Skip to main content

Directory layout

Access-key hashes are stored in the system keyring, not in config files. Set STEERHOLM_CONFIG_DIR to override the config directory (both the CLI and the daemon read it) — useful for isolated setups or testing:

File permissions

The config directory and files are created owner-only — 0700 on ~/.steerholm and its policies/ directory, and 0600 on config.json and each policy file — so --env secrets, agent policies, and grants aren’t readable by other users on the machine. Steerholm re-applies these permissions on startup, so an existing install is tightened automatically after an upgrade. On Windows, per-user AppData already provides this isolation via ACLs.

config.json

Server fields

Set env from the CLI: holm add server <name> --command "..." --env KEY=VALUE (repeatable). It’s stored here in config.json, and holm show server masks the values so secrets don’t print back.Variable names must be letters, digits, _, -, or ., and can’t start with a digit — the same rule Kubernetes and Docker use, so a config stays portable across Linux, macOS, and Windows. Values are unrestricted (they may contain =, spaces, or anything else); only the name is validated, and repeating a name is an error.

Agent fields

Defaults