Configuration reference
Every key of den.yaml, generated from the config structs den itself reads, so it
cannot drift from what den accepts. A key that is not listed here is a mistake: den
reports it as a warning when it loads the file.
den reads -c FILE, then ./den.yaml, then ~/.config/den/den.yaml (the config directory follows XDG_CONFIG_HOME; Files and folders). The repository’s
annotated den.yaml is a working example, den init --profile P writes
one for your account, and the JSON Schema gives your editor
completion and inline errors. Each feature’s page has the keys in context, with
examples; this page is the complete list.
A key marked required must be set in the entry itself. The others are optional, and many can instead come from a named environment (environments).
Top-level keys
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
version | string | |||
title | string | |||
aws | object, keys in aws | |||
menu_order | list of string | connect, tunnel, runbooks, vpn, aws, secrets, create-env, config, logs, help, updates | ||
disabled_panes | list of string | connect, tunnel, runbooks, vpn, aws, secrets, create-env, config, logs, help, updates | ||
environments | map of name → object, keys in environments.<name> | |||
services | list of objects, keys in services[] | |||
tunnels | list of objects, keys in tunnels[] | |||
vpn | list of objects, keys in vpn[] | |||
runbooks | object, keys in runbooks | |||
secrets | object, keys in secrets | |||
logs | object, keys in logs | |||
updates | object, keys in updates | |||
mcp | object, keys in mcp | |||
ai | object, keys in ai |
aws
Guide: docs/aws
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
config_path | string | |||
credentials_path | string | |||
sessions | list of objects, keys in aws.sessions[] |
aws.sessions[]
Guide: docs/aws
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
session | string | yes | ||
name | string | |||
description | string |
environments.<name>
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
region | string | |||
environment | string | |||
production | boolean | |||
ec2_instance_id | string | |||
aws_profile | string | |||
credential_profile | string | |||
aws_region_code | string | |||
transport | object, keys in environments.<name>.transport |
environments.<name>.transport
Guide: docs/transports
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
type | string | yes | ssm, ssh, eice, kubectl | |
host | string | |||
args | list of string | |||
endpoint_id | string | |||
resource | string | |||
context | string | |||
namespace | string |
services[]
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
type | string | yes | rds, redis, documentdb, redshift, opensearch, neptune, kafka, docker | |
env | string | |||
rds | object, keys in services[].rds | |||
kafka | object, keys in services[].kafka | |||
redis | object, keys in services[].redis | |||
documentdb | object, keys in services[].documentdb | |||
redshift | object, keys in services[].redshift | |||
opensearch | object, keys in services[].opensearch | |||
neptune | object, keys in services[].neptune | |||
docker | object, keys in services[].docker |
services[].rds
Guide: docs/rds
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
region | string | |||
environment | string | |||
production | boolean | |||
local_port | integer | |||
reconnect | boolean | |||
ec2_instance_id | string | |||
aws_profile | string | |||
credential_profile | string | |||
aws_region_code | string | |||
transport | object, keys in environments.<name>.transport | |||
engine | string | postgres, mysql | ||
update_pgpass | boolean | |||
rds_host | string | |||
db_name | string | |||
db_user | string |
services[].kafka
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
region | string | |||
environment | string | |||
production | boolean | |||
local_port | integer | |||
reconnect | boolean | |||
ec2_instance_id | string | |||
aws_profile | string | |||
credential_profile | string | |||
aws_region_code | string | |||
transport | object, keys in environments.<name>.transport | |||
kafka_host | string |
services[].redis
Guide: docs/elasticache
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
region | string | |||
environment | string | |||
production | boolean | |||
local_port | integer | |||
reconnect | boolean | |||
ec2_instance_id | string | |||
aws_profile | string | |||
credential_profile | string | |||
aws_region_code | string | |||
transport | object, keys in environments.<name>.transport | |||
cache_name | string | |||
user_id | string | |||
serverless | boolean | |||
memorydb | boolean | |||
redis_host | string |
services[].documentdb
Guide: docs/documentdb
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
region | string | |||
environment | string | |||
production | boolean | |||
local_port | integer | |||
reconnect | boolean | |||
ec2_instance_id | string | |||
aws_profile | string | |||
credential_profile | string | |||
aws_region_code | string | |||
transport | object, keys in environments.<name>.transport | |||
documentdb_host | string | |||
db_name | string | |||
ca_file | string |
services[].redshift
Guide: docs/redshift
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
region | string | |||
environment | string | |||
production | boolean | |||
local_port | integer | |||
reconnect | boolean | |||
ec2_instance_id | string | |||
aws_profile | string | |||
credential_profile | string | |||
aws_region_code | string | |||
transport | object, keys in environments.<name>.transport | |||
update_pgpass | boolean | |||
redshift_host | string | |||
cluster_identifier | string | |||
workgroup_name | string | |||
db_name | string | |||
db_user | string | |||
credential_ttl | string |
services[].opensearch
Guide: docs/opensearch
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
region | string | |||
environment | string | |||
production | boolean | |||
local_port | integer | |||
reconnect | boolean | |||
ec2_instance_id | string | |||
aws_profile | string | |||
credential_profile | string | |||
aws_region_code | string | |||
transport | object, keys in environments.<name>.transport | |||
opensearch_host | string | |||
serverless | boolean |
services[].neptune
Guide: docs/neptune
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
region | string | |||
environment | string | |||
production | boolean | |||
local_port | integer | |||
reconnect | boolean | |||
ec2_instance_id | string | |||
aws_profile | string | |||
credential_profile | string | |||
aws_region_code | string | |||
transport | object, keys in environments.<name>.transport | |||
neptune_host | string | |||
port | integer |
services[].docker
Guide: docs/docker
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
compose_file | string | yes | ||
services | list of string | |||
env_file | string |
tunnels[]
Guide: docs/tunnel
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
description | string | |||
command | string | yes | ||
reconnect | boolean | |||
health_check | string | |||
monitor | boolean | |||
auto_connect | object, keys in tunnels[].auto_connect |
tunnels[].auto_connect
Guide: docs/tunnel
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
vpn | string | yes | ||
enabled | boolean |
vpn[]
Guide: docs/vpn
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
gateway | string | |||
description | string | |||
config_file | string | |||
extra_args | list of string | |||
health_check | string | |||
reconnect | boolean |
runbooks
Guide: docs/runbooks
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
dirs | list of string | |||
rescan | boolean | |||
template | string | |||
agent | string | |||
agents | list of objects, keys in runbooks.agents[] | |||
defaults | object, keys in runbooks.defaults | |||
items | list of objects, keys in runbooks.items[] | |||
sequences | list of objects, keys in runbooks.sequences[] | |||
sources | list of objects, keys in runbooks.sources[] | |||
allow_sources | list of string |
runbooks.agents[]
Guide: docs/runbooks/agents/cli
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
command | string | yes | ||
kind | string | claude, codex |
runbooks.defaults
Guide: docs/runbooks
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
history | integer | |||
about | boolean | |||
shell | string | |||
editor | string | |||
agent | string |
runbooks.items[]
Guide: docs/runbooks
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
description | string | |||
command | string | yes | ||
cwd | string | |||
env | string | |||
env_vars | map of string → string | |||
params | list of objects, keys in runbooks.items[].params[] | |||
confirm | boolean | |||
timeout | string | |||
retry | object, keys in runbooks.items[].retry | |||
history | integer | |||
about | boolean | |||
shell | string | |||
editor | string | |||
agent | string |
runbooks.items[].params[]
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | |||
description | string | |||
default | string | |||
options | list of string | |||
required | boolean | |||
secret | boolean |
runbooks.items[].retry
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
until_success | boolean | |||
interval | string | yes | ||
max_attempts | integer | |||
timeout | string |
runbooks.sequences[]
Guide: docs/runbooks
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
description | string | |||
steps | list of string | yes | ||
confirm | boolean |
runbooks.sources[]
Guide: docs/runbook-sources
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
url | string | yes | ||
ref | string | |||
path | string | |||
include | list of string | |||
exclude | list of string | |||
env_map | map of string → string |
secrets
Guide: docs/secrets
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
sops | list of objects, keys in secrets.sops[] | |||
aws_secretsmanager | list of objects, keys in secrets.aws_secretsmanager[] | |||
keepassxc | list of objects, keys in secrets.keepassxc[] | |||
vault | list of objects, keys in secrets.vault[] | |||
view | string | tree, flat |
secrets.sops[]
Guide: docs/secrets
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
description | string | |||
file | string | yes | ||
aws_profile | string | |||
aws_region | string | |||
auto_reveal | boolean | |||
view | string | tree, flat |
secrets.aws_secretsmanager[]
Guide: docs/secrets
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
description | string | |||
secret_id | string | yes | ||
aws_profile | string | |||
aws_region | string | |||
version_stage | string | |||
auto_reveal | boolean | |||
view | string | tree, flat |
secrets.keepassxc[]
Guide: docs/secrets
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
description | string | |||
database | string | yes | ||
entry | string | |||
group | string | |||
key_file | string | |||
no_password | boolean | |||
attributes | list of string | |||
totp | boolean | |||
remember_password | string | |||
cli_path | string | |||
auto_reveal | boolean |
secrets.vault[]
Guide: docs/secrets
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
name | string | yes | ||
description | string | |||
address | string | |||
namespace | string | |||
ca_cert | string | |||
mount | string | |||
path | string | yes | ||
field | string | |||
version | integer | |||
login | string | |||
cli_path | string | |||
auto_reveal | boolean | |||
view | string | tree, flat |
logs
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
level | string | trace, debug, info, warn, error | ||
file_location | string |
updates
Guide: docs/updates
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
github_api | string | |||
s3_bucket | string | |||
s3_prefix | string | |||
aws_profile | string | |||
aws_region | string |
mcp
Guide: docs/mcp
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
allow | list of string | |||
allow_production | boolean | |||
allow_runbooks | boolean | |||
allow_source_runbooks | boolean |
ai
| Key | Type | Required | Allowed values | Description |
|---|---|---|---|---|
model | string |