Configuration requirements¶
As a SaaS tenant, most configuration is done in the console — identity, roles, projects, and runtime settings. The environment-level configuration below applies to self-hosted deployments.
Identity & access (all tenants)¶
Daedalus is SSO-first with a local fallback. Before operators can sign in, one identity path must be configured:
- Single sign-on — the console trusts an access assertion from the identity-aware proxy, verified against your identity provider's key set and the expected audience. First-time SSO users are auto-provisioned at a configurable default role.
- Local accounts — username/password with a forced reset on first login, for environments without SSO.
Then assign roles (Administrator / Engineer / Analyst / Viewer) per user — see RBAC & access. Every action and login is written to the audit log.
Runtime settings (in the console)¶
These knobs live in the Config tab and govern how autonomously the platform runs. The defaults are the safe ones.
| Setting | Purpose | Default |
|---|---|---|
auto_dispatch |
lets the scheduler start work without a human pressing go | off |
autonomous |
master autonomy switch; also gates auto-submission of flags | off |
max_concurrent |
hard ceiling on simultaneous agent processes | low |
local_only |
keep all inference on local models (no cloud path) | on |
| budget ceilings | per-team spend limit on the cloud path | set per team |
| local inference limits | context window, prediction length, ReAct step cap | tuned per GPU |
Environment configuration (self-host)¶
A self-hosted deployment is configured with environment variables plus the runtime settings above. The essential groups:
=== "Inference"
- **Model API URL** and the **model name** to use for agents and reports.
- Local generation limits (context window, prediction length, step cap).
- Optional **cloud model** command for executive reasoning.
=== "Executor"
- The sandbox API **URL** and its **bearer token**.
- Default and maximum sandbox **timeouts**.
- The `allow_lan` gate for the `lan` network mode (off by default).
=== "Identity"
- SSO **audience** and **team domain** for access-assertion verification.
- The **default role** for auto-provisioned SSO users.
- A break-glass switch to disable auth for lockout recovery **only**.
=== "Storage"
- The path to the **SQLite database** — the platform's state. Back this up.
Secrets stay out of the repo
Tokens, API keys, and identity secrets are supplied as environment/secret values, never committed. Treat the deployment's secret store like a password file.
Per-project scoping¶
Work is organized into projects, and a project is scoped to the zones (segments where you've enrolled agents) it may target. This scoping is the consent boundary for live activity — an agent only runs against a zone a project explicitly targets, dry-run by default, with a confirm step before anything live.