pub struct RuntimeConfig {Show 20 fields
pub mounts: Vec<MountConfig>,
pub db_path: Option<PathBuf>,
pub default_namespace: Namespace,
pub embedding_model: Option<EmbeddingModel>,
pub additional_embedding_models: Vec<EmbeddingModel>,
pub gate: GateRef,
pub packs: Vec<String>,
pub blob_hydration_bytes: u64,
pub backend_id: BackendId,
pub brain_profile: Option<String>,
pub visible_namespaces: Vec<Namespace>,
pub allowed_outbound_namespaces: Vec<Namespace>,
pub actor_id: Option<String>,
pub brain: BrainSectionConfig,
pub git_write: GitWriteSectionConfig,
pub exec: ExecSectionConfig,
pub telemetry: TelemetryConfig,
pub display_timezone: Tz,
pub events_split: Option<EventsSplitConfig>,
pub web: WebSectionConfig,
}Expand description
Runtime configuration.
The db_path field remains for backward compatibility and as input to the
supported async khive-mcp/kkernel host builders. Direct backend assembly is
reserved for an already-coordinated database; use
crate::KhiveRuntime::from_prepared_backend when that precondition has
been established. embedding_model remains as the primary-model config
shorthand beside the provider registry.
Fields§
§mounts: Vec<MountConfig>§db_path: Option<PathBuf>Path to the SQLite database file. None = in-memory (tests).
Production boot passes this value to the async khive-mcp/kkernel host builders, which coordinate V21 before constructing runtimes. Tests and already-current single-backend callers may still use it directly.
default_namespace: NamespaceNamespace used when no explicit namespace is provided.
embedding_model: Option<EmbeddingModel>Local embedding model. None alone does not disable embedding: setting
only this field to None while additional_embedding_models is
non-empty still registers those models. Both embedding_model and
additional_embedding_models must be empty to disable built-in
embedding model registration, at which point hybrid_search falls back
to text-only. Use RuntimeConfig::no_embeddings to clear both fields
together — it is the canonical constructor for this. Custom embedder
providers registered later by packs are not affected by this field.
Deprecated: embedding engines move to a per-pack EmbedderRegistry.
This field persists for backward compatibility until the embedder registry
is fully plumbed.
additional_embedding_models: Vec<EmbeddingModel>Additional embedding models to make available by request name.
embedding_model remains the default used by existing embed() and
embed_batch() callers. This list adds non-default models that can be
selected with embedder(name), embed_with_model(...), memory
remember.embedding_model, and memory recall.embedding_model.
gate: GateRefAuthorization gate consulted before each verb dispatch.
Default: AllowAllGate (permissive). For production policy enforcement,
plug in a Rego- or capability-witness-backed impl.
packs: Vec<String>Names of packs the transport layer should register into the VerbRegistry.
The transport layer (e.g. khive-mcp) reads this list and instantiates
the matching concrete pack types. Unknown names are reported as errors
by the transport, not silently ignored.
Defaults to the shipped production set returned by
RuntimeConfig::built_in_packs.
blob_hydration_bytes: u64Resolved aggregate admission budget for resident digest-verified blob buffers (ADR-160 D3), in raw bytes.
[runtime].blob_hydration_bytes may raise or lower the built-in 256 MiB
value, but config validation guarantees enough room for one maximum-size
whole-blob read.
backend_id: BackendIdIdentifies this runtime’s backend in a multi-backend deployment.
Set by the boot path when constructing per-pack runtimes from khive.toml.
Single-backend deployments use the default BackendId::MAIN.
brain_profile: Option<String>Brain profile to use for memory.feedback / knowledge.feedback and
recall-time score boosting (ADR-035 §Brain profile configuration).
Resolution order (highest to lowest, ADR-035): CLI flag, then
runtime.brain_profile in project/global khive.toml, then the
KHIVE_BRAIN_PROFILE env var as fallback default. Callers must keep
env OUT of the base config they pass in (see khive-mcp serve.rs).
--brain-profileCLI flag (explicit only)- Namespace-bound profile resolved via
brain.resolveat feedback time - Pack-local global tuning prior (default fallback)
visible_namespaces: Vec<Namespace>Operator-configured read-visibility set (ADR-007 Rev 4 Rule 3b).
OSS dispatch widens the DEFAULT multi-record read scope to
['local'] ∪ visible_namespaces. Writes remain pinned to 'local'.
An explicit namespace= request param is a precise single-namespace
escape and is not widened. Populated from actor.visible_namespaces
in khive.toml.
allowed_outbound_namespaces: Vec<Namespace>Namespaces this actor’s comm.send/reply may deliver messages INTO
(outbound, sender-side). Populated from actor.allowed_outbound_namespaces
in khive.toml. Empty by default — cross-namespace delivery denied
unless explicitly declared. The comm handler uses an ordinary
NamespaceToken (minted via with_namespace) in an append-only manner;
the token itself is NOT type-enforced write-only. The recipient-side
allowed_inbound_namespaces (bilateral mutual opt-in) is reserved for
a future cloud-path authorization ADR (not yet written).
actor_id: Option<String>Configured actor identity label (ADR-057). Populated from [actor] id in
khive.toml. When Some, authorize() mints tokens carrying this actor
label so that comm.inbox filters by to_actor instead of falling back to
the party-line “local” behavior. When None (default), tokens carry
ActorRef::anonymous() and inbox is scoped to party-line messages —
those addressed to "local" or carrying no to_actor stamp.
brain: BrainSectionConfigResolved [brain] policy from the serving process’s configuration.
git_write: GitWriteSectionConfigResolved [git_write] policy allowlist (ADR-108 Amendment), populated
from khive.toml’s [[git_write.allowed]] entries by
runtime_config_from_khive_config. Threaded through so
khive-pack-git’s write-verb handlers read an already-resolved policy
instead of re-running config discovery (which would ignore an
explicit --config path not also exported as KHIVE_CONFIG).
exec: ExecSectionConfigResolved [exec] sandbox section (ADR-181), threaded through like
git_write so the exec pack reads an already-resolved config.
telemetry: TelemetryConfigResolved carrier and failure policy for telemetry emission.
display_timezone: TzResolved rendering timezone (ADR-169), consumed today by date-only
parse_due anchoring. Populated from [display] timezone in
khive.toml by runtime_config_from_khive_config; when absent,
resolves once to the host’s local IANA zone (falling back to UTC when
the host zone cannot be determined) via resolve_default_display_timezone.
events_split: Option<EventsSplitConfig>Events-daemon split (ADR-170). None = legacy behavior: events persist
in the main store. Some routes event persistence to the events database —
forwarded over the events daemon socket in daemon deployments, opened
directly in embedded/one-shot contexts. Populated by the transport
hosts (khive-mcp serve, kkernel exec); tests and in-memory runtimes
leave it None.
web: WebSectionConfigResolved [web] policy (ADR-175 Amendment 1), threaded through like
exec/git_write so khive-pack-web reads an already-resolved config.
Implementations§
Source§impl RuntimeConfig
impl RuntimeConfig
Sourcepub fn built_in_packs() -> Vec<String>
pub fn built_in_packs() -> Vec<String>
Return the shipped pack set used when no CLI, environment, or configuration-file selection is present.
Sourcepub fn no_embeddings() -> Self
pub fn no_embeddings() -> Self
Build a RuntimeConfig with embedding disabled entirely.
embedding_model and additional_embedding_models are computed
independently inside Default::default, so RuntimeConfig { embedding_model: None, ..RuntimeConfig::default() } does NOT produce a
model-less runtime: additional_embedding_models still carries its
env-driven fallback seed, and the note-write path fans out embedding to
every registered model regardless of embedding_model: so the first
memory.remember on a machine without local model files hard-fails
instead of degrading to FTS-only.
This constructor clears both fields together and ignores
KHIVE_ADDITIONAL_EMBEDDING_MODELS unconditionally: the caller wants
zero embedders, not “zero unless the environment disagrees”. Use it on
model-less machines (CI runners, fresh installs without local model
files) instead of the two-field struct-update form.
Trait Implementations§
Source§impl Clone for RuntimeConfig
impl Clone for RuntimeConfig
Source§impl Debug for RuntimeConfig
impl Debug for RuntimeConfig
Auto Trait Implementations§
impl !RefUnwindSafe for RuntimeConfig
impl !UnwindSafe for RuntimeConfig
impl Freeze for RuntimeConfig
impl Send for RuntimeConfig
impl Sync for RuntimeConfig
impl Unpin for RuntimeConfig
impl UnsafeUnpin for RuntimeConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more