anvilsign in

collin/anvil

1# anvil configuration. Copy to `anvil.toml` and edit. All fields are optional;
2# omitted fields fall back to the defaults shown here.
3
4# Root directory for all server state (database + repositories).
5data_dir = "data"
6
7[http]
8listen = "127.0.0.1:3000"
9base_url = "http://localhost:3000"
10# Memory budget (MiB) for the cache of syntax-highlighted file views.
11# Highlighting large files is CPU-heavy, so repeat views are served from this
12# cache. Set to 0 to disable it entirely on RAM-constrained hosts.
13highlight_cache_mb = 16
14
15[ssh]
16enabled = false
17# Internal bind address. Under Docker, set host = "0.0.0.0" and forward the port.
18listen = "127.0.0.1:2222"
19# What to show users in SSH clone URLs. Set clone_port to the externally
20# forwarded port if it differs from the internal bind (e.g. Docker -p 2200:2222).
21clone_host = "localhost"
22clone_port = 2222
23clone_user = "git"
24
25[ci]
26# Job sandbox. Containers always run with no Docker socket, no mounts, all
27# capabilities dropped, and no-new-privileges; these knobs bound resources
28# (0 = unlimited). See docs/untrusted-mode.md for the threat model.
29# Images a pipeline may use: empty allows any; a tagless entry ("rust") allows
30# every tag of that image; a tagged one ("alpine:3.20") exactly itself.
31allowed_images = []
32memory_mb = 2048
33cpus = 2.0
34pids_limit = 512
35# Wall-clock limit per job, after which the container is killed.
36timeout_secs = 1800
37# Whether jobs get network access (most builds need it to fetch dependencies).
38network = true
39# User inside the job container, e.g. "1000:1000". Empty keeps the image default.
40run_as = ""
41
42# Continuous deployment: on a green run of deploy_branch in the ONE repo named
43# by deploy_repo, POST to deploy_webhook with the X-Anvil-Deploy-Secret header.
44# Empty deploy_repo/deploy_webhook disables deploys entirely.
45deploy_repo = ""
46deploy_branch = "main"
47deploy_webhook = ""
48deploy_secret = ""