systemprompt-config 0.65.0

Profile-based configuration for systemprompt.io AI governance infrastructure. Bootstraps profiles, secrets, and credentials with zero environment-variable fallback.
Documentation
//! # systemprompt-config
//!
//! Profile-based configuration for systemprompt.io. This crate is the
//! bootstrap layer: it loads the active profile YAML, the matching
//! secrets document, and installs both into process-wide singletons
//! before any other layer (database, runtime, agent) starts.
//!
//! ## Public surface
//!
//! - [`ProfileBootstrap`] / [`SecretsBootstrap`] — process-wide cells for the
//!   active profile and secrets document, initialised in that order by the
//!   entry-crate boot sequence.
//! - [`try_init_config`] / [`build_from_profile`] — build a runtime
//!   [`systemprompt_manifest::Config`] from the active profile.
//! - [`ProviderCatalogService`], [`SecurityConfigService`] — typed mutations of
//!   the services provider registry and the profile's security section, backing
//!   the `admin config catalog` / `admin config security` CLI surfaces.
//! - [`SkillConfigValidator`] — `DomainConfig` implementation that walks
//!   `skills/` and reports missing or malformed manifests.
//!
//! ## Errors
//!
//! All public APIs return [`ConfigResult<T>`] (i.e.
//! `Result<T, ConfigError>`). [`ConfigError`] composes the bootstrap,
//! profile, secrets, schema-validation, and lower-level
//! `serde`/`std::io` errors via `#[from]` so callers can use `?`
//! transparently.
//!
//! ## Feature flags
//!
//! This crate has no Cargo features — every dependency is required at
//! compile time. The `[package.metadata.docs.rs]` section in
//! `Cargo.toml` enables `all-features = true` for parity with the
//! rest of the workspace.
//!
//! Copyright (c) systemprompt.io — Business Source License 1.1.
//! See <https://systemprompt.io> for licensing details.

pub mod bootstrap;
pub(crate) mod config_loader;
pub mod error;
pub mod path_validation;
pub mod paths;
pub mod private_file;
pub(crate) mod services;
pub(crate) mod skill_validator;
pub mod state_dir;

pub use bootstrap::{
    ENCRYPTION_MASTER_KEY_BYTES, KeyMaterialError, MANIFEST_SIGNING_SEED_BYTES, ProfileBootstrap,
    ProfileBootstrapError, ResolvedSource, SecretsBootstrap, SecretsBootstrapError,
    SecretsDocument, SecretsProvider, VaultAttemptFailure, VaultError, VaultKvProvider,
    build_loaded_secrets_message, decode_master_key, decode_seed, generate_master_key,
    generate_seed, load_secrets_from_path, persist_seed, resolve_source,
};
pub use config_loader::{
    build_from_profile, resolve_instance_id, try_init_config, validate_database_config,
};
pub use error::{ConfigError, ConfigResult};
pub use paths::{
    AppPaths, BuildPaths, PathError, StoragePaths, SystemPaths, WebPaths, WritableRoot,
};
pub use private_file::write_private_atomic;
pub use services::{
    ConfigValidationError, ModelSpec, ProviderCatalogService, ProviderSpec, SecurityChange,
    SecurityConfigService, SecurityUpdate, generate_schema, validate_config, validate_yaml_file,
    validate_yaml_str,
};
pub use skill_validator::SkillConfigValidator;
pub use state_dir::{StateDirError, StateDirsError, create_state_dir, ensure_state_dirs_writable};