pub struct SettingsProxy {Show 17 fields
pub auto_start: bool,
pub auto_start_timeout: String,
pub auto_trust: bool,
pub dns: bool,
pub dns_port: i64,
pub enable: bool,
pub host: String,
pub https: bool,
pub idle_timeout: String,
pub lan: bool,
pub lan_ip: String,
pub port: i64,
pub sync_hosts: bool,
pub tld: String,
pub tls_cert: String,
pub tls_key: String,
pub wildcard: bool,
}Expand description
The proxy.* settings.
Fields§
§auto_start: boolAutomatically start daemons when accessed via proxy URL
Enabled by default. Opening a stopped daemon’s proxy URL starts its
depends dependencies first, using the same startup order and readiness
checks as pitchfork start. Oneshot dependencies must complete successfully.
The first request waits for startup. Additional requests to the same daemon receive a “Starting…” page that refreshes every two seconds until it is ready. Opening a project or stack page does not start any daemons.
Set to false to return a 502 error for stopped daemons and require manual startup.
auto_start_timeout: StringMaximum time to wait for an auto-started daemon to become ready
Limits how long a proxy request waits for dependency startup, readiness checks, and detection of the daemon’s bound port. Defaults to 30 seconds.
On timeout, the request receives an error page, but startup continues in
the background. Reload to check again, or increase this setting for a
longer startup sequence, for example "60s".
auto_trust: boolAutomatically trust the generated proxy CA certificate
When enabled (default), pitchfork attempts to install its generated CA certificate into the system trust store during HTTPS proxy startup.
On macOS, this triggers a system authorization dialog (Touch ID or password).
On Linux, use pitchfork proxy setup to install the CA with sudo while
keeping the supervisor unprivileged.
If auto-trust fails, pitchfork logs a warning and continues starting the
proxy. Use pitchfork proxy doctor to check trust, or
pitchfork proxy trust to install the CA manually (with sudo on Linux).
Set to false to disable auto-trust entirely.
dns: boolRun a loopback DNS resolver for the proxy TLD
While the proxy is running, answer UDP and TCP DNS queries on
127.0.0.1:<proxy.dns_port> for names under proxy.tld, including nested
project and worktree hostnames. Answers follow proxy.host, or the LAN
IPv4 address in LAN mode. Names outside the TLD receive REFUSED; queries
are never forwarded.
Run pitchfork proxy setup to configure system resolution separately.
Set to false when using another resolver or when DNS is not needed.
dns_port: i64Port the loopback DNS resolver listens on
The resolver binds 127.0.0.1:<dns_port> on both UDP and TCP.
The default avoids privileged port 53 and the mDNS port, 5353.
enable: boolEnable the reverse proxy server for daemons
When enabled, pitchfork starts a reverse proxy that routes a stable hostname to the daemon’s actual listening port.
Every daemon with a port gets a hostname built from its name, its
worktree when it lives in one, and its project, unless it opts out with
proxy = false. A daemon without a port is not routed.
Example: api.myproject.localhost:7777 -> localhost:3000
host: StringBind address for the reverse proxy server
IP address the reverse proxy listens on.
Security Warning: The default 127.0.0.1 only allows local connections.
Setting this to 0.0.0.0 will expose the proxy on every network interface,
including externally routable ones – anyone on the same LAN can then reach
your local daemons.
Examples:
"127.0.0.1"- Local only (default, recommended)"0.0.0.0"- All interfaces (use with caution)"::1"- IPv6 loopback
https: boolEnable HTTPS for the reverse proxy
When enabled (default), the proxy serves HTTPS instead of HTTP.
You must also configure proxy.tls_cert and proxy.tls_key, or pitchfork
will auto-generate a self-signed certificate stored in the state directory.
Set to false to use plain HTTP (e.g. for simple local development).
idle_timeout: StringStop proxy-started daemons after this long without proxy activity
Disabled by default: an empty string or "0" disables the default timeout.
Set a duration such as "15m" or "1h" to enable idle shutdown for daemons
started through their proxy URL. A daemon’s proxy_idle_timeout overrides
this setting; dependencies without an override inherit the requested
daemon’s timeout.
HTTP requests count until their response ends. Streaming responses, WebSockets, and TLS passthrough connections keep a daemon active while open. DNS lookups, idle keep-alive connections, and traffic sent directly to the daemon’s port do not count.
Only proxy-started daemons are eligible. Explicitly starting a daemon exempts it and its dependencies from idle shutdown. Live dependents and tracked shell sessions also prevent shutdown.
Eligibility is checked every general.interval (10 seconds by default).
Dependencies stop after their dependents; shutdown may take longer than
the idle timeout. The timeout is recorded at startup, and activity
tracking resets after a supervisor restart.
lan: boolEnable LAN mode for the reverse proxy
When enabled, the proxy switches to the .local TLD and publishes slug
hostnames via mDNS so that other devices on the same network can reach
your daemons (e.g. myapp.local from a phone or another computer).
LAN mode:
- Forces
proxy.tldtolocal(mDNS requirement) - Publishes each slug as an mDNS address record (
<slug>.local → <LAN-IP>) - Binds the proxy to
0.0.0.0instead of127.0.0.1(overridable viaproxy.host) - Auto-detects your LAN IP and re-publishes mDNS records if it changes
Other devices must trust the pitchfork CA certificate to use HTTPS.
Run pitchfork proxy trust on each device, or use proxy.https = false.
lan_ip: StringPin a specific LAN IP address instead of auto-detecting
When set, skips auto-detection and uses this IP for mDNS publishing.
Implies proxy.lan = true if a non-empty value is provided.
port: i64Port the reverse proxy server listens on
The port pitchfork’s reverse proxy binds to. Must be in the range 1-65535.
Default is 443 (standard HTTPS port) since the proxy defaults to HTTPS. Users can override this to any port (e.g. 7777) to avoid requiring elevated privileges.
To use standard ports without running the supervisor as root, choose
an unprivileged listener such as 8443 and run pitchfork proxy setup
to redirect local traffic on macOS or Linux. On Linux, setup can also
grant permission to bind ports below 1024 directly.
sync_hosts: boolAutomatically sync slug hostnames to /etc/hosts (deprecated)
Deprecated and scheduled for removal after one release. Run
pitchfork proxy setup, check resolution with pitchfork proxy doctor,
then set sync_hosts = false. The loopback DNS resolver supports nested
hostnames without per-host entries.
When enabled (default), pitchfork adds entries to /etc/hosts for
registered slugs (e.g. 127.0.0.1 myapp.localhost) so that browsers can
resolve them. Entries are managed in a marked block and cleaned up when
the proxy shuts down. Writing to /etc/hosts may require sudo, and it
only ever covers registered slugs, never wildcard names.
tld: StringTop-level domain used for proxy URLs
The TLD appended to daemon hostnames in proxy URLs.
With the default localhost, daemon URLs look like:
api.myproject.localhost:7777 (daemon api of project myproject)
Run pitchfork proxy setup to configure system resolution, including
for custom TLDs such as test, or use --pac for applications that honor
automatic proxy settings. Restart the supervisor after changing the TLD.
tls_cert: StringPath to TLS certificate file (PEM format) for HTTPS proxy
Path to a PEM-encoded TLS certificate file used when proxy.https = true.
It is served as-is for every hostname, and must match proxy.tls_key.
If left empty and proxy.https = true, pitchfork generates a local
certificate authority at $PITCHFORK_STATE_DIR/proxy/ca.pem and signs a
certificate per hostname from it on the first TLS handshake, caching
them in $PITCHFORK_STATE_DIR/proxy/host-certs/. Trusting the CA once
with pitchfork proxy trust covers every proxy hostname.
With a custom certificate, pitchfork serves that certificate without
signing per-hostname certificates. It must cover every hostname you
use, and clients must trust its issuer. Setup skips CA installation;
set proxy.auto_trust = false to also disable startup CA trust.
tls_key: StringPath to TLS private key file (PEM format) for HTTPS proxy
Path to a PEM-encoded private key file matching proxy.tls_cert. The
pair is checked at startup, so a mismatch is reported rather than
failing every handshake.
If left empty and proxy.https = true, pitchfork generates a CA key at
$PITCHFORK_STATE_DIR/proxy/ca-key.pem instead. See proxy.tls_cert.
wildcard: boolEnable wildcard subdomain matching for proxy routes
When enabled (default), extra labels to the left of a daemon’s hostname route to that same daemon.
For example, with a daemon reachable at api.myproject.localhost:
-
api.myproject.localhost→ exact match (always works) -
tenant.api.myproject.localhost→ wildcard fallback to the same daemon
The same holds for a legacy slug, where tenant.myapp.localhost falls
back to the slug myapp.
This is useful for multi-tenant apps where each tenant gets a unique
subdomain (e.g. acme.myapp.localhost, globex.myapp.localhost) but
all share the same backend server.
Set to false to require exact hostname matches only.
Implementations§
Source§impl SettingsProxy
impl SettingsProxy
Sourcepub const SETTINGS_PROPS: &'static [PropMeta] = <Self as ::usage_config::Props>::PROPS
pub const SETTINGS_PROPS: &'static [PropMeta] = <Self as ::usage_config::Props>::PROPS
Every setting this struct declares, one entry per field, flattened groups
included. The registry a build.rs used to generate, generated from the
struct instead — there is no second declaration to keep in step.
Sourcepub const SETTINGS_REGISTRY: Registry
pub const SETTINGS_REGISTRY: Registry
The registry over Self::SETTINGS_PROPS, for resolve, drift, and
the layers.
Sourcepub const SETTINGS_SPEC: ConfigSpec
pub const SETTINGS_SPEC: ConfigSpec
Metadata used only when lowering this declaration into a usage spec.
Sourcepub fn read(__usage_resolved: &Resolved) -> Result<Self, ReadErrors>
pub fn read(__usage_resolved: &Resolved) -> Result<Self, ReadErrors>
This resolution’s values, as the struct.
Every field is read before anything is returned, so the error is the whole list of what is wrong rather than the first thing found.
Sourcepub fn read_lossy(__usage_resolved: &Resolved) -> (Option<Self>, ReadErrors)
pub fn read_lossy(__usage_resolved: &Resolved) -> (Option<Self>, ReadErrors)
This resolution’s values, keeping every setting that reads.
Self::read is all or nothing, which leaves a CLI two moves when one
field is bad: refuse to start, or fall back to a struct of declared
defaults and lose the environment and every config file along with the
offending value. Neither is a choice this crate should be making.
So: a field that will not read falls back to its own declared default and
the rest keep what the merge gave them, with every failure returned
alongside for the CLI to raise, log, or ignore as it sees fit. The errors
are the same ::usage_config::ReadErrors Self::read returns, so a
caller that decides a bad value is fatal has lost nothing by asking.
None only where a setting has no value and no declared default — a hole
in the declaration rather than a bad value, and nothing to fall back to.
Trait Implementations§
Source§impl Clone for SettingsProxy
impl Clone for SettingsProxy
Source§fn clone(&self) -> SettingsProxy
fn clone(&self) -> SettingsProxy
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for SettingsProxy
impl Debug for SettingsProxy
Source§impl PartialEq for SettingsProxy
impl PartialEq for SettingsProxy
Source§impl Props for SettingsProxy
impl Props for SettingsProxy
Source§const PROP_SPECS: &'static [PropSpec]
const PROP_SPECS: &'static [PropSpec]
Props::PROPS.impl StructuralPartialEq for SettingsProxy
Auto Trait Implementations§
impl Freeze for SettingsProxy
impl RefUnwindSafe for SettingsProxy
impl Send for SettingsProxy
impl Sync for SettingsProxy
impl Unpin for SettingsProxy
impl UnsafeUnpin for SettingsProxy
impl UnwindSafe for SettingsProxy
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<D> OwoColorize for D
impl<D> OwoColorize for D
Source§fn fg<C>(&self) -> FgColorDisplay<'_, C, Self>where
C: Color,
fn fg<C>(&self) -> FgColorDisplay<'_, C, Self>where
C: Color,
Source§fn bg<C>(&self) -> BgColorDisplay<'_, C, Self>where
C: Color,
fn bg<C>(&self) -> BgColorDisplay<'_, C, Self>where
C: Color,
Source§fn black(&self) -> FgColorDisplay<'_, Black, Self>
fn black(&self) -> FgColorDisplay<'_, Black, Self>
Source§fn on_black(&self) -> BgColorDisplay<'_, Black, Self>
fn on_black(&self) -> BgColorDisplay<'_, Black, Self>
Source§fn red(&self) -> FgColorDisplay<'_, Red, Self>
fn red(&self) -> FgColorDisplay<'_, Red, Self>
Source§fn on_red(&self) -> BgColorDisplay<'_, Red, Self>
fn on_red(&self) -> BgColorDisplay<'_, Red, Self>
Source§fn green(&self) -> FgColorDisplay<'_, Green, Self>
fn green(&self) -> FgColorDisplay<'_, Green, Self>
Source§fn on_green(&self) -> BgColorDisplay<'_, Green, Self>
fn on_green(&self) -> BgColorDisplay<'_, Green, Self>
Source§fn yellow(&self) -> FgColorDisplay<'_, Yellow, Self>
fn yellow(&self) -> FgColorDisplay<'_, Yellow, Self>
Source§fn on_yellow(&self) -> BgColorDisplay<'_, Yellow, Self>
fn on_yellow(&self) -> BgColorDisplay<'_, Yellow, Self>
Source§fn blue(&self) -> FgColorDisplay<'_, Blue, Self>
fn blue(&self) -> FgColorDisplay<'_, Blue, Self>
Source§fn on_blue(&self) -> BgColorDisplay<'_, Blue, Self>
fn on_blue(&self) -> BgColorDisplay<'_, Blue, Self>
Source§fn magenta(&self) -> FgColorDisplay<'_, Magenta, Self>
fn magenta(&self) -> FgColorDisplay<'_, Magenta, Self>
Source§fn on_magenta(&self) -> BgColorDisplay<'_, Magenta, Self>
fn on_magenta(&self) -> BgColorDisplay<'_, Magenta, Self>
Source§fn purple(&self) -> FgColorDisplay<'_, Magenta, Self>
fn purple(&self) -> FgColorDisplay<'_, Magenta, Self>
Source§fn on_purple(&self) -> BgColorDisplay<'_, Magenta, Self>
fn on_purple(&self) -> BgColorDisplay<'_, Magenta, Self>
Source§fn cyan(&self) -> FgColorDisplay<'_, Cyan, Self>
fn cyan(&self) -> FgColorDisplay<'_, Cyan, Self>
Source§fn on_cyan(&self) -> BgColorDisplay<'_, Cyan, Self>
fn on_cyan(&self) -> BgColorDisplay<'_, Cyan, Self>
Source§fn white(&self) -> FgColorDisplay<'_, White, Self>
fn white(&self) -> FgColorDisplay<'_, White, Self>
Source§fn on_white(&self) -> BgColorDisplay<'_, White, Self>
fn on_white(&self) -> BgColorDisplay<'_, White, Self>
Source§fn default_color(&self) -> FgColorDisplay<'_, Default, Self>
fn default_color(&self) -> FgColorDisplay<'_, Default, Self>
Source§fn on_default_color(&self) -> BgColorDisplay<'_, Default, Self>
fn on_default_color(&self) -> BgColorDisplay<'_, Default, Self>
Source§fn bright_black(&self) -> FgColorDisplay<'_, BrightBlack, Self>
fn bright_black(&self) -> FgColorDisplay<'_, BrightBlack, Self>
Source§fn on_bright_black(&self) -> BgColorDisplay<'_, BrightBlack, Self>
fn on_bright_black(&self) -> BgColorDisplay<'_, BrightBlack, Self>
Source§fn bright_red(&self) -> FgColorDisplay<'_, BrightRed, Self>
fn bright_red(&self) -> FgColorDisplay<'_, BrightRed, Self>
Source§fn on_bright_red(&self) -> BgColorDisplay<'_, BrightRed, Self>
fn on_bright_red(&self) -> BgColorDisplay<'_, BrightRed, Self>
Source§fn bright_green(&self) -> FgColorDisplay<'_, BrightGreen, Self>
fn bright_green(&self) -> FgColorDisplay<'_, BrightGreen, Self>
Source§fn on_bright_green(&self) -> BgColorDisplay<'_, BrightGreen, Self>
fn on_bright_green(&self) -> BgColorDisplay<'_, BrightGreen, Self>
Source§fn bright_yellow(&self) -> FgColorDisplay<'_, BrightYellow, Self>
fn bright_yellow(&self) -> FgColorDisplay<'_, BrightYellow, Self>
Source§fn on_bright_yellow(&self) -> BgColorDisplay<'_, BrightYellow, Self>
fn on_bright_yellow(&self) -> BgColorDisplay<'_, BrightYellow, Self>
Source§fn bright_blue(&self) -> FgColorDisplay<'_, BrightBlue, Self>
fn bright_blue(&self) -> FgColorDisplay<'_, BrightBlue, Self>
Source§fn on_bright_blue(&self) -> BgColorDisplay<'_, BrightBlue, Self>
fn on_bright_blue(&self) -> BgColorDisplay<'_, BrightBlue, Self>
Source§fn bright_magenta(&self) -> FgColorDisplay<'_, BrightMagenta, Self>
fn bright_magenta(&self) -> FgColorDisplay<'_, BrightMagenta, Self>
Source§fn on_bright_magenta(&self) -> BgColorDisplay<'_, BrightMagenta, Self>
fn on_bright_magenta(&self) -> BgColorDisplay<'_, BrightMagenta, Self>
Source§fn bright_purple(&self) -> FgColorDisplay<'_, BrightMagenta, Self>
fn bright_purple(&self) -> FgColorDisplay<'_, BrightMagenta, Self>
Source§fn on_bright_purple(&self) -> BgColorDisplay<'_, BrightMagenta, Self>
fn on_bright_purple(&self) -> BgColorDisplay<'_, BrightMagenta, Self>
Source§fn bright_cyan(&self) -> FgColorDisplay<'_, BrightCyan, Self>
fn bright_cyan(&self) -> FgColorDisplay<'_, BrightCyan, Self>
Source§fn on_bright_cyan(&self) -> BgColorDisplay<'_, BrightCyan, Self>
fn on_bright_cyan(&self) -> BgColorDisplay<'_, BrightCyan, Self>
Source§fn bright_white(&self) -> FgColorDisplay<'_, BrightWhite, Self>
fn bright_white(&self) -> FgColorDisplay<'_, BrightWhite, Self>
Source§fn on_bright_white(&self) -> BgColorDisplay<'_, BrightWhite, Self>
fn on_bright_white(&self) -> BgColorDisplay<'_, BrightWhite, Self>
Source§fn bold(&self) -> BoldDisplay<'_, Self>
fn bold(&self) -> BoldDisplay<'_, Self>
Source§fn dimmed(&self) -> DimDisplay<'_, Self>
fn dimmed(&self) -> DimDisplay<'_, Self>
Source§fn italic(&self) -> ItalicDisplay<'_, Self>
fn italic(&self) -> ItalicDisplay<'_, Self>
Source§fn underline(&self) -> UnderlineDisplay<'_, Self>
fn underline(&self) -> UnderlineDisplay<'_, Self>
Source§fn blink(&self) -> BlinkDisplay<'_, Self>
fn blink(&self) -> BlinkDisplay<'_, Self>
Source§fn blink_fast(&self) -> BlinkFastDisplay<'_, Self>
fn blink_fast(&self) -> BlinkFastDisplay<'_, Self>
Source§fn reversed(&self) -> ReversedDisplay<'_, Self>
fn reversed(&self) -> ReversedDisplay<'_, Self>
Source§fn strikethrough(&self) -> StrikeThroughDisplay<'_, Self>
fn strikethrough(&self) -> StrikeThroughDisplay<'_, Self>
Source§fn color<Color>(&self, color: Color) -> FgDynColorDisplay<'_, Color, Self>where
Color: DynColor,
fn color<Color>(&self, color: Color) -> FgDynColorDisplay<'_, Color, Self>where
Color: DynColor,
OwoColorize::fg or
a color-specific method, such as OwoColorize::green, Read moreSource§fn on_color<Color>(&self, color: Color) -> BgDynColorDisplay<'_, Color, Self>where
Color: DynColor,
fn on_color<Color>(&self, color: Color) -> BgDynColorDisplay<'_, Color, Self>where
Color: DynColor,
OwoColorize::bg or
a color-specific method, such as OwoColorize::on_yellow, Read more