pub struct ServeConfig {Show 30 fields
pub listen: Vec<String>,
pub socket: PathBuf,
pub access: Option<(String, String)>,
pub allow_unauthenticated: bool,
pub remote_tools: ToolPolicy,
pub policy: RemotePolicy,
pub state_dir: PathBuf,
pub interval: Duration,
pub keys: KeySources,
pub secrets_config: PathBuf,
pub auth: AuthConfig,
pub public_url: Option<String>,
pub oauth: OAuthSettings,
pub open_signup: bool,
pub ingress: Option<IngressConfig>,
pub workspace_mcp_port: u16,
pub workspace_pool: Option<String>,
pub workspace_home_root: Option<PathBuf>,
pub preview_domain: Option<PreviewBase>,
pub audit_retention: Duration,
pub audit_all: bool,
pub history_retention: Duration,
pub history_max_rows: i64,
pub agent: Option<AgentConfig>,
pub superadmin_tailnet: Option<AllowList>,
pub superadmin_access: Option<AccessAllowList>,
pub dev_superadmin: Option<String>,
pub heartbeat: Option<Heartbeat>,
pub egress_pins: Vec<String>,
pub egress_ca: Vec<PathBuf>,
}Expand description
How isb serve runs.
Fields§
§listen: Vec<String>host:port addresses for remote MCP and the web UI: loopback, or a
tailnet address with superadmin_tailnet. Empty serves the socket
only.
socket: PathBuf§access: Option<(String, String)>Cloudflare Access team domain and application audience.
allow_unauthenticated: boolServe the TCP listener with no Access (local testing only).
remote_tools: ToolPolicyWhich tools remote callers see.
policy: RemotePolicy§state_dir: PathBuf§interval: Duration§keys: KeySourcesWhere the secrets key is looked for (and generated).
secrets_config: PathBuf~/.config/isb/secrets.toml: break-glass recipients.
auth: AuthConfigSession lifetimes and the rest of the identity store’s settings.
public_url: Option<String>Where users reach isb, for invitation and reset links, provider callbacks and the passkey relying party.
oauth: OAuthSettingsExternal sign-in providers (GitHub, Google, generic OIDC).
open_signup: boolAccounts without an invitation, for verified provider emails.
ingress: Option<IngressConfig>The HTTP(S) edge for stack domains; None leaves domains unserved.
workspace_mcp_port: u16The port each org’s workspace reaches the org-bound MCP on, on the org bridge’s address.
workspace_pool: Option<String>--workspace-pool: the storage pool new workspace homes go in,
unless the org sets its own; none: the org’s default pool.
workspace_home_root: Option<PathBuf>--workspace-home-root: workspace homes are host folders
<root>/<org>/home instead of managed volumes.
preview_domain: Option<PreviewBase>--preview-domain: where workspace ports’ previews get their origins.
audit_retention: DurationHow long audit rows are kept.
audit_all: boolRecord read-only tool calls too (secret reads always are).
history_retention: DurationHow long, and how many, history rows are kept.
history_max_rows: i64§agent: Option<AgentConfig>Run as a server’s agent for a control plane (docs/guides/servers.md): an
mTLS listener instead of the identity store, web UI and --listen.
superadmin_tailnet: Option<AllowList>--superadmin-tailnet: tailnet logins and tags with the unix
socket’s reach.
superadmin_access: Option<AccessAllowList>--superadmin-access: Access emails and service token client ids
with the unix socket’s reach.
dev_superadmin: Option<String>ISB_DEV_SUPERADMIN (crate::auth::dev; debug builds only):
every loopback request with no credential is this superadmin.
heartbeat: Option<Heartbeat>--heartbeat-url: a dead man’s switch pinged every interval.
egress_pins: Vec<String>--egress-pin NAME=IP[:PORT]: names the egress proxy connects to
at a fixed address instead of resolving.
egress_ca: Vec<PathBuf>--egress-ca FILE: roots the egress proxy trusts besides the system’s.