Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

services.omw.enable

Whether to enable the omw agent runtime.

Type: boolean

Default:

false

Example:

true

services.omw.package

The omw package to run.

Type: package

Default:

<derivation omw>

services.omw.environment

Environment variables for the service (becomes systemd Environment=). OMW__-prefixed variables layer over the file configuration, e.g. OMW__PROVIDERS__OPENAI__API_KEY overrides providers.openai.api_key, which is the intended way to supply API keys and other secrets.

Type: attribute set of string

Default:

{ }

services.omw.environmentFile

Path to a systemd EnvironmentFile for the service.

Type: null or absolute path

Default:

null

services.omw.extraArgs

Extra arguments passed to the omw command line after the mode.

Type: list of string

Default:

[ ]

services.omw.group

The group the service runs as. When both services.omw.user and services.omw.group are null, a dynamic user is allocated.

Type: null or string

Default:

null

services.omw.hardening

Enable systemd hardening (NoNewPrivileges, ProtectSystem=strict, …). Safe for stdio MCP servers (including ones wrapping commands in bwrap) and node-based servers. Sets LimitMEMLOCK=infinity alongside the empty capability set (inside containers the outer RLIMIT_MEMLOCK still wins — set OMW__TUNABLES__ALLOW_UNLOCKED_SECRETS=true in the environment there instead). Deliberately omits MemoryDenyWriteExecute, which would break the wasmtime JIT and nodejs MCP servers. Set to false if the sandbox gets in the way; services.omw.serviceConfig can override individual keys either way.

Type: boolean

Default:

true

services.omw.mode

Which mode to run omw in: run executes every agent once, loop keeps running them, restarting agents that fail.

Type: one of “run”, “loop”

Default:

"loop"

services.omw.readOnlyPaths

Extra paths exposed read-only inside the sandbox (BindReadOnlyPaths=). Needed with hardening when brains or the config file live outside the state directory (e.g. /etc).

Type: list of string

Default:

[ ]

services.omw.readWritePaths

Extra paths exposed read-write inside the sandbox (ReadWritePaths=). Needed with hardening when a filesystem MCP tooling works outside the state directory.

Type: list of string

Default:

[ ]

services.omw.serviceConfig

Extra systemd serviceConfig merged last, so it wins over the module defaults (including the hardening set). Escape hatch for anything the module does not model explicitly.

Type: attribute set

Default:

{ }

services.omw.settings

The omw configuration provided as an attribute set, rendered to TOML at build time. Mutually exclusive with services.omw.settingsFile. Secrets are layered at runtime from OMW__-prefixed environment variables (see services.omw.environment), so API keys never have to live in the Nix store.

Type: null or TOML value

Default:

null

services.omw.settingsFile

Path to an omw configuration file (TOML). Mutually exclusive with services.omw.settings.

Type: null or absolute path

Default:

null

services.omw.stateDir

Name of the state directory created for the service (StateDirectory=). When set, the directory is created under /var/lib and the service can persist state there, e.g. the workspace of a filesystem MCP tooling.

Type: null or string

Default:

null

services.omw.user

The user the service runs as. When both services.omw.user and services.omw.group are null, a dynamic user is allocated.

Type: null or string

Default:

null

services.omw.variant

Which package variant to run: default (the crates.io-equivalent build, without the rhai runtime), rhai (adds the bundled rhai interpreter via the omw-rhai package) or js (adds the bundled js interpreter via the omw-js package). Overridable with package.

Type: one of “default”, “rhai”, “js”

Default:

"default"