Skip to content
Configuration reference

Configuration reference

Every key of den.yaml, generated from the config structs den itself reads, so it cannot drift from what den accepts. A key that is not listed here is a mistake: den reports it as a warning when it loads the file.

den reads -c FILE, then ./den.yaml, then ~/.config/den/den.yaml (the config directory follows XDG_CONFIG_HOME; Files and folders). The repository’s annotated den.yaml is a working example, den init --profile P writes one for your account, and the JSON Schema gives your editor completion and inline errors. Each feature’s page has the keys in context, with examples; this page is the complete list.

A key marked required must be set in the entry itself. The others are optional, and many can instead come from a named environment (environments).

Top-level keys

KeyTypeRequiredAllowed valuesDescription
versionstring
titlestring
awsobject, keys in aws
menu_orderlist of stringconnect, tunnel, runbooks, vpn, aws, secrets, create-env, config, logs, help, updates
disabled_paneslist of stringconnect, tunnel, runbooks, vpn, aws, secrets, create-env, config, logs, help, updates
environmentsmap of name → object, keys in environments.<name>
serviceslist of objects, keys in services[]
tunnelslist of objects, keys in tunnels[]
vpnlist of objects, keys in vpn[]
runbooksobject, keys in runbooks
secretsobject, keys in secrets
logsobject, keys in logs
updatesobject, keys in updates
mcpobject, keys in mcp
aiobject, keys in ai

aws

Guide: docs/aws

KeyTypeRequiredAllowed valuesDescription
config_pathstring
credentials_pathstring
sessionslist of objects, keys in aws.sessions[]

aws.sessions[]

Guide: docs/aws

KeyTypeRequiredAllowed valuesDescription
sessionstringyes
namestring
descriptionstring

environments.<name>

KeyTypeRequiredAllowed valuesDescription
regionstring
environmentstring
productionboolean
ec2_instance_idstring
aws_profilestring
credential_profilestring
aws_region_codestring
transportobject, keys in environments.<name>.transport

environments.<name>.transport

Guide: docs/transports

KeyTypeRequiredAllowed valuesDescription
typestringyesssm, ssh, eice, kubectl
hoststring
argslist of string
endpoint_idstring
resourcestring
contextstring
namespacestring

services[]

KeyTypeRequiredAllowed valuesDescription
namestringyes
typestringyesrds, redis, documentdb, redshift, opensearch, neptune, kafka, docker
envstring
rdsobject, keys in services[].rds
kafkaobject, keys in services[].kafka
redisobject, keys in services[].redis
documentdbobject, keys in services[].documentdb
redshiftobject, keys in services[].redshift
opensearchobject, keys in services[].opensearch
neptuneobject, keys in services[].neptune
dockerobject, keys in services[].docker

services[].rds

Guide: docs/rds

KeyTypeRequiredAllowed valuesDescription
regionstring
environmentstring
productionboolean
local_portinteger
reconnectboolean
ec2_instance_idstring
aws_profilestring
credential_profilestring
aws_region_codestring
transportobject, keys in environments.<name>.transport
enginestringpostgres, mysql
update_pgpassboolean
rds_hoststring
db_namestring
db_userstring

services[].kafka

KeyTypeRequiredAllowed valuesDescription
regionstring
environmentstring
productionboolean
local_portinteger
reconnectboolean
ec2_instance_idstring
aws_profilestring
credential_profilestring
aws_region_codestring
transportobject, keys in environments.<name>.transport
kafka_hoststring

services[].redis

Guide: docs/elasticache

KeyTypeRequiredAllowed valuesDescription
regionstring
environmentstring
productionboolean
local_portinteger
reconnectboolean
ec2_instance_idstring
aws_profilestring
credential_profilestring
aws_region_codestring
transportobject, keys in environments.<name>.transport
cache_namestring
user_idstring
serverlessboolean
memorydbboolean
redis_hoststring

services[].documentdb

Guide: docs/documentdb

KeyTypeRequiredAllowed valuesDescription
regionstring
environmentstring
productionboolean
local_portinteger
reconnectboolean
ec2_instance_idstring
aws_profilestring
credential_profilestring
aws_region_codestring
transportobject, keys in environments.<name>.transport
documentdb_hoststring
db_namestring
ca_filestring

services[].redshift

Guide: docs/redshift

KeyTypeRequiredAllowed valuesDescription
regionstring
environmentstring
productionboolean
local_portinteger
reconnectboolean
ec2_instance_idstring
aws_profilestring
credential_profilestring
aws_region_codestring
transportobject, keys in environments.<name>.transport
update_pgpassboolean
redshift_hoststring
cluster_identifierstring
workgroup_namestring
db_namestring
db_userstring
credential_ttlstring

services[].opensearch

Guide: docs/opensearch

KeyTypeRequiredAllowed valuesDescription
regionstring
environmentstring
productionboolean
local_portinteger
reconnectboolean
ec2_instance_idstring
aws_profilestring
credential_profilestring
aws_region_codestring
transportobject, keys in environments.<name>.transport
opensearch_hoststring
serverlessboolean

services[].neptune

Guide: docs/neptune

KeyTypeRequiredAllowed valuesDescription
regionstring
environmentstring
productionboolean
local_portinteger
reconnectboolean
ec2_instance_idstring
aws_profilestring
credential_profilestring
aws_region_codestring
transportobject, keys in environments.<name>.transport
neptune_hoststring
portinteger

services[].docker

Guide: docs/docker

KeyTypeRequiredAllowed valuesDescription
compose_filestringyes
serviceslist of string
env_filestring

tunnels[]

Guide: docs/tunnel

KeyTypeRequiredAllowed valuesDescription
namestringyes
descriptionstring
commandstringyes
reconnectboolean
health_checkstring
monitorboolean
auto_connectobject, keys in tunnels[].auto_connect

tunnels[].auto_connect

Guide: docs/tunnel

KeyTypeRequiredAllowed valuesDescription
vpnstringyes
enabledboolean

vpn[]

Guide: docs/vpn

KeyTypeRequiredAllowed valuesDescription
namestringyes
gatewaystring
descriptionstring
config_filestring
extra_argslist of string
health_checkstring
reconnectboolean

runbooks

Guide: docs/runbooks

KeyTypeRequiredAllowed valuesDescription
dirslist of string
rescanboolean
templatestring
agentstring
agentslist of objects, keys in runbooks.agents[]
defaultsobject, keys in runbooks.defaults
itemslist of objects, keys in runbooks.items[]
sequenceslist of objects, keys in runbooks.sequences[]
sourceslist of objects, keys in runbooks.sources[]
allow_sourceslist of string

runbooks.agents[]

Guide: docs/runbooks/agents/cli

KeyTypeRequiredAllowed valuesDescription
namestringyes
commandstringyes
kindstringclaude, codex

runbooks.defaults

Guide: docs/runbooks

KeyTypeRequiredAllowed valuesDescription
historyinteger
aboutboolean
shellstring
editorstring
agentstring

runbooks.items[]

Guide: docs/runbooks

KeyTypeRequiredAllowed valuesDescription
namestringyes
descriptionstring
commandstringyes
cwdstring
envstring
env_varsmap of string → string
paramslist of objects, keys in runbooks.items[].params[]
confirmboolean
timeoutstring
retryobject, keys in runbooks.items[].retry
historyinteger
aboutboolean
shellstring
editorstring
agentstring

runbooks.items[].params[]

KeyTypeRequiredAllowed valuesDescription
namestring
descriptionstring
defaultstring
optionslist of string
requiredboolean
secretboolean

runbooks.items[].retry

KeyTypeRequiredAllowed valuesDescription
until_successboolean
intervalstringyes
max_attemptsinteger
timeoutstring

runbooks.sequences[]

Guide: docs/runbooks

KeyTypeRequiredAllowed valuesDescription
namestringyes
descriptionstring
stepslist of stringyes
confirmboolean

runbooks.sources[]

Guide: docs/runbook-sources

KeyTypeRequiredAllowed valuesDescription
namestringyes
urlstringyes
refstring
pathstring
includelist of string
excludelist of string
env_mapmap of string → string

secrets

Guide: docs/secrets

KeyTypeRequiredAllowed valuesDescription
sopslist of objects, keys in secrets.sops[]
aws_secretsmanagerlist of objects, keys in secrets.aws_secretsmanager[]
keepassxclist of objects, keys in secrets.keepassxc[]
vaultlist of objects, keys in secrets.vault[]
viewstringtree, flat

secrets.sops[]

Guide: docs/secrets

KeyTypeRequiredAllowed valuesDescription
namestringyes
descriptionstring
filestringyes
aws_profilestring
aws_regionstring
auto_revealboolean
viewstringtree, flat

secrets.aws_secretsmanager[]

Guide: docs/secrets

KeyTypeRequiredAllowed valuesDescription
namestringyes
descriptionstring
secret_idstringyes
aws_profilestring
aws_regionstring
version_stagestring
auto_revealboolean
viewstringtree, flat

secrets.keepassxc[]

Guide: docs/secrets

KeyTypeRequiredAllowed valuesDescription
namestringyes
descriptionstring
databasestringyes
entrystring
groupstring
key_filestring
no_passwordboolean
attributeslist of string
totpboolean
remember_passwordstring
cli_pathstring
auto_revealboolean

secrets.vault[]

Guide: docs/secrets

KeyTypeRequiredAllowed valuesDescription
namestringyes
descriptionstring
addressstring
namespacestring
ca_certstring
mountstring
pathstringyes
fieldstring
versioninteger
loginstring
cli_pathstring
auto_revealboolean
viewstringtree, flat

logs

KeyTypeRequiredAllowed valuesDescription
levelstringtrace, debug, info, warn, error
file_locationstring

updates

Guide: docs/updates

KeyTypeRequiredAllowed valuesDescription
github_apistring
s3_bucketstring
s3_prefixstring
aws_profilestring
aws_regionstring

mcp

Guide: docs/mcp

KeyTypeRequiredAllowed valuesDescription
allowlist of string
allow_productionboolean
allow_runbooksboolean
allow_source_runbooksboolean

ai

KeyTypeRequiredAllowed valuesDescription
modelstring
Last updated on