Skip to main content

ServeConfig

Struct ServeConfig 

Source
pub struct ServeConfig {
Show 30 fields pub listen: Vec<String>, pub socket: PathBuf, pub access: Option<(String, String)>, pub allow_unauthenticated: bool, pub remote_tools: ToolPolicy, pub policy: RemotePolicy, pub state_dir: PathBuf, pub interval: Duration, pub keys: KeySources, pub secrets_config: PathBuf, pub auth: AuthConfig, pub public_url: Option<String>, pub oauth: OAuthSettings, pub open_signup: bool, pub ingress: Option<IngressConfig>, pub workspace_mcp_port: u16, pub workspace_pool: Option<String>, pub workspace_home_root: Option<PathBuf>, pub preview_domain: Option<PreviewBase>, pub audit_retention: Duration, pub audit_all: bool, pub history_retention: Duration, pub history_max_rows: i64, pub agent: Option<AgentConfig>, pub superadmin_tailnet: Option<AllowList>, pub superadmin_access: Option<AccessAllowList>, pub dev_superadmin: Option<String>, pub heartbeat: Option<Heartbeat>, pub egress_pins: Vec<String>, pub egress_ca: Vec<PathBuf>,
}
Expand description

How isb serve runs.

Fields§

§listen: Vec<String>

host:port addresses for remote MCP and the web UI: loopback, or a tailnet address with superadmin_tailnet. Empty serves the socket only.

§socket: PathBuf§access: Option<(String, String)>

Cloudflare Access team domain and application audience.

§allow_unauthenticated: bool

Serve the TCP listener with no Access (local testing only).

§remote_tools: ToolPolicy

Which tools remote callers see.

§policy: RemotePolicy§state_dir: PathBuf§interval: Duration§keys: KeySources

Where the secrets key is looked for (and generated).

§secrets_config: PathBuf

~/.config/isb/secrets.toml: break-glass recipients.

§auth: AuthConfig

Session lifetimes and the rest of the identity store’s settings.

§public_url: Option<String>

Where users reach isb, for invitation and reset links, provider callbacks and the passkey relying party.

§oauth: OAuthSettings

External sign-in providers (GitHub, Google, generic OIDC).

§open_signup: bool

Accounts without an invitation, for verified provider emails.

§ingress: Option<IngressConfig>

The HTTP(S) edge for stack domains; None leaves domains unserved.

§workspace_mcp_port: u16

The port each org’s workspace reaches the org-bound MCP on, on the org bridge’s address.

§workspace_pool: Option<String>

--workspace-pool: the storage pool new workspace homes go in, unless the org sets its own; none: the org’s default pool.

§workspace_home_root: Option<PathBuf>

--workspace-home-root: workspace homes are host folders <root>/<org>/home instead of managed volumes.

§preview_domain: Option<PreviewBase>

--preview-domain: where workspace ports’ previews get their origins.

§audit_retention: Duration

How long audit rows are kept.

§audit_all: bool

Record read-only tool calls too (secret reads always are).

§history_retention: Duration

How long, and how many, history rows are kept.

§history_max_rows: i64§agent: Option<AgentConfig>

Run as a server’s agent for a control plane (docs/guides/servers.md): an mTLS listener instead of the identity store, web UI and --listen.

§superadmin_tailnet: Option<AllowList>

--superadmin-tailnet: tailnet logins and tags with the unix socket’s reach.

§superadmin_access: Option<AccessAllowList>

--superadmin-access: Access emails and service token client ids with the unix socket’s reach.

§dev_superadmin: Option<String>

ISB_DEV_SUPERADMIN (crate::auth::dev; debug builds only): every loopback request with no credential is this superadmin.

§heartbeat: Option<Heartbeat>

--heartbeat-url: a dead man’s switch pinged every interval.

§egress_pins: Vec<String>

--egress-pin NAME=IP[:PORT]: names the egress proxy connects to at a fixed address instead of resolving.

§egress_ca: Vec<PathBuf>

--egress-ca FILE: roots the egress proxy trusts besides the system’s.

Trait Implementations§

Source§

impl Clone for ServeConfig

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ServeConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V