this key.
// Missing optional fields remain unknown (no inference). Raw secrets and transport
// headers must never be placed here.
Attribution AuthLocalAttribution `yaml:"attribution"`
}
AuthLocalAPIKeyRecord is one operator-configured API key (secret material belongs in config files only; validation and redaction are handled elsewhere). Key must be at least 16 Unicode code points after trimming (enforced with core auth validation).
type AuthLocalAttribution ¶
type AuthLocalAttribution struct {
DisplayName string `yaml:"display_name"`
AuthMethod string `yaml:"auth_method"`
TenantID string `yaml:"tenant_id"`
OrganizationID string `yaml:"organization_id"`
WorkspaceID string `yaml:"workspace_id"`
ProjectID string `yaml:"project_id"`
DepartmentID string `yaml:"department_id"`
CostCenterID string `yaml:"cost_center_id"`
Roles []string `yaml:"roles"`
SafeClaims map[string]string `yaml:"safe_claims"`
PolicyLabels map[string]string `yaml:"policy_labels"`
}
AuthLocalAttribution mirrors coreauth.LocalAttribution for YAML decoding. Zero values mean "not configured".
type AuthRemoteConfig ¶
AuthRemoteConfig holds opaque placeholders for future remote auth wiring. No network clients are constructed from these fields in the OSS core.
type AutoResumeConfig ¶
type BackendDiscoveryConfig ¶
type BackendDiscoveryConfig struct {
Enabled bool `yaml:"enabled"`
Paths []string `yaml:"paths"`
Strict bool `yaml:"strict"`
DevelopmentMode bool `yaml:"development_mode"`
}
BackendDiscoveryConfig is the generic (provider-agnostic) discovery/trust subtree.
func DecodeBackendDiscovery ¶
func DecodeBackendDiscovery(n yaml.Node) (BackendDiscoveryConfig, error)
DecodeBackendDiscovery strictly decodes a backend_discovery mapping and rejects unknown keys.
func (*BackendDiscoveryConfig) UnmarshalYAML ¶
func (c *BackendDiscoveryConfig) UnmarshalYAML(value *yaml.Node) error
UnmarshalYAML rejects unknown keys under plugins.backend_discovery.
type CircuitBreakerConfig ¶
type ClientIPSource ¶
type ClientIPSource string
const ( ClientIPSourceDirect ClientIPSource = "direct" ClientIPSourceXForwardedFor ClientIPSource = "x_forwarded_for" ClientIPSourceForwarded ClientIPSource = "forwarded" )
type CompatibleModeConfig ¶
type CompatibleModeConfig struct {
BackendPrefix string
BaseURL string
APIKeyEnvVarRoot string
TokenizerID string
MaxConcurrentRequests int
Models CompatibleModeModelsConfig
}
CompatibleModeConfig is the strict, secret-free configuration surface for the three built-in compatible backend kinds. Successful decoding never retains literal credential values.
func DecodeCompatibleModeConfig ¶
func DecodeCompatibleModeConfig(instanceID, factoryKind string, n yaml.Node) (CompatibleModeConfig, error)
DecodeCompatibleModeConfig strictly decodes opaque compatible-mode YAML. Strictness is scoped to this decoder: it validates the mapping key set before typed decode and does not change repository-wide DecodeYAMLNode behavior. Errors are instance-scoped and never echo literal secret values.
type CompatibleModeModelItem ¶
CompatibleModeModelItem is one static inventory row.
type CompatibleModeModelsConfig ¶
type CompatibleModeModelsConfig struct {
Source string
Path string
Items []CompatibleModeModelItem
}
CompatibleModeModelsConfig is the optional static/shared inventory subtree.
type CompiledGeoIP ¶
type CompiledGeoIP struct {
// contains filtered or unexported fields
}
CompiledGeoIP is the immutable generation projection produced by pure config compilation. Database lifecycle is intentionally not represented here.
func CompileGeoIP ¶
func CompileGeoIP(in GeoIPConfig) (*CompiledGeoIP, error)
CompileGeoIP validates static GeoIP configuration without opening files, constructing services, or performing network I/O.
func (*CompiledGeoIP) ClientIPSource ¶
func (c *CompiledGeoIP) ClientIPSource() ClientIPSource
func (*CompiledGeoIP) DatabaseSource ¶
func (c *CompiledGeoIP) DatabaseSource() GeoIPDatabaseSource
func (*CompiledGeoIP) Enabled ¶
func (c *CompiledGeoIP) Enabled() bool
Enabled reports whether request enforcement is enabled in this projection.
func (*CompiledGeoIP) Policy ¶
func (c *CompiledGeoIP) Policy() *coregeoip.Policy
Policy returns the immutable policy pointer, or nil when the request wrapper must be omitted.
func (*CompiledGeoIP) TrustedProxies ¶
func (c *CompiledGeoIP) TrustedProxies() []netip.Prefix
TrustedProxies returns a defensive copy.
func (*CompiledGeoIP) UpdateInterval ¶
func (c *CompiledGeoIP) UpdateInterval() time.Duration
type CompiledSelfDefense ¶
type CompiledSelfDefense struct {
// contains filtered or unexported fields
}
CompiledSelfDefense is the immutable, provider-neutral generation projection produced by pure config compilation. It carries no mutable process state and performs no I/O.
func CompileSelfDefense ¶
func CompileSelfDefense(in SelfDefenseConfig) (*CompiledSelfDefense, error)
CompileSelfDefense validates the typed self-defense configuration and resolves documented defaults without constructing process state, binding a listener, or performing network I/O.
func (*CompiledSelfDefense) AdaptiveExemptCIDRs ¶
func (c *CompiledSelfDefense) AdaptiveExemptCIDRs() []netip.Prefix
AdaptiveExemptCIDRs returns a defensive copy of the adaptive-exemption prefixes.
func (*CompiledSelfDefense) AuthFailures ¶
func (c *CompiledSelfDefense) AuthFailures() int
AuthFailures returns the configured unauthenticated-401 threshold.
func (*CompiledSelfDefense) Enabled ¶
func (c *CompiledSelfDefense) Enabled() bool
Enabled reports whether request enforcement is enabled in this projection.
func (*CompiledSelfDefense) FailureWindow ¶
func (c *CompiledSelfDefense) FailureWindow() time.Duration
FailureWindow returns the auth-failure counting window.
func (*CompiledSelfDefense) ImpossiblePaths ¶
func (c *CompiledSelfDefense) ImpossiblePaths() bool
ImpossiblePaths reports whether the fixed impossible-path matcher is enabled. The toggle stays a request-graph concern; the core policy owns only adaptive source-defense behavior.
func (*CompiledSelfDefense) InitialQuarantine ¶
func (c *CompiledSelfDefense) InitialQuarantine() time.Duration
InitialQuarantine returns the first-offense quarantine duration.
func (*CompiledSelfDefense) MaxEntries ¶
func (c *CompiledSelfDefense) MaxEntries() int
MaxEntries returns the process-state entry capacity.
func (*CompiledSelfDefense) MaxQuarantine ¶
func (c *CompiledSelfDefense) MaxQuarantine() time.Duration
MaxQuarantine returns the exponential quarantine ceiling.
func (*CompiledSelfDefense) Policy ¶
func (c *CompiledSelfDefense) Policy() ingressdefense.Policy
Policy projects the compiled reloadable request policy onto the single authoritative core domain type. The returned value is a copy: callers cannot mutate the compiled projection through the returned exemption allowlist.
func (*CompiledSelfDefense) StateLimits ¶
func (c *CompiledSelfDefense) StateLimits() ingressdefense.StateLimits
StateLimits projects the process-owned adaptive-state sizing. These limits are restart-required in v1 and are deliberately separate from Policy so they are never carried into a per-request generation projection.
func (*CompiledSelfDefense) StateTTL ¶
func (c *CompiledSelfDefense) StateTTL() time.Duration
StateTTL returns the hostile-inactivity lifetime used to size process state.
type ConcurrencyAuthorityConfig ¶
type ConcurrencyAuthorityConfig struct {
Enabled bool `yaml:"enabled"`
Store string `yaml:"store"` // memory | sqlite | postgres
StoreID string `yaml:"store_id"`
SQLitePath string `yaml:"sqlite_path"`
PostgresDSN string `yaml:"postgres_dsn"`
LeaseTTL string `yaml:"lease_ttl"`
RenewBefore string `yaml:"renew_before"`
// SnapshotVersion is the immutable config-backed concurrency policy version (11.5).
// Empty defaults to "static" at source construction.
SnapshotVersion string `yaml:"snapshot_version"`
// AuxiliaryLeasePolicy controls whether auxiliary requests inherit the parent
// lease (default) or acquire their own top-level slot (requirement 10.10).
// Values: ""|"inherit" (default) | "acquire_own".
AuxiliaryLeasePolicy string `yaml:"auxiliary_lease_policy"`
Rules []ConcurrencyAuthorityRuleConfig `yaml:"rules"`
}
ConcurrencyAuthorityConfig controls optional logical-request concurrency leases. Disabled by default (requirement 10.4 wiring is opt-in).
func (ConcurrencyAuthorityConfig) DomainRules ¶
func (c ConcurrencyAuthorityConfig) DomainRules() ([]concurrencydomain.Rule, error)
DomainRules converts validated concurrency config into domain rules.
func (ConcurrencyAuthorityConfig) LeaseTTLDuration ¶
func (c ConcurrencyAuthorityConfig) LeaseTTLDuration() (time.Duration, error)
LeaseTTLDuration returns the default lease TTL for rules that omit lease_ttl.
func (ConcurrencyAuthorityConfig) RenewBeforeDuration ¶
func (c ConcurrencyAuthorityConfig) RenewBeforeDuration() (time.Duration, error)
RenewBeforeDuration returns the default renew-before offset.
type ConcurrencyAuthorityRuleConfig ¶
type ConcurrencyAuthorityRuleConfig struct {
ID string `yaml:"id"`
Mode string `yaml:"mode"` // strict | advisory
MaxActiveRequests int `yaml:"max_active_requests"`
Match AccountingAuthorityDimensionsConfig `yaml:"match"`
LeaseTTL string `yaml:"lease_ttl"`
RenewBefore string `yaml:"renew_before"`
FailureBehavior string `yaml:"failure_behavior"` // fail_closed | fail_open
Namespace string `yaml:"namespace"`
Version string `yaml:"version"`
}
ConcurrencyAuthorityRuleConfig is one max-active-request lease rule.
type Config ¶
type Config struct {
Server ServerConfig `yaml:"server"`
HTTPHeaders HTTPHeadersConfig `yaml:"http_headers"`
Access AccessConfig `yaml:"access"`
Auth AuthConfig `yaml:"auth"`
Logging LoggingConfig `yaml:"logging"`
Diagnostics DiagnosticsConfig `yaml:"diagnostics"`
Observability ObservabilityConfig `yaml:"observability"`
HTTPClient HTTPClientConfig `yaml:"http_client"`
Database DatabaseConfig `yaml:"database"`
Routing RoutingConfig `yaml:"routing"`
Continuity ContinuityConfig `yaml:"continuity"`
SecureSession SecureSessionConfig `yaml:"secure_session"`
StreamRecovery StreamRecoveryConfig `yaml:"stream_recovery"`
Hooks HooksConfig `yaml:"hooks"`
Accounting AccountingConfig `yaml:"accounting"`
Interleaved InterleavedConfig `yaml:"interleaved"`
Plugins PluginsConfig `yaml:"plugins"`
ModelAliases []ModelAliasConfig `yaml:"model_aliases"`
ModelCatalog ModelCatalogConfig `yaml:"model_catalog"`
ModelInventory ModelInventoryConfig `yaml:"model_inventory"`
// ControlPlane is the optional control-plane persistence/query/event-ledger
// capability. Disabled by default; enabled requires explicit startup
// validation (see validateControlPlane).
ControlPlane ControlPlaneConfig `yaml:"control_plane"`
// Metering is the optional durable metering journal (Phase 5). Disabled by
// default so Executor.MeteringRecorder stays nil until explicitly enabled.
Metering MeteringConfig `yaml:"metering"`
// Identity controls proxy-wide upstream and downstream identity presentation.
// Defaults identify as LIP (not client passthrough). Backend connector wiring
// and A-leg Server middleware are applied in later integration waves.
Identity identity.Config `yaml:"identity"`
// ConfigDir is the directory containing the loaded config file. Set by [LoadFile];
// empty when Config is constructed without loading from disk.
ConfigDir string `yaml:"-"`
}
Config contains only core-owned runtime settings and opaque plugin config payloads.
A decoded Config is not self-validating: Validate checks core fields (plugins, continuity, logging, etc.) but does not validate model_aliases. After LoadFile, call routing.ValidateModelAliasesConfig(cfg) from package internal/core/routing before wiring; composition (for example internal/infra/runtimebundle.Build) compiles model_aliases via routing.NewAliasResolver. Default route selector resolution is EffectiveDefaultRouteSelector in this package (see effective_default_route.go).
func LoadFile ¶
LoadFile decodes typed runtime configuration from YAML, applies defaults, and runs Validate. Reload candidates use the filesystem-driven configsource adapter; this compatibility entrypoint deliberately keeps core/config independent from driving adapters.
func LoadFileWithContext ¶
LoadFileWithContext is the context-aware form of LoadFile.
func (*Config) EffectiveAccessMode ¶
func (c *Config) EffectiveAccessMode() (accessmode.Mode, error)
EffectiveAccessMode returns the normalized deployment access mode (omitted access.mode defaults to single_user).
func (*Config) EffectiveAuthForAudit ¶
EffectiveAuthForAudit returns handler and required_level strings after legacy server.auth_mode merge. It is used for operator audit labels (session-start) and should stay aligned with posture validation.
func (*Config) EffectiveServerAuthMode ¶
EffectiveServerAuthMode returns the configured HTTP auth posture. Empty defaults to no_auth for developer-local defaults; startup validation restricts no_auth to explicit loopback binds.
func (*Config) EffectiveTrustEnvironmentProxy ¶
EffectiveTrustEnvironmentProxy returns whether outbound calls should honor process proxy environment variables.
func (*Config) SecureSessionEffectivelyEnabled ¶
func (*Config) SingleUserLocalMode ¶
SingleUserLocalMode reports whether startup policy permits local no-auth/synthetic-principal behavior.
type ContinuityConfig ¶
type ContinuityConfig struct {
InMemory bool `yaml:"in_memory"`
// Store names the continuity backing when InMemory is true. Empty is normalized to "memory" in LoadFile.
// Use "sqlite" for local durable storage (requires sqlite_path) or "postgres" for managed durable
// (requires postgres_dsn).
Store string `yaml:"store"`
// SQLitePath is the database file path when store is "sqlite".
SQLitePath string `yaml:"sqlite_path"`
// PostgresDSN is the connection string when store is "postgres".
PostgresDSN string `yaml:"postgres_dsn"`
// TTL is in-memory store only (A-leg eviction). Ignored by SQLite until pruning is implemented.
TTL string `yaml:"ttl"`
// MaxLegs is in-memory store only when TTL is empty. Must be >= 0. Ignored by SQLite until pruning exists.
MaxLegs int `yaml:"max_legs"`
}
type ControlPlaneConfig ¶
type ControlPlaneConfig struct {
Enabled bool `yaml:"enabled"`
Store string `yaml:"store"`
SQLitePath string `yaml:"sqlite_path"`
PostgresDSN string `yaml:"postgres_dsn"`
RecordingPolicy string `yaml:"recording_policy"`
RequiredCategories []string `yaml:"required_categories"`
Query ControlPlaneQueryConfig `yaml:"query"`
Retention ControlPlaneRetentionConfig `yaml:"retention"`
RedactionDefault string `yaml:"redaction_default"`
}
ControlPlaneConfig controls the optional control-plane persistence, query, and event-ledger capability (spec control-plane-persistence-query-event-ledger). The capability is disabled by default; enabling recording or query exposure requires explicit typed configuration and startup validation here.
Excluded enterprise features (billing, identity provisioning, policy engines, GUI, marketplace, provider forwarding, historical migration) intentionally have no configuration surface here (requirements 10.1–10.6).
type ControlPlaneQueryConfig ¶
type ControlPlaneQueryConfig struct {
Enabled bool `yaml:"enabled"`
PathPrefix string `yaml:"path_prefix"`
DefaultPageSize int `yaml:"default_page_size"`
MaxPageSize int `yaml:"max_page_size"`
MaxTimeWindow string `yaml:"max_time_window"`
}
ControlPlaneQueryConfig controls protected operator query exposure. Query routes mount only when control-plane is enabled, query is enabled, and the diagnostics shared-secret posture allows protected surfaces.
func (ControlPlaneQueryConfig) MaxTimeWindowDuration ¶
func (q ControlPlaneQueryConfig) MaxTimeWindowDuration() (time.Duration, error)
MaxTimeWindowDuration returns the effective query max time window as a time.Duration plus any validation error.
Disabled-query semantics: when q.Enabled is false the query surface is not mounted, so an invalid MaxTimeWindow is ignored and (0, nil) is returned even if the value is unparseable.
When q.Enabled is true, an empty MaxTimeWindow returns (0, nil) (meaning no bound; the query service applies its own defaults). A non-empty value must parse to a positive duration; invalid, zero, and negative durations return an error with the same wording used by [validateControlPlaneQuery] so callers that skip Validate (for example runtimebundle assembly fed an unvalidated config) still fail fast instead of silently degrading to an unbounded query service.
type ControlPlaneRetentionConfig ¶
type ControlPlaneRetentionConfig struct {
Enabled bool `yaml:"enabled"`
Window string `yaml:"window"`
}
ControlPlaneRetentionConfig controls optional retention/redaction processing. No hidden background worker is started unless explicitly configured later.
type DatabaseConfig ¶
type DatabaseConfig struct {
ConnectionMode DatabaseConnectionMode `yaml:"connection_mode"`
SchemaMode DatabaseSchemaMode `yaml:"schema_mode"`
MaxOpenConns int `yaml:"max_open_conns"`
MaxIdleConns int `yaml:"max_idle_conns"`
ConnMaxLifetime string `yaml:"conn_max_lifetime"`
ConnMaxIdleTime string `yaml:"conn_max_idle_time"`
}
DatabaseConfig is optional connection pool tuning for managed PostgreSQL handles opened by the proxy (see internal/infra/db). Omitted or zero values preserve driver defaults when no store is postgres; max_open_conns must be > 0 when any store is postgres. ConnectionMode and SchemaMode apply only to the dual-plane authority, concurrency, and metering PostgreSQL runtime paths. Other PostgreSQL stores retain their own owning lifecycle and compatibility migration behavior.
func (DatabaseConfig) EffectiveConnectionMode ¶
func (c DatabaseConfig) EffectiveConnectionMode() DatabaseConnectionMode
func (DatabaseConfig) EffectiveSchemaMode ¶
func (c DatabaseConfig) EffectiveSchemaMode() DatabaseSchemaMode
type DatabaseConnectionMode ¶
type DatabaseConnectionMode string
const ( DatabaseConnectionModeDirect DatabaseConnectionMode = "direct" DatabaseConnectionModeTransactionPool DatabaseConnectionMode = "transaction_pool" )
type DatabasePoolSettings ¶
type DatabasePoolSettings struct {
MaxOpenConns int
MaxIdleConns int
ConnMaxLifetime time.Duration
ConnMaxIdleTime time.Duration
}
DatabasePoolSettings holds validated optional *sql.DB pool tuning from DatabaseConfig. Zero values mean unset (driver defaults) when no managed PostgreSQL store is selected. When any store is postgres, Validate requires MaxOpenConns > 0 (fail-closed). Use ParseDatabasePoolSettings after YAML decode and alongside Validate for full checks.
func ParseDatabasePoolSettings ¶
func ParseDatabasePoolSettings(d DatabaseConfig) (DatabasePoolSettings, error)
ParseDatabasePoolSettings parses DatabaseConfig into DatabasePoolSettings and validates numeric and duration fields.
type DatabaseSchemaMode ¶
type DatabaseSchemaMode string
const ( DatabaseSchemaModeAutoMigrate DatabaseSchemaMode = "auto_migrate" DatabaseSchemaModeVerifyOnly DatabaseSchemaMode = "verify_only" )
type DiagnosticsConfig ¶
type DiagnosticsConfig struct {
Enabled bool `yaml:"enabled"`
HealthPath string `yaml:"health_path"`
AttemptsPath string `yaml:"attempts_path"`
// InventoryPath registers a JSON plugin inventory endpoint when non-empty (e.g. "/debug/inventory").
InventoryPath string `yaml:"inventory_path"`
// RouteTracePath registers a JSON ring buffer of recent routing decisions when non-empty.
RouteTracePath string `yaml:"route_trace_path"`
// PprofPath registers net/http/pprof handlers under this prefix when diagnostics.enabled is true
// (e.g. "/debug/pprof"). Leave empty to disable. Do not expose publicly without access controls.
PprofPath string `yaml:"pprof_path"`
// route trace, and pprof routes (not on health). Use a long random value in production.
SharedSecret string `yaml:"shared_secret"`
}
type EffectiveAutoResumeConfig ¶
type EffectiveAutoResumeConfig struct {
Enabled bool
IdleTimeout time.Duration
GracePeriod time.Duration
PostOutputPolicy StreamRecoveryPostOutputPolicy
EmitWarning bool
KeepaliveInterval time.Duration
}
func EffectiveStreamRecoveryAutoResume ¶
func EffectiveStreamRecoveryAutoResume(cfg *Config, overrides StreamRecoveryOverrides) (EffectiveAutoResumeConfig, error)
type EffectiveConfig ¶
type EffectiveConfig struct {
Config *Config
Identity EffectiveIdentity
Category LoadCategory
LoadedAt time.Time
}
EffectiveConfig is the normalized effective candidate produced by LoadEffective. Identity.PrivateDigest is private; PublicFingerprint is secret-safe.
func LoadEffective ¶
func LoadEffective(ctx context.Context, raw []byte, opts LoadEffectiveOptions) (*EffectiveConfig, error)
LoadEffective runs the deterministic effective pipeline: classify → strict one-document decode → defaults → fixed stream-recovery overrides → feature injection → core validation → extra validation → private/public identity.
type EffectiveIdentity ¶
EffectiveIdentity is the private raw/effective identity used for no-op decisions (requirements 3.6–3.8). PrivateDigest must never appear in logs, APIs, or public status. PublicFingerprint is secret-safe generation metadata.
func ComputeEffectiveIdentity ¶
func ComputeEffectiveIdentity(cfg *Config) (EffectiveIdentity, error)
ComputeEffectiveIdentity returns the private digest over the full effective config and a secret-safe public fingerprint over a redacted projection.
type ExecutionCompositionPolicy ¶
type ExecutionCompositionPolicy string
ExecutionCompositionPolicy controls whether composite routing expressions can include agent runtimes.
const ( // ExecutionCompositionSafe restricts selector composition to pure inference backends; agent runtimes are allowed only as direct routes. ExecutionCompositionSafe ExecutionCompositionPolicy = "safe" // ExecutionCompositionUnrestricted allows arbitrary composition of agent runtimes and inference backends. ExecutionCompositionUnrestricted ExecutionCompositionPolicy = "unrestricted" )
type GeoIPClientConfig ¶
type GeoIPClientConfig struct {
Source ClientIPSource `yaml:"source"`
TrustedProxies []string `yaml:"trusted_proxies"`
}
type GeoIPConfig ¶
type GeoIPConfig struct {
Enabled bool `yaml:"enabled"`
Order string `yaml:"order"`
Allow GeoIPRuleConfig `yaml:"allow"`
Deny GeoIPRuleConfig `yaml:"deny"`
ClientIP GeoIPClientConfig `yaml:"client_ip"`
Database GeoIPDBConfig `yaml:"database"`
}
GeoIPConfig describes the reloadable request-plane policy and the optional process-owned country database source.
type GeoIPDBConfig ¶
type GeoIPDBConfig struct {
Source GeoIPDatabaseSource `yaml:"source"`
Edition string `yaml:"edition"`
Directory string `yaml:"directory"`
LocalPath string `yaml:"local_path"`
Update GeoIPUpdateConfig `yaml:"update"`
}
type GeoIPDatabaseSource ¶
type GeoIPDatabaseSource string
const ( GeoIPDatabaseSourceManaged GeoIPDatabaseSource = "managed" GeoIPDatabaseSourceLocal GeoIPDatabaseSource = "local" )
type GeoIPRuleConfig ¶
type GeoIPUpdateConfig ¶
type HTTPClientConfig ¶
type HTTPClientConfig struct {
// TrustEnvironmentProxy when true (default) uses http.ProxyFromEnvironment for outbound requests.
// When false, the transport ignores HTTP_PROXY/HTTPS_PROXY/NO_PROXY (reduces deputy risk if env is untrusted).
// Omitted or null in YAML defaults to true in [LoadFile] / [EffectiveTrustEnvironmentProxy].
TrustEnvironmentProxy *bool `yaml:"trust_environment_proxy"`
// MaxIdleConns is the Transport MaxIdleConns pool cap. Omit to use the bundled default (~100).
MaxIdleConns *int `yaml:"max_idle_conns,omitempty"`
// MaxIdleConnsPerHost defaults to 64 when omitted (Go's default of 2 is usually too low for LLM APIs).
MaxIdleConnsPerHost *int `yaml:"max_idle_conns_per_host,omitempty"`
// IdleConnTimeout is a Go duration string (e.g. "90s"). Empty uses the httpclient default.
IdleConnTimeout string `yaml:"idle_conn_timeout"`
// ResponseHeaderTimeout bounds waiting for response headers (e.g. "60s"). Empty uses default.
ResponseHeaderTimeout string `yaml:"response_header_timeout"`
// DialTimeout is the net.Dialer Timeout for establishing connections (e.g. "30s").
DialTimeout string `yaml:"dial_timeout"`
// KeepAlive is the net.Dialer KeepAlive interval (e.g. "30s").
KeepAlive string `yaml:"keep_alive"`
// TLSHandshakeTimeout caps TLS handshakes (e.g. "10s").
TLSHandshakeTimeout string `yaml:"tls_handshake_timeout"`
// ExpectContinueTimeout is the Transport expect-continue timeout (e.g. "1s").
ExpectContinueTimeout string `yaml:"expect_continue_timeout"`
// ClientTimeout is [http.Client.Timeout] for the full request including body (e.g. "120s").
ClientTimeout string `yaml:"client_timeout"`
}
HTTPClientConfig tunes the shared outbound HTTP client used for upstream LLM calls.
type HTTPHeadersConfig ¶
type HTTPHeadersConfig struct {
APIKey []string `yaml:"api_key"`
Route []string `yaml:"route"`
SessionID []string `yaml:"session_id"`
ResumeToken []string `yaml:"resume_token"`
ALegID []string `yaml:"a_leg_id"`
SessionHint []string `yaml:"session_hint"`
Trace []string `yaml:"trace"`
DiagnosticsSecret []string `yaml:"diagnostics_secret"`
}
HTTPHeadersConfig lists extra inbound header names operators may send in addition to the standard LIP/vendor defaults. Empty lists keep the defaults. Configured names are appended after defaults (first non-empty wins), so X-LIP-Route still wins when both a default and an alias are present.
func (HTTPHeadersConfig) Effective ¶
func (c HTTPHeadersConfig) Effective() lipsdk.HTTPHeaders
Effective merges operator aliases after lipsdk.DefaultHTTPHeaders.
type HooksConfig ¶
type HooksConfig struct {
// ToolReactorErrorPolicy is one of: fail_open (default), fail_closed, swallow_event.
ToolReactorErrorPolicy string `yaml:"tool_reactor_error_policy"`
}
HooksConfig carries core hook-bus tuning (not plugin opaque payloads).
type InterleavedConfig ¶
type InterleavedConfig struct {
// Enabled turns on interleaved thinking. Disabled by default.
Enabled bool `yaml:"enabled"`
}
InterleavedConfig controls interleaved thinking (`[thinker]` selectors).
Minimum enablement and configuration values required for route planning. Feature-specific defaults, prompts, and instruction loading are owned by internal/plugins/features/interleavedthinking.
type LargePayloadFastPathConfig ¶
type LargePayloadFastPathConfig struct {
// Enabled gates the optimization. Default false.
Enabled bool `yaml:"enabled"`
// ThresholdBytes is the decoded-size consideration gate. Required > 0 when
// enabled.
ThresholdBytes int64 `yaml:"threshold_bytes"`
// MemorySpoolBytes bounds retained request bytes in Go heap per capture.
// Required > 0 and <= MaxInflightSpoolBytes when enabled.
MemorySpoolBytes int64 `yaml:"memory_spool_bytes"`
// MaxInflightSpoolBytes bounds global logical spool reservation.
// Required > 0 when enabled. Optimization budget only (see above).
MaxInflightSpoolBytes int64 `yaml:"max_inflight_spool_bytes"`
// MaxSemanticFactBytes bounds profile-derived metadata. Required > 0 when
// enabled.
MaxSemanticFactBytes int64 `yaml:"max_semantic_fact_bytes"`
// SpoolDir optionally overrides the spill directory. Empty selects the OS
// default temp directory. Validated during candidate generation/reload;
// an invalid value rejects the candidate and preserves last-good.
SpoolDir string `yaml:"spool_dir"`
}
LargePayloadFastPathConfig controls the optional large-payload streaming fast path (server.large_payload_fast_path, design section 3).
The feature is default-off: a zero config keeps the existing canonical path with no spool/scanner/wire allocation beyond a trivial enabled check (Requirements 1, 22).
threshold_bytes controls consideration only; it never proves eligibility and never changes the existing MaxRequestBodyBytes admission policy, whose defaults stay unchanged (Requirement 2).
max_inflight_spool_bytes is an optimization budget, not a new request-admission error source: reservation exhaustion declines to the canonical path and never produces a new 413. Canonical fallback may still allocate per the pre-existing path, so this budget is not global OOM admission (Requirement 20).
Confidentiality: spool files can contain plaintext prompt data. Operators must place spool_dir on a protected volume/filesystem; spool paths never enter logs/metrics/traces (Requirement 20).
func (LargePayloadFastPathConfig) EffectiveMaxInflightSpoolBytes ¶
func (c LargePayloadFastPathConfig) EffectiveMaxInflightSpoolBytes() int64
EffectiveMaxInflightSpoolBytes returns MaxInflightSpoolBytes when positive, else the default.
func (LargePayloadFastPathConfig) EffectiveMaxSemanticFactBytes ¶
func (c LargePayloadFastPathConfig) EffectiveMaxSemanticFactBytes() int64
EffectiveMaxSemanticFactBytes returns MaxSemanticFactBytes when positive, else the default.
func (LargePayloadFastPathConfig) EffectiveMemorySpoolBytes ¶
func (c LargePayloadFastPathConfig) EffectiveMemorySpoolBytes() int64
EffectiveMemorySpoolBytes returns MemorySpoolBytes when positive, else the default.
func (LargePayloadFastPathConfig) EffectiveSpoolDir ¶
func (c LargePayloadFastPathConfig) EffectiveSpoolDir() string
EffectiveSpoolDir returns the trimmed spool directory; empty means the OS default temp directory.
func (LargePayloadFastPathConfig) EffectiveThresholdBytes ¶
func (c LargePayloadFastPathConfig) EffectiveThresholdBytes() int64
EffectiveThresholdBytes returns ThresholdBytes when positive, else the default.
type LoadCategory ¶
type LoadCategory string
LoadCategory is a bounded, secret-safe source/decode classification. Values identify failure classes only and never contain raw YAML or secrets.
const ( CategoryOK LoadCategory = "ok" CategoryMissing LoadCategory = "source_missing" CategoryEmpty LoadCategory = "source_empty" CategoryWhitespace LoadCategory = "source_whitespace" CategoryOversize LoadCategory = "source_oversize" CategoryUnstable LoadCategory = "source_unstable" CategoryNonAtomicUpdate LoadCategory = "source_non_atomic_update" CategoryUnsupportedType LoadCategory = "source_unsupported_type" CategoryMalformedYAML LoadCategory = "decode_malformed_yaml" CategoryMultipleDocuments LoadCategory = "decode_multiple_documents" CategoryTrailingContent LoadCategory = "decode_trailing_content" CategoryUnknownCoreField LoadCategory = "decode_unknown_core_field" CategoryPartialUnreadable LoadCategory = "source_partial_unreadable" )
type LoadEffectiveOptions ¶
type LoadEffectiveOptions struct {
// ConfigDir sets Config.ConfigDir when non-empty (typically the directory of
// the fixed source path).
ConfigDir string
// FixedStreamRecovery, when non-nil, materializes CLI/env stream-recovery
// overrides into the effective config (even when the struct is zero).
FixedStreamRecovery *StreamRecoveryOverrides
// NormalizeYAML, when non-nil, transforms raw configuration bytes before
// strict decode (e.g. legacy feature syntax normalization).
NormalizeYAML func([]byte) ([]byte, error)
// InjectFeatures is the standard-distribution feature injection seam.
InjectFeatures func(*Config) error
// ExtraValidate runs after core Validate (routing aliases, prefix checks, …).
ExtraValidate func(*Config) error
}
LoadEffectiveOptions configures the shared effective-load pipeline used by startup, check-config, and runtime reload. Feature injection and extra validation are explicit seams so core/config does not import plugin packages.
type LoadError ¶
type LoadError struct {
Category LoadCategory
// contains filtered or unexported fields
}
LoadError is a secret-safe effective-load / decode failure.
type LoggingConfig ¶
type LoggingConfig struct {
// Level is one of: debug, info, warn, error (case-insensitive). Empty defaults to info in LoadFile/Validate.
Level string `yaml:"level"`
// Format is json or text (case-insensitive). Empty defaults to json in LoadFile/Validate.
Format string `yaml:"format"`
// AddSource adds source file/line to each record when true.
AddSource bool `yaml:"add_source"`
// AccessLog emits one structured line per HTTP request when true.
AccessLog bool `yaml:"access_log"`
// AccessLogSkipPaths are URL path prefixes (must start with /) for which access logs are suppressed.
AccessLogSkipPaths []string `yaml:"access_log_skip_paths"`
// AccessLogIncludeRawPath when true adds the full URL path to access logs (higher cardinality).
// Default false: only route_group.
AccessLogIncludeRawPath bool `yaml:"access_log_include_raw_path"`
}
LoggingConfig controls process-wide slog output and optional HTTP access logs.
type MeteringConfig ¶
type MeteringConfig struct {
Enabled bool `yaml:"enabled"`
Journal MeteringJournalConfig `yaml:"journal"`
}
MeteringConfig enables the optional durable metering journal (requirements 13.1–13.5). When Enabled is false, runtime leaves Executor.MeteringRecorder nil (requirement 17.1).
type MeteringJournalConfig ¶
type MeteringJournalConfig struct {
Store string `yaml:"store"` // memory | sqlite | postgres; empty with enabled defaults to memory
SQLitePath string `yaml:"sqlite_path"`
PostgresDSN string `yaml:"postgres_dsn"`
}
MeteringJournalConfig selects the journal store backend.
type MetricsConfig ¶
type MetricsConfig struct {
// Enabled exposes lip_http_* metrics and process/go collectors when true.
// When false (zero value), no /metrics handler is registered (legacy behavior).
Enabled bool `yaml:"enabled"`
// Path is the HTTP path for Prometheus scraping (e.g. "/metrics"). Empty defaults to /metrics in LoadFile.
Path string `yaml:"path"`
// ExemplarsEnabled attaches trace_id exemplars to selected histograms and enables OpenMetrics on /metrics.
ExemplarsEnabled bool `yaml:"exemplars_enabled"`
}
MetricsConfig controls the Prometheus /metrics endpoint.
type ModelAliasConfig ¶
type ModelAliasConfig struct {
Pattern string `yaml:"pattern"`
Replacement string `yaml:"replacement"`
}
ModelAliasConfig is one regexp-based rewrite of an incoming route selector (see internal/core/routing/aliases.go).
type ModelCatalogBackendModelOverrideEntry ¶
type ModelCatalogBackendModelOverrideEntry struct {
Backend string `yaml:"backend"`
Model string `yaml:"model"`
Tools *bool `yaml:"tools,omitempty"`
StructuredOutputs *bool `yaml:"structured_outputs,omitempty"`
Reasoning *bool `yaml:"reasoning,omitempty"`
Vision *bool `yaml:"vision,omitempty"`
Documents *bool `yaml:"documents,omitempty"`
ContextLimitTokens *int64 `yaml:"context_limit_tokens,omitempty"`
InputLimitTokens *int64 `yaml:"input_limit_tokens,omitempty"`
OutputLimitTokens *int64 `yaml:"output_limit_tokens,omitempty"`
}
ModelCatalogBackendModelOverrideEntry is one backend+model pair override row from configuration.
type ModelCatalogConfig ¶
type ModelCatalogConfig struct {
// Enabled when true uses the latest valid local catalog snapshot for request-time decisions (when present).
Enabled bool `yaml:"enabled"`
// ExternalUpdatesEnabled when true allows periodic background fetches of the catalog source (independent of Enabled).
ExternalUpdatesEnabled bool `yaml:"external_updates_enabled"`
// UpdateInterval is a Go duration string (e.g. "1h") for automatic refresh when ExternalUpdatesEnabled is true.
UpdateInterval string `yaml:"update_interval"`
// FetchTimeout is an optional Go duration string applied to catalog HTTP GET when the request context has no
// deadline (0 or empty = rely on transport/client timeouts only).
FetchTimeout string `yaml:"fetch_timeout"`
// SourceURL is the HTTPS (or HTTP) URL for the catalog snapshot when ExternalUpdatesEnabled is true.
SourceURL string `yaml:"source_url"`
// CachePath is the local filesystem path for the persisted snapshot file used when Enabled or ExternalUpdatesEnabled.
CachePath string `yaml:"cache_path"`
// DiagnosticsPath when non-empty registers catalog status JSON under this absolute URL path (must not overlap other diagnostics paths).
DiagnosticsPath string `yaml:"diagnostics_path"`
// ModelOverrides are operator facts keyed by route/catalog model name (see spec requirement 5.1).
ModelOverrides []ModelCatalogModelOverrideEntry `yaml:"model_overrides"`
// BackendModelOverrides take precedence over ModelOverrides for matching backend/model pairs (requirement 5.2).
BackendModelOverrides []ModelCatalogBackendModelOverrideEntry `yaml:"backend_model_overrides"`
}
ModelCatalogConfig controls models.dev catalog usage, local cache, optional external refresh, and operator overrides. Concrete fetch/cache adapters live outside core config; this struct is the typed operator surface (see design: ModelCatalogConfig).
func (ModelCatalogConfig) FetchTimeoutDuration ¶
func (mc ModelCatalogConfig) FetchTimeoutDuration() (d time.Duration, ok bool)
FetchTimeoutDuration returns a positive parsed model_catalog.fetch_timeout duration.
func (ModelCatalogConfig) UpdateIntervalDuration ¶
func (mc ModelCatalogConfig) UpdateIntervalDuration() (d time.Duration, ok bool)
UpdateIntervalDuration returns a positive parsed model_catalog.update_interval duration. Call after successful config validation when the string must be well-formed for enabled refresh paths.
type ModelCatalogModelOverrideEntry ¶
type ModelCatalogModelOverrideEntry struct {
Model string `yaml:"model"`
Tools *bool `yaml:"tools,omitempty"`
StructuredOutputs *bool `yaml:"structured_outputs,omitempty"`
Reasoning *bool `yaml:"reasoning,omitempty"`
Vision *bool `yaml:"vision,omitempty"`
Documents *bool `yaml:"documents,omitempty"`
ContextLimitTokens *int64 `yaml:"context_limit_tokens,omitempty"`
InputLimitTokens *int64 `yaml:"input_limit_tokens,omitempty"`
OutputLimitTokens *int64 `yaml:"output_limit_tokens,omitempty"`
}
ModelCatalogModelOverrideEntry is one model-scoped override row from configuration. Optional capability and limit fields use YAML omission for "unknown"; for booleans, true means explicitly supported and false means explicitly unsupported (runtimebundle maps into modelcatalog).
type ModelInventoryConfig ¶
type ModelInventoryConfig struct {
CachePath string `yaml:"cache_path"`
RefreshEnabled *bool `yaml:"refresh_enabled"`
RefreshInterval string `yaml:"refresh_interval"`
FetchTimeout string `yaml:"fetch_timeout"`
// DiagnosticsPath registers protected backend model-registry discovery JSON when non-empty
// (e.g. "/debug/model-registry"). Distinct from model_catalog.diagnostics_path (models.dev).
DiagnosticsPath string `yaml:"diagnostics_path"`
}
func (ModelInventoryConfig) EffectiveRefreshEnabled ¶
func (mc ModelInventoryConfig) EffectiveRefreshEnabled() bool
func (ModelInventoryConfig) FetchTimeoutDuration ¶
func (mc ModelInventoryConfig) FetchTimeoutDuration() time.Duration
func (ModelInventoryConfig) RefreshIntervalDuration ¶
func (mc ModelInventoryConfig) RefreshIntervalDuration() time.Duration
type ObservabilityConfig ¶
type ObservabilityConfig struct {
Metrics MetricsConfig `yaml:"metrics"`
Tracing TracingConfig `yaml:"tracing"`
}
ObservabilityConfig toggles Prometheus metrics and OpenTelemetry tracing.
type PluginConfig ¶
type PluginConfig struct {
// Kind is the bundled factory id used for registry lookup (e.g. openai-responses).
// When empty, ID is treated as both factory kind and instance id (legacy single-field configs).
Kind string `yaml:"kind,omitempty"`
// ID is the runtime instance id: routing keys, executor backend map keys, and duplicate detection.
ID string `yaml:"id"`
Enabled bool `yaml:"enabled"`
Config yaml.Node `yaml:"config"`
}
PluginConfig keeps plugin-private config opaque to the core.
func (PluginConfig) FactoryID ¶
func (p PluginConfig) FactoryID() string
FactoryID returns the registry/factory identifier for this plugin row.
func (PluginConfig) InstanceID ¶
func (p PluginConfig) InstanceID() string
InstanceID returns the configured runtime instance identifier (never empty for valid configs).
type PluginsConfig ¶
type PluginsConfig struct {
BackendDiscovery BackendDiscoveryConfig `yaml:"backend_discovery"`
Frontends []PluginConfig `yaml:"frontends"`
Backends []PluginConfig `yaml:"backends"`
Features []PluginConfig `yaml:"features"`
}
type RoutingAffinityConfig ¶
type RoutingConfig ¶
type RoutingConfig struct {
MaxAttempts int `yaml:"max_attempts"`
// DefaultRoute is the selector used when the client omits X-LIP-Route (e.g. "openai-responses:gpt-4o-mini").
DefaultRoute string `yaml:"default_route"`
Health RoutingHealthConfig `yaml:"health"`
Affinity RoutingAffinityConfig `yaml:"affinity"`
Transport RoutingTransportConfig `yaml:"transport"`
// ExecutionCompositionPolicy controls whether multi-leaf routing compositions (weighted, parallel, thinker, failover)
// can include whole-agent/orchestration runtimes. Defaults to "safe".
ExecutionCompositionPolicy ExecutionCompositionPolicy `yaml:"execution_composition_policy"`
// OverrideAdmin is the opt-in protected HTTP surface for A-leg routing overrides.
// Disabled by default. Disabling the endpoint does not clear persisted override state.
OverrideAdmin RoutingOverrideAdminConfig `yaml:"override_admin"`
}
func (RoutingConfig) EffectiveExecutionCompositionPolicy ¶
func (c RoutingConfig) EffectiveExecutionCompositionPolicy() ExecutionCompositionPolicy
EffectiveExecutionCompositionPolicy returns the normalized policy, defaulting empty to safe.
type RoutingHealthConfig ¶
type RoutingHealthConfig struct {
CircuitBreaker CircuitBreakerConfig `yaml:"circuit_breaker"`
}
type RoutingOverrideAdminConfig ¶
type RoutingOverrideAdminConfig struct {
Enabled bool `yaml:"enabled"`
PathPrefix string `yaml:"path_prefix"`
MaxBodyBytes int64 `yaml:"max_body_bytes"`
}
RoutingOverrideAdminConfig controls the protected GET/PUT/DELETE routing-override admin resource. Enablement is false by default.
type RoutingTransportConfig ¶
type RoutingTransportConfig struct {
FallbackPolicy string `yaml:"fallback_policy"`
}
type SecureSessionConfig ¶
type SecureSessionConfig struct {
// Enabled turns on secure-session validation and runtime wiring (store, tokens, audit gates).
// Omitted in YAML defaults to enabled; use a pointer so explicit false can be rejected at validation time.
Enabled *bool `yaml:"enabled"`
// Store is "memory" (non-durable), "sqlite" (local durable), or "postgres" (managed durable).
// Empty is normalized to "memory" in [LoadFile] when Enabled.
Store string `yaml:"store"`
// SQLitePath is the database file path when store is "sqlite".
SQLitePath string `yaml:"sqlite_path"`
// PostgresDSN is the connection string when store is "postgres".
PostgresDSN string `yaml:"postgres_dsn"`
// ResumeWindow is a Go duration string for inactivity-based resume limits; empty means no fixed
// window (policy default).
ResumeWindow string `yaml:"resume_window"`
// TokenFingerprintKey is deployment secret material used to HMAC resume-token fingerprints; required for sqlite store.
TokenFingerprintKey string `yaml:"token_fingerprint_key"`
// AuditDurability is "best_effort" or "durable"; durable requires a durable store (sqlite or postgres)
// and a long token fingerprint key.
AuditDurability string `yaml:"audit_durability"`
// RedactionDefault is "standard" or "strict" for operator-visible session payloads (diagnostics);
// invalid values rejected when enabled.
RedactionDefault string `yaml:"redaction_default"`
// DiagnosticsExposeSummaries registers operator session summary routes when true (requires DiagnosticsPathPrefix
// and a non-empty diagnostics.shared_secret, same minimum length as other protected diagnostics routes).
DiagnosticsExposeSummaries bool `yaml:"diagnostics_expose_summaries"`
// DiagnosticsPathPrefix is the URL prefix for secure-session diagnostics (e.g. "/debug/sessions");
// must start with "/".
DiagnosticsPathPrefix string `yaml:"diagnostics_path_prefix"`
// NonDurableWarning is "silent", "log", or "strict" when store is non-durable (memory): strict fails
// validation when audit requires durability.
NonDurableWarning string `yaml:"non_durable_warning"`
// RequireWorkspaceID when true rejects secure-session turns when no workspace id was resolved
// (maps to [WorkspaceMatchRequired] on BeginTurn; Req 11.1 / 11.6).
RequireWorkspaceID bool `yaml:"require_workspace_id"`
// WorkspaceResolveOnError is "fail_open" (default) or "fail_closed". When fail_closed, workspace
// resolver errors reject the request instead of continuing with an empty workspace (Req 11.6).
WorkspaceResolveOnError string `yaml:"workspace_resolve_on_error"`
// ResumeTokenBindPrincipalOnly when true fingerprints resume tokens using only the authenticated
// principal id (not agent digest or first-message digest), so benign client metadata drift
// between turns does not invalidate bearer resumes.
ResumeTokenBindPrincipalOnly bool `yaml:"resume_token_bind_principal_only"`
// SQLQueryCacheTTL is a Go duration string enabling process-local TTL caching of session existence
// and transcript_enabled reads in durable SQL secure-session stores. Empty disables caching.
SQLQueryCacheTTL string `yaml:"sql_query_cache_ttl"`
// SQLQueryCacheMaxEntries caps entries per logical cache when SQLQueryCacheTTL is set; zero uses a store default.
SQLQueryCacheMaxEntries int `yaml:"sql_query_cache_max_entries"`
}
SecureSessionConfig controls the core-owned secure session layer (resume proofs, durable evidence, diagnostics). When Enabled is omitted (nil), secure sessions default to on with store memory unless overridden. Explicit enabled: false is rejected by validation (legacy continuity-only executor path was removed).
type SelfDefenseAdaptiveConfig ¶
type SelfDefenseAdaptiveConfig struct {
AuthFailures *int `yaml:"auth_failures"`
Window string `yaml:"window"`
InitialQuarantine string `yaml:"initial_quarantine"`
MaxQuarantine string `yaml:"max_quarantine"`
StateTTL string `yaml:"state_ttl"`
MaxEntries *int `yaml:"max_entries"`
ExemptCIDRs []string `yaml:"exempt_cidrs"`
}
SelfDefenseAdaptiveConfig carries the request-policy fields (reloadable) plus the process-state sizing fields (restart-required in v1).
type SelfDefenseConfig ¶
type SelfDefenseConfig struct {
Enabled *bool `yaml:"enabled"`
ImpossiblePaths *bool `yaml:"impossible_paths"`
Adaptive SelfDefenseAdaptiveConfig `yaml:"adaptive"`
}
SelfDefenseConfig is the typed ingress self-defense surface. Enabled and ImpossiblePaths are presence-aware so omitted means the documented default true while explicit false is preserved. No process state is represented here.
type ServerConfig ¶
type ServerConfig struct {
Address string `yaml:"address"`
AuthMode AuthMode `yaml:"auth_mode"`
// MaxRequestBodyBytes caps HTTP request bodies for bundled frontends. Zero selects
// each handler's default limit (see internal/plugins/frontends/reqbody).
MaxRequestBodyBytes int64 `yaml:"max_request_body_bytes"`
// ReadHeaderTimeout is a Go duration string (e.g. "10s") for [http.Server.ReadHeaderTimeout].
// Empty defaults to 10s (historical stdhttp behavior).
ReadHeaderTimeout string `yaml:"read_header_timeout"`
// ReadTimeout is [http.Server.ReadTimeout] (full request body read + per-connection read deadlines).
// Empty defaults to 30s.
ReadTimeout string `yaml:"read_timeout"`
// WriteTimeout is [http.Server.WriteTimeout]. Empty defaults to 120s.
WriteTimeout string `yaml:"write_timeout"`
// IdleTimeout is [http.Server.IdleTimeout]. Empty defaults to 120s.
IdleTimeout string `yaml:"idle_timeout"`
// ShutdownTimeout bounds HTTP drain and host close on process shutdown.
// Empty defaults to 15s.
ShutdownTimeout string `yaml:"shutdown_timeout"`
// MaxConcurrentDecodes caps concurrent frontend protocol decode/materialization work.
// Zero selects the documented default (32) during validation. Body ReadAll and JSON
// preflight run before admission.
MaxConcurrentDecodes int `yaml:"max_concurrent_decodes"`
// MaxInflightDecodeBytes caps weighted in-flight decode bytes across concurrent decodes
// while decode is active. Zero selects the documented default (64 MiB) during validation.
MaxInflightDecodeBytes int64 `yaml:"max_inflight_decode_bytes"`
// MaxPendingWireEvents caps backend adapter-internal pending-event queues per stream (0 = unlimited).
MaxPendingWireEvents int `yaml:"max_pending_wire_events"`
// LargePayloadFastPath controls the optional large-payload streaming fast
// path (design section 3). Default off; see LargePayloadFastPathConfig for
// plaintext-spool and optimization-budget semantics.
LargePayloadFastPath LargePayloadFastPathConfig `yaml:"large_payload_fast_path"`
// PreRequestKeepalive optionally emits SSE comment keepalives while streaming frontends wait for
// pre-request admission handlers to finish inside executor setup.
PreRequestKeepalive PreRequestKeepaliveConfig `yaml:"pre_request_keepalive"`
}
func (ServerConfig) EffectiveIdleTimeout ¶
func (s ServerConfig) EffectiveIdleTimeout() time.Duration
EffectiveIdleTimeout returns IdleTimeout or the default (120s).
func (ServerConfig) EffectiveMaxConcurrentDecodes ¶
func (s ServerConfig) EffectiveMaxConcurrentDecodes() int
EffectiveMaxConcurrentDecodes returns MaxConcurrentDecodes when positive, otherwise the default (32).
func (ServerConfig) EffectiveMaxInflightDecodeBytes ¶
func (s ServerConfig) EffectiveMaxInflightDecodeBytes() int64
EffectiveMaxInflightDecodeBytes returns MaxInflightDecodeBytes when positive, otherwise the default (64 MiB).
func (ServerConfig) EffectiveMaxPendingWireEvents ¶
func (s ServerConfig) EffectiveMaxPendingWireEvents() int
EffectiveMaxPendingWireEvents returns MaxPendingWireEvents as configured (0 = unlimited).
func (ServerConfig) EffectiveMaxRequestBodyBytes ¶
func (s ServerConfig) EffectiveMaxRequestBodyBytes() int64
EffectiveMaxRequestBodyBytes returns MaxRequestBodyBytes when positive, otherwise zero (callers treat zero as "use handler default").
func (ServerConfig) EffectiveMaxRequestBodyBytesForBudget ¶
func (s ServerConfig) EffectiveMaxRequestBodyBytesForBudget() int64
EffectiveMaxRequestBodyBytesForBudget returns the largest single request body the server admits for decode-budget checks: MaxRequestBodyBytes when positive, otherwise the documented 8 MiB default.
func (ServerConfig) EffectivePreRequestKeepalive ¶
func (s ServerConfig) EffectivePreRequestKeepalive() EffectivePreRequestKeepaliveConfig
func (ServerConfig) EffectiveReadHeaderTimeout ¶
func (s ServerConfig) EffectiveReadHeaderTimeout() time.Duration
EffectiveReadHeaderTimeout returns ReadHeaderTimeout or the default (10s).
func (ServerConfig) EffectiveReadTimeout ¶
func (s ServerConfig) EffectiveReadTimeout() time.Duration
EffectiveReadTimeout returns ReadTimeout or the default (30s).
func (ServerConfig) EffectiveShutdownTimeout ¶
func (s ServerConfig) EffectiveShutdownTimeout() time.Duration
EffectiveShutdownTimeout returns ShutdownTimeout or the default (15s).
func (ServerConfig) EffectiveWriteTimeout ¶
func (s ServerConfig) EffectiveWriteTimeout() time.Duration
EffectiveWriteTimeout returns WriteTimeout or the default (120s).
type StreamRecoveryConfig ¶
type StreamRecoveryConfig struct {
AutoResume AutoResumeConfig `yaml:"auto_resume"`
}
type StreamRecoveryOverrides ¶
type StreamRecoveryOverrides struct {
EnvEnabled *bool
CLIEnabled *bool
EnvIdleTimeout time.Duration
CLIIdleTimeout time.Duration
EnvGracePeriod time.Duration
CLIGracePeriod time.Duration
EnvPostOutputPolicy StreamRecoveryPostOutputPolicy
CLIPostOutputPolicy StreamRecoveryPostOutputPolicy
EnvEmitWarning *bool
CLIEmitWarning *bool
}
func StreamRecoveryOverridesFromEnv ¶
func StreamRecoveryOverridesFromEnv() (StreamRecoveryOverrides, error)
type StreamRecoveryPostOutputPolicy ¶
type StreamRecoveryPostOutputPolicy string
const ( StreamRecoveryPostOutputFinishWithWarning StreamRecoveryPostOutputPolicy = "finish_with_warning" StreamRecoveryPostOutputFail StreamRecoveryPostOutputPolicy = "fail" )
type TracingConfig ¶
type TracingConfig struct {
// Enabled turns on SDK wiring, W3C propagation, and outbound HTTP tracing on the shared upstream client.
Enabled bool `yaml:"enabled"`
// ServiceName sets otel resource service.name when non-empty; otherwise OTEL_SERVICE_NAME or "lipstd".
ServiceName string `yaml:"service_name"`
// SampleRatio when set and strictly between 0 and 1 applies ParentBased(TraceIDRatioBased) for root spans.
// When nil or 1, the SDK default sampler applies (typically full sampling for new roots).
SampleRatio *float64 `yaml:"sample_ratio"`
}
TracingConfig enables OpenTelemetry traces (incoming otelhttp + OTLP export via standard OTEL_* env vars).
type WireModelForBackend ¶
WireModelForBackend resolves the default model token for a backend factory id (plugin kind) when synthesizing a fallback route selector. Supplied at composition time (typically standardplugins.DefaultWireModel) so policy stays independent of HTTP mounting.
Source Files
¶
- access_auth_model.go
- access_auth_validate.go
- accounting_authority.go
- accounting_concurrency.go
- accounting_validate.go
- auth_errors.go
- backend_discovery.go
- compatible_mode_config.go
- continuity_effective.go
- control_plane.go
- database_pool.go
- diagnostics_posture.go
- doc.go
- effective_default_route.go
- effective_identity.go
- effective_load.go
- effective_secure_session.go
- geoip.go
- hooks_parse.go
- http_headers.go
- interleaved.go
- large_payload_fast_path.go
- listen_defaults.go
- listen_loopback.go
- loader.go
- metering_validate.go
- model.go
- model_catalog.go
- model_catalog_duration.go
- model_inventory.go
- pointers.go
- registrations.go
- routing_override_admin.go
- self_defense.go
- server_limits_defaults.go
- stream_recovery.go
- strict_decode.go
- transport.go
- validate.go
- validate_helpers.go
- yaml.go