anvilsign in

collin/anvil

1# anvil configuration. Copy to `anvil.toml` and edit. All fields are optional;
2# omitted fields fall back to the defaults shown here.
3
4# Root directory for all server state (database + repositories).
5data_dir = "data"
6
7[http]
8listen = "127.0.0.1:3000"
9base_url = "http://localhost:3000"
10# Memory budget (MiB) for the cache of syntax-highlighted file views.
11# Highlighting large files is CPU-heavy, so repeat views are served from this
12# cache. Set to 0 to disable it entirely on RAM-constrained hosts.
13highlight_cache_mb = 16
14# Maximum size (MiB) of a single uploaded attachment (e.g. an image pasted
15# into the web file editor). Larger uploads are rejected.
16attachment_max_mb = 16
17# Per-repository cap (MiB) on total stored attachments. An upload that would
18# exceed it is rejected; re-uploading existing (deduped) content is free.
19# 0 means unlimited.
20attachment_quota_mb = 0
21
22# Single sign-on against an OpenID Connect provider (see docs/oidc.md).
23# Off unless `issuer` is set; password sign-in keeps working either way.
24[oidc]
25# e.g. "https://login.richardscollin.com", or "https://login.localhost" for a
26# provider running locally. Empty disables single sign-on entirely.
27issuer = ""
28# Client id registered at the provider.
29client_id = "anvil"
30# Client secret. Prefer the ANVIL_OIDC_CLIENT_SECRET environment variable —
31# config files get committed, this must not. Empty for a public client.
32client_secret = ""
33# Defaults to base_url + "/-/oidc/callback". Must match the URI registered at
34# the provider exactly; there are no wildcards.
35redirect_uri = ""
36# Sign-in button text, after "Sign in with ". Defaults to the issuer's host.
37label = ""
38# Whether signing out of anvil also ends the provider's session. Needs a
39# post-logout URI registered for this client to come back here afterwards.
40sso_logout = true
41
42[ssh]
43enabled = false
44# Internal bind address. Under Docker, set host = "0.0.0.0" and forward the port.
45listen = "127.0.0.1:2222"
46# What to show users in SSH clone URLs. Set clone_port to the externally
47# forwarded port if it differs from the internal bind (e.g. Docker -p 2200:2222).
48clone_host = "localhost"
49clone_port = 2222
50clone_user = "git"
51
52[ci]
53# Job sandbox. Containers always run with no Docker socket, no mounts, all
54# capabilities dropped, and no-new-privileges; these knobs bound resources
55# (0 = unlimited). See docs/untrusted-mode.md for the threat model.
56# Images a pipeline may use: empty allows any; a tagless entry ("rust") allows
57# every tag of that image; a tagged one ("alpine:3.20") exactly itself.
58allowed_images = []
59memory_mb = 2048
60cpus = 2.0
61pids_limit = 512
62# Wall-clock limit per job, after which the container is killed.
63timeout_secs = 1800
64# Whether jobs get network access (most builds need it to fetch dependencies).
65network = true
66# User inside the job container, e.g. "1000:1000". Empty keeps the image default.
67run_as = ""
68
69# Artifact caps (MiB, 0 = unlimited): one artifact / one run's total / the
70# rolling per-repo budget. Over the repo budget, the oldest commits' artifacts
71# are deleted after each run (branch tips pinned). See docs/ci-artifacts.md.
72artifact_max_mb = 256
73artifact_run_max_mb = 512
74artifact_quota_mb = 4096
75
76# Continuous deployment: on a green run of deploy_branch in the ONE repo named
77# by deploy_repo, POST to deploy_webhook with the X-Anvil-Deploy-Secret header.
78# Empty deploy_repo/deploy_webhook disables deploys entirely.
79deploy_repo = ""
80deploy_branch = "main"
81deploy_webhook = ""
82deploy_secret = ""