Runtime
Use this page to reference durable stores, brokers, tracing, work directories, and sandboxes.
The Runtime manifest
One Runtime per configuration folder names the store plugin and the broker plugin, with the
environment variables that hold their connection strings. A Runtime may instead set only
workDir, sandbox or tracer — a local run needs no store:
apiVersion: afe.dev/v1alpha1
kind: Runtime
metadata:
name: prod
spec:
store:
type: postgres
dsnEnv: AFE_POSTGRES_DSN
broker:
type: redis
urlEnv: AFE_REDIS_URL
type names a plugin's stores or brokers port; dsnEnv/urlEnv name the environment
variables, never their values. The connection strings are read at startup and never appear in an
error, a log or an event. An unknown store or broker, an empty variable or a connection failure
stops the process before any ticket runs. A broker without a store is a validation error: the
queue and the lock need a durable store to point at.
export AFE_POSTGRES_DSN="postgresql://afe:afe@127.0.0.1:5434/afe"
export AFE_REDIS_URL="redis://127.0.0.1:6381/0"
afe serve -c ./config
afe worker -c ./config
Without a Runtime the engine uses the in-memory adapters, exactly as in V4, and afe run --local still runs a ticket in its own process.
Fields
RuntimeSpec (spec)
| Field | Type | Default | Meaning |
|---|---|---|---|
store | StoreRef or null | null | The store plugin and its DSN variable; absent means no durable data. |
broker | BrokerRef or null | null | The broker plugin and its URL variable; a broker needs a durable store. |
tracer | TracerRef or null | null | Where runs are reported; absent means nothing is traced. |
workDir | str | ~/.afe-work | Where clones and worktrees live; ~ is expanded. |
sandbox | SandboxRef | SandboxRef() | The sandbox plugin a flow that runs commands opens. |
StoreRef (spec.store)
| Field | Type | Default | Meaning |
|---|---|---|---|
type | str | required | The store plugin type, e.g. postgres. |
dsnEnv | str | required | The environment variable holding the connection string. |
BrokerRef (spec.broker)
| Field | Type | Default | Meaning |
|---|---|---|---|
type | str | required | The broker plugin type, e.g. redis. |
urlEnv | str | required | The environment variable holding the broker URL. |
TracerRef (spec.tracer)
| Field | Type | Default | Meaning |
|---|---|---|---|
type | langfuse or otlp | required | The tracer plugin type. |
hostEnv | str or null | null | langfuse: the variable holding the host. |
publicKeyEnv | str or null | null | langfuse: the variable holding the public key. |
secretKeyEnv | str or null | null | langfuse: the variable holding the secret key. |
endpointEnv | str or null | null | otlp: the variable holding the collector endpoint. |
headersEnv | str or null | null | otlp: the variable holding the exporter headers. |
SandboxRef (spec.sandbox)
| Field | Type | Default | Meaning |
|---|---|---|---|
type | str | docker | The sandbox plugin type. |
namespace | str | afe-sandbox | Kubernetes: the namespace the ticket Pods and PVCs live in. |
storageClass | str or null | null | Kubernetes: the PVC's storageClassName; unset means the cluster default. |
storage | str | 2Gi | Kubernetes: the PVC's requested size, e.g. 5Gi; independent of the memory limit. |
runtimeClassName | str or null | null | Kubernetes: the Pod's runtimeClassName, e.g. kata; unset means runc. gVisor is refused (netlock needs netfilter). |
envSecret | str or null | null | Kubernetes: the Secret an env name resolves from, by key; required when a project declares sandbox.env. |
On Kubernetes a project's sandbox.env names resolve from envSecret (a secretKeyRef per name,
never a value in the Pod spec), so a project with env names and no envSecret is refused. The
other fields are set by the operator in V7c; a git project always takes the Kubernetes sandbox.
See also
- Project for project workspace and sandbox fields.
- Operations for health and metrics endpoints.