Skip to main content

Settings

Settings is a destination in the WebUI rail. Every panel in it writes the same ~/.nanoinfra/config.json you could edit by hand. This page is the bridge between the two: you are looking at a screen, and you want to know which config key it sets.

For normal local use, prefer the panel. Edit the file directly when you need a field no panel exposes, when you automate a deployment, or when you keep configuration as code.

The panels​

PanelWhat it setsReference
OverviewNothing. It reports the state of the rest — which model answers, what is configured, what is missing—
AppearanceThe theme. A local browser preference, not config.json—
ModelsThe active model and preset, the providers and their credentialsProvider and Model Configuration
Imagetools.imageGeneration — provider, model, aspect ratio, size, maxImagesPerTurn, saveDirImage Generation
Voicetranscription — provider, model, language, duration and upload capsConfiguration
Webtools.web — whether search and fetch are on, the search provider, timeouts, the proxy, the user agentAgent and Tool Configuration
Channelschannels.* — one block per chat platform, with guided setup for the ones that have it, and the agent that answers eachChannels
Tool groupsagents.defaults.toolGroups — which groups of tools the agent may useBuilt-in tool groups
KnowledgeThe knowledge base — which sources the agent may search, and how it cites themKnowledge
Promptsagents.defaults.addendum and agents.defaults.promptSections — what is appended to the prompt, and which sections are replaced outrightAgent and Tool Configuration
SystemThe gateway, the API server, timezone, heartbeat, subagent concurrency, auto-compactionConfiguration
SecurityWorkspace restriction, the exec sandbox, the capability gates and pairingSecurity Configuration

Four more surfaces are destinations of their own rather than Settings panels, because they are things you do rather than values you set. Those four are Apps for CLI Apps and MCP servers, Skills, Automations, and Metrics.

Which changes need a restart​

This is the part a panel cannot show you until after you have saved, and the reason a change sometimes appears to do nothing. The behaviour is per panel:

PanelOn save
Appearance, Models, ProvidersApplies live. No restart
Web, Image, System, AppsGateway restart. The WebUI says so, and the running agent picks the change up afterwards
SecurityFull restart. The supervisor starts each confined helper process with its policy, so a new policy needs new processes

Security is the strictest for a reason rather than out of caution. The executor, the fetcher, the MCP host and the connector host each start under a Landlock ruleset built from config. The kernel applies a ruleset to a process before it runs, so it cannot be widened or narrowed underneath one. See Per-Process Confinement.

What a panel will not do​

  • It will not write a credential the agent could read back. Secrets go to the encrypted store. A panel shows a masked hint rather than the value. See Secrets and Servers.
  • It will not widen the capability gate for one turn. A gate decision is a policy question, answered in config and reviewed in git. The runtime answer to a single action is an approval, not a setting. See Capability Gates.
  • It will not expose every field. The schema has 278 of them and most are not decisions a person makes twice. Configuration is the complete reference, in four pages.
  • Configuration — how config is loaded, where a setting lives, environment variables for secrets
  • WebUI — the rest of the browser workbench
  • Metrics — the numbers, which are a destination and not a setting