Skip to content
Alvo is pre-v0.1: the image runs from its edge tag, and no NuGet package or release is published yet.Pre-v0.1: no release yet.Roadmap and status

Configuration keys

Every Alvo:* option, its type and default, generated from the options types.

Configuration uses the standard .NET options pattern. In environment variables, replace : with __ (Alvo__Api__DefaultPageSize).

Standalone host (the ghcr.io/burgyn/alvo image). Options type: AlvoHostOptions.

KeyTypeDefaultDescription
Alvo:DescriptorPathstring/alvo/descriptor.jsonGets or sets the project descriptor’s path (default /alvo/descriptor.json, the image’s mount point).
Alvo:Database:ProviderstringsqliteGets or sets the driver to register — Sqlite or PostgreSql.
Alvo:Database:SqliteConnectionStringstringData Source=/alvo/data/alvo.dbGets or sets the connection string used when Provider is Sqlite and ConnectionStrings:Alvo is not set.
Alvo:PathBasestring?—Gets or sets the path base the host is served under, for a deployment behind a reverse proxy that does not rewrite (default none).
Alvo:ForwardedHeaders:EnabledboolfalseGets or sets whether X-Forwarded-For, -Proto, -Host and -Prefix are honoured (default false).
Alvo:Docs:EnabledbooltrueGets or sets whether the docs UI and the OpenAPI document are served (default true).

Bound by the standalone host; an embedded host configures it in code. Options type: AlvoIdentityOptions.

KeyTypeDefaultDescription
Alvo:Admin:BootstrapEmailstring?—Gets or sets the address of the bootstrap administrator, or null for none.
Alvo:Admin:BootstrapPasswordFilestring?—Gets or sets the path of the file holding the bootstrap administrator’s password.

Bound by the standalone host; an embedded host configures it in code. Options type: AlvoAdminOptions.

KeyTypeDefaultDescription
Alvo:Admin:Dashboard:EnabledbooltrueWhether the dashboard is mapped at all. Defaults to true.
Alvo:Admin:Dashboard:DocsPathstring?—Where this host serves its interactive API documentation, or null when it serves none. The standalone host overwrites this after binding: /scalar when Alvo:Docs:Enabled is true, otherwise none. Set it only in an embedded host.
Alvo:Admin:Dashboard:OpenApiPathstring?—Where this host serves the OpenAPI document itself, or null when it serves none. The standalone host overwrites this after binding: /openapi/v1.json when Alvo:Docs:Enabled is true, otherwise none. Set it only in an embedded host.

Any host (bound by the core). Options type: AlvoAiOptions.

KeyTypeDefaultDescription
Alvo:Ai:Kindstring?—Gets or sets which protocol the endpoint speaks — openai-compatible or azure-openai.
Alvo:Ai:Endpointstring?—Gets or sets the base address to dial, e.g. http://localhost:11434/v1.
Alvo:Ai:Modelstring?—Gets or sets the model or deployment name to ask for.
Alvo:Ai:ApiKeySecretRefstring?—Gets or sets the name of the secret holding the API key, resolved through the secret store.

Bound by the standalone host; an embedded host configures it in code. Options type: AlvoApiOptions.

KeyTypeDefaultDescription
Alvo:Api:RoutePrefixstring/apiThe route prefix every generated endpoint sits under. Default /api.
Alvo:Api:DefaultPageSizeint50The page size used when a request names none. Default 50.
Alvo:Api:MaxPageSizeint200The largest page a request may ask for. Default 200. Server-enforced rather than advisory: a maximum is required, because an unbounded limit is a denial-of-service one query long.
Alvo:Api:MaxRequestBodyBytesint1048576The largest request body a write endpoint will read. Default 1 MiB.
Alvo:Api:MaxPayloadDepthint32How deeply a request body may nest. Default 32.
Alvo:Api:MaxPayloadKeysint512How many property names a request body may carry in total, at any depth. Default 512.
Alvo:Api:MaxBatchRowsint1000The most rows one batch request may carry. Default 1000.
Alvo:Api:MaxIdempotencyKeyBytesint255The longest Idempotency-Key a create will accept, in UTF-8 bytes. Defaults to MaxKeyBytes, and may only be lowered.

Bound by the standalone host; an embedded host configures it in code. Options type: AlvoAuthOptions.

KeyTypeDefaultDescription
Alvo:Auth:DevKeys:{n}:KeyIdstring""Gets or sets the key’s public identifier.
Alvo:Auth:DevKeys:{n}:Secretstring""Gets or sets the plaintext secret as configured; retained on the options instance for the process lifetime — a dev mechanism only, not a production issuance path.
Alvo:Auth:DevKeys:{n}:UserGuid00000000-0000-0000-0000-000000000000Gets or sets the user this key authenticates as.
Alvo:Auth:DevKeys:{n}:Roles:{n}stringemptyGets the names of the roles this key grants.
Alvo:Auth:DevKeys:{n}:TenantGuid?—Gets or sets the tenant this key is scoped to, if any.
Alvo:Auth:DevKeys:{n}:Scopes:{n}stringemptyGets the entity/access scopes this key grants, in the descriptor form "<entity|*>:<read|write>".
Alvo:Auth:DevKeys:{n}:ExpiresAtDateTimeOffset?—Gets or sets when this key expires, if ever.
Alvo:Auth:HeaderNamestringX-Alvo-Api-KeyGets the HTTP header a presented API key is read from, consumed by the HTTP Data API.
Alvo:Auth:TenantHeaderNamestringX-Alvo-TenantGets the HTTP header the tenant a caller asks to act in is read from, consumed by the HTTP Data API.

Any host (bound by the core). Options type: AlvoEventOptions.

KeyTypeDefaultDescription
Alvo:Events:EnabledbooltrueGets or sets whether this process drains the outbox. Defaults to true.
Alvo:Events:PollIntervalTimeSpan00:00:01Gets or sets how long the pump waits after finding nothing to claim, before claiming again. Defaults to one second, and must be greater than zero.
Alvo:Events:BatchSizeint100Gets or sets the most entries one claim takes. Defaults to 100, and must be at least 1.
Alvo:Events:MaxAttemptsint10Gets or sets how many times one event may be claimed before it is left alone. Defaults to 10, and must be at least 1.
Alvo:Events:ClaimLeaseTimeSpan00:05:00Gets or sets how long a claim holds before another claimant may take the entry back. Defaults to five minutes, and must be longer than PollInterval.
Alvo:Events:WebhookAllowedNetworks:{n}stringemptyGets the non-public networks, in CIDR notation, a webhook may be delivered to. Empty by default, which allows only globally reachable addresses — and loopback, when the endpoint names it literally.

Any host (bound by the core). Options type: AlvoManagementOptions.

KeyTypeDefaultDescription
Alvo:Management:RoutePrefixstring/managementThe route prefix every management endpoint sits under. Default /management.

Any host (bound by the core). Options type: AlvoSchemaOptions.

KeyTypeDefaultDescription
Alvo:Schema:Startupone of: Verify, Apply, SkipApplyGets or sets what a boot does when the descriptor has drifted from the applied schema. Defaults to Apply, which brings the database up to the descriptor and still refuses any step that would discard data.
Alvo:Schema:Projectstring?—Gets or sets the project a dashboard-first host boots — the project whose stored descriptor the boot reads when no IDescriptorSource is configured. null in code-first mode, where the descriptor names the project itself.
Alvo:Schema:AllowDestructiveboolfalseGets or sets whether a boot may apply a plan that drops or narrows something — the guardrail that separates Apply from data loss. Defaults to false, so a destructive plan is refused even under Apply.

Any host (bound by the core). Options type: AlvoSecretOptions.

KeyTypeDefaultDescription
Alvo:Secrets:EncryptionKeyFilestring?—Gets or sets the path to the file holding the key the database-backed store encrypts with — 32 bytes, base64.
Alvo:Secrets:Values:{name}stringemptyGets or sets the secrets this deployment supplies through configuration itself, by name.

These public options types are not read from any configuration section:

  • AlvoOptions — Configured in code with Configure<AlvoOptions>; no host binds it from configuration.
  • MigrationOptions — A per-call argument to the schema migrator, not a configuration section; the Alvo:Schema keys decide what start-up passes it.
  • PostgreSqlProviderOptions — Set in code by UsePostgreSql(…); its connection string comes from ConnectionStrings:Alvo, listed below.
  • SqliteProviderOptions — Set in code by UseSqlite(…); its connection string comes from ConnectionStrings:Alvo, listed below.

These keys are read directly rather than through an options type.

KeyTypeDefaultDescription
ConnectionStrings:Alvostring—The database connection string. The parameterless UseSqlite() and UsePostgreSql() read it; the standalone host reads it for either driver and, for SQLite only, falls back to Alvo:Database:SqliteConnectionString when it is unset.
Alvo:Admin:CredentialAttemptsPerMinuteint20Standalone host: sign-in and set-password attempts per minute for one subject (an address, or a set-password token) from one client. Must be positive while the dashboard is on.
Alvo:Admin:CredentialCeilingPerMinuteint200Standalone host: the ceiling per client per minute, shared by both credential forms, over the per-subject budget. Must be positive while the dashboard is on.
Alvo:Admin:SessionRevalidationSecondsint30A test seam, not a setting: how often an open dashboard tab’s session is re-checked. It can only shorten the interval; anything but a whole number from 1 to 30 is refused at start.