services.omw.enable
Whether to enable the omw agent runtime.
Type: boolean
Default:
false
Example:
true
services.omw.package
The omw package to run.
Type: package
Default:
<derivation omw>
services.omw.environment
Environment variables for the service (becomes systemd Environment=).
OMW__-prefixed variables layer over the file configuration, e.g.
OMW__PROVIDERS__OPENAI__API_KEY overrides providers.openai.api_key, which is
the intended way to supply API keys and other secrets.
Type: attribute set of string
Default:
{ }
services.omw.environmentFile
Path to a systemd EnvironmentFile for the service.
Type: null or absolute path
Default:
null
services.omw.extraArgs
Extra arguments passed to the omw command line after the mode.
Type: list of string
Default:
[ ]
services.omw.group
The group the service runs as. When both services.omw.user and
services.omw.group are null, a dynamic user is allocated.
Type: null or string
Default:
null
services.omw.hardening
Enable systemd hardening (NoNewPrivileges, ProtectSystem=strict, …). Safe
for stdio MCP servers (including ones wrapping commands in bwrap) and
node-based servers. Sets LimitMEMLOCK=infinity alongside the empty capability
set (inside containers the outer RLIMIT_MEMLOCK still wins — set
OMW__TUNABLES__ALLOW_UNLOCKED_SECRETS=true in the environment there instead).
Deliberately omits MemoryDenyWriteExecute, which would break the wasmtime JIT
and nodejs MCP servers. Set to false if the sandbox gets in the way;
services.omw.serviceConfig can override individual keys either way.
Type: boolean
Default:
true
services.omw.mode
Which mode to run omw in: run executes every agent once, loop keeps running
them, restarting agents that fail.
Type: one of “run”, “loop”
Default:
"loop"
services.omw.readOnlyPaths
Extra paths exposed read-only inside the sandbox (BindReadOnlyPaths=). Needed
with hardening when brains or the config file live outside the state directory
(e.g. /etc).
Type: list of string
Default:
[ ]
services.omw.readWritePaths
Extra paths exposed read-write inside the sandbox (ReadWritePaths=). Needed
with hardening when a filesystem MCP tooling works outside the state directory.
Type: list of string
Default:
[ ]
services.omw.serviceConfig
Extra systemd serviceConfig merged last, so it wins over the module defaults
(including the hardening set). Escape hatch for anything the module does not
model explicitly.
Type: attribute set
Default:
{ }
services.omw.settings
The omw configuration provided as an attribute set, rendered to TOML at build
time. Mutually exclusive with services.omw.settingsFile. Secrets are layered
at runtime from OMW__-prefixed environment variables (see
services.omw.environment), so API keys never have to live in the Nix store.
Type: null or TOML value
Default:
null
services.omw.settingsFile
Path to an omw configuration file (TOML). Mutually exclusive with
services.omw.settings.
Type: null or absolute path
Default:
null
services.omw.stateDir
Name of the state directory created for the service (StateDirectory=). When
set, the directory is created under /var/lib and the service can persist state
there, e.g. the workspace of a filesystem MCP tooling.
Type: null or string
Default:
null
services.omw.user
The user the service runs as. When both services.omw.user and
services.omw.group are null, a dynamic user is allocated.
Type: null or string
Default:
null
services.omw.variant
Which package variant to run: default (the crates.io-equivalent build,
without the rhai runtime), rhai (adds the bundled rhai interpreter via the
omw-rhai package) or js (adds the bundled js interpreter via the omw-js
package). Overridable with package.
Type: one of “default”, “rhai”, “js”
Default:
"default"