Expand description
Local configuration files (RON).
Two distinct files, split by audience:
project.cfg— one per project folder, read by the client commands (sync,build,bundle,validate): where/how to publish, the optional build/bundle steps, and the deploy-scopedroutingconfig that is folded into the immutable deployment manifest. SeeProjectConfig.boatramp.cfg— the server daemon config, read byserve:serve/handlers/cluster. SeeServerConfig.
Both are RON; a missing file yields the default config.
Structs§
- Bindings
Config handlers.bindings— per-binding backend configuration. kv/blob reuse the server’s own KV/Storage backends (per-site prefixed);sqlis the single libsql backend, whose single-node-vs-cluster split is the only choice.- Blob
Fallback Config [serve.blob_fallback]— a read-only SECONDARY blob backend for a zero-downtime backend switch (blob-backend migration Part 2). Same backend-descriptor shape as the PRIMARY ([serve]’sblobs/s3_*/gcs_*/azure_*fields) so a source/dest is fully described by config, plus its OWN optionals3_credential(the secondary can source its base S3 credential from the sealed[secrets]store via its ownboatramp:/env:ref, #505). Constructed exactly like the primary but with NO watcher provisioning (a read-only drain source never watches). Serving wrapsFallbackStorage::new(primary, secondary, …)so a primary miss on a boatramp-owned key falls through to this secondary; writes/deletes are primary-only.- Build
Config buildsection.- Bundle
Config bundlesection — the in-process Rust bundler (bundlerfeature).- Cluster
Config clustersection — self-hosted cluster mode. Parsed in every build so config files stay portable; only consumed when theclusterfeature is compiled in (boatramp serve --mode cluster).- Compute
Config computesection — opt-in compute backends. Present ⇒serveregisters the backends this node can offer and advertises them to the scheduler; backends are capability-detected (container on Linux, remote docker when a daemon is reachable, VMM when/dev/kvmexists).- Console
Config [serve.console]— the embedded web console (a Wasm SPA baked into the binary with theconsolebuild feature). Opt-in: the static shell holds no secrets and the/apiit drives is token-gated, so it is served unauthenticated at a deliberately obscure path (a bearer token can’t gate a top-level browser navigation anyway — the path is the obscurity, the token is the real gate).- External
Database Config - One external SQL database for the handler
sqlbinding. Its source is one of two mutually-exclusive forms: - Handlers
Config handlerssection — server-side handler runtime config (read byserve). Parsed in every build (so config files stay portable), but only consumed when thehandlersfeature is compiled in.- Mesh
Config [cluster.mesh]— mesh identity + TLS knobs.- Project
Config - Project configuration, loaded from
project.cfg(RON) in the project folder. - Publish
Config publishsection — where and what to deploy (thesynctarget).- S3Credential
Config [serve.s3_credential]— a node-level base S3 credential source (#505) sourcing the base AWS credential from boatramp’s[secrets]sealed store rather than the ambient env chain. Consumed by BOTH the S3 blob object backend and the AWS blob-upload cloud minter (one shared source, since it is the same bucket key). Additive/non-breaking: absent ⇒ the ambient AWS env chain (unchanged).- S3Ingress
Cloud [serve.s3_ingress_cloud]— the cloud-brokering knobs for the M4 blob-upload minter (which native credential the mint brokers when the node’s blob backend is a cloud object store). Only the fields for the active blob backend are consulted; aNonehere ⇒ the local S3 face mints.- Secrets
Config secretssection — envelope encryption for private keys at rest.- Serve
Config servesection — server defaults, overridden by flags/env.- Server
Config - Server daemon configuration, loaded from
boatramp.cfg(RON). Read byboatramp serve; flags/env override theservevalues. - SqlBinding
Config - libsql settings for the handler
sqlbinding — the single SQL backend. Each site gets a real database boundary (an embedded file per site, or a sqld namespace per site), never schema separation (which arbitrary guest SQL escapes). Settingurlswitches from single-node to a shared sqld cluster; everything else stays identical. - Vault
Secrets Config - Vault Transit settings for
envelope = "vault". The token is read from the environment (token_env), never stored in the config file.
Enums§
- Auth
Signer Config - External token signer selector (
serve.signer). Maps toboatramp_server::signer::SignerConfig; secrets (tokens/PINs) are resolved from the named env vars at startup, never stored in config. Written as a RON enum —signer: Vault(...),signer: AwsKms(...),signer: Pkcs11(...), …. - Config
Error - A failure loading or parsing a local config file (
project.cfg/boatramp.cfg). - Config
Format - The wire format an operator-authored config file is decoded as (v0.6.5).
- Managed
DbPrivilege - How a managed database (PLAN-managed-compute-sql) runs its stock image on a
shared-kernel backend, whose entrypoint would otherwise fail under the dropped-
ALLhardening.rootless(the default) needs no capabilities and works under any posture;capsis the fallback for an image that won’t run rootless. - Signer
Alg - The signing algorithm for a signer that can choose one (
Local,Vault,Pkcs11). ES256 is the portable default; the cloud KMS backends are ES256-only and ignore this. Written as a RON enum:alg: Es256/alg: Ed25519. - Tenant
Isolation - How a managed compute-backed database is physically isolated per tenant (2×2 axis
1).
Single= a dedicated server (container) per tenant (isolation by separate process);Shared= one server with a per-tenant database + login role (isolation by grants — PostgresREVOKE CONNECT FROM PUBLIC+ owner grant; MySQL per-schema grant), so a tenant’s role cannot connect to another tenant’s database. - Tenant
Scope - The grain of a tenant for a managed compute-backed database (2×2 axis 2) —
Project(default) orSite. The two grains are parallel; the isolation mechanism isTenantIsolation.
Constants§
- BOATRAMP_
KERNEL_ SIGNING_ PUBKEY - The built-in boatramp kernel-signing public key (
es256:…), whose private half lives as theKERNEL_SIGNING_KEYActions secret inBoatRamp/boatramp-vmlinux. Shipped as a default trust anchor so the first-party signedboatramp-vmlinuxverifies out of the box under the strict posture. An operator can replacekernel_signing_pubkeysto trust only their own keys. - DEFAULT_
BLOB_ FALLBACK_ TIMEOUT_ SECS - Default bound (seconds) on a
[serve.blob_fallback]secondary read whensecondary_timeout_secsis unset: 5s — long enough for a cloud round-trip, short enough that a wedged secondary degrades a primary miss toNotFoundpromptly rather than hanging serving. - DEFAULT_
S3_ INGRESS_ MINT_ MAX_ TTL_ SECS - The default operator ceiling on a minted S3 upload credential’s TTL when
[serve].s3_ingress_mint_max_ttl_secsis unset: 1 hour — long enough for a browser UGC upload or a bulk-agent burst, short enough to bound a leaked short-lived credential.
Functions§
- resolve_
format - Resolve the
ConfigFormatfor a config path. - ron_
options - RON parse options shared by both loaders:
implicit_somelets optional fields be written as bare values (server: "...", notSome("...")).pubso the binary (which re-exports this module) can parse a manifest with the same options after the module moved into this crate.