pub struct SettingsSupervisor {Show 22 fields
pub auto_start: bool,
pub cleanup_orphans: bool,
pub container: bool,
pub cpu_violation_threshold: i64,
pub cron_check_interval: String,
pub file_watch_debounce: String,
pub health_check_interval: String,
pub health_check_retries: i64,
pub health_cmd_timeout: String,
pub health_http_timeout: String,
pub health_port_timeout: String,
pub http_client_timeout: String,
pub log_flush_interval: String,
pub orphan_policy: String,
pub port_bump_attempts: i64,
pub ready_check_interval: String,
pub restart_delay: String,
pub oneshot_timeout: String,
pub stop_timeout: String,
pub user: String,
pub watch_interval: String,
pub watch_poll_interval: String,
}Expand description
The supervisor.* settings.
Fields§
§auto_start: boolAutomatically start the supervisor when a client command needs it
When enabled (default), commands such as pitchfork start, pitchfork list,
the TUI, and shell activation start a background supervisor automatically when
one is not already running.
Disable this when the supervisor is managed by systemd, launchd, or another service manager:
[settings.supervisor]
auto_start = falseWith auto-start disabled, client commands wait for the configured IPC
connection attempts and then fail with an actionable error instead of spawning
an unmanaged supervisor. Explicit pitchfork supervisor start and
pitchfork supervisor run commands are unaffected.
cleanup_orphans: boolReconcile orphaned daemon processes when supervisor starts
When enabled, the supervisor scans the state file on startup for daemon
processes left behind by a previous supervisor instance that was killed
unexpectedly (for example, with kill -9) and reconciles them according
to supervisor.orphan_policy (re-adopt by default, or terminate).
Before acting, the recorded process identity (PID plus kernel start time) is verified so that a PID recycled by the OS to an unrelated process is never adopted or killed — in that case only the stale state entry is cleared. When terminating, Linux and Windows also pin that identity with a pidfd or open process handle, so a recycled PID cannot be signaled. If the identity cannot be verified or pinned, reconciliation fails closed: the live process and its running state are retained rather than risk acting on the wrong process or allowing a duplicate instance to start.
Disabling this leaves orphaned processes and their state entries
completely untouched. This is a legacy escape hatch; prefer
orphan_policy = "adopt" (the default), which keeps daemons running
across a supervisor crash while resuming supervision.
container: boolEnable container/PID1 mode for running inside Docker containers
When enabled, pitchfork operates as a proper PID 1 process inside a container:
- Installs a SIGCHLD handler to reap all orphaned/zombie child processes
- Routes SIGTERM/SIGINT through the graceful shutdown sequence
This is essential when running pitchfork as the entrypoint of a Docker container, where PID 1 must reap zombie processes to prevent process table exhaustion.
Can also be enabled via the --container CLI flag on pitchfork supervisor run.
cpu_violation_threshold: i64Consecutive CPU-over-limit samples before killing a daemon
When a daemon has cpu_limit configured, the supervisor checks CPU usage at
each interval tick. To avoid killing daemons during transient spikes (e.g. JIT
warm-up, burst responses), the process is only killed after this many
consecutive samples exceed the limit. A single sample below the limit
resets the counter.
Examples:
1- Kill immediately on first over-limit sample (no grace period)3- Require 3 consecutive over-limit samples (default)5- More tolerant of short bursts
With the default interval of 10s, a threshold of 3 means a daemon must
exceed its CPU limit for ~30 seconds before being killed.
cron_check_interval: StringInterval for checking cron schedules
How often to check if any cron-scheduled daemons should be triggered.
The default of 10 seconds supports sub-minute cron schedules. Increase for lower resource usage if you don’t need fine-grained scheduling.
file_watch_debounce: StringFile watch debounce duration
When using watch patterns to auto-restart daemons on file changes,
this controls how long to wait after the last change before triggering
a restart.
This prevents rapid restart cycles when many files change at once (e.g., during a build or git checkout).
health_check_interval: StringDefault time between health probes
When a daemon has health_cmd, health_http or health_port
configured but does not set its own interval, the supervisor probes
it this often.
health_check_retries: i64Default consecutive health-check failures before killing a daemon
When a daemon’s health_cmd, health_http or health_port fails this
many times in a row, the daemon is killed as a crash so the retry logic
restarts it. Individual daemons can override this with retries in
their health check configuration.
health_cmd_timeout: StringDefault per-probe timeout for health_cmd
Maximum time to wait for a health_cmd shell command to finish before
counting the probe as failed and cancelling it.
health_http_timeout: StringDefault per-request timeout for health_http
Maximum time to wait for a response from a health_http endpoint before
counting the probe as failed.
health_port_timeout: StringDefault per-connect timeout for health_port
Maximum time to wait for a TCP connection to a health_port to
establish before counting the probe as failed.
http_client_timeout: StringTimeout for HTTP ready checks
Maximum time to wait for a response when checking ready_http endpoints.
Increase if your services take a while to respond during startup.
log_flush_interval: StringDaemon log buffer flush interval
How often daemon log output is flushed to disk. Lower values mean logs appear faster in the UI but may impact performance.
orphan_policy: StringWhat to do with live orphaned daemons on supervisor startup: adopt or kill
When the supervisor starts and finds daemons in the state file whose processes are still alive from a previous supervisor instance that died uncleanly, this policy decides what happens (after the process identity is verified via PID plus kernel start time):
adopt(default): keep the process running and resume supervision. The daemon keeps its state (status, ports, proxy routing) and is monitored by polling. Log capture is unaffected, because a daemon’s output is read by a sibling sink process rather than by the supervisor, so it continues uninterrupted across the crash. Exit codes of adopted daemons cannot be observed, though; an adopted daemon that dies unexpectedly is markederroredwith an unknown exit code, which makes it eligible for its configured retries.kill: terminate the orphaned process group so the new supervisor starts with a clean slate, matching pre-adoption behavior.
Daemons whose recorded PID is dead, or whose PID now belongs to a different process, have their state reset under either policy. If the process identity cannot be verified, reconciliation fails closed and retains the running state without adopting or killing.
The same policy applies when the interval watcher finds a running daemon that has lost its monitor at runtime.
This setting has no effect when cleanup_orphans is disabled.
port_bump_attempts: i64Maximum port increment attempts when auto_bump_port is enabled
When auto_bump_port = true is set on a daemon, pitchfork will try incrementing
all of the daemon’s ports by the same offset to find a free range. This setting
controls how many offsets are tried before giving up with an error.
For example, with port = [3000] and port_bump_attempts = 10, pitchfork will
try ports 3000, 3001, 3002, … up to 3009 before reporting failure.
This is a global default; individual daemons can override it with
port_bump_attempts in their daemon configuration.
ready_check_interval: StringInterval between ready checks (HTTP, TCP, command)
How often to poll when checking if a daemon is ready using:
ready_http- HTTP health endpointready_port- TCP port listeningready_cmd- Shell command exit code
Lower values detect readiness faster but use more resources.
restart_delay: StringDelay between stop and start during restart
Brief pause after stopping a daemon before starting it again. Helps ensure resources (like ports) are fully released.
oneshot_timeout: StringMaximum time to wait for a oneshot daemon to finish
A oneshot = true daemon is ready when its process exits 0, so there is no
readiness check to bound the wait. pitchfork start gives up after this long
and reports a timeout; the task itself keeps running and is still recorded as
completed if it later exits successfully. A nonzero exit remains a failure.
Set to 0 for no limit. Raise it for long migrations, backfills, or seeds.
stop_timeout: StringMaximum time to wait for daemon to stop gracefully
When stopping a daemon, pitchfork sends its configured signal (SIGTERM by default) and waits this long for the process to exit gracefully before sending SIGKILL.
Increase for daemons that need time to clean up (e.g., flush data).
user: StringDefault user to run daemon processes as
Default Unix user for daemon processes spawned by the supervisor.
When set, all daemons run as this user unless an individual daemon sets
user = "...". The value may be a username (for example "postgres") or
a numeric UID (for example "501").
If unset and the supervisor is running as root via sudo, daemons default to
the sudo-calling user from SUDO_UID/SUDO_GID instead of running as root.
watch_interval: StringFile watcher config refresh interval
How often the supervisor refreshes file watch configuration when using watch patterns.
This controls how quickly newly started/stopped daemons with watch patterns are reflected in the active watcher set.
For polling watcher cadence, use supervisor.watch_poll_interval.
Lower values react faster to configuration/runtime changes but use more CPU.
The default "10s" is appropriate for most environments.
watch_poll_interval: StringPolling watcher filesystem scan interval
How often polling-based file watchers scan for changes.
This applies when daemon watch_mode is poll, or when watch_mode = "auto"
falls back to polling because native watchers are unavailable.
Lower values detect changes faster but use more CPU and I/O.
"100ms" is useful for highly interactive workflows;
"500ms" is a practical default for remote/networked filesystems.
Implementations§
Source§impl SettingsSupervisor
impl SettingsSupervisor
Sourcepub const SETTINGS_PROPS: &'static [PropMeta] = <Self as ::usage_config::Props>::PROPS
pub const SETTINGS_PROPS: &'static [PropMeta] = <Self as ::usage_config::Props>::PROPS
Every setting this struct declares, one entry per field, flattened groups
included. The registry a build.rs used to generate, generated from the
struct instead — there is no second declaration to keep in step.
Sourcepub const SETTINGS_REGISTRY: Registry
pub const SETTINGS_REGISTRY: Registry
The registry over Self::SETTINGS_PROPS, for resolve, drift, and
the layers.
Sourcepub const SETTINGS_SPEC: ConfigSpec
pub const SETTINGS_SPEC: ConfigSpec
Metadata used only when lowering this declaration into a usage spec.
Sourcepub fn read(__usage_resolved: &Resolved) -> Result<Self, ReadErrors>
pub fn read(__usage_resolved: &Resolved) -> Result<Self, ReadErrors>
This resolution’s values, as the struct.
Every field is read before anything is returned, so the error is the whole list of what is wrong rather than the first thing found.
Sourcepub fn read_lossy(__usage_resolved: &Resolved) -> (Option<Self>, ReadErrors)
pub fn read_lossy(__usage_resolved: &Resolved) -> (Option<Self>, ReadErrors)
This resolution’s values, keeping every setting that reads.
Self::read is all or nothing, which leaves a CLI two moves when one
field is bad: refuse to start, or fall back to a struct of declared
defaults and lose the environment and every config file along with the
offending value. Neither is a choice this crate should be making.
So: a field that will not read falls back to its own declared default and
the rest keep what the merge gave them, with every failure returned
alongside for the CLI to raise, log, or ignore as it sees fit. The errors
are the same ::usage_config::ReadErrors Self::read returns, so a
caller that decides a bad value is fatal has lost nothing by asking.
None only where a setting has no value and no declared default — a hole
in the declaration rather than a bad value, and nothing to fall back to.
Trait Implementations§
Source§impl Clone for SettingsSupervisor
impl Clone for SettingsSupervisor
Source§fn clone(&self) -> SettingsSupervisor
fn clone(&self) -> SettingsSupervisor
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for SettingsSupervisor
impl Debug for SettingsSupervisor
Source§impl PartialEq for SettingsSupervisor
impl PartialEq for SettingsSupervisor
Source§impl Props for SettingsSupervisor
impl Props for SettingsSupervisor
Source§const PROP_SPECS: &'static [PropSpec]
const PROP_SPECS: &'static [PropSpec]
Props::PROPS.impl StructuralPartialEq for SettingsSupervisor
Auto Trait Implementations§
impl Freeze for SettingsSupervisor
impl RefUnwindSafe for SettingsSupervisor
impl Send for SettingsSupervisor
impl Sync for SettingsSupervisor
impl Unpin for SettingsSupervisor
impl UnsafeUnpin for SettingsSupervisor
impl UnwindSafe for SettingsSupervisor
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<D> OwoColorize for D
impl<D> OwoColorize for D
Source§fn fg<C>(&self) -> FgColorDisplay<'_, C, Self>where
C: Color,
fn fg<C>(&self) -> FgColorDisplay<'_, C, Self>where
C: Color,
Source§fn bg<C>(&self) -> BgColorDisplay<'_, C, Self>where
C: Color,
fn bg<C>(&self) -> BgColorDisplay<'_, C, Self>where
C: Color,
Source§fn black(&self) -> FgColorDisplay<'_, Black, Self>
fn black(&self) -> FgColorDisplay<'_, Black, Self>
Source§fn on_black(&self) -> BgColorDisplay<'_, Black, Self>
fn on_black(&self) -> BgColorDisplay<'_, Black, Self>
Source§fn red(&self) -> FgColorDisplay<'_, Red, Self>
fn red(&self) -> FgColorDisplay<'_, Red, Self>
Source§fn on_red(&self) -> BgColorDisplay<'_, Red, Self>
fn on_red(&self) -> BgColorDisplay<'_, Red, Self>
Source§fn green(&self) -> FgColorDisplay<'_, Green, Self>
fn green(&self) -> FgColorDisplay<'_, Green, Self>
Source§fn on_green(&self) -> BgColorDisplay<'_, Green, Self>
fn on_green(&self) -> BgColorDisplay<'_, Green, Self>
Source§fn yellow(&self) -> FgColorDisplay<'_, Yellow, Self>
fn yellow(&self) -> FgColorDisplay<'_, Yellow, Self>
Source§fn on_yellow(&self) -> BgColorDisplay<'_, Yellow, Self>
fn on_yellow(&self) -> BgColorDisplay<'_, Yellow, Self>
Source§fn blue(&self) -> FgColorDisplay<'_, Blue, Self>
fn blue(&self) -> FgColorDisplay<'_, Blue, Self>
Source§fn on_blue(&self) -> BgColorDisplay<'_, Blue, Self>
fn on_blue(&self) -> BgColorDisplay<'_, Blue, Self>
Source§fn magenta(&self) -> FgColorDisplay<'_, Magenta, Self>
fn magenta(&self) -> FgColorDisplay<'_, Magenta, Self>
Source§fn on_magenta(&self) -> BgColorDisplay<'_, Magenta, Self>
fn on_magenta(&self) -> BgColorDisplay<'_, Magenta, Self>
Source§fn purple(&self) -> FgColorDisplay<'_, Magenta, Self>
fn purple(&self) -> FgColorDisplay<'_, Magenta, Self>
Source§fn on_purple(&self) -> BgColorDisplay<'_, Magenta, Self>
fn on_purple(&self) -> BgColorDisplay<'_, Magenta, Self>
Source§fn cyan(&self) -> FgColorDisplay<'_, Cyan, Self>
fn cyan(&self) -> FgColorDisplay<'_, Cyan, Self>
Source§fn on_cyan(&self) -> BgColorDisplay<'_, Cyan, Self>
fn on_cyan(&self) -> BgColorDisplay<'_, Cyan, Self>
Source§fn white(&self) -> FgColorDisplay<'_, White, Self>
fn white(&self) -> FgColorDisplay<'_, White, Self>
Source§fn on_white(&self) -> BgColorDisplay<'_, White, Self>
fn on_white(&self) -> BgColorDisplay<'_, White, Self>
Source§fn default_color(&self) -> FgColorDisplay<'_, Default, Self>
fn default_color(&self) -> FgColorDisplay<'_, Default, Self>
Source§fn on_default_color(&self) -> BgColorDisplay<'_, Default, Self>
fn on_default_color(&self) -> BgColorDisplay<'_, Default, Self>
Source§fn bright_black(&self) -> FgColorDisplay<'_, BrightBlack, Self>
fn bright_black(&self) -> FgColorDisplay<'_, BrightBlack, Self>
Source§fn on_bright_black(&self) -> BgColorDisplay<'_, BrightBlack, Self>
fn on_bright_black(&self) -> BgColorDisplay<'_, BrightBlack, Self>
Source§fn bright_red(&self) -> FgColorDisplay<'_, BrightRed, Self>
fn bright_red(&self) -> FgColorDisplay<'_, BrightRed, Self>
Source§fn on_bright_red(&self) -> BgColorDisplay<'_, BrightRed, Self>
fn on_bright_red(&self) -> BgColorDisplay<'_, BrightRed, Self>
Source§fn bright_green(&self) -> FgColorDisplay<'_, BrightGreen, Self>
fn bright_green(&self) -> FgColorDisplay<'_, BrightGreen, Self>
Source§fn on_bright_green(&self) -> BgColorDisplay<'_, BrightGreen, Self>
fn on_bright_green(&self) -> BgColorDisplay<'_, BrightGreen, Self>
Source§fn bright_yellow(&self) -> FgColorDisplay<'_, BrightYellow, Self>
fn bright_yellow(&self) -> FgColorDisplay<'_, BrightYellow, Self>
Source§fn on_bright_yellow(&self) -> BgColorDisplay<'_, BrightYellow, Self>
fn on_bright_yellow(&self) -> BgColorDisplay<'_, BrightYellow, Self>
Source§fn bright_blue(&self) -> FgColorDisplay<'_, BrightBlue, Self>
fn bright_blue(&self) -> FgColorDisplay<'_, BrightBlue, Self>
Source§fn on_bright_blue(&self) -> BgColorDisplay<'_, BrightBlue, Self>
fn on_bright_blue(&self) -> BgColorDisplay<'_, BrightBlue, Self>
Source§fn bright_magenta(&self) -> FgColorDisplay<'_, BrightMagenta, Self>
fn bright_magenta(&self) -> FgColorDisplay<'_, BrightMagenta, Self>
Source§fn on_bright_magenta(&self) -> BgColorDisplay<'_, BrightMagenta, Self>
fn on_bright_magenta(&self) -> BgColorDisplay<'_, BrightMagenta, Self>
Source§fn bright_purple(&self) -> FgColorDisplay<'_, BrightMagenta, Self>
fn bright_purple(&self) -> FgColorDisplay<'_, BrightMagenta, Self>
Source§fn on_bright_purple(&self) -> BgColorDisplay<'_, BrightMagenta, Self>
fn on_bright_purple(&self) -> BgColorDisplay<'_, BrightMagenta, Self>
Source§fn bright_cyan(&self) -> FgColorDisplay<'_, BrightCyan, Self>
fn bright_cyan(&self) -> FgColorDisplay<'_, BrightCyan, Self>
Source§fn on_bright_cyan(&self) -> BgColorDisplay<'_, BrightCyan, Self>
fn on_bright_cyan(&self) -> BgColorDisplay<'_, BrightCyan, Self>
Source§fn bright_white(&self) -> FgColorDisplay<'_, BrightWhite, Self>
fn bright_white(&self) -> FgColorDisplay<'_, BrightWhite, Self>
Source§fn on_bright_white(&self) -> BgColorDisplay<'_, BrightWhite, Self>
fn on_bright_white(&self) -> BgColorDisplay<'_, BrightWhite, Self>
Source§fn bold(&self) -> BoldDisplay<'_, Self>
fn bold(&self) -> BoldDisplay<'_, Self>
Source§fn dimmed(&self) -> DimDisplay<'_, Self>
fn dimmed(&self) -> DimDisplay<'_, Self>
Source§fn italic(&self) -> ItalicDisplay<'_, Self>
fn italic(&self) -> ItalicDisplay<'_, Self>
Source§fn underline(&self) -> UnderlineDisplay<'_, Self>
fn underline(&self) -> UnderlineDisplay<'_, Self>
Source§fn blink(&self) -> BlinkDisplay<'_, Self>
fn blink(&self) -> BlinkDisplay<'_, Self>
Source§fn blink_fast(&self) -> BlinkFastDisplay<'_, Self>
fn blink_fast(&self) -> BlinkFastDisplay<'_, Self>
Source§fn reversed(&self) -> ReversedDisplay<'_, Self>
fn reversed(&self) -> ReversedDisplay<'_, Self>
Source§fn strikethrough(&self) -> StrikeThroughDisplay<'_, Self>
fn strikethrough(&self) -> StrikeThroughDisplay<'_, Self>
Source§fn color<Color>(&self, color: Color) -> FgDynColorDisplay<'_, Color, Self>where
Color: DynColor,
fn color<Color>(&self, color: Color) -> FgDynColorDisplay<'_, Color, Self>where
Color: DynColor,
OwoColorize::fg or
a color-specific method, such as OwoColorize::green, Read moreSource§fn on_color<Color>(&self, color: Color) -> BgDynColorDisplay<'_, Color, Self>where
Color: DynColor,
fn on_color<Color>(&self, color: Color) -> BgDynColorDisplay<'_, Color, Self>where
Color: DynColor,
OwoColorize::bg or
a color-specific method, such as OwoColorize::on_yellow, Read more