anvilsign in

collin/anvil

1# anvil configuration. Copy to `anvil.toml` and edit. All fields are optional;
2# omitted fields fall back to the defaults shown here.
3
4# Root directory for all server state (database + repositories).
5data_dir = "data"
6
7[http]
8listen = "127.0.0.1:3000"
9base_url = "http://localhost:3000"
10
11[ssh]
12enabled = false
13# Internal bind address. Under Docker, set host = "0.0.0.0" and forward the port.
14listen = "127.0.0.1:2222"
15# What to show users in SSH clone URLs. Set clone_port to the externally
16# forwarded port if it differs from the internal bind (e.g. Docker -p 2200:2222).
17clone_host = "localhost"
18clone_port = 2222
19clone_user = "git"
20
21[ci]
22# Job sandbox. Containers always run with no Docker socket, no mounts, all
23# capabilities dropped, and no-new-privileges; these knobs bound resources
24# (0 = unlimited). See docs/untrusted-mode.md for the threat model.
25# Images a pipeline may use: empty allows any; a tagless entry ("rust") allows
26# every tag of that image; a tagged one ("alpine:3.20") exactly itself.
27allowed_images = []
28memory_mb = 2048
29cpus = 2.0
30pids_limit = 512
31# Wall-clock limit per job, after which the container is killed.
32timeout_secs = 1800
33# Whether jobs get network access (most builds need it to fetch dependencies).
34network = true
35# User inside the job container, e.g. "1000:1000". Empty keeps the image default.
36run_as = ""
37
38# Continuous deployment: on a green run of deploy_branch in the ONE repo named
39# by deploy_repo, POST to deploy_webhook with the X-Anvil-Deploy-Secret header.
40# Empty deploy_repo/deploy_webhook disables deploys entirely.
41deploy_repo = ""
42deploy_branch = "main"
43deploy_webhook = ""
44deploy_secret = ""