配置字段参考
本页是 config.yaml 的全量字段参考。代码真源是 packages/core/src/config.ts 中的 Zod schema。本页以该 schema 为准审计;当两者不一致时,以 schema 为准。各命名空间的叙述请跟随链接到对应配置页。
下面每个命名空间都链接到其叙述页,并列出 schema 校验的每个字段(类型、默认值、一句话描述)。没有 schema 默认值的可选字段在“默认值”列标记为 —。
这些枚举值出现在多个命名空间中,集中放在这里方便查阅。
| 概念 | 枚举值 |
|---|---|
Trigger kind |
gitea、forgejo、github、gitlab、p4、svn、scheduled、manual |
| Agent 执行模式 | kilo、opencode、zoo、copilot-cli、claude-code、pi、oh-my-pi、native-llm |
Sandbox kind |
native、docker、podman、docker_socket、k8s_pod、firecracker |
Sandbox engine |
auto、docker、podman |
Queue kind |
memory、sqlite、redis、rabbitmq(预留) |
Storage database.kind |
sqlite、postgres |
Storage cache.kind |
memory、redis、none |
Storage object.kind |
filesystem、s3 |
Model catalog cache.backend |
sqlite、redis、memory |
Context repository kind |
git、p4、svn |
LLM provider kind |
openai_compatible、azure_openai、anthropic、vertex_ai、bedrock、google_ai_studio、ollama、copilot |
叙述:LLM 提供商与模型。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
llm.providers[] |
array | [] |
LLM provider 连接;每项有 id、kind,以及可选的 base_url、api_key_env、api_version、catalog_provider、catalog_id |
llm.providers[].id |
string | — | 被 model_chain 引用的 provider 标识 |
llm.providers[].kind |
enum | — | provider kind(见上方 LLM provider 枚举) |
llm.providers[].base_url |
URL | — | provider API base URL |
llm.providers[].api_key_env |
string | — | 持有 API key 的环境变量名 |
llm.providers[].api_key |
string | — | 明文 API key;与 api_key_env 互斥(明文优先);发布到数据库后加密落库 |
llm.providers[].api_version |
string | — | API 版本(Azure 等) |
llm.providers[].catalog_provider |
string | — | 覆盖 catalog 查询时的 models.dev provider id |
llm.providers[].catalog_id |
string | — | 覆盖 catalog 查询时的 models.dev <provider>/<model> id |
llm.providers[].reasoning_effort |
enum | — | 推理强度档位:minimal、low、medium、high、max(透传字段) |
llm.providers[].thinking_level |
enum | — | 思考强度抽象档位:off、minimal、low、medium、high、max(透传字段) |
llm.providers[].thinking_budget_tokens |
int | — | 显式思考预算 token 数(透传字段) |
llm.model_chain |
map | {} |
分组名到有序模型列表的映射 |
llm.model_chain.<id>[] |
array | — | 非空列表;首项为默认模型,其余项按序切换。每项有 provider、model、role(light/heavy/any) |
llm.default_model_chain |
string | default |
全局主链组名;已配置分组时必须存在 |
llm.triage_model_chain |
string | 继承 | 生命周期分析组名;缺省继承当前 workspace 主链 |
llm.author_resolution_model_chain |
string | 继承 | 目录身份分析模型组;缺省使用 llm.default_model_chain |
llm.retry |
object | — | 单次调用重试策略 |
llm.retry.max_attempts |
int > 0 | — | 单次 LLM 调用最大尝试次数 |
llm.retry.respect_retry_after |
boolean | — | 遵守 Retry-After 响应头 |
llm.retry.backoff |
object | — | kind(exponential/linear/constant)、base_ms、max_ms、jitter |
llm.retry.give_up_after_seconds |
number > 0 | — | 硬性挂钟放弃时间 |
llm.budget |
object | — | 预算上限 |
llm.budget.per_run_usd |
number ≥ 0 | — | 单次 run USD 上限 |
llm.budget.per_repo_daily_usd |
number ≥ 0 | — | 单仓每日 USD 上限 |
llm.per_provider_overrides |
map | — | 按 provider id 配置 max_attempts / give_up_after_seconds |
llm.model_catalog |
object | 见下 | models.dev 元数据 catalog |
llm.model_catalog
Section titled “llm.model_catalog”| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
llm.model_catalog.enabled |
boolean | false |
启用 models.dev 元数据查询 |
llm.model_catalog.source_url |
URL | https://models.dev/api.json |
catalog 源 |
llm.model_catalog.refresh_interval_hours |
int > 0 | 24 |
刷新间隔 |
llm.model_catalog.fetch_timeout_ms |
int > 0 | 10000 |
拉取超时 |
llm.model_catalog.offline |
boolean | false |
永不访问网络;仅用缓存 + 打包快照 |
llm.model_catalog.apply_to_model_spec |
boolean | true |
将 catalog 元数据合并进解析后的 ModelSpec |
llm.model_catalog.cache.backend |
enum | sqlite |
刷新缓存后端;redis 需要 storage.cache.kind: redis + redis.url_env |
llm.model_catalog.overrides |
map | {} |
手填的按 <provider>/<model> 覆盖;显式值始终优先于 catalog 数据。支持 supported_reasoning_efforts、default_reasoning_effort 等字段 |
triggers
Section titled “triggers”叙述:VCS 提供商。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
triggers[].name |
string | — | trigger profile 名;被 workspaces.instances.<id>.source_repo.trigger 引用 |
triggers[].kind |
enum | — | trigger kind(见枚举表) |
triggers[].enabled |
boolean | — | 未设置时启用;false 停止该 profile 的新任务准入,历史快照保留 |
triggers[].watch_path |
string[] | — | 只分析这些 depot/仓库相对子路径下的文件 |
triggers[].include_cr_file |
string[] | — | glob 模式;文件必须至少匹配一个才会被分析 |
triggers[].exclude_cr_file |
string[] | — | glob 模式;匹配任一则跳过 |
triggers[].commit_url_template |
string | — | commit 链接的 URL 模板(变量会做 URL 编码) |
triggers[].revision_url_template |
string | — | revision 链接的 URL 模板 |
triggers[].change_url_template |
string | — | changelist 链接的 URL 模板(P4 Swarm 等) |
triggers[].app |
object | — | GitHub App 认证块;仅 kind: github,与 token/token_env 互斥 |
triggers[].app.app_id |
string | int | — | GitHub App ID(与 client_id 至少填一个) |
triggers[].app.client_id |
string | — | GitHub App client ID(app_id 的替代项) |
triggers[].app.private_key_env |
string | — | 持有 App 私钥 PEM 的环境变量(与 private_key/private_key_path 恰好填一个) |
triggers[].app.private_key_path |
string | — | App 私钥 PEM 文件路径(与 private_key/private_key_env 恰好填一个) |
triggers[].app.private_key |
string | — | 明文 App 私钥 PEM 或 base64 PEM(与 private_key_env/private_key_path 恰好填一个);发布到数据库后加密落库 |
triggers[].app.installation_id |
string | int | — | 固定 installation id;缺省时按 owner/repo 动态解析 |
triggers[].token |
string | — | 明文出站 VCS token(git 系);与 token_env 和 app 互斥;发布到数据库后加密落库 |
triggers[].webhook_secret |
string | — | 明文入站 webhook 密钥(git 系);与 webhook_secret_env 互斥;发布到数据库后加密落库 |
triggers[].user |
string | — | 明文 P4 用户名(标识符,不封存);与 user_env 互斥 |
triggers[].ticket |
string | — | 明文 P4 ticket;与 ticket_env 互斥;发布到数据库后加密落库 |
triggers[].password |
string | — | 明文 P4/SVN 密码;与 password_env 互斥;发布到数据库后加密落库 |
triggers[].username |
string | — | 明文 SVN 用户名(标识符,不封存);与 username_env 互斥 |
provider 专属字段(webhook_secret_env、token_env、port、user_env、password_env、depot_path、workspace、repository_url)通过 passthrough 校验接受,文档见VCS 提供商与认证与密钥。
workspaces
Section titled “workspaces”叙述:配置总览。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
workspaces.root |
string | — | workspace 实例的目录布局根;相对路径按 server base 目录解析。默认 <baseDir>/workspaces默认值 <baseDir>/workspaces |
workspaces.cache.max_total_gb |
number > 0 | 50 |
workspace 缓存总大小上限(GB) |
workspaces.cache.eviction |
enum | lru |
淘汰策略:lru、mru、ttl |
workspaces.cache.ttl_days |
int > 0 | 30 |
ttl 淘汰的 TTL(天) |
workspaces.defaults |
object | {} |
合并进每个 instance 的默认值(sandbox、review、agent、outputs、prompt、context_repositories) |
workspaces.defaults.sandbox |
object | — | 默认 sandbox 配置(见 agent.sandbox) |
workspaces.defaults.review |
object | — | 默认 review 配置(见 review) |
workspaces.defaults.model_chain |
string | 继承 | 覆盖主链组名,引用 llm.model_chain |
workspaces.defaults.triage_model_chain |
string | 继承 | 覆盖生命周期分析组名;各层均未配置时使用该 workspace 主链 |
workspaces.defaults.author_resolution_model_chain |
string | 继承 | 覆盖 llm.author_resolution_model_chain 的身份分析模型组 |
workspaces.defaults.agent.default |
enum | — | 这组 workspace 的默认执行模式;每次运行按 全局 → defaults → 实例 → 路由 analysis 解析(见下方说明) |
workspaces.defaults.agent.timeout_seconds |
int > 0 | — | 单次 run 硬超时;超时时杀整棵进程树 |
workspaces.defaults.agent.auto_approve |
boolean | — | 传给所选 adapter;CLI 支持时 false 取消自动批准 |
workspaces.defaults.agent.context_compaction.auto |
boolean | — | 启用自动压缩 |
workspaces.defaults.agent.context_compaction.threshold_percent |
int 1–100 | — | 压缩触发阈值 |
workspaces.defaults.agent.context_compaction.prune |
boolean | — | 修剪压缩后的历史 |
workspaces.defaults.agent.web_search.enabled |
boolean | — | 为评审启用 agent 内置搜索工具(omp web_search.enabled;kilo/opencode permission + 激活 env;claude-code/copilot-cli CLI 开关) |
workspaces.defaults.agent.web_search.providers |
string[] | — | 有序 provider:omp 使用完整链;kilo 仅接受 exa;opencode 选择首个 exa/parallel |
workspaces.defaults.agent.web_search.exclude |
string[] | — | 从搜索链路剔除的 provider id → providers.webSearchExclude |
workspaces.defaults.agent.web_search.timeout_seconds |
int 1–300 | — | 单 provider 传输超时 → providers.webSearchTimeoutSeconds |
workspaces.defaults.agent.web_search.credentials.<id> |
string | object | — | 搜索凭据 id → 宿主 env 名(字符串)或 { value } 明文;启用搜索的 adapter 通过 ${VAR} 引用注入所支持的原生 env,明文直接注入 |
workspaces.defaults.agent.web_search.credentials.<id>.value |
string | — | 明文搜索凭据(对象形式);发布到数据库后加密落库 |
workspaces.defaults.agent.web_search.searxng.endpoint |
string | — | SearXNG 端点 URL |
workspaces.defaults.agent.web_search.searxng.categories |
string | — | SearXNG 分类过滤 |
workspaces.defaults.agent.web_search.searxng.engines |
string | — | SearXNG 引擎过滤 |
workspaces.defaults.agent.web_search.searxng.language |
string | — | SearXNG 语言过滤 |
workspaces.defaults.agent.web_search.searxng.safesearch |
int 0–2 | — | SearXNG 安全搜索级别 |
workspaces.defaults.outputs |
object | — | 默认 outputs(见 outputs 的 workspace 字段) |
workspaces.defaults.prompt.base_system_prompt_file |
string | — | 自定义 base system prompt 文件(相对于部署根目录) |
workspaces.defaults.prompt.system_prompt |
string | — | 引用 prompts.system.<name> 的命名 system prompt,替换基底 prompt(优先于 base_system_prompt_file 与内置默认) |
workspaces.defaults.prompt.extra_system_prompt |
string | — | 引用 prompts.system.<name> 的命名 system prompt,拼接在解析后的基底之后 |
workspaces.defaults.prompt.force_skills |
string[] | — | 始终激活的技能名,忽略 Applies To glob |
workspaces.defaults.context_repositories[].alias |
string | — | path-safe 别名(^[A-Za-z0-9][A-Za-z0-9._-]*$,同 workspace 内唯一) |
workspaces.defaults.context_repositories[].kind |
enum | — | git、p4、svn |
workspaces.defaults.context_repositories[].url |
string | — | git 仓库 URL(kind: git 必填) |
workspaces.defaults.context_repositories[].ref |
string | — | git branch/tag pin |
workspaces.defaults.context_repositories[].token_env |
string | — | git http(s) 认证 token 的环境变量名 |
workspaces.defaults.context_repositories[].token |
string | — | 明文 git http(s) token;与 token_env 互斥;发布到数据库后加密落库 |
workspaces.defaults.context_repositories[].repository_url |
string | — | SVN 仓库 URL(kind: svn 必填) |
workspaces.defaults.context_repositories[].revision |
string | int | — | svn/p4 的版本 pin |
workspaces.defaults.context_repositories[].port |
string | — | P4 端口 |
workspaces.defaults.context_repositories[].user_env |
string | — | P4 用户名的环境变量名 |
workspaces.defaults.context_repositories[].user |
string | — | 明文 P4 用户名(标识符,不封存);与 user_env 互斥 |
workspaces.defaults.context_repositories[].ticket_env |
string | — | P4 ticket 的环境变量名 |
workspaces.defaults.context_repositories[].ticket |
string | — | 明文 P4 ticket;与 ticket_env 互斥;发布到数据库后加密落库 |
workspaces.defaults.context_repositories[].password_env |
string | — | P4 密码的环境变量名 |
workspaces.defaults.context_repositories[].password |
string | — | 明文 P4 密码;与 password_env 互斥;发布到数据库后加密落库 |
workspaces.defaults.context_repositories[].depot_path |
string | — | P4 depot 路径(kind: p4 必填) |
workspaces.defaults.context_repositories[].max_mb |
int > 0 | 512 |
单仓库物化后大小上限(MB) |
workspaces.instances |
map | {} |
按 workspace id 组织的 instance |
workspaces.instances.<id>.source_repo.trigger |
string | — | trigger profile 名 |
workspaces.instances.<id>.source_repo.repo |
string | — | 仓库引用 |
workspaces.instances.<id>.match[] |
array | — | 多工程匹配规则(规则间 OR,规则内字段 AND),与 source_repo 互斥。git 系 webhook(GitHub/GitLab/Gitea/Forgejo)接受期匹配已生效;P4/SVN 使用后台路由回执(见下方说明) |
workspaces.instances.<id>.match[].id |
string | — | 可选规则 id,同一 definition 内唯一 |
workspaces.instances.<id>.match[].triggers |
string[] | — | trigger 名称,每个名称必须存在于 triggers[] |
workspaces.instances.<id>.match[].source.<id>.exact |
string | — | 来源字段(vcs、repo_ref、repository、namespace、project_key、branch、ref)的大小写敏感精确匹配,exact/glob/regex 三选一 |
workspaces.instances.<id>.match[].source.<id>.glob |
string | — | 全字段 glob,* 可跨 /,? 匹配一个码点,无 extglob/花括号/字符类语义 |
workspaces.instances.<id>.match[].source.<id>.regex |
string | — | RE2 正则,未用 ^/$ 锚定时为子串匹配 |
workspaces.instances.<id>.match[].source.<id>.ignore_case |
boolean | — | 仅匹配时折叠大小写,不改写身份 |
workspaces.instances.<id>.work_path |
string | — | Handlebars 路径模板(AST 白名单,仅 segment/default/hash/lower,输出必须是相对 / 路径),需配合 match,默认 {{workspace.id}} |
workspaces.instances.<id>.enabled |
boolean | — | 未设置时启用;false 停止新任务准入,保留已有快照 |
workspaces.instances.<id>.model_chain |
string | 继承 | 覆盖主链组名,引用 llm.model_chain |
workspaces.instances.<id>.triage_model_chain |
string | 继承 | 覆盖生命周期分析组名;各层均未配置时使用该 workspace 主链 |
workspaces.instances.<id>.author_resolution_model_chain |
string | 继承 | 身份分析模型组覆盖;向上依次继承 workspace defaults、全局身份组、llm.default_model_chain |
workspaces.instances.<id>.agent.default |
enum | — | 执行模式覆盖;每次运行按合并后的 workspace 各层选择(见下方说明) |
workspaces.instances.<id>.agent.timeout_seconds |
int > 0 | — | 单次 run 硬超时;超时时杀整棵进程树 |
workspaces.instances.<id>.agent.auto_approve |
boolean | — | 传给所选 adapter;CLI 支持时 false 取消自动批准 |
workspaces.instances.<id>.agent.context_compaction.auto |
boolean | — | 启用自动压缩 |
workspaces.instances.<id>.agent.context_compaction.threshold_percent |
int 1–100 | — | 压缩触发阈值 |
workspaces.instances.<id>.agent.context_compaction.prune |
boolean | — | 修剪压缩后的历史 |
workspaces.instances.<id>.agent.web_search.enabled |
boolean | — | 为评审启用 agent 内置搜索工具(omp web_search.enabled;kilo/opencode permission + 激活 env;claude-code/copilot-cli CLI 开关) |
workspaces.instances.<id>.agent.web_search.providers |
string[] | — | 有序 provider:omp 使用完整链;kilo 仅接受 exa;opencode 选择首个 exa/parallel |
workspaces.instances.<id>.agent.web_search.exclude |
string[] | — | 从搜索链路剔除的 provider id → providers.webSearchExclude |
workspaces.instances.<id>.agent.web_search.timeout_seconds |
int 1–300 | — | 单 provider 传输超时 → providers.webSearchTimeoutSeconds |
workspaces.instances.<id>.agent.web_search.credentials.<id> |
string | object | — | 搜索凭据 id → 宿主 env 名(字符串)或 { value } 明文;启用搜索的 adapter 通过 ${VAR} 引用注入所支持的原生 env,明文直接注入 |
workspaces.instances.<id>.agent.web_search.credentials.<id>.value |
string | — | 明文搜索凭据(对象形式);发布到数据库后加密落库 |
workspaces.instances.<id>.agent.web_search.searxng.endpoint |
string | — | SearXNG 端点 URL |
workspaces.instances.<id>.agent.web_search.searxng.categories |
string | — | SearXNG 分类过滤 |
workspaces.instances.<id>.agent.web_search.searxng.engines |
string | — | SearXNG 引擎过滤 |
workspaces.instances.<id>.agent.web_search.searxng.language |
string | — | SearXNG 语言过滤 |
workspaces.instances.<id>.agent.web_search.searxng.safesearch |
int 0–2 | — | SearXNG 安全搜索级别 |
workspaces.instances.<id>.review |
object | — | review 配置覆盖(见 review) |
workspaces.instances.<id>.outputs |
object | — | outputs 覆盖 |
workspaces.instances.<id>.sandbox |
object | — | sandbox 覆盖;每次运行在 全局 → defaults → 实例 之上按 section 深合并(见下方说明) |
workspaces.instances.<id>.triage |
object | — | issue triage 覆盖(仅 Gitea/Forgejo) |
workspaces.instances.<id>.prompt |
object | — | prompt 覆盖(形状同 workspaces.defaults.prompt) |
workspaces.instances.<id>.context_repositories[].alias |
string | — | path-safe 别名(^[A-Za-z0-9][A-Za-z0-9._-]*$,同 workspace 内唯一);挂载路径用其命名 |
workspaces.instances.<id>.context_repositories[].kind |
enum | — | git、p4、svn |
workspaces.instances.<id>.context_repositories[].url |
string | — | git 仓库 URL(kind: git 必填) |
workspaces.instances.<id>.context_repositories[].ref |
string | — | git branch/tag pin(缺省远端默认分支) |
workspaces.instances.<id>.context_repositories[].token_env |
string | — | git http(s) 认证 token 的环境变量名(经 http.extraHeader 注入,不落盘) |
workspaces.instances.<id>.context_repositories[].token |
string | — | 明文 git http(s) token;与 token_env 互斥;发布到数据库后加密落库 |
workspaces.instances.<id>.context_repositories[].repository_url |
string | — | SVN 仓库 URL(kind: svn 必填) |
workspaces.instances.<id>.context_repositories[].revision |
string | int | — | svn/p4 的版本 pin(缺省取最新) |
workspaces.instances.<id>.context_repositories[].port |
string | — | P4 端口(如 ssl:p4.example.com:1666) |
workspaces.instances.<id>.context_repositories[].user_env |
string | — | P4 用户名的环境变量名 |
workspaces.instances.<id>.context_repositories[].user |
string | — | 明文 P4 用户名(标识符,不封存);与 user_env 互斥 |
workspaces.instances.<id>.context_repositories[].ticket_env |
string | — | P4 ticket 的环境变量名 |
workspaces.instances.<id>.context_repositories[].ticket |
string | — | 明文 P4 ticket;与 ticket_env 互斥;发布到数据库后加密落库 |
workspaces.instances.<id>.context_repositories[].password_env |
string | — | P4 密码的环境变量名(与 ticket_env 同义入口) |
workspaces.instances.<id>.context_repositories[].password |
string | — | 明文 P4 密码;与 password_env 互斥;发布到数据库后加密落库 |
workspaces.instances.<id>.context_repositories[].depot_path |
string | — | P4 depot 路径(kind: p4 必填,通常以 /... 结尾) |
workspaces.instances.<id>.context_repositories[].max_mb |
int > 0 | 512 |
单仓库物化后大小上限(MB),超限判失败并清理 |
workspaces.instances.<id>.auth.api_key_env |
string | — | workspace 级 API key 环境变量 |
workspaces.instances.<id>.auth.api_key |
string | — | 明文 workspace 级 API key;与 api_key_env 互斥;发布到数据库后加密落库 |
workspaces.instances.<id>.auth.enabled |
boolean | true |
切换 workspace 级 API key |
workspace id 不能与保留键 cache、defaults、instances 冲突。
instance 定义自己的 context_repositories 时整体替换 workspaces.defaults 中的列表,不逐项合并。
outputs
Section titled “outputs”叙述:输出通道与路由。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
outputs.template_engine |
enum | handlebars |
模板引擎。eta 被 schema 接受但尚未实现,只有 handlebars 可用 |
outputs.templates.<id> |
string | — | 命名 Handlebars 模板文档(markdown,可带 frontmatter 元数据;运行时只使用正文),供 channel templates.* 引用 |
outputs.no_problems |
object | — | 全局零问题策略 |
outputs.no_problems.action |
enum | — | publish、suppress 或 publish_if_summary |
outputs.channels[] |
array | [] |
输出 channel 定义 |
outputs.channels[].name |
string | — | 用于路由和模板解析的 channel 名 |
outputs.channels[].kind |
string | — | channel kind(自由字符串;受输出注册表约束) |
outputs.channels[].trigger |
string | — | 该 channel 绑定的 trigger 名 |
outputs.channels[].mention_author |
boolean | — | @ mention 解析出的提交作者 |
outputs.channels[].mention_fallback |
enum | — | 作者无法解析时取 all 或 skip |
outputs.channels[].no_problems |
object | — | channel 级零问题策略 |
outputs.channels[].commit_url_template |
string | — | commit 链接模板 |
outputs.channels[].revision_url_template |
string | — | revision 链接模板 |
outputs.channels[].change_url_template |
string | — | changelist 链接模板 |
outputs.channels[].templates.problem |
string | — | 引用 outputs.templates.<name> 的 problem 模板;优先于 workspace 目录与内置模板 |
outputs.channels[].templates.summary |
string | — | 引用 outputs.templates.<name> 的 summary 模板;优先于 workspace 目录与内置模板 |
outputs.channels[].marker_prefix |
string | — | managed issue 标题前缀(默认 [AICR]) |
outputs.channels[].marker_label |
string | — | 用于界定 managed issue 的隐藏 body 标记 |
outputs.channels[].label_ids |
int[] | — | 要附加的 Gitea label ID |
outputs.channels[].labels |
string[] | — | 要附加的 GitHub label 名 |
outputs.channels[].issue_mode |
enum | — | per_problem、consolidated、per_commit |
outputs.channels[].issue_link_card |
enum | — | summary 路由同时记录托管 issue、卡片附带其链接时的飞书卡片内容:brief(标题 + 计数 + 链接)、titles(追加逐条问题标题;运行时默认)、full(完整问题区块);仅 feishu_bot/feishu_app |
outputs.channels[].resolved_action |
enum | — | none、close、mark_resolved、delete(仅 Gitea) |
outputs.channels[].assign_committer |
boolean | — | 创建托管 issue 时指派解析后的评审作者(默认 true);邮箱黑名单阻止 API/pusher 兜底,OWNERS 独立处理 |
outputs.channels[].owners_file |
string | — | owners 文件路径(默认 OWNERS) |
outputs.channels[].add_owners_as_assignees |
boolean | — | 把匹配到的 OWNERS 条目加为 assignee |
outputs.channels[].severity_label_prefix |
string | — | 自动创建/附加一个 severity label,如 aicr:problem:high |
outputs.channels[].severity_label_colors |
map | — | 自动创建 label 的 severity 到颜色映射 |
outputs.channels[].review_mode |
enum | — | auto、review、comment |
outputs.channels[].review_event |
enum | — | COMMENT 或 REQUEST_CHANGES |
outputs.channels[].review_update_strategy |
enum | — | always_new 或 update_existing |
outputs.channels[].notify_feishu |
object | — | issue 创建时的 Feishu 通知(webhook_url_env 或明文 webhook_url,可选 secret_env/明文 secret) |
outputs.channels[].token |
string | — | 明文 channel API token;与 token_env 互斥;发布到数据库后加密落库 |
outputs.channels[].webhook_url |
string | — | 明文机器人 webhook URL(feishu_bot/wecom_bot);与 webhook_url_env 互斥;发布到数据库后加密落库 |
outputs.channels[].secret |
string | — | 明文 Feishu 签名密钥;与 secret_env 互斥;发布到数据库后加密落库 |
outputs.author_resolution |
object | — | email_mappings 映射、email_blacklist 数组和 directory_cache_ttl_seconds |
outputs.author_resolution.directory_cache_ttl_seconds |
int | 43200 | 全局成员目录缓存时长,0–604800 秒;0 表示不复用缓存 |
outputs.routes.default |
object | — | 无规则匹配时应用的默认路由 |
outputs.routes.rules[] |
array | [] |
有序路由规则 |
outputs.routes.rules[].match.trigger |
string | — | 要匹配的 trigger 名 |
outputs.routes.rules[].match.target_kind |
enum | — | 目标类型(pull_request、push、commit、issue、manual、scheduled);pr 会被归一化为 pull_request。GitLab MR 以 pull_request 报告。 |
outputs.routes.rules[].line_comments |
string[] | — | 接收行评论输出的 channel 名 |
outputs.routes.rules[].summary |
string[] | — | 接收 summary 输出的 channel 名 |
飞书应用渠道字段
Section titled “飞书应用渠道字段”以下字段只适用于 feishu_app,配置步骤见 IM 机器人指南。
| 字段 | 类型 | 默认值 | 含义 |
|---|---|---|---|
outputs.channels[].app_id |
string | — | 必填,自建应用 ID |
outputs.channels[].app_secret |
string | — | 明文 App Secret;数据库配置加密存储;与 app_secret_env 互斥 |
outputs.channels[].app_secret_env |
string | — | 持有 App Secret 的环境变量名 |
outputs.channels[].receive_id |
string | — | 必填,报告接收对象 |
outputs.channels[].receive_id_type |
enum | — | chat_id、open_id、user_id、union_id 或 email;运行时默认 chat_id |
outputs.channels[].member_directory.chat_id |
string | — | 成员身份目录的来源群 |
outputs.channels[].member_directory.cache_ttl_seconds |
int | — | 目录缓存时长,0–604800 秒;覆盖 outputs.author_resolution.directory_cache_ttl_seconds;运行时默认 43200(12 小时) |
outputs.channels[].user_mappings.<id> |
string | — | 作者或 workspace 标识精确映射到当前应用的 open_id |
outputs.channels[].guess_author |
boolean | — | 运行时默认 true;允许精确匹配后的 workspace 推测及专用模型兜底;mention_author 单独控制通知 |
成员目录来源与 IM 频道关联
Section titled “成员目录来源与 IM 频道关联”member_directory 接受历史飞书 API 形态(chat_id,可选 cache_ttl_seconds)、
显式 source: feishu_api 的同字段形态,以及由严格 YAML/JSON 成员文件支撑的
source: file 形态。file 来源、author_mappings、connection 与 target
当前仅通过 schema 校验,发送与目录接线随 IM 计划逐步落地(见
IM 机器人指南);数据库发布侧仍拒绝没有运行时
消费者的频道记录,这些字段本身不构成可用集成。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
outputs.channels[].member_directory.source |
enum | — | feishu_api(历史目录的显式形态)或 file(外部成员目录);缺省表示旧版 {chat_id, cache_ttl_seconds} 形态 |
outputs.channels[].member_directory.path |
string | — | 仅 file:成员文件路径;按主配置文件所在目录解析,绝不按进程工作目录解析 |
outputs.channels[].member_directory.directory_id |
string | — | 仅 file:本频道使用的成员文件内目录名 |
outputs.channels[].member_directory.identity_scope.kind |
enum | — | 仅 file:身份命名空间类型 — wecom_corp、feishu_app 或 feishu_tenant |
outputs.channels[].member_directory.identity_scope.id |
string | — | 仅 file:企业/应用/租户命名空间 id;不同 scope 下的相同 id 不会合并 |
outputs.channels[].member_directory.watch |
boolean | — | 仅 file:运行时默认 true;false 只保留周期性校验 |
outputs.channels[].member_directory.debounce_ms |
int 50–2000 | — | 仅 file:watch 防抖窗口;运行时默认 300 |
outputs.channels[].member_directory.poll_interval_seconds |
int 5–300 | — | 仅 file:周期内容摘要校验间隔;运行时默认 30 |
outputs.channels[].member_directory.allowed_root |
string | — | 仅 file:真实路径边界检查的受信根;缺省为主配置文件目录 |
outputs.channels[].author_mappings.<id> |
string | — | 作者或 workspace 标识精确映射到文件成员 key;与 user_mappings 互斥 |
outputs.channels[].connection |
string | — | 对 im.connections 的引用;wecom_app 频道必填,feishu_app 频道用它替代内联凭据 |
outputs.channels[].target |
object | — | 仅 wecom_app:{kind: recipients, users/parties/tags} 或 {kind: appchat, chat_id} — 收件人列表与群目标严格二选一 |
IM 连接与命令绑定(IM 机器人指南)。
schema 已接受该命名空间,发送、回调与 worker 随计划逐步接线;绑定默认停用,
数据库发布侧持续拒绝没有消费者的记录,仅配置 im 不会启用聊天命令。
review 命令另需持久化配置存储。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
im.connections.<id> |
object | — | 命名连接映射;连接 id 需匹配 [A-Za-z0-9][A-Za-z0-9_-]*;kind 选择 wecom_app(corp_id、agent_id、app_secret/app_secret_env)、wecom_aibot(corp_id;回调模式带 callback 与可选 aibot_id,长连接模式带 aibot_id 与 secret/secret_env)或 feishu_app(app_id、app_secret/app_secret_env、可选 base_url、tenant_key),均带可选 callback(运行时默认停用;企业微信 token/encoding_aes_key 与飞书 verification_token/encrypt_key 各为明文与 *_env 成对,启用回调时必填其一)。wecom_aibot 与 feishu_app 的接收模式均按 callback.enabled 区分:true 走事件回调(GET/POST /callbacks/im/<id>),未启用回调时由服务端主动建立长连接接收(企微需 aibot_id+secret,飞书需 app_id+app_secret,即官方 SDK 长连接) |
im.command_bindings.<id>.enabled |
boolean | — | 运行时默认 false;接线完成前禁用草稿始终可保存 |
im.command_bindings.<id>.connection |
string | — | 对 im.connections 的命名引用;启用绑定时要求连接存在且启用 |
im.command_bindings.<id>.actors[] |
object | — | 匹配器数组,任一命中即授权。范围匹配器形态以 kind 判别:any(任意已认证操作人)、wecom_department(部门,recursive 缺省 true 含子部门)、wecom_tag(标签,承载角色/用户组语义)、wecom_position(职位)、wecom_extattr(自定义字段 name+value)、feishu_chat(群成员 chat_id)、feishu_department(部门)、feishu_job_title(职务);匹配器按连接平台适配,目录事实来自服务端目录快照,目录不可用时该维度不授权(fail-closed) |
im.command_bindings.<id>.actors[].type |
enum | — | 精确 principal 形态:wecom_userid、wecom_encrypted_userid 或 feishu_open_id;身份命名空间继承自连接 |
im.command_bindings.<id>.actors[].id |
string | — | 精确的带类型平台 id;不做模糊匹配或目录推导授权 |
im.command_bindings.<id>.actors[].expires_at |
string | — | RFC 3339 时间戳;到期的匹配器(含精确 principal 与 any)自动停止匹配,是临时授权的通用机制 |
im.command_bindings.<id>.conversations[] |
object | — | app_direct(企业微信/飞书应用)、bot_direct(企业微信 API 机器人)或带非空 id 的 group;类型必须匹配连接协议 |
im.command_bindings.<id>.allow_all_repositories |
boolean | — | 运行时默认 false;开启后仓库别名在 repositories 注册表之外还可按 workspace id 或仓库全名精确匹配已观测的项目(projects 表),对查询与 review 命令生效 |
im.command_bindings.<id>.commands |
enum[] | — | help、chat-id、review、status、cancel 与查询命令 projects、reviews、commits、prs、detail、prdetail、queue、running 的去重子集 |
im.command_bindings.<id>.repositories.<id>.workspace |
string | — | 仓库别名目标:workspace id;发布时按路由/VCS 范围校验 |
im.command_bindings.<id>.repositories.<id>.source_trigger |
string | — | 仓库别名目标:来源触发器名;发布时按路由/VCS 范围校验 |
im.command_bindings.<id>.repositories.<id>.repo_ref |
string | — | 仓库别名目标:仓库引用;发布时按路由/VCS 范围校验 |
im.command_bindings.<id>.report_policy |
enum | — | 仅 workspace_routes;运行时默认 |
prompts
Section titled “prompts”命名 system prompt 文档(markdown,可带 frontmatter 元数据;运行时只使用正文)。
workspace 的 prompt.system_prompt 引用其中一个名称替换内置基底 prompt,
prompt.extra_system_prompt 引用一个名称拼接在基底之后。内置基底
(prompts/system/code-reviewer.system.md)永不入库,管理界面以只读形式提供
“复制为新配置”。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
prompts.system.<id> |
string | — | 名称 → system prompt 文档 |
叙述:Agent 与沙箱。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
agent.default |
enum | kilo |
执行模式:kilo、opencode、zoo、copilot-cli、claude-code、pi、oh-my-pi 或 native-llm(直连 gateway) |
agent.timeout_seconds |
int > 0 | 1800 |
CLI agent 单次运行硬超时;超时时杀整棵进程树;native-llm 不使用 |
agent.auto_approve |
boolean | true |
传给所选 CLI adapter;CLI 支持时 false 取消自动批准;native-llm 不使用 |
agent.sandbox |
object | {} |
CLI 沙箱后端;native-llm 不使用 |
agent.sandbox.kind |
enum | — | sandbox kind(见枚举表) |
agent.sandbox.engine |
enum | — | 容器引擎选择 |
agent.sandbox.image |
string | — | 使用的容器镜像 |
agent.context_compaction |
object | { auto: true, prune: true } |
注入各 agent 的对话级自动压缩 |
agent.context_compaction.auto |
boolean | true |
启用自动压缩 |
agent.context_compaction.threshold_percent |
int 1–100 | — | 压缩触发阈值 |
agent.context_compaction.prune |
boolean | true |
修剪压缩后的历史 |
agent.web_search |
object | { enabled: false } |
各 agent 内置搜索工具的控制(omp/kilo/opencode 配置级,claude-code/copilot-cli 仅开关,zoo/pi 无);AICR 始终物化显式开关 |
agent.web_search.enabled |
boolean | false |
为评审启用 agent 内置搜索工具(omp web_search.enabled;kilo/opencode permission + 激活 env;claude-code/copilot-cli CLI 开关) |
agent.web_search.providers |
string[] | [] |
有序 provider:omp 使用完整链;kilo 仅接受 exa;opencode 选择首个 exa/parallel |
agent.web_search.exclude |
string[] | [] |
从搜索链路剔除的 provider id → providers.webSearchExclude |
agent.web_search.timeout_seconds |
int 1–300 | — | 单 provider 传输超时 → providers.webSearchTimeoutSeconds |
agent.web_search.credentials |
map | {} |
搜索凭据 id → 宿主 env 名;启用搜索的 adapter 通过 ${VAR} 引用注入所支持的原生 env |
agent.web_search.searxng |
object | — | 自托管 SearXNG 设置(查询保留在内网) |
agent.web_search.searxng.endpoint |
string | — | SearXNG 端点 URL |
agent.web_search.searxng.categories |
string | — | SearXNG 分类过滤 |
agent.web_search.searxng.engines |
string | — | SearXNG 引擎过滤 |
agent.web_search.searxng.language |
string | — | SearXNG 语言过滤 |
agent.web_search.searxng.safesearch |
int 0–2 | — | SearXNG 安全搜索级别 |
review
Section titled “review”| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
review.languages_auto_detect |
boolean | true |
自动检测评审语言 |
review.include |
string[] | ["**/*"] |
路径 glob:* 只匹配当前目录,** 匹配零个或多个目录 |
review.exclude |
string[] | ["**/vendor/**", "**/*.min.js", "**/*.lock"] |
排除的 glob 模式(在 include 之后应用) |
review.max_files |
int > 0 | 2000 |
单次评审最大分析文件数;只统计通过 review.include/exclude 过滤的文件——超出上限的过滤后路径被截断并记录可见日志,被排除的文件从不计数 |
review.max_patch_bytes |
int > 0 | 20971520 |
UTF-8 patch 预算(20 MiB),只计分析用 diff:被评审过滤规则排除的文件从不计入;分析集超额在调用模型前拒绝,拒绝原因以失败 run 显示在 Recent Runs |
review.incremental |
boolean | true |
false 追加 head 完整文件,受 max_patch_bytes 限制 |
review.skip_lgtm |
boolean | true |
跳过看起来干净的评审 |
review.output_language |
string | zh-CN |
summary 输出语言 |
review.commit_strategy |
enum | aggregate |
端点聚合、一次分析中的逐提交标记补丁或仅 head;历史改写保持端点比较 |
review.log_thinking |
boolean | true |
记录编排器的 thinking/执行日志(设为 false 关闭) |
review.git.allow_deepen |
boolean | false |
允许对浅克隆执行 git fetch --deepen |
review.labels.ignore |
string[] | ["aicr:ignore", "aicr-ignore"] |
跳过评审的 label |
review.labels.auto_tag |
string | — | AICR 启动时附加的固定 tag |
review.labels.reviewed_tag |
string | — | 评审完成时附加的 tag |
review.problem_issue.max_recent_issues |
int 1–200 | 30 |
单次 run 对账的最近 open managed issue 上限 |
review.fetch_extra.max_bytes |
int > 0 | — | 每次 run 额外上下文 UTF-8 字节总量,包含并发请求 |
review.fetch_extra.max_files |
int > 0 | — | 每次 run 额外上下文的不同路径数 |
review.fetch_extra.allow_paths |
string[] | — | 额外上下文拉取允许的路径 glob |
review.reflection.enabled |
boolean | false |
启用 reflection memory |
review.reflection.mode |
enum | — | off、light、thorough |
review.reflection.memory.max_size_kb |
int > 0 | — | memory 最大大小(KB) |
review.reflection.memory.max_entries |
int > 0 | — | memory 最大条目数 |
review.reflection.memory.retention_days |
int > 0 | 90 |
memory TTL(天) |
review.auto_commit.delay_seconds |
int 0–31536000 | 300 |
自动提交首次接收后的固定延迟;0 表示不等待 |
review.auto_commit.queued_timeout_hours |
int 0–8760 | 72 |
自动提交条目/批次及 IM 请求从接受起的最长等待时间;超龄以 queued_timeout 关闭,IM 发送通知;保留有效租约的活动执行;0 关闭超时 |
review.auto_commit.schedule.timezone |
string | UTC |
执行时段使用的 IANA 时区 |
review.auto_commit.schedule.rules[] |
object[] | — | 周计划规则组(days 星期集合 + windows HH:mm 时间段,组间取并集);rules: [] 解除全部周限制 |
review.auto_commit.exclude_sources[] |
object[] | — | 机器人/CI 来源排除规则(id、vcs、match 字段匹配器,glob/regex 二选一);[] 清除继承规则 |
review.auto_commit.include_branches |
string[] | — | 不带 refs/heads/ 的完整分支名,区分大小写,不展开 glob/regex;未列分支的自动推送在落 receipt 前忽略,不影响 PR/MR/评论及无分支的 P4/SVN hook;最近层整体胜出,[] 接受全部分支 |
review.pull_request.schedule.timezone |
string | UTC |
PR/MR 执行时段使用的 IANA 时区 |
review.pull_request.schedule.rules[] |
object[] | — | PR/MR 评审的周计划规则组(days 星期集合 + windows HH:mm 时间段,组间取并集);rules: [] 解除全部周限制;各层均未设置时回退到 review.auto_commit.schedule |
review.pull_request.include_target_branches |
string[] | — | PR/MR 目标(base)分支的完整名称,区分大小写,不展开 glob/regex;未列目标在接收时忽略,目标未知时放行,不影响 push/issue/手动流程;最近层整体胜出,[] 接受全部目标分支 |
叙述:队列与重试。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
queue.kind |
enum | memory |
队列后端:memory、sqlite、redis;rabbitmq 预留(告警并回退到 memory) |
queue.sqlite.path |
string | data/queue.sqlite |
SQLite 队列 DB 路径 |
queue.sqlite.lock_ttl_seconds |
int > 0 | 300 |
stale running job 回收 TTL |
queue.workers.concurrency |
int > 0 | 4 |
全局 worker 并发 |
queue.workers.per_workspace_concurrency |
int > 0 | 1 |
单 workspace 并发上限 |
queue.workers.lock_ttl_seconds |
int > 0 | 1800 |
预留;锁过期时间由 queue backend 配置 |
queue.rate_limit.per_provider_rps |
map | — | 按 provider 的每秒请求数上限 |
queue.retry.attempts |
int > 0 | 3 |
trigger 级重试次数(兼容旧 max_attempts) |
queue.retry.backoff |
object | exponential,5000→60000ms,带 jitter |
kind、base_ms、max_ms、jitter |
queue.dead_letter.enabled |
boolean | — | 预留——schema 接受但运行时未消费 |
queue.dead_letter.max_age_hours |
int > 0 | — | 预留——schema 接受但运行时未消费 |
config_sources
Section titled “config_sources”动态配置来源开关(默认仅文件)。本节属于启动边界:数据库不可修改。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
config_sources.database.enabled |
boolean | false |
启用数据库配置源。启用后 webhook 准入采用持久配置 head、管理端配置 API 可发布 revision;关闭时保持仅文件行为。 |
config_sources.database.backend |
enum | storage |
storage 复用 storage.database(SQLite/PostgreSQL);redis 复用 storage.cache.redis 连接声明。 |
config_sources.database.namespace |
string | default |
配置命名空间:1–64 个字母、数字、点、下划线或连字符,以字母或数字开头。 |
config_sources.runtime.refresh_interval_seconds |
int 1–3600 | 5 |
后台 generation 刷新周期。不是准入一致性屏障:无论该值如何,每次 webhook 准入都会重读持久 head。 |
config_sources.secret_refs[].env |
string | — | 部署授权的环境变量名 |
config_sources.secret_refs[].target |
string[] | — | 精确路径 token;实体 ID/name、上下文仓库 alias 替代对应数组下标 |
config_sources.secret_refs[].destinations.<id> |
unknown | — | 精确目标信息,含 kind、endpoint 和关联 trigger 的目的地;见 example/config.yaml |
storage
Section titled “storage”叙述:存储。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
storage.database.kind |
enum | sqlite |
数据库后端(sqlite 或 postgres) |
storage.database.sqlite.path |
string | /app/data/aicr.sqlite |
SQLite DB 路径 |
storage.database.postgres.url_env |
string | — | Postgres 连接串环境变量 |
storage.database.migrate |
enum | auto |
启动 schema 迁移模式(auto 应用、verify 检查配置与业务 schema) |
storage.cache.kind |
enum | memory |
缓存后端 |
storage.cache.redis.url_env |
string | — | Redis 连接串环境变量 |
storage.cache.ttl_seconds |
int > 0 | — | 缓存 TTL |
storage.object.kind |
enum | filesystem |
对象存储后端 |
storage.object.filesystem.root |
string | /app/data/objects |
文件系统对象根目录 |
storage.object.s3.endpoint_url_env |
string | — | S3 兼容 endpoint 环境变量(AWS S3、MinIO、RustFS) |
storage.object.s3.bucket |
string | — | bucket 名 |
storage.object.s3.region_env |
string | — | region 环境变量 |
storage.object.s3.access_key_id_env |
string | — | access key id 环境变量 |
storage.object.s3.secret_access_key_env |
string | — | secret access key 环境变量 |
storage.object.s3.force_path_style |
boolean | — | 使用 path-style 寻址(MinIO/RustFS) |
storage.retention.deleted_project_grace_days |
int ≥ 0 | 30 |
软删除项目的硬删除宽限期(天) |
storage.retention.recent_runs.max_count |
int 1–1000000 | 2000 |
保留最近的逐次运行详情数量;汇总统计继续保留 |
storage.retention.recent_runs.max_age_months |
int 1–1200 | 6 |
运行详情最长保留 UTC 日历月数,从运行开始时间计算 |
storage.retention.events.max_count |
int 1–1000000 | 2000 |
保留最近的接收事件数量 |
storage.retention.events.max_age_months |
int 1–1200 | 6 |
事件最长保留 UTC 日历月数,从接收时间计算 |
storage.retention.queue.max_count |
int 1–1000000 | 1000 |
保留最近的已结束自动提交批次数量;活动和待重试任务不受影响 |
storage.retention.queue.max_age_months |
int 1–1200 | 6 |
已结束批次历史最长保留 UTC 日历月数,从批次创建时间计算 |
compression
Section titled “compression”| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
compression.trigger_tokens |
int > 0 | 按模型派生,见下 | 触发 diff 压缩的 token 阈值 |
compression.max_input_ratio |
number 0–1 | 0.6 |
压缩前的最大输入占比 |
compression.summarize_model_role |
string | light |
summarize 阶段使用的 model role(light/heavy/any) |
compression.keep_hunks_top_k |
int > 0 | 30 |
原样保留的最高风险 hunk 数 |
compression.context_lines |
int > 0 | 5 |
保留 hunk 周围的上下文行数 |
compression.per_model_overrides |
map | — | 按 model 配置 trigger_tokens 覆盖 |
当 compression 缺省时,bootstrap 会从 review model 的 context window 派生默认
trigger_tokens = min(131072, max(8192, floor(contextWindow × 0.6)))。
server
Section titled “server”| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
server.port |
int > 0 | 8080 |
HTTP 监听端口 |
server.hostname |
string | 0.0.0.0 |
监听 hostname |
server.trust_proxy |
boolean | enum | string[] | false |
trust proxy 设置(loopback/linklocal/uniquelocal 或 CIDR 列表) |
server.base_url |
string | — | 外部 base URL |
server.path_prefix |
string | — | URL 路径前缀(反代子路径) |
server.auth.api_key_env |
string | — | 全局 API key 环境变量(保护 /triggers/*) |
server.auth.api_key |
string | — | 明文全局 API key;与 api_key_env 互斥(明文优先) |
server.auth.enabled |
boolean | true |
切换全局 API key |
叙述:Dashboard 与日志。
| 字段 | 类型 | 默认值 | 描述 |
|---|---|---|---|
admin.username_env |
string | AICR_ADMIN_USERNAME |
管理员用户名环境变量 |
admin.password_env |
string | AICR_ADMIN_PASSWORD |
管理员密码环境变量 |
admin.password_hash_env |
string | — | 管理员密码哈希环境变量(sha256:<hex>);优先于 password_env |
admin.password |
string | — | 明文管理员密码;与 password_env 互斥(明文优先) |
admin.password_hash |
string | — | 明文管理员密码哈希(sha256:<hex>);与 password_hash_env 互斥 |
admin.session_ttl_seconds |
int > 0 | 86400 |
session TTL(秒,不是分钟) |