diff --git a/plan/configuration.md b/plan/configuration.md index 6f515eb..ae89f24 100644 --- a/plan/configuration.md +++ b/plan/configuration.md @@ -25,10 +25,40 @@ in another hemisphere. There is a config file now, `~/.config/atgc/config.toml`, and the entry under Done is mostly about why that was a decision about precedence rather than -about a parser. +about a parser. It holds one key. What belongs beside it, and whether a single +identity should be able to say anything of its own, are the two open entries +below. ## What it needs +- [ ] `config.toml` holds one key. The file exists and `default` is the only + thing in it, which is the right place to have stopped — a format is + easier to add to than to change once something writes it — but it is + not where this should stay. The candidates were named when the file was + argued for: log retention and the `ATGC_LOG` filter, both of which are + standing preferences a person sets once and neither of which has + anywhere to live but a shell export today. The test is whether a + setting is *held constant by a person* rather than varied per + invocation; anything varied per invocation is a flag, and anything a + script sets is an environment variable. Endpoints stay out on purpose + and the entry under Done says why. What has to stay true as keys are + added is the chain `auth login` and `auth default` print at people: + flag beats env beats file beats persisted state, and a file that + silently outranked a variable would make those sentences lies +- [ ] No per-identity configuration. `dids///` is one directory + per identity holding its account entry, its sessions, its keys and its + lock, so it is the obvious home for settings that belong to one agent + rather than to the machine — and there is no mechanism for those at + all. The shape of the want is clear enough: a fleet where one agent + pushes to a different knot, or asks for narrower scopes at login, or + keeps its logs longer than its siblings. The shape of the *content* is + not, which is why this is a direction and not a design. Two things it + should inherit when it happens: the precedence above, with an + identity's file beating the machine's for the same reason a flag beats + an environment variable — the more specific statement wins; and + `account.json` as the file, rather than a second one beside it, unless + what goes in turns out to be something a person edits, in which case it + is TOML for the reason the machine's is - [ ] Neither bound can be switched off: 0 is refused, because an unbounded connect is the wait `clients/http.rs` was written for. Revisit if a case turns up that a very large number cannot serve