Skip to main content

Module engine_config

Module engine_config 

Source
Expand description

TOML-based embedding engine configuration for khive.

Loads .khive/config.toml (or --config / KHIVE_CONFIG) and exposes an [[engines]] array for arbitrary-N embedding engine registration. Falls back to KHIVE_EMBEDDING_MODEL env vars when no config file is present.

Structs§

ActorConfig
Actor configuration — the default namespace / identity for this khive instance.
BackendConfig
Configuration for a named storage backend.
BrainSectionConfig
[brain] read policy resolved by the serving process.
DisplaySectionConfig
[display] section in khive.toml — the timezone khive anchors date-only input to (ADR-169 Implementation step 1).
EngineConfig
Configuration for a single embedding engine.
ExecLimitsConfig
[exec.limits]: per-run resource limits applied to the sandboxed child and inherited by its descendants (setrlimit before exec).
ExecSectionConfig
[exec] section (ADR-181): where runs materialize, what they may read, which caller environment keys pass through, which executable paths the never list matches, and the output caps, wall-clock defaults and resource limits. never matches paths, not a program’s capabilities (ADR-181 A9).
GateSectionConfig
Built-in caller-enrollment policy configured by [gate].
GitWriteActorConfig
GitWriteEntryConfig
One [[git_write.allowed]] entry: a repo this operator has declared trusted for khive-mediated git writes, plus the branches on it a write verb (git.commit/git.branch/git.update_ref/git.push) may target.
GitWriteRepositoryConfig
GitWriteSectionConfig
[git_write] section — the closed repo/branch allowlist consulted by khive-pack-git’s write verbs at the handler level (ADR-108 Amendment), independent of Gate policy. Absent or empty allowed is the fail-closed default: the write verbs report themselves unavailable rather than defaulting open.
KhiveConfig
Top-level khive configuration loaded from khive.toml or config.toml.
PackConfig
Per-pack backend assignment.
RuntimeSectionConfig
[runtime] section in khive.toml.
StorageSectionConfig
[storage] section in khive.toml. Holds storage-layer config not already covered by [[backends]] (ADR-028).
WebAllowlistEntry
One [[web.allowlist]] entry: an exclusive host the operator has opted into reachability for web.fetch/web.search. Presence of ANY entry makes the allowlist exclusive (ADR-175 A1.2.3); absence leaves the public internet reachable subject to the other egress rules. Matched by exact, normalized (lowercase, trailing-dot-stripped) host equality only — no suffix wildcarding, unlike [[web.credentials]].hosts (A1.2.6).
WebCeilings
Effective operator bounds shared by file validation and programmatic web dispatch.
WebCredentialConfig
One [[web.credentials]] entry: a named secret, read from the process environment at request time (never accepted as a verb argument), bound to the set of hosts it may be presented to. Each hosts entry is either an exact IP-literal address (matched exactly, never as a suffix) or a hostname suffix (example.com matches example.com and any *.example.com at a DNS label boundary) — ADR-175 A1.2.6.
WebFixtureResult
One canned result inside a kind = "fixture" [[web.search_providers]] entry — deterministic, non-networked search results (demos, offline corpora, and the fixture arm of web.search’s own test suite).
WebSectionConfig
[web] section (ADR-175 Amendment 1, ADR-191 D3): operator policy for web.fetch and web.search — ceilings, the address allowlist, credential host-set bindings, and configured search providers.

Enums§

BackendKind
Storage backend kind.
BlobConfig
[storage.blob] section: a closed backend = "fs" | "s3" selector.
ConfigError
Errors produced while loading or validating a KhiveConfig.
WebSearchProviderConfig
One [[web.search_providers]] entry (ADR-175 A1.3). The provider is operator configuration; web.search’s provider argument only selects among entries declared here by name. Closed, tagged on kind.

Functions§

config_from_env
Build an in-memory KhiveConfig from the legacy env-var path.