anvilsign in

collin/anvil

1# Config for the local Docker instance started by deploy/dev.sh.
2#
3# Committed on purpose (unlike deploy/anvil.toml, which is gitignored because it
4# holds production's deploy secret): nothing here is sensitive, and a working
5# local instance should be one command away.
6
7data_dir = "/data"
8
9[http]
10# Inside the container; deploy/dev.sh publishes it to 127.0.0.1 on the host.
11listen = "0.0.0.0:3000"
12# What the browser sees. dev.sh also passes ANVIL_BASE_URL, which wins — so a
13# differently named instance (ANVIL_DEV_NAME=anvil2) still gets correct links.
14base_url = "https://anvil.localhost"
15
16# Single sign-on against the local instance of login.richardscollin.com
17# (../login-richardscollin, `portless` → https://login.localhost). The dev
18# client there is registered as *public* — PKCE only, no secret — so this needs
19# no credential in the file and none in the environment. See docs/oidc.md.
20# With that provider not running, the sign-in button is there but the provider
21# is not, so use a password.
22[oidc]
23issuer = "https://login.localhost"
24client_id = "anvil"
25
26[ssh]
27enabled = true
28listen = "0.0.0.0:2222"
29# The published host port, i.e. dev.sh's $SSH_PORT (default: web port + 1).
30# portless proxies HTTP only, so SSH clone URLs point straight at localhost.
31clone_host = "localhost"
32clone_port = 20641
33clone_user = "git"
34
35[ci]
36# The secret the local runners present (compose.override.yaml's `runner-1` and
37# `runner-2`). Committed like the rest of this file: it authenticates runners
38# to an instance that only listens on 127.0.0.1. Production's token lives in
39# the gitignored deploy/anvil.toml. Empty here would refuse every claim with a
40# 503 and leave queued runs sitting.
41runner_token = "dev-runner-token"
42# The job container is a sibling on the host's Docker daemon, as in production.
43memory_mb = 2048
44cpus = 2.0
45timeout_secs = 600
46
47[agent]
48# On here so the feature is reachable one command away, same as the rest of
49# this file. See docs/untrusted-mode.md before ever turning this on outside a
50# local instance. credentials_dir is left empty: run `anvild secret` style
51# unlock isn't a thing here, so sessions start without a logged-in agent CLI
52# until credentials_dir is pointed at a real ~/.claude on the host.
53enabled = true
54memory_mb = 4096
55max_concurrent = 2
56
57[periodic]
58# Local instances are small; scanning every 10 minutes keeps language stats and
59# preview images fresh while you poke at things.
60language_detection_interval_secs = 600
61preview_image_interval_secs = 600
62disk_usage_interval_secs = 600