axm-config
Non-sensitive runtime config under ~/.axm (env>file>default)
Overview
Non-sensitive runtime config under ~/.axm (env>file>default)
Features
- 🏠
~/.axmhome —axm_home()resolves and creates the per-user config directory0700(idempotent, tightens looser perms) - 🧪 Isolated profiles —
AXM_PROFILE=devroutes reads, writes, deletes, model loading, legacy files, and enumeration to~/.axm/profiles/dev/config.toml. A missing profile store falls through to defaults, never production; the directory is created on first write - 🧭 Layered resolution —
get/set_/deleteresolve a(namespace, key)withenv > file > defaultprecedence; the env name is derived deterministically asAXM_<NS>_<KEY>(upper-cased, each namespace dot → a double underscore). The mapping is provably injective and POSIX-valid - ⚙️ Typed execution policies — per-ticket-type backend/model and analysis
overrides use the same atomic store. For
dev.work, the environment keys are exactlyAXM_EXECUTION__DEV__WORK_BACKEND,AXM_EXECUTION__DEV__WORK_MODEL, andAXM_EXECUTION__DEV__WORK_ANALYSIS_ENABLED - 🗄️ Single-file store per profile — production uses the atomic
~/.axm/config.toml(0600); named profiles use~/.axm/profiles/<name>/config.toml. Each has a[namespace]table per namespace; a read-modify-write preserves every other section, an absent/corrupt file degrades to{}, and profile-local legacy files are folded in on the next write - 🛡️ Path-traversal safe —
namespace/keyare validated at every public boundary (lowercase-only patterns; traversal/empty/NUL raiseConfigError), and aHOMEresolving inside a git checkout is refused asUnsafeHomeError - 🧬 Model binding —
load(namespace, model)populates a pydantic model, resolving each field by name; a missing required field raisesConfigError - 🩺 Provenance doctor — the
config_doctorAXMTool reports which layer (env/file/default) wins per visible key, read-only; over MCP, theaxmCLI, andaxm-config doctor - 🖥️
axm-configCLI —get/set/delete/path/doctorwrap the same central resolution layer for shell use
Installation
uv add axm-config
Or as a workspace dependency in pyproject.toml:
[project]
dependencies = ["axm-config"]
[tool.uv.sources]
axm-config = { workspace = true }
Development
This package is part of the axm-forge workspace.
git clone https://github.com/axm-protocols/axm-forge.git
cd axm-forge
uv sync --all-groups
uv run --package axm-config --directory packages/axm-config pytest -x -q
License
Apache-2.0 — © 2026 Gabriel Jarry
Metadata
Release files for axm-config 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| axm_config-0.1.0.tar.gz | 60.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| axm_config-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 94.4 kB
Release files / axm_config-0.1.0.tar.gz
| Download URL | axm_config-0.1.0.tar.gz |
|---|---|
| Size | 60.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
903389395c7f4147d1883bd7e5d7d950f5db20bb7d762c99cb57e2dae8b4a9ba
|
|
BLAKE2b-256 checksum How to use checksums |
9eac433260d4d45a3826b568a684cafa00ff47b291a9f16c6cdccf42dee5ac37
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.
Transparency logRelease files / axm_config-0.1.0-py3-none-any.whl
| Download URL | axm_config-0.1.0-py3-none-any.whl |
|---|---|
| Size | 33.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
47c1d90c885a183902c66a12429a9fd01b9119ee012bf54a299ba0f1e032d349
|
|
BLAKE2b-256 checksum How to use checksums |
5ebe5488f95803e85a1069422d5555f78ad1f0a65acc966477031f15770bc6a8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.
Transparency log