Skip to content

environments

This page is generated from the same Go declarations the loader enforces, so it cannot drift from what ob validate accepts.

allowAgentProposals · backupKeyMaterial · backupMaxAge · basePath · envFiles · file · host · jump · migrations · minOneboxVersion · minPlanSchema · overrides · policy · port · provider · requireApproval · requireBackup · requireRestoreTest · server · services · user · workloads

FieldTypeDefaultWhat it does
<name>.basePathstring—Environment-specific replacement for the Application basePath. Expects an absolute path with no control character or shell metacharacter.
<name>.envFileslist—Default ordered environment-file list for application, worker, and job workloads in this environment.
<name>.envFiles[].file *string—Repository-relative environment file path. Expects a path inside the repository, with no control character or shell metacharacter.
<name>.envFiles[].providerSops—Decryptor used before staging the file. The supported encrypted provider is sops.
<name>.jumpobject—Optional SSH jump host tunnelling the connection to this server, written as user@host or as an object with host, user, and port. Onebox verifies and authenticates both hops and never forwards the SSH agent. Also accepts user@host or user@host:port.
<name>.jump.hoststring—Jump host name or IP address.
<name>.jump.portinteger—SSH port on the jump host. The SSH default is used when omitted.
<name>.jump.userstring—SSH user on the jump host. $USER is used when omitted; ob does not read ~/.ssh/config.
<name>.overridesobject—Environment-specific operational tuning. Overrides cannot change workload identity or data semantics.
<name>.overrides.servicesmap—Allowed service tuning keyed by service name: resources and settings.
<name>.overrides.workloadsmap—Allowed workload tuning keyed by workload name: replicas, resources, env, envFiles, strategy, and routes.
<name>.policyobject—Approval, runner compatibility, and migration-backup requirements for this environment.
<name>.policy.allowAgentProposalsbooleantrueDeclared permission for agent-authored proposals. The current CLI does not distinguish agent identity; execution remains approval-gated.
<name>.policy.migrationsobject—What this environment requires of a release carrying migration risk.
<name>.policy.migrations.backupKeyMateriallist—Key-material identities the backup report must name.
<name>.policy.migrations.backupMaxAgestring24hMaximum age of a backup report accepted for a migration. Expects a duration such as 30s, 5m, 1h30m or 14d.
<name>.policy.migrations.requireBackupbooleanfalseRequire a plan-bound backup report before a release with migration risk.
<name>.policy.migrations.requireRestoreTestbooleanfalseRequire the backup report to state that a restore test succeeded.
<name>.policy.minOneboxVersionstring—Oldest released Onebox runner allowed to operate this environment. Expects a CalVer release such as v2026.8.0.
<name>.policy.minPlanSchemastring—Oldest executable plan schema accepted by this environment. Expects a plan schema identity such as onebox.run/executable-deploy-plan/v1alpha2.
<name>.policy.requireApprovalbooleantrueRequire a plan-bound local confirmation before mutating this environment.
<name>.serverobject—SSH server, written as user@host or as an object with host, user, and port. Also accepts user@host.
<name>.server.hoststring—SSH hostname or IP address.
<name>.server.portinteger—SSH port. The SSH default is used when omitted.
<name>.server.userstring—SSH user. $USER is used when omitted; ob does not read ~/.ssh/config.

* marks a field that is required within its own object.