Hosts, routes, and secrets
Configure API, console, WebSocket, database, Redis, and internal secret values.
Authentication and sessions
Configure OIDC, password authentication, browser sessions, and signup policy.
Models and runtime limits
Configure providers, models, budgets, reasoning summaries, and gateway readiness.
Approvals and retention
Configure write confirmation, Workflow duration, report retention, and auditing.
MCP egress and registries
Constrain remote MCP destinations and bootstrap registry sources.
Webhooks
Configure durable delivery, retry limits, payload bounds, and private destinations.
Configuration ownership
Keep these scopes distinct:- Deployment configuration sets the maximum available policy and infrastructure behavior.
- Workspace configuration selects from deployment-supported roles, providers, integrations, and capabilities.
- Target configuration controls one cluster or VM and its connector policy.
- Run scope contains the exact resources and tools authorized for one execution.