Configuration keys
Every Alvo:* option, its type and default, generated from the options types.
Configuration uses the standard .NET options pattern. In environment variables, replace : with __ (Alvo__Api__DefaultPageSize).
Standalone host (the ghcr.io/burgyn/alvo image). Options type: AlvoHostOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:DescriptorPath | string | /alvo/descriptor.json | Gets or sets the project descriptor’s path (default /alvo/descriptor.json, the image’s mount point). |
Alvo:Database:Provider | string | sqlite | Gets or sets the driver to register — Sqlite or PostgreSql. |
Alvo:Database:SqliteConnectionString | string | Data Source=/alvo/data/alvo.db | Gets or sets the connection string used when Provider is Sqlite and ConnectionStrings:Alvo is not set. |
Alvo:PathBase | string? | — | Gets or sets the path base the host is served under, for a deployment behind a reverse proxy that does not rewrite (default none). |
Alvo:ForwardedHeaders:Enabled | bool | false | Gets or sets whether X-Forwarded-For, -Proto, -Host and -Prefix are honoured (default false). |
Alvo:Docs:Enabled | bool | true | Gets or sets whether the docs UI and the OpenAPI document are served (default true). |
Alvo:Admin
Section titled “Alvo:Admin”Bound by the standalone host; an embedded host configures it in code. Options type: AlvoIdentityOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Admin:BootstrapEmail | string? | — | Gets or sets the address of the bootstrap administrator, or null for none. |
Alvo:Admin:BootstrapPasswordFile | string? | — | Gets or sets the path of the file holding the bootstrap administrator’s password. |
Alvo:Admin:Dashboard
Section titled “Alvo:Admin:Dashboard”Bound by the standalone host; an embedded host configures it in code. Options type: AlvoAdminOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Admin:Dashboard:Enabled | bool | true | Whether the dashboard is mapped at all. Defaults to true. |
Alvo:Admin:Dashboard:DocsPath | string? | — | Where this host serves its interactive API documentation, or null when it serves none. The standalone host overwrites this after binding: /scalar when Alvo:Docs:Enabled is true, otherwise none. Set it only in an embedded host. |
Alvo:Admin:Dashboard:OpenApiPath | string? | — | Where this host serves the OpenAPI document itself, or null when it serves none. The standalone host overwrites this after binding: /openapi/v1.json when Alvo:Docs:Enabled is true, otherwise none. Set it only in an embedded host. |
Alvo:Ai
Section titled “Alvo:Ai”Any host (bound by the core). Options type: AlvoAiOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Ai:Kind | string? | — | Gets or sets which protocol the endpoint speaks — openai-compatible or azure-openai. |
Alvo:Ai:Endpoint | string? | — | Gets or sets the base address to dial, e.g. http://localhost:11434/v1. |
Alvo:Ai:Model | string? | — | Gets or sets the model or deployment name to ask for. |
Alvo:Ai:ApiKeySecretRef | string? | — | Gets or sets the name of the secret holding the API key, resolved through the secret store. |
Alvo:Api
Section titled “Alvo:Api”Bound by the standalone host; an embedded host configures it in code. Options type: AlvoApiOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Api:RoutePrefix | string | /api | The route prefix every generated endpoint sits under. Default /api. |
Alvo:Api:DefaultPageSize | int | 50 | The page size used when a request names none. Default 50. |
Alvo:Api:MaxPageSize | int | 200 | The largest page a request may ask for. Default 200. Server-enforced rather than advisory: a maximum is required, because an unbounded limit is a denial-of-service one query long. |
Alvo:Api:MaxRequestBodyBytes | int | 1048576 | The largest request body a write endpoint will read. Default 1 MiB. |
Alvo:Api:MaxPayloadDepth | int | 32 | How deeply a request body may nest. Default 32. |
Alvo:Api:MaxPayloadKeys | int | 512 | How many property names a request body may carry in total, at any depth. Default 512. |
Alvo:Api:MaxBatchRows | int | 1000 | The most rows one batch request may carry. Default 1000. |
Alvo:Api:MaxIdempotencyKeyBytes | int | 255 | The longest Idempotency-Key a create will accept, in UTF-8 bytes. Defaults to MaxKeyBytes, and may only be lowered. |
Alvo:Auth
Section titled “Alvo:Auth”Bound by the standalone host; an embedded host configures it in code. Options type: AlvoAuthOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Auth:DevKeys:{n}:KeyId | string | "" | Gets or sets the key’s public identifier. |
Alvo:Auth:DevKeys:{n}:Secret | string | "" | Gets or sets the plaintext secret as configured; retained on the options instance for the process lifetime — a dev mechanism only, not a production issuance path. |
Alvo:Auth:DevKeys:{n}:User | Guid | 00000000-0000-0000-0000-000000000000 | Gets or sets the user this key authenticates as. |
Alvo:Auth:DevKeys:{n}:Roles:{n} | string | empty | Gets the names of the roles this key grants. |
Alvo:Auth:DevKeys:{n}:Tenant | Guid? | — | Gets or sets the tenant this key is scoped to, if any. |
Alvo:Auth:DevKeys:{n}:Scopes:{n} | string | empty | Gets the entity/access scopes this key grants, in the descriptor form "<entity|*>:<read|write>". |
Alvo:Auth:DevKeys:{n}:ExpiresAt | DateTimeOffset? | — | Gets or sets when this key expires, if ever. |
Alvo:Auth:HeaderName | string | X-Alvo-Api-Key | Gets the HTTP header a presented API key is read from, consumed by the HTTP Data API. |
Alvo:Auth:TenantHeaderName | string | X-Alvo-Tenant | Gets the HTTP header the tenant a caller asks to act in is read from, consumed by the HTTP Data API. |
Alvo:Events
Section titled “Alvo:Events”Any host (bound by the core). Options type: AlvoEventOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Events:Enabled | bool | true | Gets or sets whether this process drains the outbox. Defaults to true. |
Alvo:Events:PollInterval | TimeSpan | 00:00:01 | Gets or sets how long the pump waits after finding nothing to claim, before claiming again. Defaults to one second, and must be greater than zero. |
Alvo:Events:BatchSize | int | 100 | Gets or sets the most entries one claim takes. Defaults to 100, and must be at least 1. |
Alvo:Events:MaxAttempts | int | 10 | Gets or sets how many times one event may be claimed before it is left alone. Defaults to 10, and must be at least 1. |
Alvo:Events:ClaimLease | TimeSpan | 00:05:00 | Gets or sets how long a claim holds before another claimant may take the entry back. Defaults to five minutes, and must be longer than PollInterval. |
Alvo:Events:WebhookAllowedNetworks:{n} | string | empty | Gets the non-public networks, in CIDR notation, a webhook may be delivered to. Empty by default, which allows only globally reachable addresses — and loopback, when the endpoint names it literally. |
Alvo:Management
Section titled “Alvo:Management”Any host (bound by the core). Options type: AlvoManagementOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Management:RoutePrefix | string | /management | The route prefix every management endpoint sits under. Default /management. |
Alvo:Schema
Section titled “Alvo:Schema”Any host (bound by the core). Options type: AlvoSchemaOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Schema:Startup | one of: Verify, Apply, Skip | Apply | Gets or sets what a boot does when the descriptor has drifted from the applied schema. Defaults to Apply, which brings the database up to the descriptor and still refuses any step that would discard data. |
Alvo:Schema:Project | string? | — | Gets or sets the project a dashboard-first host boots — the project whose stored descriptor the boot reads when no IDescriptorSource is configured. null in code-first mode, where the descriptor names the project itself. |
Alvo:Schema:AllowDestructive | bool | false | Gets or sets whether a boot may apply a plan that drops or narrows something — the guardrail that separates Apply from data loss. Defaults to false, so a destructive plan is refused even under Apply. |
Alvo:Secrets
Section titled “Alvo:Secrets”Any host (bound by the core). Options type: AlvoSecretOptions.
| Key | Type | Default | Description |
|---|---|---|---|
Alvo:Secrets:EncryptionKeyFile | string? | — | Gets or sets the path to the file holding the key the database-backed store encrypts with — 32 bytes, base64. |
Alvo:Secrets:Values:{name} | string | empty | Gets or sets the secrets this deployment supplies through configuration itself, by name. |
Not bound from configuration
Section titled “Not bound from configuration”These public options types are not read from any configuration section:
AlvoOptions— Configured in code withConfigure<AlvoOptions>; no host binds it from configuration.MigrationOptions— A per-call argument to the schema migrator, not a configuration section; theAlvo:Schemakeys decide what start-up passes it.PostgreSqlProviderOptions— Set in code byUsePostgreSql(…); its connection string comes fromConnectionStrings:Alvo, listed below.SqliteProviderOptions— Set in code byUseSqlite(…); its connection string comes fromConnectionStrings:Alvo, listed below.
Keys read outside an options type
Section titled “Keys read outside an options type”These keys are read directly rather than through an options type.
| Key | Type | Default | Description |
|---|---|---|---|
ConnectionStrings:Alvo | string | — | The database connection string. The parameterless UseSqlite() and UsePostgreSql() read it; the standalone host reads it for either driver and, for SQLite only, falls back to Alvo:Database:SqliteConnectionString when it is unset. |
Alvo:Admin:CredentialAttemptsPerMinute | int | 20 | Standalone host: sign-in and set-password attempts per minute for one subject (an address, or a set-password token) from one client. Must be positive while the dashboard is on. |
Alvo:Admin:CredentialCeilingPerMinute | int | 200 | Standalone host: the ceiling per client per minute, shared by both credential forms, over the per-subject budget. Must be positive while the dashboard is on. |
Alvo:Admin:SessionRevalidationSeconds | int | 30 | A test seam, not a setting: how often an open dashboard tab’s session is re-checked. It can only shorten the interval; anything but a whole number from 1 to 30 is refused at start. |