Configuration
kapsl works with no configuration at all: the defaults are the product, and a fresh machine runs every published tool. Configuration is for the cases where a default is the wrong call for you — a private registry for your own tools, an extra pass-through variable, a scan threshold your supply chain has chosen.
When you do configure, the file is ~/.config/kapsl/kapsl.toml (override the path with KAPSL_CONFIG), and a broken file fails loudly on every run rather than silently falling back to defaults.
Precedence
Settings layer, lowest to highest:
| Layer | Where | What it can do |
|---|---|---|
| Built-in defaults | in the binary | the zero-trust posture. |
[tools] | kapsl.toml | define what a name is; per-tool grants. |
.kapslrc | project root, committed | grant capabilities/ports/env for the project. Cannot redefine what a name is. |
| CLI flags | the command line | --cap, --port, everything, for this run. |
[enforce] | kapsl.toml | a floor above all of the above — the catalogue, the project and the flags cannot clear it. |
The rule that makes the table safe: each layer above grants or narrows; none of them redefines the layer below. A project can ask for network; it cannot make kapsl python a different python.
The three pages:
- The configuration file — every section of
kapsl.toml, at its default. - Environment variables — what crosses into a container, and how to add to it.
- Offline mode — running with no network at all.
Pages in this section
- Environment variables What crosses into a container by default, how to add to it, and the deny lists that make a broad pass-through safe.
- Offline Mode Running with no host-side network at all: what --offline changes, what it cannot do, and how to prepare a sealed machine.
- Configuration File Every section of kapsl.toml, at its default — the annotated reference