mirror of
https://github.com/turnstonelabs/turnstone.git
synced 2026-08-12 23:12:23 -06:00
eb2a119da9
Deletes the _periodic_refresh task and its supporting state
(_refresh_task, _refresh_failures, _refresh_backoff_until,
_REFRESH_BACKOFF_BASE/MAX, _DEFAULT_REFRESH_INTERVAL, refresh_interval
kwarg) from MCPClientManager. Push notifications and operator-driven
manual refresh now cover all catalog-update needs; the long-running
4-hour timer was dead complexity that obscured the per-user pool
work to come.
Catalog freshness on auto-reconnect is preserved by scheduling an
unblocking _refresh_server task on the mcp-loop after _connect_one
succeeds; the calling thread returns immediately so half-open
recovery latency does not double. Adds MCPClientManager.reconnect_sync
(clears the circuit, closes any existing session, calls _connect_one,
clears stale catalog on failure).
Wires a new pair of operator endpoints —
POST /v1/api/admin/mcp-servers/{name}/refresh and
/v1/api/admin/mcp-servers/{name}/reconnect — that fan out to all
nodes through the existing _internal route family, with per-row
"Refresh" and "Reconnect" buttons in the MCP Servers admin tab.
The new node-internal paths /api/_internal/mcp-{refresh,reconnect}/
are gated to the approve scope to prevent direct unprivileged
reconnects bypassing the console's admin.mcp gate. Internal
endpoints return generic error messages and a filtered status
payload (no command/url) to keep transport details admin-gated.
Drops the [mcp] refresh_interval setting, the
--mcp-refresh-interval CLI flag, and the matching config-mapping
entry; updates docs/architecture.md, docs/tools.md,
docs/settings.md, and the three PlantUML diagrams that referenced
the periodic loop.
Tradeoffs (intentional):
- Idle nodes will not auto-rejoin a recovered MCP server until
traffic arrives or an operator clicks Reconnect. The previous
background reconnection loop is gone by design — push
notifications + operator controls replace it.
- Console fan-out blocks on the slowest node (existing pattern);
not changed here.
This is Phase 1 of the OAuth-MCP series — feature subtraction
ahead of per-user state.
126 lines
4.8 KiB
TOML
126 lines
4.8 KiB
TOML
# turnstone.toml — shared bootstrap configuration
|
|
#
|
|
# This file is read once at startup. Values here are overridden by
|
|
# environment variables, which are in turn overridden by CLI flags.
|
|
#
|
|
# All sections are optional. Missing sections use binary defaults.
|
|
# Config file location precedence:
|
|
# 1. --config flag
|
|
# 2. $TURNSTONE_CONFIG env var
|
|
# 3. ~/.config/turnstone/config.toml
|
|
|
|
# --- LLM API (turnstone, node, eval) ---
|
|
|
|
[api]
|
|
# base_url = "" # API endpoint; empty = binary default
|
|
# api_key = "" # env: OPENAI_API_KEY or ANTHROPIC_API_KEY
|
|
|
|
# --- Default Model (turnstone, node, eval) ---
|
|
|
|
[model]
|
|
# name = "" # Model ID; empty = provider default (gpt-5 / claude-sonnet-4)
|
|
# temperature = 0.0 # 0 = provider default
|
|
# reasoning_effort = "" # "none", "minimal", "low", "medium", "high", "xhigh", "max"
|
|
# context_window = 0 # 0 = auto-detect from provider capabilities
|
|
# max_tokens = 0 # 0 = provider default
|
|
#
|
|
# Sub-agent routing (plan_agent, task_agent tools). Each falls back to
|
|
# agent_model when unset, then to the session model. Use this to point
|
|
# the rare-but-expensive plan agent at a stronger model than the
|
|
# frequent task agent.
|
|
# agent_model = "" # legacy single-knob: both plan and task share this
|
|
# plan_model = "" # plan_agent override (e.g. "claude" for a smart planner)
|
|
# task_model = "" # task_agent override (e.g. "local" for cheap subtasks)
|
|
# plan_effort = "" # reasoning effort for plan_agent (default: "high")
|
|
# task_effort = "" # reasoning effort for task_agent (default: inherit session)
|
|
#
|
|
# At call time, the calling LLM may also pass `model="<alias>"` to
|
|
# plan_agent / task_agent to override these per-invocation. Tool
|
|
# descriptions list available aliases dynamically; bad aliases return
|
|
# an error so the model retries with a valid choice.
|
|
|
|
# --- Named Models (turnstone, node, eval) ---
|
|
# Define model aliases with per-model overrides. Useful for local model
|
|
# servers or mixing providers. Reference by name with --model flag.
|
|
#
|
|
# [models.local]
|
|
# name = "llama-3-70b"
|
|
# provider = "openai"
|
|
# base_url = "http://localhost:8000/v1"
|
|
# context_window = 8192
|
|
#
|
|
# [models.local.capabilities]
|
|
# supports_vision = false
|
|
# supports_web_search = false
|
|
#
|
|
# [models.claude]
|
|
# name = "claude-opus-4-7"
|
|
# provider = "anthropic"
|
|
|
|
# --- Database (turnstone, node, console) ---
|
|
|
|
[database]
|
|
# url = "" # postgres://user:pass@host/db or /path/to.db
|
|
# env: TURNSTONE_DB_URL
|
|
# SSL params (passed through to SQLAlchemy connection):
|
|
# sslmode = "prefer" # disable, allow, prefer, require, verify-ca, verify-full
|
|
# sslrootcert = "" # path to CA cert for verify-ca/verify-full
|
|
# sslcert = "" # path to client cert (mTLS)
|
|
# sslkey = "" # path to client key (mTLS)
|
|
|
|
# --- Auth (node, console) ---
|
|
|
|
[auth]
|
|
# Auth is always enabled. JWT secret is required.
|
|
# jwt_secret = "" # HS256 signing secret (min 32 bytes recommended)
|
|
# env: TURNSTONE_JWT_SECRET
|
|
|
|
# --- Logging (turnstone, node, console) ---
|
|
|
|
[log]
|
|
# level = "" # "debug", "info", "warn", "error"
|
|
# empty = binary default (warn for CLI, info for servers)
|
|
# env: TURNSTONE_LOG_LEVEL
|
|
# json = false # JSON output; auto-enabled when stderr is not a TTY
|
|
|
|
# --- Session (turnstone, node) ---
|
|
|
|
[session]
|
|
# instructions = "" # Default system message
|
|
# compact_max_tokens = 32768 # Max tokens for context compaction summary
|
|
# auto_compact_pct = 0.8 # Trigger compaction at this % of context window
|
|
|
|
# --- Tools (turnstone, node) ---
|
|
|
|
[tools]
|
|
# timeout = 120 # Tool execution timeout in seconds
|
|
# skip_permissions = false # Auto-approve all tool calls
|
|
|
|
# --- Judge (turnstone, node) ---
|
|
|
|
[judge]
|
|
# enabled = true # Enable intent validation
|
|
# confidence_threshold = 0.7 # Minimum confidence for heuristic verdicts
|
|
# output_guard = true # Scan tool output for security signals
|
|
# redact_secrets = true # Redact detected credentials in output
|
|
|
|
# --- Memory (turnstone, node) ---
|
|
|
|
[memory]
|
|
# relevance_k = 5 # Top-K memories for context injection
|
|
# fetch_limit = 50 # Max memories to fetch for ranking
|
|
# max_content = 32768 # Max memory content size in chars
|
|
# nudge_cooldown = 300 # Min seconds between metacognitive nudges
|
|
# nudges = true # Enable memory nudges
|
|
|
|
# --- MCP (turnstone, node) ---
|
|
|
|
[mcp]
|
|
# config_path = "" # Path to MCP servers config file (JSON)
|
|
|
|
# --- Server (node, console) ---
|
|
|
|
[server]
|
|
# max_workstreams = 50 # Maximum concurrent workstreams per node
|
|
# env: TURNSTONE_MAX_WORKSTREAMS
|