collin/anvil
10116d77570fea8ab4ec551107da11c2010d5f87 / anvil.example.toml
| 1 | # anvil configuration. Copy to `anvil.toml` and edit. All fields are optional; |
| 2 | # omitted fields fall back to the defaults shown here. |
| 3 | |
| 4 | # Root directory for all server state (database + repositories). |
| 5 | data_dir = "data" |
| 6 | |
| 7 | [http] |
| 8 | listen = "127.0.0.1:3000" |
| 9 | base_url = "http://localhost:3000" |
| 10 | # Memory budget (MiB) for the cache of syntax-highlighted file views. |
| 11 | # Highlighting large files is CPU-heavy, so repeat views are served from this |
| 12 | # cache. Set to 0 to disable it entirely on RAM-constrained hosts. |
| 13 | highlight_cache_mb = 16 |
| 14 | # Maximum size (MiB) of a single uploaded attachment (e.g. an image pasted |
| 15 | # into the web file editor). Larger uploads are rejected. |
| 16 | attachment_max_mb = 16 |
| 17 | # Per-repository cap (MiB) on total stored attachments. An upload that would |
| 18 | # exceed it is rejected; re-uploading existing (deduped) content is free. |
| 19 | # 0 means unlimited. |
| 20 | attachment_quota_mb = 0 |
| 21 | |
| 22 | [ssh] |
| 23 | enabled = false |
| 24 | # Internal bind address. Under Docker, set host = "0.0.0.0" and forward the port. |
| 25 | listen = "127.0.0.1:2222" |
| 26 | # What to show users in SSH clone URLs. Set clone_port to the externally |
| 27 | # forwarded port if it differs from the internal bind (e.g. Docker -p 2200:2222). |
| 28 | clone_host = "localhost" |
| 29 | clone_port = 2222 |
| 30 | clone_user = "git" |
| 31 | |
| 32 | [ci] |
| 33 | # Job sandbox. Containers always run with no Docker socket, no mounts, all |
| 34 | # capabilities dropped, and no-new-privileges; these knobs bound resources |
| 35 | # (0 = unlimited). See docs/untrusted-mode.md for the threat model. |
| 36 | # Images a pipeline may use: empty allows any; a tagless entry ("rust") allows |
| 37 | # every tag of that image; a tagged one ("alpine:3.20") exactly itself. |
| 38 | allowed_images = [] |
| 39 | memory_mb = 2048 |
| 40 | cpus = 2.0 |
| 41 | pids_limit = 512 |
| 42 | # Wall-clock limit per job, after which the container is killed. |
| 43 | timeout_secs = 1800 |
| 44 | # Whether jobs get network access (most builds need it to fetch dependencies). |
| 45 | network = true |
| 46 | # User inside the job container, e.g. "1000:1000". Empty keeps the image default. |
| 47 | run_as = "" |
| 48 | |
| 49 | # Artifact caps (MiB, 0 = unlimited): one artifact / one run's total / the |
| 50 | # rolling per-repo budget. Over the repo budget, the oldest commits' artifacts |
| 51 | # are deleted after each run (branch tips pinned). See docs/ci-artifacts.md. |
| 52 | artifact_max_mb = 256 |
| 53 | artifact_run_max_mb = 512 |
| 54 | artifact_quota_mb = 4096 |
| 55 | |
| 56 | # Continuous deployment: on a green run of deploy_branch in the ONE repo named |
| 57 | # by deploy_repo, POST to deploy_webhook with the X-Anvil-Deploy-Secret header. |
| 58 | # Empty deploy_repo/deploy_webhook disables deploys entirely. |
| 59 | deploy_repo = "" |
| 60 | deploy_branch = "main" |
| 61 | deploy_webhook = "" |
| 62 | deploy_secret = "" |