Configuration¶
Argus loads typed settings from config/settings.yaml and ARGUS_ environment
variables. Nested keys use a double underscore, for example
ARGUS_API_SECURITY__TRUSTED_HOSTS and ARGUS_FEATURES__ASYNC_TASKS_ENABLED.
Environment values override YAML.
Setting groups¶
| Group | Controls |
|---|---|
runtime |
local, test, staging, or production; service name and debug |
database |
PostgreSQL URL or components, pool size, overflow |
redis |
Redis URL or components, database, socket timeout |
object_storage |
S3 or filesystem backend, endpoint, bucket, credentials, TLS |
api_key / jwt |
Signing secrets, digest/algorithm, JWT TTL |
oauth |
Casdoor issuer, API/MCP audiences, shared institution, JWT validation, CLI PKCE |
audit |
Mandatory logging/redaction and retention days |
data_license |
License file, default policy, enforcement |
connectors |
Registry, enablement, timeout, live tests, fail-closed behavior |
api_security |
Hosts, public URL, CORS, metrics authentication |
mcp |
Transport, bind host/port/path, public URL, metrics endpoint |
client_distribution |
Published wheel URL, SHA-256, release version |
features |
Structured queries, stage two, vector evidence retrieval, async tasks |
Secrets¶
Local/test settings may use direct values for convenience. Production Compose uses
root-owned file-backed secrets for PostgreSQL, Redis, API-key signing, JWT signing,
metrics, provider access, and primary machine credentials. Do not put secret values in
.env.production, Compose interpolation, command arguments, documentation, or
container health output.
Production preflight checks ownership, mode, placeholders, minimum strength, required providers, and consistency before starting the application image. See Deployment for the exact file layout and commands.
Security constraints¶
- Non-local API hosts and public URLs must be explicit and HTTPS at the edge.
- Production metrics require a dedicated token.
- Public API/MCP services bind to loopback behind the TLS reverse proxy.
- Object storage using S3 in non-local environments requires secure transport.
- Audit and sensitive-value redaction cannot be disabled.
- License and redistribution enforcement default to disabled in both settings models and service constructors. The server switch propagates to nested ingestion, publication, record readers, PIT and bounded stream checks; source metadata and the independent external-model processing gate remain active. This does not establish provider subscription rights.
- CORS is empty unless a specific browser origin is intentionally allowed.
- OAuth issuers use HTTPS outside local/test; only configured asymmetric algorithms are accepted.
Feature flags¶
Feature flags expose maturity boundaries, not permission bypasses. Enabling vector evidence search, stage-two services, or async work does not change machine scopes, license status, output policy, or the requirement for evidence. Validate migrations, dependencies, provider configuration, and the relevant test gate before enabling a flag outside local development.
Validate configuration¶
For local parsing and redaction checks:
uv run python -c "from argus.config import load_settings; print(load_settings().redacted_model_dump())"
redacted_model_dump() recursively masks secret-bearing keys, including nested
database, Redis, object-storage, and provider credentials. Do not replace it
with a top-level model_dump(..., exclude=...): top-level exclusions do not protect
nested secrets.
For production, use scripts/production-preflight.sh; it performs substantially
more checks than merely loading Pydantic settings. Never print a full settings
object in a production shell because nested provider or storage credentials may be
present.