config

package
v0.1.0-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 34 Imported by: 0

Documentation

Overview

Package config owns typed runtime configuration for the core only.

Index

Constants

View Source
const (
	DefaultAccountingAuthorityEvaluationTimeout = 250 * time.Millisecond
	DefaultAccountingAuthorityCleanupTimeout    = 2 * time.Second
)
View Source
const (
	DefaultConcurrencyLeaseTTL    = 60 * time.Second
	DefaultConcurrencyRenewBefore = 15 * time.Second
)
View Source
const (
	// DefaultLargePayloadThresholdBytes is the evidence-adjustable decoded-size
	// gate for fast-path consideration (design section 3, Task 19).
	DefaultLargePayloadThresholdBytes int64 = 1 << 20
	// DefaultLargePayloadMemorySpoolBytes bounds retained request bytes in Go
	// heap per captured request.
	DefaultLargePayloadMemorySpoolBytes int64 = 64 << 10
	// DefaultLargePayloadMaxInflightSpoolBytes bounds global logical spool
	// reservation across concurrent captures.
	DefaultLargePayloadMaxInflightSpoolBytes int64 = 256 << 20
	// DefaultLargePayloadMaxSemanticFactBytes bounds profile-derived metadata
	// such as normalized part shapes.
	DefaultLargePayloadMaxSemanticFactBytes int64 = 256 << 10
)
View Source
const (
	DefaultShutdownTimeout = 15 * time.Second

	DefaultMaxConcurrentDecodes   = 32
	DefaultMaxInflightDecodeBytes = 64 << 20
)
View Source
const (
	DefaultModelInventoryRefreshInterval = time.Hour
	DefaultModelInventoryFetchTimeout    = 30 * time.Second
)
View Source
const (
	// DefaultRoutingOverrideAdminPathPrefix is used when override admin is enabled
	// without an explicit path_prefix.
	DefaultRoutingOverrideAdminPathPrefix = "/admin/routing-overrides"
	// DefaultRoutingOverrideAdminMaxBodyBytes is MaxRouteSelectorBytes plus bounded JSON overhead.
	DefaultRoutingOverrideAdminMaxBodyBytes = int64(lipapi.MaxRouteSelectorBytes + 4096)
)
View Source
const DefaultConfigMaxBytes int64 = 2 << 20 // 2 MiB

DefaultConfigMaxBytes is the shared upper bound for one configuration document. Filesystem adapters may apply a smaller startup-fixed limit.

View Source
const DefaultFallbackRouteSelector = "openai-responses:" + DefaultFallbackWireModel

DefaultFallbackRouteSelector is used only when wireModel is nil (tests / degenerate bootstrap).

View Source
const DefaultFallbackWireModel = "gpt-4o-mini"

DefaultFallbackWireModel is the compile-time model token used when synthesizing a default route selector and no WireModelForBackend mapping is available.

View Source
const DefaultMaxAttempts = 3

Variables

View Source
var (
	ErrInvalidAuthEventDelivery             = errors.New("config: invalid auth.event_delivery")
	ErrInvalidAuthEventFailurePolicy        = errors.New("config: invalid auth.event_failure_policy")
	ErrAuthLocalAPIKeysRequired             = errors.New("config: auth.local_api_keys required for local_api_key handler")
	ErrAuthLocalAPIKeysRequiredForRemoteSSO = errors.New("config: auth.local_api_keys required for remote api_key_sso")
)

Sentinel errors for access/auth validation. Use errors.Is after Validate or LoadFile.

Functions

func ApplyStreamRecoveryOverrides

func ApplyStreamRecoveryOverrides(cfg *Config, overrides StreamRecoveryOverrides) error

ApplyStreamRecoveryOverrides materializes effective auto-resume settings into cfg.

func AuthorityQueryEffectivelyExposed

func AuthorityQueryEffectivelyExposed(cfg *Config) bool

AuthorityQueryEffectivelyExposed reports whether the protected authority surface is configured to mount.

func BoolPtr

func BoolPtr(v bool) *bool

func ConfiguredDataPlanePaths

func ConfiguredDataPlanePaths(cfg *Config) []string

ConfiguredDataPlanePaths returns every operator-configured data-plane path in cfg, normalized, from the same chokepoint that validates them.

It exists so a default-on request-graph layer can know which paths the operator actually published without keeping its own copy of the configurable path surface. Those values are any normalized absolute non-root path, which includes paths inside the frozen ingress impossible-path families, so a consumer that refuses requests before the router must treat a published path as authoritative.

The error is deliberately dropped: it is produced only by the same per-field checks Validate already runs, so a configuration that reached a caller has none. A caller that needs the error uses validation instead.

func ControlPlaneQueryEffectivelyExposed

func ControlPlaneQueryEffectivelyExposed(cfg *Config) bool

ControlPlaneQueryEffectivelyExposed reports whether the protected control-plane query surface is configured for exposure. Used by diagnostics posture checks and runtimebundle wiring to decide mounting and fail-closed behavior.

func DecodeYAMLNode

func DecodeYAMLNode(n yaml.Node, into any) error

DecodeYAMLNode decodes a YAML node into a typed struct when the node is present.

func EffectiveContinuityStore

func EffectiveContinuityStore(c ContinuityConfig) string

EffectiveContinuityStore returns the continuity backing name after applying the same rules as Validate (in_memory forces memory; empty store defaults to memory).

func EffectiveDatabaseModes

func EffectiveDatabaseModes(d DatabaseConfig) (DatabaseConnectionMode, DatabaseSchemaMode, error)

EffectiveDatabaseModes returns compatibility-preserving connection and schema modes for dual-plane PostgreSQL runtime paths after validating their combination.

func EffectiveDefaultRouteSelector

func EffectiveDefaultRouteSelector(cfg *Config, wireModel WireModelForBackend) string

EffectiveDefaultRouteSelector returns the selector used when clients omit explicit routing (e.g. X-LIP-Route). Single implementation for the proxy; routing alias validation stays in package routing (see routing.ValidateModelAliasesConfig).

Resolution order:

  1. cfg.Routing.DefaultRoute when non-empty after trim
  2. first enabled backend row in cfg.Plugins.Backends, as "<instance_id>:<wireModel(factory_id)>"
  3. compile-time fallback "openai-responses:<wireModel(openai-responses)>" when wireModel is set
  4. literal "openai-responses:gpt-4o-mini" only if wireModel is nil (tests / degenerate bootstrap)

func EffectiveSecureSessionSQLQueryCache

func EffectiveSecureSessionSQLQueryCache(ss SecureSessionConfig) (ttl time.Duration, maxEntries uint64, enabled bool)

EffectiveSecureSessionSQLQueryCache returns parsed TTL and capacity for durable secure-session SQL metadata caches. enabled is false when sql_query_cache_ttl is empty. Max entries zero coerces to defaultSecureSessionSQLQueryCacheMaxEntries.

func EffectiveTransportFallbackPolicy

func EffectiveTransportFallbackPolicy(cfg *Config) lipapi.TransportFallbackPolicy

func IsExplicitLoopbackListenAddress

func IsExplicitLoopbackListenAddress(raw string) bool

IsExplicitLoopbackListenAddress reports whether raw is a conservative loopback bind (127/8, ::1, or localhost), not an all-interfaces or non-loopback address.

func ParseToolReactorErrorPolicy

func ParseToolReactorErrorPolicy(s string) sdk.ToolReactorErrorPolicy

ParseToolReactorErrorPolicy maps YAML values to the stable hook-bus policy.

func RegistrationsFromConfig

func RegistrationsFromConfig(cfg *Config) []lipsdk.Registration

RegistrationsFromConfig maps YAML plugin rows to SDK registrations. The core only forwards opaque config nodes; it does not interpret plugin-private schema.

func RoutingOverrideAdminPathPrefix

func RoutingOverrideAdminPathPrefix(cfg *Config) string

RoutingOverrideAdminPathPrefix returns the configured or default admin path prefix.

func StrictDecode

func StrictDecode(raw []byte) (*Config, LoadCategory, error)

StrictDecode decodes exactly one YAML document into Config with KnownFields. Plugin-private yaml.Node subtrees are preserved. Failures are secret-safe.

func Validate

func Validate(cfg *Config) error

Validate checks plugin identity rules and continuity/store consistency after decoding. It does not validate model_aliases; call routing.ValidateModelAliasesConfig after LoadFile, or rely on runtimebundle.Build.

func ValidateAuthLocalAPIKeyRecords

func ValidateAuthLocalAPIKeyRecords(records []AuthLocalAPIKeyRecord) error

ValidateAuthLocalAPIKeyRecords converts AuthLocalAPIKeyRecord values to core auth records and delegates to coreauth.ValidateLocalAPIKeyRecords (duplicates, required fields, min key runes).

func ValidateBackendDiscovery

func ValidateBackendDiscovery(cfg *Config) error

ValidateBackendDiscovery enforces path and production development_mode rules.

func ValidateProtectedDiagnosticsPosture

func ValidateProtectedDiagnosticsPosture(cfg *Config) error

ValidateProtectedDiagnosticsPosture rejects exposing protected operator surfaces on a non-loopback bind without diagnostics.shared_secret (minimum length enforced separately by Validate via validateDiagnosticsSecret). Health-only diagnostics never require a secret. Loopback binds may use an empty secret with protected surfaces (local trust posture).

Types

type AccessConfig

type AccessConfig struct {
	Mode        string            `yaml:"mode"`
	GeoIP       GeoIPConfig       `yaml:"geoip"`
	SelfDefense SelfDefenseConfig `yaml:"self_defense"`
}

AccessConfig selects deployment access posture (single-user vs multi-user). Empty Mode is normalized to single_user during validation/load.

type AccountingAdminConfig

type AccountingAdminConfig struct {
	Enabled      bool   `yaml:"enabled"`
	Path         string `yaml:"path"`
	MaxBodyBytes int64  `yaml:"max_body_bytes"`
}

type AccountingAuthorityConfig

type AccountingAuthorityConfig struct {
	Enabled            bool   `yaml:"enabled"`
	Mode               string `yaml:"mode"`
	Store              string `yaml:"store"`
	SQLitePath         string `yaml:"sqlite_path"`
	PostgresDSN        string `yaml:"postgres_dsn"`
	StartupPosture     string `yaml:"startup_posture"`
	UnknownAttribution string `yaml:"unknown_attribution"`
	EvaluationTimeout  string `yaml:"evaluation_timeout"`
	CleanupTimeout     string `yaml:"cleanup_timeout"`
	// SnapshotVersion is the immutable config-backed policy version (requirement 11.5).
	// Empty defaults to "static" at source construction.
	SnapshotVersion string                          `yaml:"snapshot_version"`
	Query           AccountingAuthorityQueryConfig  `yaml:"query"`
	Rules           []AccountingAuthorityRuleConfig `yaml:"rules"`
	// Quota is an optional provider account-window authority. Its presence is
	// the explicit opt-in; no telemetry is inferred as quota authority when it
	// is omitted.
	Quota *AccountingQuotaConfig `yaml:"quota"`
}

AccountingAuthorityConfig controls the optional usage-authority capability. It is disabled by default and only becomes visible when explicitly enabled.

func (AccountingAuthorityConfig) CleanupTimeoutDuration

func (a AccountingAuthorityConfig) CleanupTimeoutDuration() (time.Duration, error)

CleanupTimeoutDuration returns the bounded budget for detached settlement, release, reconciliation, advisory usage, and compensation work.

func (AccountingAuthorityConfig) DomainConfig

DomainConfig converts the validated config surface into the pure domain authority config consumed by the app layer.

func (AccountingAuthorityConfig) EvaluationTimeoutDuration

func (a AccountingAuthorityConfig) EvaluationTimeoutDuration() (time.Duration, error)

EvaluationTimeoutDuration returns the bounded admission evaluation budget. The zero configuration value is deliberately normalized to the conservative default so enabling authority cannot accidentally restore unbounded waits.

type AccountingAuthorityDimensionMatcherConfig

type AccountingAuthorityDimensionMatcherConfig struct {
	Value        scope.Value `yaml:"value"`
	MatchUnknown bool        `yaml:"match_unknown"`
}

AccountingAuthorityDimensionMatcherConfig preserves unknown versus known-empty attribution semantics for one dimension.

func (AccountingAuthorityDimensionMatcherConfig) DomainMatcher

type AccountingAuthorityDimensionsConfig

type AccountingAuthorityDimensionsConfig struct {
	Principal    AccountingAuthorityDimensionMatcherConfig            `yaml:"principal"`
	Credential   AccountingAuthorityDimensionMatcherConfig            `yaml:"credential"`
	Tenant       AccountingAuthorityDimensionMatcherConfig            `yaml:"tenant"`
	Organization AccountingAuthorityDimensionMatcherConfig            `yaml:"organization"`
	Workspace    AccountingAuthorityDimensionMatcherConfig            `yaml:"workspace"`
	Project      AccountingAuthorityDimensionMatcherConfig            `yaml:"project"`
	Department   AccountingAuthorityDimensionMatcherConfig            `yaml:"department"`
	CostCenter   AccountingAuthorityDimensionMatcherConfig            `yaml:"cost_center"`
	Backend      AccountingAuthorityDimensionMatcherConfig            `yaml:"backend"`
	Model        AccountingAuthorityDimensionMatcherConfig            `yaml:"model"`
	Route        AccountingAuthorityDimensionMatcherConfig            `yaml:"route"`
	Labels       map[string]AccountingAuthorityDimensionMatcherConfig `yaml:"labels"`
}

AccountingAuthorityDimensionsConfig carries all safe scope dimensions the authority may match against.

func (AccountingAuthorityDimensionsConfig) DomainMatcher

type AccountingAuthorityQueryConfig

type AccountingAuthorityQueryConfig struct {
	Enabled         bool   `yaml:"enabled"`
	PathPrefix      string `yaml:"path_prefix"`
	DefaultPageSize int    `yaml:"default_page_size"`
	MaxPageSize     int    `yaml:"max_page_size"`
}

AccountingAuthorityQueryConfig controls the protected status and bounded query routes for authority state.

type AccountingAuthorityRuleConfig

type AccountingAuthorityRuleConfig struct {
	ID                   string                              `yaml:"id"`
	Kind                 string                              `yaml:"kind"`
	Mode                 string                              `yaml:"mode"`
	Unit                 string                              `yaml:"unit"`
	Limit                int64                               `yaml:"limit"`
	Currency             string                              `yaml:"currency"`
	AuthorityRequirement string                              `yaml:"authority_requirement"`
	FailureBehavior      string                              `yaml:"failure_behavior"`
	Perspective          string                              `yaml:"perspective"`
	LifecycleScope       string                              `yaml:"lifecycle_scope"`
	Basis                string                              `yaml:"basis"`
	Namespace            string                              `yaml:"namespace"`
	Version              string                              `yaml:"version"`
	Window               AccountingAuthorityWindowConfig     `yaml:"window"`
	Match                AccountingAuthorityDimensionsConfig `yaml:"match"`
}

AccountingAuthorityRuleConfig mirrors the pure domain rule shape with YAML-friendly primitives.

func (AccountingAuthorityRuleConfig) DomainRule

func (r AccountingAuthorityRuleConfig) DomainRule(defaultMode string) (authoritydomain.Rule, error)

type AccountingAuthorityWindowConfig

type AccountingAuthorityWindowConfig struct {
	Algorithm string `yaml:"algorithm"`
	Size      string `yaml:"size"`
	Anchor    string `yaml:"anchor"`
}

AccountingAuthorityWindowConfig defines a fixed window using config-native duration and timestamp strings.

func (AccountingAuthorityWindowConfig) DomainWindow

type AccountingBillingConfig

type AccountingBillingConfig struct {
	// ReportsPath selects the protected billing report surface for an injected
	// billing composition. Empty selects /admin/billing.
	ReportsPath string `yaml:"reports_path"`
}

AccountingBillingConfig enables journal-backed monetary settlement and reports.

type AccountingConfig

type AccountingConfig struct {
	Enabled bool   `yaml:"enabled"`
	Mode    string `yaml:"mode"`
	// CountTimeout bounds provider/local count calls; empty selects the composition-root default.
	CountTimeout  string                        `yaml:"count_timeout"`
	Tokenizer     AccountingTokenizerConfig     `yaml:"tokenizer"`
	Preflight     AccountingPreflightConfig     `yaml:"preflight"`
	Ledger        AccountingLedgerConfig        `yaml:"ledger"`
	Admin         AccountingAdminConfig         `yaml:"admin"`
	Observability AccountingObservabilityConfig `yaml:"observability"`
	// StrictAuthoritative rejects backend wiring unless every configured backend can provide authoritative usage.
	StrictAuthoritative bool                       `yaml:"strict_authoritative"`
	Pricing             AccountingPricingConfig    `yaml:"pricing"`
	Authority           AccountingAuthorityConfig  `yaml:"authority"`
	Concurrency         ConcurrencyAuthorityConfig `yaml:"concurrency"`
	// Billing contains report-path configuration for an injected composition.
	// Billing is enabled only by complete host composition.
	Billing AccountingBillingConfig `yaml:"billing"`
}

type AccountingLedgerConfig

type AccountingLedgerConfig struct {
	// Store/SQLitePath/PostgresDSN/WritePolicy remain accepted for
	// backward-compatible YAML. Phase 8 no longer opens or writes this ledger;
	// Bun billingstore is the monetary journal.
	Store       string `yaml:"store"`
	SQLitePath  string `yaml:"sqlite_path"`
	PostgresDSN string `yaml:"postgres_dsn"`
	WritePolicy string `yaml:"write_policy"`
}

type AccountingModelPriceConfig

type AccountingModelPriceConfig struct {
	Backend              string `yaml:"backend"`
	Model                string `yaml:"model"`
	InputPer1M           string `yaml:"input_per_1m"`
	CachedInputPer1M     string `yaml:"cached_input_per_1m"`
	CacheWriteInputPer1M string `yaml:"cache_write_input_per_1m"`
	OutputPer1M          string `yaml:"output_per_1m"`
	ReasoningOutputPer1M string `yaml:"reasoning_output_per_1m"`
}

type AccountingObservabilityConfig

type AccountingObservabilityConfig struct {
	Enabled bool `yaml:"enabled"`
}

type AccountingPreflightConfig

type AccountingPreflightConfig struct {
	Mode                 string `yaml:"mode"`
	MaxInputTokens       int64  `yaml:"max_input_tokens"`
	MaxOutputTokens      int64  `yaml:"max_output_tokens"`
	MaxContextTokens     int64  `yaml:"max_context_tokens"`
	ClampMaxOutputTokens bool   `yaml:"clamp_max_output_tokens"`
	// UnknownOutputPolicy selects how to bound exposure when the client omits
	// max_output_tokens: require_client_limit | configured_default |
	// model_backend_maximum | clamp | deny. Empty applies the documented default.
	UnknownOutputPolicy string `yaml:"unknown_output_policy"`
}

type AccountingPricingConfig

type AccountingPricingConfig struct {
	Currency       string                       `yaml:"currency"`
	CatalogVersion string                       `yaml:"catalog_version"`
	Models         []AccountingModelPriceConfig `yaml:"models"`
}

type AccountingQuotaConfig

type AccountingQuotaConfig struct {
	ID                 string                           `yaml:"id"`
	Version            string                           `yaml:"version"`
	Method             string                           `yaml:"method"`
	StoreID            string                           `yaml:"store_id"`
	TenantID           string                           `yaml:"tenant_id"`
	ProviderAccountKey string                           `yaml:"provider_account_key"`
	PoolID             string                           `yaml:"pool_id"`
	WindowID           string                           `yaml:"window_id"`
	ResetAt            string                           `yaml:"reset_at"`
	Freshness          string                           `yaml:"freshness"`
	Required           []metering.ComponentKey          `yaml:"required"`
	Thresholds         []AccountingQuotaThresholdConfig `yaml:"thresholds"`
	Failures           AccountingQuotaFailureConfig     `yaml:"failures"`
}

AccountingQuotaConfig is the host-facing, YAML-friendly source form for one immutable provider quota policy. It contains only nonfinancial account-window identity, gauge fields, thresholds, and explicit telemetry failure actions.

func (*AccountingQuotaConfig) PolicyConfig

PolicyConfig parses the host-facing quota policy into the public immutable policy source form. CompileQuotaPolicy performs the final identity and nonfinancial policy validation.

type AccountingQuotaFailureConfig

type AccountingQuotaFailureConfig struct {
	Missing     string `yaml:"missing"`
	Stale       string `yaml:"stale"`
	Partial     string `yaml:"partial"`
	Unavailable string `yaml:"unavailable"`
	Mismatch    string `yaml:"mismatch"`
	Future      string `yaml:"future"`
}

AccountingQuotaFailureConfig makes every non-complete evidence posture independently configurable. Empty actions are normalized by the policy to fail closed.

type AccountingQuotaThresholdConfig

type AccountingQuotaThresholdConfig struct {
	Kind      string                `yaml:"kind"`
	Field     metering.ComponentKey `yaml:"field"`
	ValueKind string                `yaml:"value_kind"`
	Value     string                `yaml:"value"`
}

AccountingQuotaThresholdConfig keeps exact decimal thresholds as text so YAML never routes an allowance comparison through floating point.

type AccountingTokenizerConfig

type AccountingTokenizerConfig struct {
	DefaultEncoding string            `yaml:"default_encoding"`
	ModelMappings   map[string]string `yaml:"model_mappings"`
}

type AuthConfig

type AuthConfig struct {
	Handler            string `yaml:"handler"`
	RequiredLevel      string `yaml:"required_level"`
	EventFailurePolicy string `yaml:"event_failure_policy"`
	// EventDelivery selects how auth/session events are delivered: default (structured log sink),
	// disabled (no sink; explicit no delivery), or custom (requires BuildOptions.AuthEventSink at wiring).
	// Empty behaves like default.
	EventDelivery string                  `yaml:"event_delivery"`
	LocalAPIKeys  []AuthLocalAPIKeyRecord `yaml:"local_api_keys"`
	Remote        AuthRemoteConfig        `yaml:"remote"`
}

AuthConfig selects authentication handler, required level, event delivery policy, local key material, and remote delegation placeholders.

type AuthLocalAPIKeyRecord

type AuthLocalAPIKeyRecord struct {
	KeyID       string `yaml:"key_id"`
	PrincipalID string `yaml:"principal_id"`
	Key         string `yaml:"key"`
	// Attribution carries optional operator-controlled safe attribution for this key.
	// Missing optional fields remain unknown (no inference). Raw secrets and transport
	// headers must never be placed here.
	Attribution AuthLocalAttribution `yaml:"attribution"`
}

AuthLocalAPIKeyRecord is one operator-configured API key (secret material belongs in config files only; validation and redaction are handled elsewhere). Key must be at least 16 Unicode code points after trimming (enforced with core auth validation).

type AuthLocalAttribution

type AuthLocalAttribution struct {
	DisplayName    string            `yaml:"display_name"`
	AuthMethod     string            `yaml:"auth_method"`
	TenantID       string            `yaml:"tenant_id"`
	OrganizationID string            `yaml:"organization_id"`
	WorkspaceID    string            `yaml:"workspace_id"`
	ProjectID      string            `yaml:"project_id"`
	DepartmentID   string            `yaml:"department_id"`
	CostCenterID   string            `yaml:"cost_center_id"`
	Roles          []string          `yaml:"roles"`
	SafeClaims     map[string]string `yaml:"safe_claims"`
	PolicyLabels   map[string]string `yaml:"policy_labels"`
}

AuthLocalAttribution mirrors coreauth.LocalAttribution for YAML decoding. Zero values mean "not configured".

type AuthMode

type AuthMode string
const (
	// AuthModeNoAuth permits unauthenticated local single-user traffic only on explicit loopback binds.
	AuthModeNoAuth AuthMode = "no_auth"
	// AuthModeExternal requires an injected or configured auth layer and may bind non-loopback interfaces.
	AuthModeExternal AuthMode = "external"
)

type AuthRemoteConfig

type AuthRemoteConfig struct {
	Endpoint string `yaml:"endpoint"`
	Handler  string `yaml:"handler"`
}

AuthRemoteConfig holds opaque placeholders for future remote auth wiring. No network clients are constructed from these fields in the OSS core.

type AutoResumeConfig

type AutoResumeConfig struct {
	Enabled           *bool  `yaml:"enabled"`
	IdleTimeout       string `yaml:"idle_timeout"`
	GracePeriod       string `yaml:"grace_period"`
	PostOutputPolicy  string `yaml:"post_output_policy"`
	EmitWarning       *bool  `yaml:"emit_warning"`
	KeepaliveInterval string `yaml:"keepalive_interval"`
}

type BackendDiscoveryConfig

type BackendDiscoveryConfig struct {
	Enabled         bool     `yaml:"enabled"`
	Paths           []string `yaml:"paths"`
	Strict          bool     `yaml:"strict"`
	DevelopmentMode bool     `yaml:"development_mode"`
}

BackendDiscoveryConfig is the generic (provider-agnostic) discovery/trust subtree.

func DecodeBackendDiscovery

func DecodeBackendDiscovery(n yaml.Node) (BackendDiscoveryConfig, error)

DecodeBackendDiscovery strictly decodes a backend_discovery mapping and rejects unknown keys.

func (*BackendDiscoveryConfig) UnmarshalYAML

func (c *BackendDiscoveryConfig) UnmarshalYAML(value *yaml.Node) error

UnmarshalYAML rejects unknown keys under plugins.backend_discovery.

type CircuitBreakerConfig

type CircuitBreakerConfig struct {
	Enabled          bool   `yaml:"enabled"`
	FailureThreshold int    `yaml:"failure_threshold"`
	OpenFor          string `yaml:"open_for"`
}

type ClientIPSource

type ClientIPSource string
const (
	ClientIPSourceDirect        ClientIPSource = "direct"
	ClientIPSourceXForwardedFor ClientIPSource = "x_forwarded_for"
	ClientIPSourceForwarded     ClientIPSource = "forwarded"
)

type CompatibleModeConfig

type CompatibleModeConfig struct {
	BackendPrefix         string
	BaseURL               string
	APIKeyEnvVarRoot      string
	TokenizerID           string
	MaxConcurrentRequests int
	Models                CompatibleModeModelsConfig
}

CompatibleModeConfig is the strict, secret-free configuration surface for the three built-in compatible backend kinds. Successful decoding never retains literal credential values.

func DecodeCompatibleModeConfig

func DecodeCompatibleModeConfig(instanceID, factoryKind string, n yaml.Node) (CompatibleModeConfig, error)

DecodeCompatibleModeConfig strictly decodes opaque compatible-mode YAML. Strictness is scoped to this decoder: it validates the mapping key set before typed decode and does not change repository-wide DecodeYAMLNode behavior. Errors are instance-scoped and never echo literal secret values.

type CompatibleModeModelItem

type CompatibleModeModelItem struct {
	CanonicalID string
	NativeID    string
	DisplayName string
}

CompatibleModeModelItem is one static inventory row.

type CompatibleModeModelsConfig

type CompatibleModeModelsConfig struct {
	Source string
	Path   string
	Items  []CompatibleModeModelItem
}

CompatibleModeModelsConfig is the optional static/shared inventory subtree.

type CompiledGeoIP

type CompiledGeoIP struct {
	// contains filtered or unexported fields
}

CompiledGeoIP is the immutable generation projection produced by pure config compilation. Database lifecycle is intentionally not represented here.

func CompileGeoIP

func CompileGeoIP(in GeoIPConfig) (*CompiledGeoIP, error)

CompileGeoIP validates static GeoIP configuration without opening files, constructing services, or performing network I/O.

func (*CompiledGeoIP) ClientIPSource

func (c *CompiledGeoIP) ClientIPSource() ClientIPSource

func (*CompiledGeoIP) DatabaseSource

func (c *CompiledGeoIP) DatabaseSource() GeoIPDatabaseSource

func (*CompiledGeoIP) Enabled

func (c *CompiledGeoIP) Enabled() bool

Enabled reports whether request enforcement is enabled in this projection.

func (*CompiledGeoIP) Policy

func (c *CompiledGeoIP) Policy() *coregeoip.Policy

Policy returns the immutable policy pointer, or nil when the request wrapper must be omitted.

func (*CompiledGeoIP) TrustedProxies

func (c *CompiledGeoIP) TrustedProxies() []netip.Prefix

TrustedProxies returns a defensive copy.

func (*CompiledGeoIP) UpdateInterval

func (c *CompiledGeoIP) UpdateInterval() time.Duration

type CompiledSelfDefense

type CompiledSelfDefense struct {
	// contains filtered or unexported fields
}

CompiledSelfDefense is the immutable, provider-neutral generation projection produced by pure config compilation. It carries no mutable process state and performs no I/O.

func CompileSelfDefense

func CompileSelfDefense(in SelfDefenseConfig) (*CompiledSelfDefense, error)

CompileSelfDefense validates the typed self-defense configuration and resolves documented defaults without constructing process state, binding a listener, or performing network I/O.

func (*CompiledSelfDefense) AdaptiveExemptCIDRs

func (c *CompiledSelfDefense) AdaptiveExemptCIDRs() []netip.Prefix

AdaptiveExemptCIDRs returns a defensive copy of the adaptive-exemption prefixes.

func (*CompiledSelfDefense) AuthFailures

func (c *CompiledSelfDefense) AuthFailures() int

AuthFailures returns the configured unauthenticated-401 threshold.

func (*CompiledSelfDefense) Enabled

func (c *CompiledSelfDefense) Enabled() bool

Enabled reports whether request enforcement is enabled in this projection.

func (*CompiledSelfDefense) FailureWindow

func (c *CompiledSelfDefense) FailureWindow() time.Duration

FailureWindow returns the auth-failure counting window.

func (*CompiledSelfDefense) ImpossiblePaths

func (c *CompiledSelfDefense) ImpossiblePaths() bool

ImpossiblePaths reports whether the fixed impossible-path matcher is enabled. The toggle stays a request-graph concern; the core policy owns only adaptive source-defense behavior.

func (*CompiledSelfDefense) InitialQuarantine

func (c *CompiledSelfDefense) InitialQuarantine() time.Duration

InitialQuarantine returns the first-offense quarantine duration.

func (*CompiledSelfDefense) MaxEntries

func (c *CompiledSelfDefense) MaxEntries() int

MaxEntries returns the process-state entry capacity.

func (*CompiledSelfDefense) MaxQuarantine

func (c *CompiledSelfDefense) MaxQuarantine() time.Duration

MaxQuarantine returns the exponential quarantine ceiling.

func (*CompiledSelfDefense) Policy

Policy projects the compiled reloadable request policy onto the single authoritative core domain type. The returned value is a copy: callers cannot mutate the compiled projection through the returned exemption allowlist.

func (*CompiledSelfDefense) StateLimits

StateLimits projects the process-owned adaptive-state sizing. These limits are restart-required in v1 and are deliberately separate from Policy so they are never carried into a per-request generation projection.

func (*CompiledSelfDefense) StateTTL

func (c *CompiledSelfDefense) StateTTL() time.Duration

StateTTL returns the hostile-inactivity lifetime used to size process state.

type ConcurrencyAuthorityConfig

type ConcurrencyAuthorityConfig struct {
	Enabled     bool   `yaml:"enabled"`
	Store       string `yaml:"store"` // memory | sqlite | postgres
	StoreID     string `yaml:"store_id"`
	SQLitePath  string `yaml:"sqlite_path"`
	PostgresDSN string `yaml:"postgres_dsn"`
	LeaseTTL    string `yaml:"lease_ttl"`
	RenewBefore string `yaml:"renew_before"`
	// SnapshotVersion is the immutable config-backed concurrency policy version (11.5).
	// Empty defaults to "static" at source construction.
	SnapshotVersion string `yaml:"snapshot_version"`
	// AuxiliaryLeasePolicy controls whether auxiliary requests inherit the parent
	// lease (default) or acquire their own top-level slot (requirement 10.10).
	// Values: ""|"inherit" (default) | "acquire_own".
	AuxiliaryLeasePolicy string                           `yaml:"auxiliary_lease_policy"`
	Rules                []ConcurrencyAuthorityRuleConfig `yaml:"rules"`
}

ConcurrencyAuthorityConfig controls optional logical-request concurrency leases. Disabled by default (requirement 10.4 wiring is opt-in).

func (ConcurrencyAuthorityConfig) DomainRules

DomainRules converts validated concurrency config into domain rules.

func (ConcurrencyAuthorityConfig) LeaseTTLDuration

func (c ConcurrencyAuthorityConfig) LeaseTTLDuration() (time.Duration, error)

LeaseTTLDuration returns the default lease TTL for rules that omit lease_ttl.

func (ConcurrencyAuthorityConfig) RenewBeforeDuration

func (c ConcurrencyAuthorityConfig) RenewBeforeDuration() (time.Duration, error)

RenewBeforeDuration returns the default renew-before offset.

type ConcurrencyAuthorityRuleConfig

type ConcurrencyAuthorityRuleConfig struct {
	ID                string                              `yaml:"id"`
	Mode              string                              `yaml:"mode"` // strict | advisory
	MaxActiveRequests int                                 `yaml:"max_active_requests"`
	Match             AccountingAuthorityDimensionsConfig `yaml:"match"`
	LeaseTTL          string                              `yaml:"lease_ttl"`
	RenewBefore       string                              `yaml:"renew_before"`
	FailureBehavior   string                              `yaml:"failure_behavior"` // fail_closed | fail_open
	Namespace         string                              `yaml:"namespace"`
	Version           string                              `yaml:"version"`
}

ConcurrencyAuthorityRuleConfig is one max-active-request lease rule.

type Config

type Config struct {
	Server         ServerConfig         `yaml:"server"`
	HTTPHeaders    HTTPHeadersConfig    `yaml:"http_headers"`
	Access         AccessConfig         `yaml:"access"`
	Auth           AuthConfig           `yaml:"auth"`
	Logging        LoggingConfig        `yaml:"logging"`
	Diagnostics    DiagnosticsConfig    `yaml:"diagnostics"`
	Observability  ObservabilityConfig  `yaml:"observability"`
	HTTPClient     HTTPClientConfig     `yaml:"http_client"`
	Database       DatabaseConfig       `yaml:"database"`
	Routing        RoutingConfig        `yaml:"routing"`
	Continuity     ContinuityConfig     `yaml:"continuity"`
	SecureSession  SecureSessionConfig  `yaml:"secure_session"`
	StreamRecovery StreamRecoveryConfig `yaml:"stream_recovery"`
	Hooks          HooksConfig          `yaml:"hooks"`
	Accounting     AccountingConfig     `yaml:"accounting"`
	Interleaved    InterleavedConfig    `yaml:"interleaved"`
	Plugins        PluginsConfig        `yaml:"plugins"`
	ModelAliases   []ModelAliasConfig   `yaml:"model_aliases"`
	ModelCatalog   ModelCatalogConfig   `yaml:"model_catalog"`
	ModelInventory ModelInventoryConfig `yaml:"model_inventory"`
	// ControlPlane is the optional control-plane persistence/query/event-ledger
	// capability. Disabled by default; enabled requires explicit startup
	// validation (see validateControlPlane).
	ControlPlane ControlPlaneConfig `yaml:"control_plane"`
	// Metering is the optional durable metering journal (Phase 5). Disabled by
	// default so Executor.MeteringRecorder stays nil until explicitly enabled.
	Metering MeteringConfig `yaml:"metering"`
	// Identity controls proxy-wide upstream and downstream identity presentation.
	// Defaults identify as LIP (not client passthrough). Backend connector wiring
	// and A-leg Server middleware are applied in later integration waves.
	Identity identity.Config `yaml:"identity"`
	// ConfigDir is the directory containing the loaded config file. Set by [LoadFile];
	// empty when Config is constructed without loading from disk.
	ConfigDir string `yaml:"-"`
}

Config contains only core-owned runtime settings and opaque plugin config payloads.

A decoded Config is not self-validating: Validate checks core fields (plugins, continuity, logging, etc.) but does not validate model_aliases. After LoadFile, call routing.ValidateModelAliasesConfig(cfg) from package internal/core/routing before wiring; composition (for example internal/infra/runtimebundle.Build) compiles model_aliases via routing.NewAliasResolver. Default route selector resolution is EffectiveDefaultRouteSelector in this package (see effective_default_route.go).

func LoadFile

func LoadFile(path string) (*Config, error)

LoadFile decodes typed runtime configuration from YAML, applies defaults, and runs Validate. Reload candidates use the filesystem-driven configsource adapter; this compatibility entrypoint deliberately keeps core/config independent from driving adapters.

func LoadFileWithContext

func LoadFileWithContext(ctx context.Context, rawPath string) (*Config, error)

LoadFileWithContext is the context-aware form of LoadFile.

func (*Config) EffectiveAccessMode

func (c *Config) EffectiveAccessMode() (accessmode.Mode, error)

EffectiveAccessMode returns the normalized deployment access mode (omitted access.mode defaults to single_user).

func (*Config) EffectiveAuthForAudit

func (c *Config) EffectiveAuthForAudit() (handler, requiredLevel string)

EffectiveAuthForAudit returns handler and required_level strings after legacy server.auth_mode merge. It is used for operator audit labels (session-start) and should stay aligned with posture validation.

func (*Config) EffectiveServerAuthMode

func (c *Config) EffectiveServerAuthMode() AuthMode

EffectiveServerAuthMode returns the configured HTTP auth posture. Empty defaults to no_auth for developer-local defaults; startup validation restricts no_auth to explicit loopback binds.

func (*Config) EffectiveTrustEnvironmentProxy

func (c *Config) EffectiveTrustEnvironmentProxy() bool

EffectiveTrustEnvironmentProxy returns whether outbound calls should honor process proxy environment variables.

func (*Config) SecureSessionEffectivelyEnabled

func (c *Config) SecureSessionEffectivelyEnabled() bool

func (*Config) SingleUserLocalMode

func (c *Config) SingleUserLocalMode() bool

SingleUserLocalMode reports whether startup policy permits local no-auth/synthetic-principal behavior.

type ContinuityConfig

type ContinuityConfig struct {
	InMemory bool `yaml:"in_memory"`
	// Store names the continuity backing when InMemory is true. Empty is normalized to "memory" in LoadFile.
	// Use "sqlite" for local durable storage (requires sqlite_path) or "postgres" for managed durable
	// (requires postgres_dsn).
	Store string `yaml:"store"`
	// SQLitePath is the database file path when store is "sqlite".
	SQLitePath string `yaml:"sqlite_path"`
	// PostgresDSN is the connection string when store is "postgres".
	PostgresDSN string `yaml:"postgres_dsn"`
	// TTL is in-memory store only (A-leg eviction). Ignored by SQLite until pruning is implemented.
	TTL string `yaml:"ttl"`
	// MaxLegs is in-memory store only when TTL is empty. Must be >= 0. Ignored by SQLite until pruning exists.
	MaxLegs int `yaml:"max_legs"`
}

type ControlPlaneConfig

type ControlPlaneConfig struct {
	Enabled            bool                        `yaml:"enabled"`
	Store              string                      `yaml:"store"`
	SQLitePath         string                      `yaml:"sqlite_path"`
	PostgresDSN        string                      `yaml:"postgres_dsn"`
	RecordingPolicy    string                      `yaml:"recording_policy"`
	RequiredCategories []string                    `yaml:"required_categories"`
	Query              ControlPlaneQueryConfig     `yaml:"query"`
	Retention          ControlPlaneRetentionConfig `yaml:"retention"`
	RedactionDefault   string                      `yaml:"redaction_default"`
}

ControlPlaneConfig controls the optional control-plane persistence, query, and event-ledger capability (spec control-plane-persistence-query-event-ledger). The capability is disabled by default; enabling recording or query exposure requires explicit typed configuration and startup validation here.

Excluded enterprise features (billing, identity provisioning, policy engines, GUI, marketplace, provider forwarding, historical migration) intentionally have no configuration surface here (requirements 10.1–10.6).

type ControlPlaneQueryConfig

type ControlPlaneQueryConfig struct {
	Enabled         bool   `yaml:"enabled"`
	PathPrefix      string `yaml:"path_prefix"`
	DefaultPageSize int    `yaml:"default_page_size"`
	MaxPageSize     int    `yaml:"max_page_size"`
	MaxTimeWindow   string `yaml:"max_time_window"`
}

ControlPlaneQueryConfig controls protected operator query exposure. Query routes mount only when control-plane is enabled, query is enabled, and the diagnostics shared-secret posture allows protected surfaces.

func (ControlPlaneQueryConfig) MaxTimeWindowDuration

func (q ControlPlaneQueryConfig) MaxTimeWindowDuration() (time.Duration, error)

MaxTimeWindowDuration returns the effective query max time window as a time.Duration plus any validation error.

Disabled-query semantics: when q.Enabled is false the query surface is not mounted, so an invalid MaxTimeWindow is ignored and (0, nil) is returned even if the value is unparseable.

When q.Enabled is true, an empty MaxTimeWindow returns (0, nil) (meaning no bound; the query service applies its own defaults). A non-empty value must parse to a positive duration; invalid, zero, and negative durations return an error with the same wording used by [validateControlPlaneQuery] so callers that skip Validate (for example runtimebundle assembly fed an unvalidated config) still fail fast instead of silently degrading to an unbounded query service.

type ControlPlaneRetentionConfig

type ControlPlaneRetentionConfig struct {
	Enabled bool   `yaml:"enabled"`
	Window  string `yaml:"window"`
}

ControlPlaneRetentionConfig controls optional retention/redaction processing. No hidden background worker is started unless explicitly configured later.

type DatabaseConfig

type DatabaseConfig struct {
	ConnectionMode  DatabaseConnectionMode `yaml:"connection_mode"`
	SchemaMode      DatabaseSchemaMode     `yaml:"schema_mode"`
	MaxOpenConns    int                    `yaml:"max_open_conns"`
	MaxIdleConns    int                    `yaml:"max_idle_conns"`
	ConnMaxLifetime string                 `yaml:"conn_max_lifetime"`
	ConnMaxIdleTime string                 `yaml:"conn_max_idle_time"`
}

DatabaseConfig is optional connection pool tuning for managed PostgreSQL handles opened by the proxy (see internal/infra/db). Omitted or zero values preserve driver defaults when no store is postgres; max_open_conns must be > 0 when any store is postgres. ConnectionMode and SchemaMode apply only to the dual-plane authority, concurrency, and metering PostgreSQL runtime paths. Other PostgreSQL stores retain their own owning lifecycle and compatibility migration behavior.

func (DatabaseConfig) EffectiveConnectionMode

func (c DatabaseConfig) EffectiveConnectionMode() DatabaseConnectionMode

func (DatabaseConfig) EffectiveSchemaMode

func (c DatabaseConfig) EffectiveSchemaMode() DatabaseSchemaMode

type DatabaseConnectionMode

type DatabaseConnectionMode string
const (
	DatabaseConnectionModeDirect          DatabaseConnectionMode = "direct"
	DatabaseConnectionModeTransactionPool DatabaseConnectionMode = "transaction_pool"
)

type DatabasePoolSettings

type DatabasePoolSettings struct {
	MaxOpenConns    int
	MaxIdleConns    int
	ConnMaxLifetime time.Duration
	ConnMaxIdleTime time.Duration
}

DatabasePoolSettings holds validated optional *sql.DB pool tuning from DatabaseConfig. Zero values mean unset (driver defaults) when no managed PostgreSQL store is selected. When any store is postgres, Validate requires MaxOpenConns > 0 (fail-closed). Use ParseDatabasePoolSettings after YAML decode and alongside Validate for full checks.

func ParseDatabasePoolSettings

func ParseDatabasePoolSettings(d DatabaseConfig) (DatabasePoolSettings, error)

ParseDatabasePoolSettings parses DatabaseConfig into DatabasePoolSettings and validates numeric and duration fields.

type DatabaseSchemaMode

type DatabaseSchemaMode string
const (
	DatabaseSchemaModeAutoMigrate DatabaseSchemaMode = "auto_migrate"
	DatabaseSchemaModeVerifyOnly  DatabaseSchemaMode = "verify_only"
)

type DiagnosticsConfig

type DiagnosticsConfig struct {
	Enabled      bool   `yaml:"enabled"`
	HealthPath   string `yaml:"health_path"`
	AttemptsPath string `yaml:"attempts_path"`
	// InventoryPath registers a JSON plugin inventory endpoint when non-empty (e.g. "/debug/inventory").
	InventoryPath string `yaml:"inventory_path"`
	// RouteTracePath registers a JSON ring buffer of recent routing decisions when non-empty.
	RouteTracePath string `yaml:"route_trace_path"`
	// PprofPath registers net/http/pprof handlers under this prefix when diagnostics.enabled is true
	// (e.g. "/debug/pprof"). Leave empty to disable. Do not expose publicly without access controls.
	PprofPath string `yaml:"pprof_path"`
	// SharedSecret when non-empty requires header X-LIP-Diagnostics-Secret on attempts, inventory,
	// route trace, and pprof routes (not on health). Use a long random value in production.
	SharedSecret string `yaml:"shared_secret"`
}

type EffectiveAutoResumeConfig

type EffectiveAutoResumeConfig struct {
	Enabled           bool
	IdleTimeout       time.Duration
	GracePeriod       time.Duration
	PostOutputPolicy  StreamRecoveryPostOutputPolicy
	EmitWarning       bool
	KeepaliveInterval time.Duration
}

func EffectiveStreamRecoveryAutoResume

func EffectiveStreamRecoveryAutoResume(cfg *Config, overrides StreamRecoveryOverrides) (EffectiveAutoResumeConfig, error)

type EffectiveConfig

type EffectiveConfig struct {
	Config   *Config
	Identity EffectiveIdentity
	Category LoadCategory
	LoadedAt time.Time
}

EffectiveConfig is the normalized effective candidate produced by LoadEffective. Identity.PrivateDigest is private; PublicFingerprint is secret-safe.

func LoadEffective

func LoadEffective(ctx context.Context, raw []byte, opts LoadEffectiveOptions) (*EffectiveConfig, error)

LoadEffective runs the deterministic effective pipeline: classify → strict one-document decode → defaults → fixed stream-recovery overrides → feature injection → core validation → extra validation → private/public identity.

type EffectiveIdentity

type EffectiveIdentity struct {
	PrivateDigest     [32]byte
	PublicFingerprint string
}

EffectiveIdentity is the private raw/effective identity used for no-op decisions (requirements 3.6–3.8). PrivateDigest must never appear in logs, APIs, or public status. PublicFingerprint is secret-safe generation metadata.

func ComputeEffectiveIdentity

func ComputeEffectiveIdentity(cfg *Config) (EffectiveIdentity, error)

ComputeEffectiveIdentity returns the private digest over the full effective config and a secret-safe public fingerprint over a redacted projection.

type EffectivePreRequestKeepaliveConfig

type EffectivePreRequestKeepaliveConfig struct {
	Enabled  bool
	Interval time.Duration
}

type ExecutionCompositionPolicy

type ExecutionCompositionPolicy string

ExecutionCompositionPolicy controls whether composite routing expressions can include agent runtimes.

const (
	// ExecutionCompositionSafe restricts selector composition to pure inference backends; agent runtimes are allowed only as direct routes.
	ExecutionCompositionSafe ExecutionCompositionPolicy = "safe"
	// ExecutionCompositionUnrestricted allows arbitrary composition of agent runtimes and inference backends.
	ExecutionCompositionUnrestricted ExecutionCompositionPolicy = "unrestricted"
)

type GeoIPClientConfig

type GeoIPClientConfig struct {
	Source         ClientIPSource `yaml:"source"`
	TrustedProxies []string       `yaml:"trusted_proxies"`
}

type GeoIPConfig

type GeoIPConfig struct {
	Enabled  bool              `yaml:"enabled"`
	Order    string            `yaml:"order"`
	Allow    GeoIPRuleConfig   `yaml:"allow"`
	Deny     GeoIPRuleConfig   `yaml:"deny"`
	ClientIP GeoIPClientConfig `yaml:"client_ip"`
	Database GeoIPDBConfig     `yaml:"database"`
}

GeoIPConfig describes the reloadable request-plane policy and the optional process-owned country database source.

type GeoIPDBConfig

type GeoIPDBConfig struct {
	Source    GeoIPDatabaseSource `yaml:"source"`
	Edition   string              `yaml:"edition"`
	Directory string              `yaml:"directory"`
	LocalPath string              `yaml:"local_path"`
	Update    GeoIPUpdateConfig   `yaml:"update"`
}

type GeoIPDatabaseSource

type GeoIPDatabaseSource string
const (
	GeoIPDatabaseSourceManaged GeoIPDatabaseSource = "managed"
	GeoIPDatabaseSourceLocal   GeoIPDatabaseSource = "local"
)

type GeoIPRuleConfig

type GeoIPRuleConfig struct {
	Countries []string `yaml:"countries"`
	CIDRs     []string `yaml:"cidrs"`
}

type GeoIPUpdateConfig

type GeoIPUpdateConfig struct {
	Enabled  bool   `yaml:"enabled"`
	Interval string `yaml:"interval"`
}

type HTTPClientConfig

type HTTPClientConfig struct {
	// TrustEnvironmentProxy when true (default) uses http.ProxyFromEnvironment for outbound requests.
	// When false, the transport ignores HTTP_PROXY/HTTPS_PROXY/NO_PROXY (reduces deputy risk if env is untrusted).
	// Omitted or null in YAML defaults to true in [LoadFile] / [EffectiveTrustEnvironmentProxy].
	TrustEnvironmentProxy *bool `yaml:"trust_environment_proxy"`
	// MaxIdleConns is the Transport MaxIdleConns pool cap. Omit to use the bundled default (~100).
	MaxIdleConns *int `yaml:"max_idle_conns,omitempty"`
	// MaxIdleConnsPerHost defaults to 64 when omitted (Go's default of 2 is usually too low for LLM APIs).
	MaxIdleConnsPerHost *int `yaml:"max_idle_conns_per_host,omitempty"`
	// IdleConnTimeout is a Go duration string (e.g. "90s"). Empty uses the httpclient default.
	IdleConnTimeout string `yaml:"idle_conn_timeout"`
	// ResponseHeaderTimeout bounds waiting for response headers (e.g. "60s"). Empty uses default.
	ResponseHeaderTimeout string `yaml:"response_header_timeout"`
	// DialTimeout is the net.Dialer Timeout for establishing connections (e.g. "30s").
	DialTimeout string `yaml:"dial_timeout"`
	// KeepAlive is the net.Dialer KeepAlive interval (e.g. "30s").
	KeepAlive string `yaml:"keep_alive"`
	// TLSHandshakeTimeout caps TLS handshakes (e.g. "10s").
	TLSHandshakeTimeout string `yaml:"tls_handshake_timeout"`
	// ExpectContinueTimeout is the Transport expect-continue timeout (e.g. "1s").
	ExpectContinueTimeout string `yaml:"expect_continue_timeout"`
	// ClientTimeout is [http.Client.Timeout] for the full request including body (e.g. "120s").
	ClientTimeout string `yaml:"client_timeout"`
}

HTTPClientConfig tunes the shared outbound HTTP client used for upstream LLM calls.

type HTTPHeadersConfig

type HTTPHeadersConfig struct {
	APIKey            []string `yaml:"api_key"`
	Route             []string `yaml:"route"`
	SessionID         []string `yaml:"session_id"`
	ResumeToken       []string `yaml:"resume_token"`
	ALegID            []string `yaml:"a_leg_id"`
	SessionHint       []string `yaml:"session_hint"`
	Trace             []string `yaml:"trace"`
	DiagnosticsSecret []string `yaml:"diagnostics_secret"`
}

HTTPHeadersConfig lists extra inbound header names operators may send in addition to the standard LIP/vendor defaults. Empty lists keep the defaults. Configured names are appended after defaults (first non-empty wins), so X-LIP-Route still wins when both a default and an alias are present.

func (HTTPHeadersConfig) Effective

func (c HTTPHeadersConfig) Effective() lipsdk.HTTPHeaders

Effective merges operator aliases after lipsdk.DefaultHTTPHeaders.

type HooksConfig

type HooksConfig struct {
	// ToolReactorErrorPolicy is one of: fail_open (default), fail_closed, swallow_event.
	ToolReactorErrorPolicy string `yaml:"tool_reactor_error_policy"`
}

HooksConfig carries core hook-bus tuning (not plugin opaque payloads).

type InterleavedConfig

type InterleavedConfig struct {
	// Enabled turns on interleaved thinking. Disabled by default.
	Enabled bool `yaml:"enabled"`
}

InterleavedConfig controls interleaved thinking (`[thinker]` selectors).

Minimum enablement and configuration values required for route planning. Feature-specific defaults, prompts, and instruction loading are owned by internal/plugins/features/interleavedthinking.

type LargePayloadFastPathConfig

type LargePayloadFastPathConfig struct {
	// Enabled gates the optimization. Default false.
	Enabled bool `yaml:"enabled"`
	// ThresholdBytes is the decoded-size consideration gate. Required > 0 when
	// enabled.
	ThresholdBytes int64 `yaml:"threshold_bytes"`
	// MemorySpoolBytes bounds retained request bytes in Go heap per capture.
	// Required > 0 and <= MaxInflightSpoolBytes when enabled.
	MemorySpoolBytes int64 `yaml:"memory_spool_bytes"`
	// MaxInflightSpoolBytes bounds global logical spool reservation.
	// Required > 0 when enabled. Optimization budget only (see above).
	MaxInflightSpoolBytes int64 `yaml:"max_inflight_spool_bytes"`
	// MaxSemanticFactBytes bounds profile-derived metadata. Required > 0 when
	// enabled.
	MaxSemanticFactBytes int64 `yaml:"max_semantic_fact_bytes"`
	// SpoolDir optionally overrides the spill directory. Empty selects the OS
	// default temp directory. Validated during candidate generation/reload;
	// an invalid value rejects the candidate and preserves last-good.
	SpoolDir string `yaml:"spool_dir"`
}

LargePayloadFastPathConfig controls the optional large-payload streaming fast path (server.large_payload_fast_path, design section 3).

The feature is default-off: a zero config keeps the existing canonical path with no spool/scanner/wire allocation beyond a trivial enabled check (Requirements 1, 22).

threshold_bytes controls consideration only; it never proves eligibility and never changes the existing MaxRequestBodyBytes admission policy, whose defaults stay unchanged (Requirement 2).

max_inflight_spool_bytes is an optimization budget, not a new request-admission error source: reservation exhaustion declines to the canonical path and never produces a new 413. Canonical fallback may still allocate per the pre-existing path, so this budget is not global OOM admission (Requirement 20).

Confidentiality: spool files can contain plaintext prompt data. Operators must place spool_dir on a protected volume/filesystem; spool paths never enter logs/metrics/traces (Requirement 20).

func (LargePayloadFastPathConfig) EffectiveMaxInflightSpoolBytes

func (c LargePayloadFastPathConfig) EffectiveMaxInflightSpoolBytes() int64

EffectiveMaxInflightSpoolBytes returns MaxInflightSpoolBytes when positive, else the default.

func (LargePayloadFastPathConfig) EffectiveMaxSemanticFactBytes

func (c LargePayloadFastPathConfig) EffectiveMaxSemanticFactBytes() int64

EffectiveMaxSemanticFactBytes returns MaxSemanticFactBytes when positive, else the default.

func (LargePayloadFastPathConfig) EffectiveMemorySpoolBytes

func (c LargePayloadFastPathConfig) EffectiveMemorySpoolBytes() int64

EffectiveMemorySpoolBytes returns MemorySpoolBytes when positive, else the default.

func (LargePayloadFastPathConfig) EffectiveSpoolDir

func (c LargePayloadFastPathConfig) EffectiveSpoolDir() string

EffectiveSpoolDir returns the trimmed spool directory; empty means the OS default temp directory.

func (LargePayloadFastPathConfig) EffectiveThresholdBytes

func (c LargePayloadFastPathConfig) EffectiveThresholdBytes() int64

EffectiveThresholdBytes returns ThresholdBytes when positive, else the default.

type LoadCategory

type LoadCategory string

LoadCategory is a bounded, secret-safe source/decode classification. Values identify failure classes only and never contain raw YAML or secrets.

const (
	CategoryOK                LoadCategory = "ok"
	CategoryMissing           LoadCategory = "source_missing"
	CategoryEmpty             LoadCategory = "source_empty"
	CategoryWhitespace        LoadCategory = "source_whitespace"
	CategoryOversize          LoadCategory = "source_oversize"
	CategoryUnstable          LoadCategory = "source_unstable"
	CategoryNonAtomicUpdate   LoadCategory = "source_non_atomic_update"
	CategoryUnsupportedType   LoadCategory = "source_unsupported_type"
	CategoryMalformedYAML     LoadCategory = "decode_malformed_yaml"
	CategoryMultipleDocuments LoadCategory = "decode_multiple_documents"
	CategoryTrailingContent   LoadCategory = "decode_trailing_content"
	CategoryUnknownCoreField  LoadCategory = "decode_unknown_core_field"
	CategoryPartialUnreadable LoadCategory = "source_partial_unreadable"
)

type LoadEffectiveOptions

type LoadEffectiveOptions struct {
	// ConfigDir sets Config.ConfigDir when non-empty (typically the directory of
	// the fixed source path).
	ConfigDir string
	// FixedStreamRecovery, when non-nil, materializes CLI/env stream-recovery
	// overrides into the effective config (even when the struct is zero).
	FixedStreamRecovery *StreamRecoveryOverrides
	// NormalizeYAML, when non-nil, transforms raw configuration bytes before
	// strict decode (e.g. legacy feature syntax normalization).
	NormalizeYAML func([]byte) ([]byte, error)
	// InjectFeatures is the standard-distribution feature injection seam.
	InjectFeatures func(*Config) error
	// ExtraValidate runs after core Validate (routing aliases, prefix checks, …).
	ExtraValidate func(*Config) error
}

LoadEffectiveOptions configures the shared effective-load pipeline used by startup, check-config, and runtime reload. Feature injection and extra validation are explicit seams so core/config does not import plugin packages.

type LoadError

type LoadError struct {
	Category LoadCategory
	// contains filtered or unexported fields
}

LoadError is a secret-safe effective-load / decode failure.

func (*LoadError) Error

func (e *LoadError) Error() string

func (*LoadError) Unwrap

func (e *LoadError) Unwrap() error

type LoggingConfig

type LoggingConfig struct {
	// Level is one of: debug, info, warn, error (case-insensitive). Empty defaults to info in LoadFile/Validate.
	Level string `yaml:"level"`
	// Format is json or text (case-insensitive). Empty defaults to json in LoadFile/Validate.
	Format string `yaml:"format"`
	// AddSource adds source file/line to each record when true.
	AddSource bool `yaml:"add_source"`
	// AccessLog emits one structured line per HTTP request when true.
	AccessLog bool `yaml:"access_log"`
	// AccessLogSkipPaths are URL path prefixes (must start with /) for which access logs are suppressed.
	AccessLogSkipPaths []string `yaml:"access_log_skip_paths"`
	// AccessLogIncludeRawPath when true adds the full URL path to access logs (higher cardinality).
	// Default false: only route_group.
	AccessLogIncludeRawPath bool `yaml:"access_log_include_raw_path"`
}

LoggingConfig controls process-wide slog output and optional HTTP access logs.

type MeteringConfig

type MeteringConfig struct {
	Enabled bool                  `yaml:"enabled"`
	Journal MeteringJournalConfig `yaml:"journal"`
}

MeteringConfig enables the optional durable metering journal (requirements 13.1–13.5). When Enabled is false, runtime leaves Executor.MeteringRecorder nil (requirement 17.1).

type MeteringJournalConfig

type MeteringJournalConfig struct {
	Store       string `yaml:"store"` // memory | sqlite | postgres; empty with enabled defaults to memory
	SQLitePath  string `yaml:"sqlite_path"`
	PostgresDSN string `yaml:"postgres_dsn"`
}

MeteringJournalConfig selects the journal store backend.

type MetricsConfig

type MetricsConfig struct {
	// Enabled exposes lip_http_* metrics and process/go collectors when true.
	// When false (zero value), no /metrics handler is registered (legacy behavior).
	Enabled bool `yaml:"enabled"`
	// Path is the HTTP path for Prometheus scraping (e.g. "/metrics"). Empty defaults to /metrics in LoadFile.
	Path string `yaml:"path"`
	// ExemplarsEnabled attaches trace_id exemplars to selected histograms and enables OpenMetrics on /metrics.
	ExemplarsEnabled bool `yaml:"exemplars_enabled"`
}

MetricsConfig controls the Prometheus /metrics endpoint.

type ModelAliasConfig

type ModelAliasConfig struct {
	Pattern     string `yaml:"pattern"`
	Replacement string `yaml:"replacement"`
}

ModelAliasConfig is one regexp-based rewrite of an incoming route selector (see internal/core/routing/aliases.go).

type ModelCatalogBackendModelOverrideEntry

type ModelCatalogBackendModelOverrideEntry struct {
	Backend string `yaml:"backend"`
	Model   string `yaml:"model"`

	Tools             *bool `yaml:"tools,omitempty"`
	StructuredOutputs *bool `yaml:"structured_outputs,omitempty"`
	Reasoning         *bool `yaml:"reasoning,omitempty"`
	Vision            *bool `yaml:"vision,omitempty"`
	Documents         *bool `yaml:"documents,omitempty"`

	ContextLimitTokens *int64 `yaml:"context_limit_tokens,omitempty"`
	InputLimitTokens   *int64 `yaml:"input_limit_tokens,omitempty"`
	OutputLimitTokens  *int64 `yaml:"output_limit_tokens,omitempty"`
}

ModelCatalogBackendModelOverrideEntry is one backend+model pair override row from configuration.

type ModelCatalogConfig

type ModelCatalogConfig struct {
	// Enabled when true uses the latest valid local catalog snapshot for request-time decisions (when present).
	Enabled bool `yaml:"enabled"`
	// ExternalUpdatesEnabled when true allows periodic background fetches of the catalog source (independent of Enabled).
	ExternalUpdatesEnabled bool `yaml:"external_updates_enabled"`
	// UpdateInterval is a Go duration string (e.g. "1h") for automatic refresh when ExternalUpdatesEnabled is true.
	UpdateInterval string `yaml:"update_interval"`
	// FetchTimeout is an optional Go duration string applied to catalog HTTP GET when the request context has no
	// deadline (0 or empty = rely on transport/client timeouts only).
	FetchTimeout string `yaml:"fetch_timeout"`
	// SourceURL is the HTTPS (or HTTP) URL for the catalog snapshot when ExternalUpdatesEnabled is true.
	SourceURL string `yaml:"source_url"`
	// CachePath is the local filesystem path for the persisted snapshot file used when Enabled or ExternalUpdatesEnabled.
	CachePath string `yaml:"cache_path"`
	// DiagnosticsPath when non-empty registers catalog status JSON under this absolute URL path (must not overlap other diagnostics paths).
	DiagnosticsPath string `yaml:"diagnostics_path"`
	// ModelOverrides are operator facts keyed by route/catalog model name (see spec requirement 5.1).
	ModelOverrides []ModelCatalogModelOverrideEntry `yaml:"model_overrides"`
	// BackendModelOverrides take precedence over ModelOverrides for matching backend/model pairs (requirement 5.2).
	BackendModelOverrides []ModelCatalogBackendModelOverrideEntry `yaml:"backend_model_overrides"`
}

ModelCatalogConfig controls models.dev catalog usage, local cache, optional external refresh, and operator overrides. Concrete fetch/cache adapters live outside core config; this struct is the typed operator surface (see design: ModelCatalogConfig).

func (ModelCatalogConfig) FetchTimeoutDuration

func (mc ModelCatalogConfig) FetchTimeoutDuration() (d time.Duration, ok bool)

FetchTimeoutDuration returns a positive parsed model_catalog.fetch_timeout duration.

func (ModelCatalogConfig) UpdateIntervalDuration

func (mc ModelCatalogConfig) UpdateIntervalDuration() (d time.Duration, ok bool)

UpdateIntervalDuration returns a positive parsed model_catalog.update_interval duration. Call after successful config validation when the string must be well-formed for enabled refresh paths.

type ModelCatalogModelOverrideEntry

type ModelCatalogModelOverrideEntry struct {
	Model string `yaml:"model"`

	Tools             *bool `yaml:"tools,omitempty"`
	StructuredOutputs *bool `yaml:"structured_outputs,omitempty"`
	Reasoning         *bool `yaml:"reasoning,omitempty"`
	Vision            *bool `yaml:"vision,omitempty"`
	Documents         *bool `yaml:"documents,omitempty"`

	ContextLimitTokens *int64 `yaml:"context_limit_tokens,omitempty"`
	InputLimitTokens   *int64 `yaml:"input_limit_tokens,omitempty"`
	OutputLimitTokens  *int64 `yaml:"output_limit_tokens,omitempty"`
}

ModelCatalogModelOverrideEntry is one model-scoped override row from configuration. Optional capability and limit fields use YAML omission for "unknown"; for booleans, true means explicitly supported and false means explicitly unsupported (runtimebundle maps into modelcatalog).

type ModelInventoryConfig

type ModelInventoryConfig struct {
	CachePath       string `yaml:"cache_path"`
	RefreshEnabled  *bool  `yaml:"refresh_enabled"`
	RefreshInterval string `yaml:"refresh_interval"`
	FetchTimeout    string `yaml:"fetch_timeout"`
	// DiagnosticsPath registers protected backend model-registry discovery JSON when non-empty
	// (e.g. "/debug/model-registry"). Distinct from model_catalog.diagnostics_path (models.dev).
	DiagnosticsPath string `yaml:"diagnostics_path"`
}

func (ModelInventoryConfig) EffectiveRefreshEnabled

func (mc ModelInventoryConfig) EffectiveRefreshEnabled() bool

func (ModelInventoryConfig) FetchTimeoutDuration

func (mc ModelInventoryConfig) FetchTimeoutDuration() time.Duration

func (ModelInventoryConfig) RefreshIntervalDuration

func (mc ModelInventoryConfig) RefreshIntervalDuration() time.Duration

type ObservabilityConfig

type ObservabilityConfig struct {
	Metrics MetricsConfig `yaml:"metrics"`
	Tracing TracingConfig `yaml:"tracing"`
}

ObservabilityConfig toggles Prometheus metrics and OpenTelemetry tracing.

type PluginConfig

type PluginConfig struct {
	// Kind is the bundled factory id used for registry lookup (e.g. openai-responses).
	// When empty, ID is treated as both factory kind and instance id (legacy single-field configs).
	Kind string `yaml:"kind,omitempty"`
	// ID is the runtime instance id: routing keys, executor backend map keys, and duplicate detection.
	ID      string    `yaml:"id"`
	Enabled bool      `yaml:"enabled"`
	Config  yaml.Node `yaml:"config"`
}

PluginConfig keeps plugin-private config opaque to the core.

func (PluginConfig) FactoryID

func (p PluginConfig) FactoryID() string

FactoryID returns the registry/factory identifier for this plugin row.

func (PluginConfig) InstanceID

func (p PluginConfig) InstanceID() string

InstanceID returns the configured runtime instance identifier (never empty for valid configs).

type PluginsConfig

type PluginsConfig struct {
	BackendDiscovery BackendDiscoveryConfig `yaml:"backend_discovery"`
	Frontends        []PluginConfig         `yaml:"frontends"`
	Backends         []PluginConfig         `yaml:"backends"`
	Features         []PluginConfig         `yaml:"features"`
}

type PreRequestKeepaliveConfig

type PreRequestKeepaliveConfig struct {
	Enabled  bool   `yaml:"enabled"`
	Interval string `yaml:"interval"`
}

type RoutingAffinityConfig

type RoutingAffinityConfig struct {
	Store           string `yaml:"store"`
	MissingIdentity string `yaml:"missing_identity"`
}

type RoutingConfig

type RoutingConfig struct {
	MaxAttempts int `yaml:"max_attempts"`
	// DefaultRoute is the selector used when the client omits X-LIP-Route (e.g. "openai-responses:gpt-4o-mini").
	DefaultRoute string                 `yaml:"default_route"`
	Health       RoutingHealthConfig    `yaml:"health"`
	Affinity     RoutingAffinityConfig  `yaml:"affinity"`
	Transport    RoutingTransportConfig `yaml:"transport"`
	// ExecutionCompositionPolicy controls whether multi-leaf routing compositions (weighted, parallel, thinker, failover)
	// can include whole-agent/orchestration runtimes. Defaults to "safe".
	ExecutionCompositionPolicy ExecutionCompositionPolicy `yaml:"execution_composition_policy"`
	// OverrideAdmin is the opt-in protected HTTP surface for A-leg routing overrides.
	// Disabled by default. Disabling the endpoint does not clear persisted override state.
	OverrideAdmin RoutingOverrideAdminConfig `yaml:"override_admin"`
}

func (RoutingConfig) EffectiveExecutionCompositionPolicy

func (c RoutingConfig) EffectiveExecutionCompositionPolicy() ExecutionCompositionPolicy

EffectiveExecutionCompositionPolicy returns the normalized policy, defaulting empty to safe.

type RoutingHealthConfig

type RoutingHealthConfig struct {
	CircuitBreaker CircuitBreakerConfig `yaml:"circuit_breaker"`
}

type RoutingOverrideAdminConfig

type RoutingOverrideAdminConfig struct {
	Enabled      bool   `yaml:"enabled"`
	PathPrefix   string `yaml:"path_prefix"`
	MaxBodyBytes int64  `yaml:"max_body_bytes"`
}

RoutingOverrideAdminConfig controls the protected GET/PUT/DELETE routing-override admin resource. Enablement is false by default.

type RoutingTransportConfig

type RoutingTransportConfig struct {
	FallbackPolicy string `yaml:"fallback_policy"`
}

type SecureSessionConfig

type SecureSessionConfig struct {
	// Enabled turns on secure-session validation and runtime wiring (store, tokens, audit gates).
	// Omitted in YAML defaults to enabled; use a pointer so explicit false can be rejected at validation time.
	Enabled *bool `yaml:"enabled"`
	// Store is "memory" (non-durable), "sqlite" (local durable), or "postgres" (managed durable).
	// Empty is normalized to "memory" in [LoadFile] when Enabled.
	Store string `yaml:"store"`
	// SQLitePath is the database file path when store is "sqlite".
	SQLitePath string `yaml:"sqlite_path"`
	// PostgresDSN is the connection string when store is "postgres".
	PostgresDSN string `yaml:"postgres_dsn"`
	// ResumeWindow is a Go duration string for inactivity-based resume limits; empty means no fixed
	// window (policy default).
	ResumeWindow string `yaml:"resume_window"`
	// TokenFingerprintKey is deployment secret material used to HMAC resume-token fingerprints; required for sqlite store.
	TokenFingerprintKey string `yaml:"token_fingerprint_key"`
	// AuditDurability is "best_effort" or "durable"; durable requires a durable store (sqlite or postgres)
	// and a long token fingerprint key.
	AuditDurability string `yaml:"audit_durability"`
	// RedactionDefault is "standard" or "strict" for operator-visible session payloads (diagnostics);
	// invalid values rejected when enabled.
	RedactionDefault string `yaml:"redaction_default"`
	// DiagnosticsExposeSummaries registers operator session summary routes when true (requires DiagnosticsPathPrefix
	// and a non-empty diagnostics.shared_secret, same minimum length as other protected diagnostics routes).
	DiagnosticsExposeSummaries bool `yaml:"diagnostics_expose_summaries"`
	// DiagnosticsPathPrefix is the URL prefix for secure-session diagnostics (e.g. "/debug/sessions");
	// must start with "/".
	DiagnosticsPathPrefix string `yaml:"diagnostics_path_prefix"`
	// NonDurableWarning is "silent", "log", or "strict" when store is non-durable (memory): strict fails
	// validation when audit requires durability.
	NonDurableWarning string `yaml:"non_durable_warning"`
	// RequireWorkspaceID when true rejects secure-session turns when no workspace id was resolved
	// (maps to [WorkspaceMatchRequired] on BeginTurn; Req 11.1 / 11.6).
	RequireWorkspaceID bool `yaml:"require_workspace_id"`
	// WorkspaceResolveOnError is "fail_open" (default) or "fail_closed". When fail_closed, workspace
	// resolver errors reject the request instead of continuing with an empty workspace (Req 11.6).
	WorkspaceResolveOnError string `yaml:"workspace_resolve_on_error"`
	// ResumeTokenBindPrincipalOnly when true fingerprints resume tokens using only the authenticated
	// principal id (not agent digest or first-message digest), so benign client metadata drift
	// between turns does not invalidate bearer resumes.
	ResumeTokenBindPrincipalOnly bool `yaml:"resume_token_bind_principal_only"`
	// SQLQueryCacheTTL is a Go duration string enabling process-local TTL caching of session existence
	// and transcript_enabled reads in durable SQL secure-session stores. Empty disables caching.
	SQLQueryCacheTTL string `yaml:"sql_query_cache_ttl"`
	// SQLQueryCacheMaxEntries caps entries per logical cache when SQLQueryCacheTTL is set; zero uses a store default.
	SQLQueryCacheMaxEntries int `yaml:"sql_query_cache_max_entries"`
}

SecureSessionConfig controls the core-owned secure session layer (resume proofs, durable evidence, diagnostics). When Enabled is omitted (nil), secure sessions default to on with store memory unless overridden. Explicit enabled: false is rejected by validation (legacy continuity-only executor path was removed).

type SelfDefenseAdaptiveConfig

type SelfDefenseAdaptiveConfig struct {
	AuthFailures      *int     `yaml:"auth_failures"`
	Window            string   `yaml:"window"`
	InitialQuarantine string   `yaml:"initial_quarantine"`
	MaxQuarantine     string   `yaml:"max_quarantine"`
	StateTTL          string   `yaml:"state_ttl"`
	MaxEntries        *int     `yaml:"max_entries"`
	ExemptCIDRs       []string `yaml:"exempt_cidrs"`
}

SelfDefenseAdaptiveConfig carries the request-policy fields (reloadable) plus the process-state sizing fields (restart-required in v1).

type SelfDefenseConfig

type SelfDefenseConfig struct {
	Enabled         *bool                     `yaml:"enabled"`
	ImpossiblePaths *bool                     `yaml:"impossible_paths"`
	Adaptive        SelfDefenseAdaptiveConfig `yaml:"adaptive"`
}

SelfDefenseConfig is the typed ingress self-defense surface. Enabled and ImpossiblePaths are presence-aware so omitted means the documented default true while explicit false is preserved. No process state is represented here.

type ServerConfig

type ServerConfig struct {
	Address  string   `yaml:"address"`
	AuthMode AuthMode `yaml:"auth_mode"`
	// MaxRequestBodyBytes caps HTTP request bodies for bundled frontends. Zero selects
	// each handler's default limit (see internal/plugins/frontends/reqbody).
	MaxRequestBodyBytes int64 `yaml:"max_request_body_bytes"`
	// ReadHeaderTimeout is a Go duration string (e.g. "10s") for [http.Server.ReadHeaderTimeout].
	// Empty defaults to 10s (historical stdhttp behavior).
	ReadHeaderTimeout string `yaml:"read_header_timeout"`
	// ReadTimeout is [http.Server.ReadTimeout] (full request body read + per-connection read deadlines).
	// Empty defaults to 30s.
	ReadTimeout string `yaml:"read_timeout"`
	// WriteTimeout is [http.Server.WriteTimeout]. Empty defaults to 120s.
	WriteTimeout string `yaml:"write_timeout"`
	// IdleTimeout is [http.Server.IdleTimeout]. Empty defaults to 120s.
	IdleTimeout string `yaml:"idle_timeout"`
	// ShutdownTimeout bounds HTTP drain and host close on process shutdown.
	// Empty defaults to 15s.
	ShutdownTimeout string `yaml:"shutdown_timeout"`
	// MaxConcurrentDecodes caps concurrent frontend protocol decode/materialization work.
	// Zero selects the documented default (32) during validation. Body ReadAll and JSON
	// preflight run before admission.
	MaxConcurrentDecodes int `yaml:"max_concurrent_decodes"`
	// MaxInflightDecodeBytes caps weighted in-flight decode bytes across concurrent decodes
	// while decode is active. Zero selects the documented default (64 MiB) during validation.
	MaxInflightDecodeBytes int64 `yaml:"max_inflight_decode_bytes"`
	// MaxPendingWireEvents caps backend adapter-internal pending-event queues per stream (0 = unlimited).
	MaxPendingWireEvents int `yaml:"max_pending_wire_events"`
	// LargePayloadFastPath controls the optional large-payload streaming fast
	// path (design section 3). Default off; see LargePayloadFastPathConfig for
	// plaintext-spool and optimization-budget semantics.
	LargePayloadFastPath LargePayloadFastPathConfig `yaml:"large_payload_fast_path"`
	// PreRequestKeepalive optionally emits SSE comment keepalives while streaming frontends wait for
	// pre-request admission handlers to finish inside executor setup.
	PreRequestKeepalive PreRequestKeepaliveConfig `yaml:"pre_request_keepalive"`
}

func (ServerConfig) EffectiveIdleTimeout

func (s ServerConfig) EffectiveIdleTimeout() time.Duration

EffectiveIdleTimeout returns IdleTimeout or the default (120s).

func (ServerConfig) EffectiveMaxConcurrentDecodes

func (s ServerConfig) EffectiveMaxConcurrentDecodes() int

EffectiveMaxConcurrentDecodes returns MaxConcurrentDecodes when positive, otherwise the default (32).

func (ServerConfig) EffectiveMaxInflightDecodeBytes

func (s ServerConfig) EffectiveMaxInflightDecodeBytes() int64

EffectiveMaxInflightDecodeBytes returns MaxInflightDecodeBytes when positive, otherwise the default (64 MiB).

func (ServerConfig) EffectiveMaxPendingWireEvents

func (s ServerConfig) EffectiveMaxPendingWireEvents() int

EffectiveMaxPendingWireEvents returns MaxPendingWireEvents as configured (0 = unlimited).

func (ServerConfig) EffectiveMaxRequestBodyBytes

func (s ServerConfig) EffectiveMaxRequestBodyBytes() int64

EffectiveMaxRequestBodyBytes returns MaxRequestBodyBytes when positive, otherwise zero (callers treat zero as "use handler default").

func (ServerConfig) EffectiveMaxRequestBodyBytesForBudget

func (s ServerConfig) EffectiveMaxRequestBodyBytesForBudget() int64

EffectiveMaxRequestBodyBytesForBudget returns the largest single request body the server admits for decode-budget checks: MaxRequestBodyBytes when positive, otherwise the documented 8 MiB default.

func (ServerConfig) EffectivePreRequestKeepalive

func (s ServerConfig) EffectivePreRequestKeepalive() EffectivePreRequestKeepaliveConfig

func (ServerConfig) EffectiveReadHeaderTimeout

func (s ServerConfig) EffectiveReadHeaderTimeout() time.Duration

EffectiveReadHeaderTimeout returns ReadHeaderTimeout or the default (10s).

func (ServerConfig) EffectiveReadTimeout

func (s ServerConfig) EffectiveReadTimeout() time.Duration

EffectiveReadTimeout returns ReadTimeout or the default (30s).

func (ServerConfig) EffectiveShutdownTimeout

func (s ServerConfig) EffectiveShutdownTimeout() time.Duration

EffectiveShutdownTimeout returns ShutdownTimeout or the default (15s).

func (ServerConfig) EffectiveWriteTimeout

func (s ServerConfig) EffectiveWriteTimeout() time.Duration

EffectiveWriteTimeout returns WriteTimeout or the default (120s).

type StreamRecoveryConfig

type StreamRecoveryConfig struct {
	AutoResume AutoResumeConfig `yaml:"auto_resume"`
}

type StreamRecoveryOverrides

type StreamRecoveryOverrides struct {
	EnvEnabled          *bool
	CLIEnabled          *bool
	EnvIdleTimeout      time.Duration
	CLIIdleTimeout      time.Duration
	EnvGracePeriod      time.Duration
	CLIGracePeriod      time.Duration
	EnvPostOutputPolicy StreamRecoveryPostOutputPolicy
	CLIPostOutputPolicy StreamRecoveryPostOutputPolicy
	EnvEmitWarning      *bool
	CLIEmitWarning      *bool
}

func StreamRecoveryOverridesFromEnv

func StreamRecoveryOverridesFromEnv() (StreamRecoveryOverrides, error)

type StreamRecoveryPostOutputPolicy

type StreamRecoveryPostOutputPolicy string
const (
	StreamRecoveryPostOutputFinishWithWarning StreamRecoveryPostOutputPolicy = "finish_with_warning"
	StreamRecoveryPostOutputFail              StreamRecoveryPostOutputPolicy = "fail"
)

type TracingConfig

type TracingConfig struct {
	// Enabled turns on SDK wiring, W3C propagation, and outbound HTTP tracing on the shared upstream client.
	Enabled bool `yaml:"enabled"`
	// ServiceName sets otel resource service.name when non-empty; otherwise OTEL_SERVICE_NAME or "lipstd".
	ServiceName string `yaml:"service_name"`
	// SampleRatio when set and strictly between 0 and 1 applies ParentBased(TraceIDRatioBased) for root spans.
	// When nil or 1, the SDK default sampler applies (typically full sampling for new roots).
	SampleRatio *float64 `yaml:"sample_ratio"`
}

TracingConfig enables OpenTelemetry traces (incoming otelhttp + OTLP export via standard OTEL_* env vars).

type WireModelForBackend

type WireModelForBackend func(factoryID string) string

WireModelForBackend resolves the default model token for a backend factory id (plugin kind) when synthesizing a fallback route selector. Supplied at composition time (typically standardplugins.DefaultWireModel) so policy stays independent of HTTP mounting.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL