[{"data":1,"prerenderedAt":1057},["ShallowReactive",2],{"navigation_docs":3,"-reference-configuration-environment-variables":270,"-reference-configuration-environment-variables-surround":1052},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":180,"body":272,"description":1045,"extension":1046,"links":1047,"meta":1048,"navigation":1049,"path":181,"seo":1050,"stem":182,"__hash__":1051},"docs\u002F4.reference\u002F2.configuration\u002F9.environment-variables.md",{"type":273,"value":274,"toc":1037},"minimark",[275,280,318,579,583,589,704,723,727,730,791,795,986],[276,277,279],"h2",{"id":278},"set-by-an-operator","Set by an operator",[281,282,283,284,288,289,292,293,296,297,300,301,296,304,296,307,296,310,313,314,317],"p",{},"Set these in the shell that starts ",[285,286,287],"code",{},"kraft",", or in the service unit.\n",[285,290,291],{},"kraft admin install-service"," copies ",[285,294,295],{},"KRAFT_HOME",", ",[285,298,299],{},"KRAFT_RUN_DIR",",\n",[285,302,303],{},"KRAFT_TEMPLATES_DIR",[285,305,306],{},"KRAFT_SKILLS_DIR",[285,308,309],{},"KRAFT_HOST",[285,311,312],{},"KRAFT_PORT"," and\n",[285,315,316],{},"PATH"," into the unit it writes.",[319,320,321,337],"table",{},[322,323,324],"thead",{},[325,326,327,331,334],"tr",{},[328,329,330],"th",{},"Variable",[328,332,333],{},"Default",[328,335,336],{},"What it does",[338,339,340,363,377,401,415,436,455,476,512,531,547,563],"tbody",{},[325,341,342,347,352],{},[343,344,345],"td",{},[285,346,295],{},[343,348,349],{},[285,350,351],{},"~\u002F.kraft",[343,353,354,355,358,359,362],{},"The directory Kraft keeps everything in. ",[285,356,357],{},"just dev"," points it at ",[285,360,361],{},".dev\u002F"," so a dev instance cannot touch the real one.",[325,364,365,369,374],{},[343,366,367],{},[285,368,299],{},[343,370,371],{},[285,372,373],{},"$KRAFT_HOME\u002Frun",[343,375,376],{},"Databases, logs, worktrees, the pidfile and the MCP token.",[325,378,379,383,388],{},[343,380,381],{},[285,382,303],{},[343,384,385],{},[285,386,387],{},"$KRAFT_HOME\u002Ftemplates",[343,389,390,391,296,394,296,397,400],{},"The config directory: ",[285,392,393],{},"policy.yaml",[285,395,396],{},"repos.yaml",[285,398,399],{},"access.yaml",", chains and the rest.",[325,402,403,407,412],{},[343,404,405],{},[285,406,306],{},[343,408,409],{},[285,410,411],{},"$KRAFT_HOME\u002Fskills",[343,413,414],{},"Where a skill file overrides the bundled one of the same name. Usually absent.",[325,416,417,421,429],{},[343,418,419],{},[285,420,309],{},[343,422,423,426,427],{},[285,424,425],{},"bind"," in ",[285,428,399],{},[343,430,431,432,435],{},"The address the server binds and the CLI connects to. ",[285,433,434],{},"kraft admin start --host"," overrides it.",[325,437,438,442,449],{},[343,439,440],{},[285,441,312],{},[343,443,444,426,447],{},[285,445,446],{},"port",[285,448,399],{},[343,450,451,452,435],{},"The port the server binds and the CLI connects to. ",[285,453,454],{},"kraft admin start --port",[325,456,457,462,465],{},[343,458,459],{},[285,460,461],{},"KRAFT_NO_UPDATE_CHECK",[343,463,464],{},"unset",[343,466,467,468,471,472,475],{},"Any value turns off the release check in ",[285,469,470],{},"kraft admin start"," and ",[285,473,474],{},"kraft admin doctor",".",[325,477,478,483,493],{},[343,479,480],{},[285,481,482],{},"KRAFT_EDITOR",[343,484,485,486,296,489,492],{},"the OS opener (",[285,487,488],{},"open",[285,490,491],{},"xdg-open",")",[343,494,495,496,499,500,296,502,296,505,508,509,475],{},"The editor ",[285,497,498],{},"kraft view doc --open"," and the board use when none is named: ",[285,501,285],{},[285,503,504],{},"cursor",[285,506,507],{},"zed"," or ",[285,510,511],{},"obsidian",[325,513,514,519,528],{},[343,515,516],{},[285,517,518],{},"KRAFT_EMBED_CACHE",[343,520,521,524,525],{},[285,522,523],{},"$XDG_CACHE_HOME\u002Fkraft\u002Ffastembed",", else ",[285,526,527],{},"~\u002F.cache\u002Fkraft\u002Ffastembed",[343,529,530],{},"Where semantic search keeps its model weights.",[325,532,533,538,540],{},[343,534,535],{},[285,536,537],{},"KRAFT_BD_CWD",[343,539,464],{},[343,541,542,543,546],{},"The directory ",[285,544,545],{},"bd"," runs in for bead operations and bead search, instead of each repo.",[325,548,549,554,557],{},[343,550,551],{},[285,552,553],{},"KRAFT_FRONTEND_DIST",[343,555,556],{},"the bundled web UI",[343,558,559,560,562],{},"The built web UI to serve. ",[285,561,357],{}," points it at Vite's output.",[325,564,565,570,572],{},[343,566,567],{},[285,568,569],{},"KRAFT_INDEX_REPOS",[343,571,464],{},[343,573,574,575,578],{},"More repo paths for the search index to scan, besides the connected ones, separated by ",[285,576,577],{},":",". Used by end-to-end tests.",[276,580,582],{"id":581},"passed-to-workers","Passed to workers",[281,584,585,586,588],{},"Kraft sets these in each agent session's environment. A worker's own ",[285,587,287],{},"\ncommand and MCP client read them.",[319,590,591,602],{},[322,592,593],{},[325,594,595,597,600],{},[328,596,330],{},[328,598,599],{},"Set to",[328,601,336],{},[338,603,604,621,634,652,666,688],{},[325,605,606,611,614],{},[343,607,608],{},[285,609,610],{},"KRAFT_WORK_ITEM_ID",[343,612,613],{},"The work item's id",[343,615,616,617,620],{},"Marks the session as a Kraft worker. The CLI and MCP server use it as the default work item, and refuse a worker's decisions about its own item (see ",[618,619,236],"a",{"href":237},"). Not set for an escalation turn, which runs as a person's session.",[325,622,623,628,631],{},[343,624,625],{},[285,626,627],{},"KRAFT_SESSION_ID",[343,629,630],{},"The session's id",[343,632,633],{},"Sent with each API call, so a route can tell the calling session apart.",[325,635,636,641,647],{},[343,637,638],{},[285,639,640],{},"KRAFT_RESULT_PATH",[343,642,643,644],{},"A file under ",[285,645,646],{},"run\u002F",[343,648,649,650,475],{},"Where the agent writes its result: status, concerns, a question, usage. Subprocess tasks get it too. See ",[618,651,198],{"href":199},[325,653,654,659,663],{},[343,655,656],{},[285,657,658],{},"KRAFT_REVIEW_PACKAGE",[343,660,643,661],{},[285,662,646],{},[343,664,665],{},"For a review task: the commit list, files changed and diff to review.",[325,667,668,673,678],{},[343,669,670],{},[285,671,672],{},"KRAFT_PERMISSION_FAIL_CLOSED",[343,674,675],{},[285,676,677],{},"1",[343,679,680,681,684,685,475],{},"Set when a hooked harness (Cursor, Codex) runs under an ",[285,682,683],{},"allowed_tools"," list. The hook then denies a call when it cannot reach Kraft. See ",[618,686,202],{"href":687},"\u002Freference\u002Fpermissions#cursor",[325,689,690,698,701],{},[343,691,692,296,695],{},[285,693,694],{},"KRAFT_DAEMON_PID",[285,696,697],{},"KRAFT_DAEMON_PORT",[343,699,700],{},"The server's pid and port",[343,702,703],{},"Lets a worker tell the Kraft server apart from a stray process before it kills anything on a port.",[281,705,706,707,296,709,296,711,300,713,296,715,471,717,719,720,722],{},"A worker also gets ",[285,708,295],{},[285,710,299],{},[285,712,303],{},[285,714,306],{},[285,716,309],{},[285,718,312],{}," when the server has them, so\nits ",[285,721,287],{}," command reaches the instance that started it.",[276,724,726],{"id":725},"set-by-kraft-for-itself","Set by Kraft for itself",[281,728,729],{},"You do not set these.",[319,731,732,740],{},[322,733,734],{},[325,735,736,738],{},[328,737,330],{},[328,739,336],{},[338,741,742,760,778],{},[325,743,744,749],{},[343,745,746],{},[285,747,748],{},"KRAFT_CLIENT",[343,750,751,752,755,756,759],{},"Set to ",[285,753,754],{},"mcp"," by ",[285,757,758],{},"kraft admin mcp",", so the API can tell an agent's call from a person's.",[325,761,762,767],{},[343,763,764],{},[285,765,766],{},"KRAFT_DETACHED",[343,768,769,770,773,774,777],{},"Set on the child of ",[285,771,772],{},"kraft admin start --detach",", so ",[285,775,776],{},"kraft admin restart"," starts it the same way.",[325,779,780,785],{},[343,781,782],{},[285,783,784],{},"KRAFT_LOG_REDIRECTED",[343,786,787,788,475],{},"Set on the same child, whose output already goes to ",[285,789,790],{},"run\u002Flogs\u002Fserver.log",[276,792,794],{"id":793},"other-variables","Other variables",[319,796,797,808],{},[322,798,799],{},[325,800,801,803,806],{},[328,802,330],{},[328,804,805],{},"Read by",[328,807,336],{},[338,809,810,841,857,881,899,912,927,941,958,973],{},[325,811,812,816,819],{},[343,813,814],{},[285,815,316],{},[343,817,818],{},"the server",[343,820,821,822,825,826,296,829,296,832,471,835,837,838,840],{},"Where Kraft finds ",[285,823,824],{},"claude",", the other agent CLIs, ",[285,827,828],{},"git",[285,830,831],{},"gh",[285,833,834],{},"glab",[285,836,545],{},". Under a service, this is the unit's ",[285,839,316],{},", not your shell's.",[325,842,843,851,854],{},[343,844,845,296,848],{},[285,846,847],{},"ANTHROPIC_API_KEY",[285,849,850],{},"CLAUDE_CODE_OAUTH_TOKEN",[343,852,853],{},"workers",[343,855,856],{},"Claude Code's credentials. Passed to every worker, sandboxed or not.",[325,858,859,871,873],{},[343,860,861,296,864,296,867,870],{},[285,862,863],{},"CODEX_API_KEY",[285,865,866],{},"GEMINI_API_KEY",[285,868,869],{},"CURSOR_API_KEY",", and other agents' keys",[343,872,853],{},[343,874,875,876,475],{},"Not passed by default. Name one in the repo's ",[618,877,878],{"href":147},[285,879,880],{},"env_passthrough",[325,882,883,888,893],{},[343,884,885],{},[285,886,887],{},"CODEX_HOME",[343,889,890],{},[285,891,892],{},"kraft admin permission-hook codex",[343,894,895,896,475],{},"Codex's config directory. Default ",[285,897,898],{},"~\u002F.codex",[325,900,901,906,909],{},[343,902,903],{},[285,904,905],{},"NO_COLOR",[343,907,908],{},"the CLI",[343,910,911],{},"Turns off colored output.",[325,913,914,919,921],{},[343,915,916],{},[285,917,918],{},"PAGER",[343,920,908],{},[343,922,923,924,475],{},"The pager for long output. Default ",[285,925,926],{},"less -R",[325,928,929,934,938],{},[343,930,931],{},[285,932,933],{},"SHELL",[343,935,936],{},[285,937,474],{},[343,939,940],{},"Which shell's completion line to suggest.",[325,942,943,948,952],{},[343,944,945],{},[285,946,947],{},"XDG_CONFIG_HOME",[343,949,950],{},[285,951,291],{},[343,953,954,955,475],{},"Where the systemd user unit goes. Default ",[285,956,957],{},"~\u002F.config",[325,959,960,965,968],{},[343,961,962],{},[285,963,964],{},"XDG_CACHE_HOME",[343,966,967],{},"semantic search",[343,969,970,971,475],{},"The base of the default ",[285,972,518],{},[325,974,975,980,983],{},[343,976,977],{},[285,978,979],{},"SSL_CERT_FILE",[343,981,982],{},"the sandbox",[343,984,985],{},"An extra CA bundle a sandboxed worker trusts, for a TLS-intercepting proxy.",[281,987,988,989,296,992,296,995,296,998,296,1000,296,1003,296,1006,296,1009,296,1012,300,1015,1018,1019,471,1022,1024,1025,1030,1031,508,1034,475],{},"A worker's environment is an allowlist. Besides the variables above, it gets\n",[285,990,991],{},"HOME",[285,993,994],{},"USER",[285,996,997],{},"LOGNAME",[285,999,933],{},[285,1001,1002],{},"LANG",[285,1004,1005],{},"LC_ALL",[285,1007,1008],{},"TERM",[285,1010,1011],{},"TZ",[285,1013,1014],{},"TMPDIR",[285,1016,1017],{},"SSH_AUTH_SOCK",", the proxy variables and the CA variables, then the repo's\n",[285,1020,1021],{},"env",[285,1023,880],{},". See the\n",[618,1026,1027,1029],{"href":147},[285,1028,1021],{}," field in repos.yaml",". Kraft does not read\n",[285,1032,1033],{},"EDITOR",[285,1035,1036],{},"VISUAL",{"title":1038,"searchDepth":1039,"depth":1039,"links":1040},"",2,[1041,1042,1043,1044],{"id":278,"depth":1039,"text":279},{"id":581,"depth":1039,"text":582},{"id":725,"depth":1039,"text":726},{"id":793,"depth":1039,"text":794},"Every KRAFT_* variable Kraft reads or sets, and the other variables it reads or passes to workers.","md",null,{},true,{"title":180,"description":1045},"DZ0Z8LU1kdNBBiNF_DKcu1v0-dsEnbvo6tBjRVh-2jk",[1053,1055],{"title":176,"path":177,"stem":178,"description":1054,"children":-1},"Every field in sandbox.yaml: which container CLI runs sandboxed tasks, how they get past SELinux, and which extra CA they trust.",{"title":10,"path":185,"stem":186,"description":1056,"children":-1},"Node keys, task kinds, read_only, extends, and canonical paths in chain files.",1790824543838]