Settings
Settings is a destination in the WebUI rail. Every panel in it writes the
same ~/.nanoinfra/config.json you could edit by hand. This page is the bridge
between the two: you are looking at a screen, and you want to know which config
key it sets.
For normal local use, prefer the panel. Edit the file directly when you need a field no panel exposes, when you automate a deployment, or when you keep configuration as code.
The panels
| Panel | What it sets | Reference |
|---|---|---|
| Overview | Nothing. It reports the state of the rest — which model answers, what is configured, what is missing | — |
| Appearance | The theme. A local browser preference, not config.json | — |
| Models | The active model and preset, the providers and their credentials | Provider and Model Configuration |
| Image | tools.imageGeneration — provider, model, aspect ratio, size, maxImagesPerTurn, saveDir | Image Generation |
| Voice | transcription — provider, model, language, duration and upload caps | Configuration |
| Web | tools.web — whether search and fetch are on, the search provider, timeouts, the proxy, the user agent | Agent and Tool Configuration |
| Channels | channels.* — one block per chat platform, with guided setup for the ones that have it, and the agent that answers each | Channels |
| Tool groups | agents.defaults.toolGroups — which groups of tools the agent may use | Built-in tool groups |
| Knowledge | The knowledge base — which sources the agent may search, and how it cites them | Knowledge |
| Prompts | agents.defaults.addendum and agents.defaults.promptSections — what is appended to the prompt, and which sections are replaced outright | Agent and Tool Configuration |
| System | The gateway, the API server, timezone, heartbeat, subagent concurrency, auto-compaction | Configuration |
| Security | Workspace restriction, the exec sandbox, the capability gates and pairing | Security Configuration |
Four more surfaces are destinations of their own rather than Settings panels, because they are things you do rather than values you set. Those four are Apps for CLI Apps and MCP servers, Skills, Automations, and Metrics.
Which changes need a restart
This is the part a panel cannot show you until after you have saved, and the reason a change sometimes appears to do nothing. The behaviour is per panel:
| Panel | On save |
|---|---|
| Appearance, Models, Providers | Applies live. No restart |
| Web, Image, System, Apps | Gateway restart. The WebUI says so, and the running agent picks the change up afterwards |
| Security | Full restart. The supervisor starts each confined helper process with its policy, so a new policy needs new processes |
Security is the strictest for a reason rather than out of caution. The executor, the fetcher, the MCP host and the connector host each start under a Landlock ruleset built from config. The kernel applies a ruleset to a process before it runs, so it cannot be widened or narrowed underneath one. See Per-Process Confinement.
What a panel will not do
- It will not write a credential the agent could read back. Secrets go to the encrypted store. A panel shows a masked hint rather than the value. See Secrets and Servers.
- It will not widen the capability gate for one turn. A gate decision is a policy question, answered in config and reviewed in git. The runtime answer to a single action is an approval, not a setting. See Capability Gates.
- It will not expose every field. The schema has 278 of them and most are not decisions a person makes twice. Configuration is the complete reference, in four pages.
Related
- Configuration — how config is loaded, where a setting lives, environment variables for secrets
- WebUI — the rest of the browser workbench
- Metrics — the numbers, which are a destination and not a setting