EasyP

Configuration Reference

Every setting the service reads: YAML key, environment variable, type, default and meaning.

How settings are resolved

Each setting has exactly one YAML key and one environment variable. For every setting the first of these that supplies a value wins:

  1. the environment;
  2. the YAML file named by --cfg (or EASYP_CONFIG);
  3. the default compiled into the binary.

An unrecognised key in the YAML file refuses the start, so a typo is an error rather than a silently ignored setting. The only command-line flag that overrides a setting is --log-level on service start.

The binary can tell you what applies:

easyp-svc config validate --cfg config.yml            # would it start?
easyp-svc config print --cfg config.yml --origin      # value and source of each setting
easyp-svc config print --cfg config.yml --changed     # only what differs from defaults

Without --cfg both resolve from the environment alone, which is how a Helm deployment is configured. Secrets are printed as a placeholder unless --show-secrets is given. At every start the service logs the same summary as one configuration resolved line.

Variables outside the settings tree

VariableRead byMeaning
EASYP_CONFIGevery command that takes --cfgPath to the YAML file. Lets the image's HEALTHCHECK (easyp-svc health) find the same file as the service.
EASYP_TOKENplugins registerWrite token, when --token is not given.
OTEL_EXPORTER_OTLP_ENDPOINTthe serviceAlias of TELEMETRY_OTLP_ENDPOINT.

Durations and sizes

Durations use Go syntax: 30s, 10m, 6h. Sizes are bytes as integers.

server

YAML keyEnvironmentTypeDefaultDescription
server.hostSERVER_HOSTstring0.0.0.0Address all listeners bind to.
server.port.grpcSERVER_PORT_GRPCstring23410gRPC API.
server.port.metricSERVER_PORT_METRICstring23411Prometheus /metrics.
server.port.healthSERVER_PORT_HEALTHstring23412/live (liveness) and / (readiness).
server.port.mcpSERVER_PORT_MCPstring23413MCP endpoint /mcp, only when mcp.enabled.
server.tls.cert_fileSERVER_TLS_CERT_FILEstring—Server certificate (PEM). Empty disables TLS: the gRPC listener is plaintext and logs a warning.
server.tls.key_fileSERVER_TLS_KEY_FILEstring—Private key for cert_file.
server.tls.client_ca_fileSERVER_TLS_CLIENT_CA_FILEstring—CA bundle; when set, clients must present a certificate signed by it (mutual TLS). Only the CA is checked, not the subject.
server.force_shutdown_afterSERVER_FORCE_SHUTDOWN_AFTERduration150sHard exit this long after SIGTERM. Must exceed worker_pool.generation_timeout.
server.trusted_proxiesSERVER_TRUSTED_PROXIESlist of CIDRs—Peers whose X-Forwarded-For/X-Real-IP are believed. Required behind a proxy, otherwise every caller shares one rate-limit bucket and the audit log records the proxy.
server.max_recv_msg_sizeSERVER_MAX_RECV_MSG_SIZEint67108864Largest gRPC request, bytes.
server.max_send_msg_sizeSERVER_MAX_SEND_MSG_SIZEint67108864Largest gRPC response, bytes. Must be at least registry.max_output_size.
server.max_concurrent_streamsSERVER_MAX_CONCURRENT_STREAMSuint32256Concurrent streams per connection.

db

YAML keyEnvironmentTypeDefaultDescription
db.postgresDB_POSTGRES_DSNstring, secret—PostgreSQL connection string, e.g. postgres://user:pass@host:5432/easyp?sslmode=require. Required.

registry

YAML keyEnvironmentTypeDefaultDescription
registry.plugins_dirREGISTRY_PLUGINS_DIRstring/pluginsWhere plugin executables live (local mode) or are unpacked (object storage mode). Must be writable. A plugin's command[0] must resolve inside it.
registry.max_output_sizeREGISTRY_MAX_OUTPUT_SIZEint6467108864Largest plugin stdout, bytes. Larger output fails the generation.
registry.cache_max_bytesREGISTRY_CACHE_MAX_BYTESint6421474836480Bound on unpacked plugins on disk; least-recently-used versions are evicted beyond it. 0 disables eviction. Meaningful only with object storage.
registry.s3.endpointREGISTRY_S3_ENDPOINTstring—S3 endpoint URL, e.g. http://minio:9000. Empty uses AWS.
registry.s3.bucketREGISTRY_S3_BUCKETstring—Bucket for plugin archives. Empty disables object storage.
registry.s3.regionREGISTRY_S3_REGIONstringus-east-1Region.
registry.s3.prefixREGISTRY_S3_PREFIXstring—Key prefix for archives.
registry.s3.access_key_idREGISTRY_S3_ACCESS_KEY_IDstring—Access key. When both keys are empty, the default AWS credential chain is used.
registry.s3.secret_access_keyREGISTRY_S3_SECRET_ACCESS_KEYstring, secret—Secret key.
registry.s3.force_path_styleREGISTRY_S3_FORCE_PATH_STYLEbool— (false)Path-style addressing; required by MinIO and RustFS.

worker_pool

YAML keyEnvironmentTypeDefaultDescription
worker_pool.workersWORKER_POOL_WORKERSint4Concurrent plugin lookups (database read, download on cache miss). Community caps it at 4.
worker_pool.queue_sizeWORKER_POOL_QUEUE_SIZEint16Waiting room for lookups and for generations. Beyond it: RESOURCE_EXHAUSTED / SERVER_OVERLOADED.
worker_pool.max_concurrent_generationsWORKER_POOL_MAX_CONCURRENT_GENERATIONSint16Concurrent plugin processes. Community caps it at 16.
worker_pool.generation_timeoutWORKER_POOL_GENERATION_TIMEOUTduration120sTime one plugin run may take, excluding the wait for a slot.
worker_pool.max_retriesWORKER_POOL_MAX_RETRIESint2Extra attempts for errors containing connection refused or temporary failure.
worker_pool.shutdown_timeoutWORKER_POOL_SHUTDOWN_TIMEOUTduration30sTime the pool waits for queued lookups on shutdown.

Community ceilings lower workers and max_concurrent_generations at start and log <setting> lowered to the licence tier's limit; they do not refuse the configuration.

license

YAML keyEnvironmentTypeDefaultDescription
license.keyLICENSE_KEYstring, secret—PASETO v4.public licence token. Takes priority over license.file.
license.fileLICENSE_FILEstring—Path to a file holding the token.
license.public_keysLICENSE_PUBLIC_KEYSmap key id → hex—Ed25519 public keys that may sign licences. Key id "*" verifies any token. Environment form: <kid>:<hex>,<kid>:<hex>. Without a key the token is ignored and the service runs as Community.
license.cache_ttlLICENSE_CACHE_TTLduration5mHow often the token is re-validated (expiry, grace).

rate_limit

YAML keyEnvironmentTypeDefaultDescription
rate_limit.requests_per_secondRATE_LIMIT_REQUESTS_PER_SECONDfloat10.0Token-bucket rate per client address.
rate_limit.burstRATE_LIMIT_BURSTint20Bucket size.
rate_limit.cleanup_intervalRATE_LIMIT_CLEANUP_INTERVALduration10mHow often idle client buckets are dropped.
rate_limit.max_concurrent_per_ipRATE_LIMIT_MAX_CONCURRENT_PER_IPint2Requests one client address may have in flight. 0 disables the check. CI runners behind one NAT share an address.

audit

Audit rows are written only with an Enterprise licence.

YAML keyEnvironmentTypeDefaultDescription
audit.buffer_sizeAUDIT_BUFFER_SIZEint1000Queue between operations and the writer.
audit.batch_sizeAUDIT_BATCH_SIZEint100Rows per insert.
audit.flush_intervalAUDIT_FLUSH_INTERVALduration1sFlush period for partial batches.
audit.max_save_retriesAUDIT_MAX_SAVE_RETRIESint3Retries of a failed batch before it is counted as lost.
audit.enqueue_timeoutAUDIT_ENQUEUE_TIMEOUTduration1sHow long an operation waits for queue space before dropping its entry.
audit.flush_timeoutAUDIT_FLUSH_TIMEOUTduration5sBound on one write, retries included.
audit.retention_monthsAUDIT_RETENTION_MONTHSint12Monthly partitions older than this are dropped — a real delete.
audit.pre_create_monthsAUDIT_PRE_CREATE_MONTHSint3Partitions created ahead.
audit.partition_check_intervalAUDIT_PARTITION_CHECK_INTERVALduration6hPartition maintenance period.
audit.partition_op_timeoutAUDIT_PARTITION_OP_TIMEOUTduration30sBound on one partition create/drop.

auth

YAML keyEnvironmentTypeDefaultDescription
auth.write_tokensAUTH_WRITE_TOKENSlist of {name, sha256}—Tokens allowed to call CreatePlugin, UpdatePlugin, DeletePlugin. Only sha256 digests are stored. Environment form: name=<64 hex>,name=<64 hex>. Empty denies all writes.
auth.require_authenticationAUTH_REQUIRE_AUTHENTICATIONboolfalseRequire a token on every RPC (not Health) and on MCP. The easyp CLI cannot send a token, so it stops working against a service with this on.

telemetry

YAML keyEnvironmentTypeDefaultDescription
telemetry.otlp_endpointTELEMETRY_OTLP_ENDPOINTstring—OTLP gRPC collector, host:port or http://host:port. Empty: no exporter is built.
telemetry.pyroscope_endpointTELEMETRY_PYROSCOPE_ENDPOINTstring—Pyroscope server. Empty: no profiling.
telemetry.service_tierTELEMETRY_SERVICE_TIERstring—Tag for traces and profiles when Community and Enterprise deployments share backends. A value that disagrees with the licence tier sets easyp_config_service_tier_mismatch.

mcp and log

YAML keyEnvironmentTypeDefaultDescription
mcp.enabledMCP_ENABLEDboolfalseServe /mcp on server.port.mcp. See MCP.
log.levelLOG_LEVELstringinfodebug, info, warn, error. --log-level overrides it.

Example file

server:
  tls:
    cert_file: /certs/tls.crt
    key_file: /certs/tls.key
    client_ca_file: /certs/ca.crt
  trusted_proxies: ["10.42.0.0/16"]

registry:
  plugins_dir: /plugins
  s3:
    endpoint: http://minio:9000
    bucket: easyp-plugins
    force_path_style: true

worker_pool:
  max_concurrent_generations: 16

license:
  public_keys:
    "2026-08": "81322461987167d5cfd529e9cb8b96f4797f12fce6be4399a0866e250c9b6bb5"

mcp:
  enabled: false

Secrets — DB_POSTGRES_DSN, REGISTRY_S3_ACCESS_KEY_ID, REGISTRY_S3_SECRET_ACCESS_KEY, LICENSE_KEY, AUTH_WRITE_TOKENS — are better supplied through the environment than written into the file.

This table was generated from the binary's own list of settings (config.Leaves() in internal/config/fields.go) for v1.0.2: 55 settings. easyp-svc config print on your version is the authority if they ever disagree.

On this page