Skip to main content

Config

Struct Config 

Source
pub struct Config {
Show 29 fields pub http_proxy: String, pub https_proxy: String, pub proxy_auth: Option<ProxyAuth>, pub proxy_auth_encrypted: Option<String>, pub headless_auth: bool, pub provider: String, pub defaults: Option<DefaultsConfig>, pub providers: ProviderConfigs, pub provider_instances: HashMap<String, ProviderInstanceConfig>, pub default_provider_instance: Option<String>, pub server: ServerConfig, pub keyword_masking: KeywordMaskingConfig, pub anthropic_model_mapping: AnthropicModelMapping, pub gemini_model_mapping: GeminiModelMapping, pub hooks: HooksConfig, pub tools: ToolsConfig, pub skills: SkillsConfig, pub env_vars: Vec<EnvVarEntry>, pub default_work_area: Option<DefaultWorkAreaConfig>, pub access_control: Option<AccessControlConfig>, pub features: FeatureFlags, pub memory: Option<MemoryConfig>, pub subagents: SubagentsConfig, pub cluster_fabric: ClusterFabricConfig, pub mcp: McpConfig, pub notifications: NotificationsConfig, pub connect: ConnectConfig, pub plugin_trust: PluginTrustConfig, pub extra: BTreeMap<String, Value>,
}
Expand description

Main configuration structure for Bamboo agent

Contains all settings needed to run the agent, including provider credentials, proxy settings, model selection, and server configuration.

Fields§

§http_proxy: String

HTTP proxy URL (e.g., http://proxy.example.com:8080)

§https_proxy: String

HTTPS proxy URL (e.g., https://proxy.example.com:8080)

§proxy_auth: Option<ProxyAuth>

Proxy authentication credentials

Note: this is kept in-memory only. On disk we store proxy_auth_encrypted.

§proxy_auth_encrypted: Option<String>

Encrypted proxy authentication credentials (nonce:ciphertext)

This is the at-rest storage representation. When present, Bamboo will decrypt it into proxy_auth at load time.

§headless_auth: bool

Deprecated: Use providers.copilot.headless_auth instead

§provider: String

Default LLM provider to use (e.g., “anthropic”, “openai”, “gemini”, “copilot”)

§defaults: Option<DefaultsConfig>

Default model assignments (used when features.provider_model_ref is enabled).

§providers: ProviderConfigs

Provider-specific configurations (legacy, single-instance per type).

§provider_instances: HashMap<String, ProviderInstanceConfig>

Multi-instance provider configurations keyed by instance id.

When provider_instances is non-empty, the registry and router prefer instance ids as routing keys. Legacy providers / provider fields are still supported for backward compatibility; see [Config::synthesize_legacy_instances].

§default_provider_instance: Option<String>

The default provider instance id used when a request does not specify one.

When set, this takes precedence over the legacy provider field.

§server: ServerConfig

HTTP server configuration

§keyword_masking: KeywordMaskingConfig

Global keyword masking configuration.

Previously persisted in keyword_masking.json (now unified into config.json).

§anthropic_model_mapping: AnthropicModelMapping

Anthropic model mapping configuration.

Previously persisted in anthropic-model-mapping.json (now unified into config.json).

§gemini_model_mapping: GeminiModelMapping

Gemini model mapping configuration.

Previously persisted in gemini-model-mapping.json (now unified into config.json).

§hooks: HooksConfig

Request preflight hooks.

These hooks can inspect and rewrite outgoing requests before they are sent upstream (e.g. image fallback behavior for text-only models).

§tools: ToolsConfig

Global tool toggles.

Any tool listed in disabled is omitted from the tool schemas sent to the LLM.

§skills: SkillsConfig

Global skill toggles.

Any skill listed in disabled is excluded from skill context construction and cannot be loaded through the skill runtime tools.

§env_vars: Vec<EnvVarEntry>

User-managed environment variables injected into Bash tool processes.

Secret entries are encrypted at rest; plaintext values are hydrated in memory.

§default_work_area: Option<DefaultWorkAreaConfig>

Default work area used when a session has no explicit active workspace.

§access_control: Option<AccessControlConfig>

Access control / password gate configuration.

§features: FeatureFlags

Feature flags for incremental rollout.

§memory: Option<MemoryConfig>

Memory/background summarization settings.

§subagents: SubagentsConfig

Sub-agent execution settings.

Sub-agents ALWAYS run as independent actor subprocesses (crash isolation, true parallelism) — the in-process runtime was removed, so there is no runtime toggle (a stray runtime/overrides key in an old config is silently ignored). Most users need nothing here; the fields below (max_concurrent, broker, remote/schedulable placements) are advanced.

§cluster_fabric: ClusterFabricConfig

Remote Cluster Fabric: operator-managed nodes & clusters for deploying broker-agent workers locally or over SSH. Additive/back-compat: absent ⇒ empty. SSH secrets are encrypted at rest (see crate::cluster_fabric).

§mcp: McpConfig

MCP server configuration.

Previously persisted in mcp.json (now unified into config.json).

§notifications: NotificationsConfig

Notification delivery channels (desktop + push-relay services). Secrets (ntfy token, Bark device key) are encrypted at rest — see Config::hydrate_notifications_from_encrypted / Config::refresh_notifications_encrypted.

§connect: ConnectConfig

bamboo-connect IM-platform bridges (Telegram first, #452 / epic #447). Secrets (each platform’s token) are encrypted at rest — see Config::hydrate_connect_platform_tokens_from_encrypted / Config::refresh_connect_platform_tokens_encrypted.

§plugin_trust: PluginTrustConfig

Plugin URL-install source-trust policy (host allowlist + ed25519 publisher keys). See PluginTrustConfig’s docs for the three-layer model this stacks with the checksum layer.

§extra: BTreeMap<String, Value>

Extension fields stored at the root of config.json.

This keeps the config forward-compatible and allows unrelated subsystems (e.g. setup UI state) to persist their own keys without getting dropped by typed (de)serialization.

Implementations§

Source§

impl Config

Source

pub fn hydrate_cluster_fabric_from_encrypted(&mut self)

Decrypt SSH secrets into in-memory plaintext after loading config.

Mirrors Config::hydrate_env_vars_from_encrypted: only fills a plaintext field that is currently empty, from its *_encrypted counterpart.

Source

pub fn refresh_cluster_fabric_encrypted(&mut self) -> Result<(), Error>

Re-encrypt SSH secrets from current in-memory plaintext before persisting.

Mirrors Config::refresh_env_vars_encrypted: a non-empty plaintext is (re-)encrypted; an empty plaintext leaves any existing ciphertext intact (so a redacted round-trip where the client never re-sent the secret keeps it). To CLEAR a secret, the caller swaps the whole auth variant.

Source

pub fn sanitize_cluster_fabric_for_disk(&mut self)

Clear plaintext SSH secrets before serialization to disk.

Source§

impl Config

Source

pub fn new() -> Config

Load configuration from file with environment variable overrides

Configuration loading order:

  1. Try loading from config.json ({data_dir}/config.json)
  2. Use defaults
  3. Apply environment variable overrides (highest priority)
§Environment Variables
  • BAMBOO_PORT: Override server port
  • BAMBOO_BIND: Override bind address
  • BAMBOO_DATA_DIR: Override data directory
  • BAMBOO_PROVIDER: Override default provider
  • BAMBOO_HEADLESS: Enable headless authentication mode
  • BAMBOO_MEMORY_PROJECT_PROMPT_INJECTION: Override project durable-memory index prompt injection
  • BAMBOO_MEMORY_RELEVANT_RECALL: Override relevant durable-memory recall prompt injection
  • BAMBOO_MEMORY_RELEVANT_RECALL_RERANK: Override model-based relevant recall reranking
  • BAMBOO_MEMORY_PROJECT_FIRST_DREAM: Override project-first Dream prompt behavior
Source

pub fn from_data_dir(data_dir: Option<PathBuf>) -> Config

Load config from disk AND publish its env vars to the process-global cache (so Bash tools inject them). For the context that OWNS that cache — the server bootstrap. Library / secondary readers that only need to read a value must use Config::from_data_dir_without_publish instead, or they will clobber the server’s live cache with stale disk data (#38 / #40).

Source

pub fn from_data_dir_without_publish(data_dir: Option<PathBuf>) -> Config

Load config from disk WITHOUT publishing env vars to the global cache. For non-owning readers (e.g. permission storage) that just need a config value and must not clobber the live env-var cache. #40.

Source

pub fn from_data_dir_without_env(data_dir: Option<PathBuf>) -> Config

Load config from disk WITHOUT applying BAMBOO_* env-var overrides and WITHOUT publishing to the global cache. For one-shot CLI writers (bamboo init / config set) that immediately re-save: applying env overrides here would bake transient values (port/bind/provider/memory flags) permanently into config.json. Same corruption-recovery + default fallback as the normal load.

Source

pub fn get_model(&self) -> Option<String>

Get the effective default model for the currently active provider.

When features.provider_model_ref is enabled, reads from defaults.chat before falling back to legacy provider-specific config.

Note: for most providers this is a required config value (returns None when absent). Copilot has a built-in fallback when no model is configured.

Source

pub fn get_fast_model(&self) -> Option<String>

Get the fast/cheap model for the currently active provider.

When features.provider_model_ref is enabled, reads from defaults.fast before falling back to legacy provider-specific config.

Used for lightweight tasks like title generation and summarization. Falls back to get_model() when no fast_model is configured.

Source

pub fn get_task_summary_model(&self) -> Option<String>

Get the configured task summarization model.

When features.provider_model_ref is enabled, reads from defaults.task_summary before falling back through defaults.memory_backgrounddefaults.fastdefaults.chat.

This is used for conversation/task summarization and context compression.

Source

pub fn get_memory_background_model(&self) -> Option<String>

Get the configured memory/background summarization model.

When features.provider_model_ref is enabled, reads from defaults.memory_background before falling back to legacy config.

Falls back to the provider fast model when no background model is configured or resolves to an empty string.

IMPORTANT: this intentionally does not fall back to the main interaction model. Memory compaction / reflection should be skipped or fail loudly when no background/fast model is configured.

Source

pub fn get_default_work_area_path(&self) -> Option<PathBuf>

Resolve the configured default work area path when present.

This validates that the configured directory exists, but intentionally returns the stable expanded path rather than the platform-specific canonicalized path. On macOS, canonicalize() may rewrite /var/... to /private/var/..., which is correct at the filesystem layer but undesirable as a user-facing/config-derived workspace path.

Source

pub fn get_vision_model(&self) -> Option<String>

Get the vision-capable model for the currently active provider.

Used for image understanding tasks. Falls back to get_model() when no vision_model is configured.

Source

pub fn get_reasoning_effort(&self) -> Option<ReasoningEffort>

Get the default reasoning effort for the currently active provider.

Source

pub fn reasoning_effort_for_key(&self, key: &str) -> Option<ReasoningEffort>

Resolve the configured default reasoning effort for a provider routing key.

The key may be a multi-instance provider id (for example "copilot-work") or a legacy provider type (for example "openai"). In multi-instance mode the per-instance reasoning_effort lives under provider_instances[<id>], so we resolve instance ids there first; otherwise we fall back to the legacy per-provider config. Both the execute path (crate’s get_reasoning_effort_for_provider) and the session-create path (Self::get_reasoning_effort) delegate here so the two cannot drift.

Source

pub fn disabled_tool_names(&self) -> BTreeSet<String>

Get normalized disabled tool names.

Source

pub fn normalize_tool_settings(&mut self)

Normalize tool settings (trim / dedupe / sort).

Source

pub fn disabled_skill_ids(&self) -> BTreeSet<String>

Get normalized disabled skill IDs.

Source

pub fn normalize_skill_settings(&mut self)

Normalize skill settings (trim / dedupe / sort).

Source

pub fn normalize_plugin_trust_settings(&mut self)

Normalize plugin_trust.trusted_hosts entries (trim / lowercase / drop empties) so a hand-edited config.json doesn’t silently accumulate mixed-case or whitespace-padded entries. is_host_trusted itself already matches case-insensitively regardless of how an entry is stored, so this is defense in depth / a canonical on-disk form, not the source of the security fix — that’s the host/path-component matching in is_host_trusted itself.

Source

pub fn effective_default_provider(&self) -> &str

Return the effective default provider key.

Prefers default_provider_instance when set; falls back to the legacy provider string.

Source

pub fn has_provider_instances(&self) -> bool

Whether provider instances are configured (new multi-instance path).

Source

pub fn env_vars_as_map(&self) -> HashMap<String, String>

Build a flat map of all env vars with non-empty values (for process injection).

Source

pub fn publish_env_vars(&self)

Update the global env vars cache (called on config load / reload).

Source

pub fn current_env_vars() -> HashMap<String, String>

Read the current env vars snapshot (called by Bash tool at process spawn time).

Source

pub fn current_prompt_safe_env_vars() -> Vec<PromptSafeEnvVarEntry>

Read the current prompt-safe env var snapshot (names + metadata only; no secret values).

Source

pub fn server_addr(&self) -> String

Get the full server address (bind:port)

Source

pub fn save(&self) -> Result<(), Error>

Save configuration to disk

Source

pub fn save_to_dir(&self, data_dir: PathBuf) -> Result<(), Error>

Save configuration to disk under the provided data directory.

Configuration is always stored as {data_dir}/config.json.

Source§

impl Config

Source

pub fn hydrate_proxy_auth_from_encrypted(&mut self)

Populate proxy_auth (plaintext) from proxy_auth_encrypted if present.

Many parts of the code rely on proxy_auth being hydrated in-memory so we can re-encrypt deterministically on save without ever persisting plaintext credentials.

Source

pub fn refresh_proxy_auth_encrypted(&mut self) -> Result<(), Error>

Refresh proxy_auth_encrypted from the current in-memory proxy_auth.

This is used both when persisting the config to disk and when generating API responses that should never include plaintext proxy credentials.

Source

pub fn hydrate_provider_api_keys_from_encrypted(&mut self)

Source

pub fn refresh_provider_api_keys_encrypted(&mut self) -> Result<(), Error>

Source

pub fn hydrate_provider_instance_api_keys_from_encrypted(&mut self)

Hydrate plaintext api_key fields on provider instances from their encrypted counterparts.

Source

pub fn refresh_provider_instance_api_keys_encrypted( &mut self, ) -> Result<(), Error>

Re-encrypt all provider instance API keys and write back to api_key_encrypted. Used before persisting to disk.

Source

pub fn hydrate_mcp_secrets_from_encrypted(&mut self)

Source

pub fn refresh_mcp_secrets_encrypted(&mut self) -> Result<(), Error>

Source

pub fn hydrate_env_vars_from_encrypted(&mut self)

Decrypt secret env vars into in-memory plaintext after loading config.

Source

pub fn refresh_env_vars_encrypted(&mut self) -> Result<(), Error>

Re-encrypt secret env vars before persisting to disk.

Source

pub fn sanitize_env_vars_for_disk(&mut self)

Clear plaintext values for secrets before serialization to disk.

Source

pub fn hydrate_broker_token_from_encrypted(&mut self)

Decrypt the broker token into in-memory plaintext after loading config.

Source

pub fn refresh_broker_token_encrypted(&mut self) -> Result<(), Error>

Re-encrypt the broker token before persisting to disk.

Source

pub fn sanitize_broker_token_for_disk(&mut self)

Clear the plaintext broker token before serialization to disk.

Source

pub fn hydrate_notifications_from_encrypted(&mut self)

Decrypt notification-channel secrets into in-memory plaintext after loading config. Mirrors Config::hydrate_provider_api_keys_from_encrypted: the plaintext fields are #[serde(skip_serializing)] (never on disk), so this is the only way they get populated after a fresh load.

Source

pub fn refresh_notifications_encrypted(&mut self) -> Result<(), Error>

Re-encrypt notification-channel secrets from current in-memory plaintext before persisting to disk. Mirrors Config::refresh_provider_api_keys_encrypted: an empty/absent plaintext leaves any existing ciphertext intact (a redacted round-trip where the client never re-sent the secret keeps it).

Source

pub fn hydrate_connect_platform_tokens_from_encrypted(&mut self)

Decrypt every configured platform’s token (and Feishu app_secret) into in-memory plaintext after loading config. Mirrors Config::hydrate_notifications_from_encrypted: both fields are #[serde(skip_serializing)] (never on disk), so this is the only way they get populated after a fresh load.

Source

pub fn refresh_connect_platform_tokens_encrypted(&mut self) -> Result<(), Error>

Re-encrypt every configured platform’s token (and Feishu app_secret) from current in-memory plaintext before persisting to disk. Mirrors Config::refresh_notifications_encrypted: an empty/absent plaintext leaves any existing ciphertext intact (a redacted round-trip where the client never re-sent the secret keeps it).

Source

pub fn preserve_env_sourced_provider_keys(&mut self, previous: &Config)

Restore env-sourced provider api_keys that a serde round-trip dropped.

api_key is #[serde(skip_serializing)], so serializing previous and deserializing it back — as the settings-PATCH merge in config_manager::build_merged_config does — loses every provider’s plaintext key. hydrate_provider_api_keys_from_encrypted then restores only keys that have a persisted ciphertext, which an env-injected key never has (that’s the #253 design). Without this, a PATCH to ANY provider setting silently blanks the live env-sourced key of every OTHER provider until the process restarts.

Copies the key back from previous for each provider still flagged env-sourced there whose key wasn’t explicitly re-set by the patch (i.e. is empty after the round-trip), so an explicit api_key in the patch still wins. #373.

Trait Implementations§

Source§

impl Clone for Config

Source§

fn clone(&self) -> Config

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Config

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for Config

Source§

fn default() -> Config

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for Config

Source§

fn deserialize<__D>( __deserializer: __D, ) -> Result<Config, <__D as Deserializer<'de>>::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for Config

Source§

fn serialize<__S>( &self, __serializer: __S, ) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> NoneValue for T
where T: Default,

Source§

type NoneType = T

Source§

fn null_value() -> T

The none-equivalent value.
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more