Configuration

kapsl works with no configuration at all: the defaults are the product, and a fresh machine runs every published tool. Configuration is for the cases where a default is the wrong call for you — a private registry for your own tools, an extra pass-through variable, a scan threshold your supply chain has chosen.

When you do configure, the file is ~/.config/kapsl/kapsl.toml (override the path with KAPSL_CONFIG), and a broken file fails loudly on every run rather than silently falling back to defaults.

Precedence

Settings layer, lowest to highest:

LayerWhereWhat it can do
Built-in defaultsin the binarythe zero-trust posture.
[tools]kapsl.tomldefine what a name is; per-tool grants.
.kapslrcproject root, committedgrant capabilities/ports/env for the project. Cannot redefine what a name is.
CLI flagsthe command line--cap, --port, everything, for this run.
[enforce]kapsl.tomla floor above all of the above — the catalogue, the project and the flags cannot clear it.

The rule that makes the table safe: each layer above grants or narrows; none of them redefines the layer below. A project can ask for network; it cannot make kapsl python a different python.

The three pages:

Pages in this section

  • Environment variables What crosses into a container by default, how to add to it, and the deny lists that make a broad pass-through safe.
  • Offline Mode Running with no host-side network at all: what --offline changes, what it cannot do, and how to prepare a sealed machine.
  • Configuration File Every section of kapsl.toml, at its default — the annotated reference