Repository navigation
Expand file tree
/
Copy pathconfig.example.toml
More file actions
200 lines (183 loc) · 10.2 KB
/
Copy pathconfig.example.toml
File metadata and controls
200 lines (183 loc) · 10.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
# coop configuration
# Copy to ~/.coop/config.toml and uncomment fields to override defaults.
# An empty file (or no file at all) gives you sensible defaults.
# Run `coop validate` to check your config.
# data_dir = "~/.coop" # VM artifacts: images, instances, keys
# ssh_port = 22 # Guest SSH port
# firecracker_bin = "~/.coop/firecracker" # Linux only
# post_create = "sudo apt-get update && sudo apt-get install -y htop"
# Creation commands run once per VM creation, after workspace setup.
# post_start = "echo guest ready" # Every boot, after creation/workspace setup
# GitHub auth strategy. Pick ONE of the two forms below — `github` cannot
# be both a string and a table at the same time.
#
# Form A — simple string:
# github = "auto" # "auto", "env", "off", or "pat"
#
# Form B — table, required when you want per-repo PAT entries.
# Run `coop github setup-pat --repo owner/name` to populate it via wizard.
# Select an existing entry for a VM with:
# coop github assign-pat --vm projects --repo owner/name
# The VM stores only the entry key; it overrides workspace-based selection.
# Form B `mode = "pat"` is equivalent to form A `github = "pat"`.
#
# [github]
# mode = "pat"
# skip = ["owner/big-repo"] # repos to skip the auto-prompt for
#
# [github.pat."trailofbits/coop"]
# token = "cmd:security find-generic-password -s coop-github-pat -a trailofbits-coop -w"
# Optional copies into each VM, refreshed before agent bootstrap at every boot.
# Repeat [[guest_files]] for multiple sources. ~ in destination means guest home.
# [[guest_files]]
# source = "~/.config/agents"
# destination = "~/.config/agents"
#
# [[guest_files]]
# source = "~/dotfiles/gitconfig"
# destination = "~/.gitconfig"
# [setup]
# prompt_for_pat = true # auto-prompt to set up a PAT at `coop start`
# [vm]
# vcpu_count = 2 # vCPUs per VM (override: --vcpus)
# mem_size_mib = 4096 # Memory in MiB (override: --mem)
# template_size_gib = 8 # Template disk in GiB (override: --template-size)
# kernel_path = "~/.coop/vmlinux" # Linux/Firecracker only
# boot_args = "console=ttyS0 reboot=k panic=1 pci=off root=/dev/vda rw"
# [network] # Linux/Firecracker only
# host_ip = "172.16.0.1"
# subnet_mask = "/24"
# host_iface = "auto" # "auto" detects at runtime
#
# Exact paths for non-FHS Linux hosts. Set fields only when the corresponding
# built-in /usr/{bin,sbin} or /{bin,sbin} candidates are unsuitable. A set
# field replaces the built-in candidates for that tool; it never falls back.
# [network.host_tools]
# sudo = "/run/wrappers/bin/sudo" # NixOS example
# ip = "/run/current-system/sw/bin/ip"
# bridge = "/run/current-system/sw/bin/bridge"
# iptables = "/run/current-system/sw/bin/iptables"
# sysctl = "/run/current-system/sw/bin/sysctl"
# [guest_env] # Literal env vars to set in the guest.
# # Overrides forwarded values on key
# # collision (warning logged). Avoid for
# # secrets — use `env_forward` instead.
# RUST_LOG = "info"
# MY_FLAG = "1"
# [claude]
# Copies CLAUDE.md, keybindings.json, rules/, commands/, skills/, agents/,
# output-styles/, themes/, workflows/ (complete bundles; follows symlinks).
# Narrowly imports disableAllHooks, outputStyle and copied @skills-dir plugin
# preferences; unrelated host settings and plugin installation state stay out.
# Restarts overlay files; host deletions/false retain copies. Active-source
# preference removal restores prior guest values; false retains last preferences.
# Sources with skills/manifest.json sync bookkeeping need a separate custom source.
# config_dir = "~/.claude" # custom source path, or false to stop copying
# env_forward = ["CUSTOM_TOKEN"] # Extra env vars to forward to guest
# marketplaces = ["https://github.com/anthropics/claude-plugins-official"]
# plugins = ["rust-analyzer-lsp@claude-plugins-official"]
#
# Secrets: any field below that holds a secret accepts a "cmd:" prefix.
# The remainder is run via `sh -c` at VM start time and its trimmed
# stdout is used as the value. Examples for api_key:
# api_key = "cmd:op read op://Private/Anthropic/credential" # 1Password
# api_key = "cmd:security find-generic-password -s anthropic -w" # macOS Keychain
# api_key = "cmd:pass show anthropic/api-key" # pass
# api_key = "sk-ant-..." # Plain value also works
# [claude.mcp_servers.my-server]
# command = "/usr/bin/my-mcp-server"
# args = ["--verbose"]
# env = { API_KEY = "MY_HOST_ENV_VAR" }
# # Header values also accept the "cmd:" prefix:
# # headers = { Authorization = "cmd:op read op://Private/Sentry/token" }
# [claude.local_model] # Route Claude Code at a host-side model.
# # Enable per VM with `coop model <vm> local`
# # (disable with `coop model <vm> remote`).
# # host_url is as seen on the *host*; a
# # localhost host is rewritten to the guest's
# # view of the host automatically.
# host_url = "http://localhost:11434" # Must serve the Anthropic Messages API
# # (vLLM / LM Studio native; Ollama needs a
# # proxy). Prompt caching is lost locally.
# model = "qwen2.5-coder:32b"
# auth_token = "sk-..." # Optional; permissive servers ignore it.
# [codex]
# auth = "api_key" # "api_key" (default) or "chatgpt" for ChatGPT account/workspace auth
# config_dir = "~/.codex" # path to copy AGENTS.md, prompts/, config.toml, auth.json from (false to disable)
# env_forward = ["CUSTOM_TOKEN"] # Extra env vars to forward to guest
# marketplaces = ["trailofbits/codex-plugins"] # owner/repo, git URL, or local path
# plugins = ["my-lsp@codex-plugins"] # plugin@marketplace to install
#
# Note: the "chatgpt" mode stores Codex credentials in the guest Linux
# keyring, and neither copies auth.json nor forwards OPENAI_API_KEY.
# Sign in once with `coop codex -- login --device-auth`.
#
# Secrets: with auth = "api_key", `api_key` accepts the same "cmd:" prefix as
# `claude.api_key`.
# api_key = "cmd:op read op://Private/OpenAI/credential"
# api_key = "sk-proj-..."
# [codex.mcp_servers.my-server]
# command = "npx"
# args = ["-y", "@openai/some-mcp-server"]
# env = { API_KEY = "MY_HOST_ENV_VAR" }
# [codex.local_model] # Route Codex at a host-side model.
# # Toggled per VM with `coop model <vm>
# # local|remote`, same as claude.local_model.
# host_url = "http://localhost:11434/v1/" # Must serve the Responses API
# # (Ollama / vLLM / LM Studio; ~64K
# # context floor).
# model = "gpt-oss:120b"
# auth_token = "sk-..." # Optional; permissive servers ignore it.
# [grok]
# Copies AGENTS.md, auth.json, lsp.json, rules/, skills/, commands/, plugins/,
# hooks/, agents/, workflows/. Skips directory symlinks, hidden dirs, and *.git.
# Host config.toml is merged except [plugins]. Restarts overlay files; host
# deletions/false retain copies. Guest [plugins] stays.
# config_dir = "~/.grok" # custom source path, or false to stop copying
# env_forward = ["CUSTOM_TOKEN"] # Extra env vars to forward to guest
# marketplaces = ["owner/grok-plugins"] # owner/repo, git URL, or local path
# plugins = ["my-skill"] # plugin name (`grok plugin install --trust`)
#
# Secrets: `api_key` accepts the same "cmd:" prefix as `claude.api_key`.
# api_key = "cmd:op read op://Private/xAI/credential"
# api_key = "xai-..."
# Host `~/.grok/auth.json` is copied into the guest (same as Codex). A
# copied session token takes precedence over `XAI_API_KEY`. If there is
# no host file, sign in with `coop grok -- login --device-auth`.
# [grok.mcp_servers.my-server]
# command = "npx"
# args = ["-y", "@example/mcp-server"]
# env = { API_KEY = "MY_HOST_ENV_VAR" }
# [proxy] # Host-side credential-injecting proxy
# # (issue #411). Opt-in: when set, coop runs
# # a `coop-proxy` process on the host and the
# # raw credential never enters the guest —
# # the guest is pointed at the proxy and gets
# # only a per-instance capability token, and
# # the raw API key is no longer forwarded.
# # Applies only in remote model mode
# # (`coop model <vm> remote`); local mode
# # takes precedence. Works on both backends.
# `coop proxy setup [--openai] [--vm <name>]` writes this for you: it takes a
# pasted credential, stores it in Keychain / 1Password / a 0600 file, and fills
# in the `cmd:` reference. Anthropic covers Claude Code; openai covers Codex.
# A `--vm <name>` override is stored in that VM's instance state (not here);
# `coop proxy status` shows what each VM resolves to (override → default → off).
# [proxy.anthropic]
# credential = "cmd:op read op://Private/Anthropic/credential" # same "cmd:" support
# auth = "api_key" # api_key → x-api-key (default); bearer →
# # Authorization: Bearer, for a Claude
# # `setup-token` (run `claude setup-token`).
# [proxy.openai] # Codex. OpenAI keys are always Bearer.
# credential = "cmd:op read op://Private/OpenAI/credential"
# auth = "bearer" # OpenAI keys inject as Authorization: Bearer.
# # Cannot be combined with
# # [codex] auth = "chatgpt"; proxy mode uses
# # an API key.
# [profiles.my-tools]
# apt_packages = ["ripgrep", "fd-find", "jq"]
# pre_install = "curl -fsSL https://example.com/setup.sh | bash"
# post_install = "echo 'done'"
# [updates]
# mode = "notify" # off | notify (default: notify)
# check_interval_hours = 24 # minimum age before background re-check