ov/skills/settings/SKILL.md
Runtime configuration management for the ov CLI. MUST be invoked before any work involving: ov settings commands, runtime configuration, engine selection, bind address, storage paths, or secret backend configuration.
npx skillsauth add overthinkos/overthink-plugins settingsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Manage ov's runtime configuration stored in ~/.config/ov/settings.yml. Controls engine selection, networking, storage paths, secret backend, and agent forwarding.
| Action | Command | Description |
|--------|---------|-------------|
| Get a setting | ov settings get <key> | Show current value |
| Set a setting | ov settings set <key> <value> | Update a setting |
| List all | ov settings list | Show all settings with values |
| Reset to default | ov settings reset <key> | Remove override, use default |
| Config path | ov settings path | Print path to settings.yml |
| Migrate secrets | ov settings migrate-secrets [--dry-run] | Move plaintext credentials to keyring |
| Key | Default | Env Var | Description |
|-----|---------|---------|-------------|
| engine.build | docker | OV_ENGINE_BUILD | Build engine (docker/podman) |
| engine.run | docker | OV_ENGINE_RUN | Run engine (docker/podman) |
| run_mode | quadlet | OV_RUN_MODE | Deployment mode (quadlet/direct) |
| bind_address | 127.0.0.1 | OV_BIND_ADDRESS | Default bind address for ports |
| encrypted_storage_path | ~/.local/share/ov/encrypted | OV_ENCRYPTED_STORAGE_PATH | Base path for gocryptfs volumes |
| volumes_path | ~/.local/share/ov/volumes | OV_VOLUMES_PATH | Base path for bind-mounted volumes |
| secret_backend | auto | OV_SECRET_BACKEND | Credential backend (auto/keyring/kdbx/config) |
| keyring_collection_label | (empty) | OV_KEYRING_COLLECTION_LABEL | Preferred Secret Service collection label. Empty = iterate naturally (default alias → listing order). Set to pin ov to a specific collection in multi-database setups (e.g. KeePassXC with multiple open databases). See /ov:enc for the full iteration order. |
| forward_gpg_agent | true | OV_FORWARD_GPG_AGENT | Forward GPG agent into containers |
| forward_ssh_agent | true | OV_FORWARD_SSH_AGENT | Forward SSH agent into containers |
| secrets.kdbx_path | (none) | OV_KDBX_PATH | Path to KeePass .kdbx database |
| secrets.kdbx_cache | true | OV_KDBX_CACHE | Cache kdbx password in kernel keyring |
| secrets.kdbx_cache_timeout | 3600 | OV_KDBX_CACHE_TIMEOUT | Kernel keyring cache TTL (seconds) |
| hosts.<alias> | (none) | — | SSH target for ov --host <alias> remote execution. Free-form: host, user@host, user@host:port. Consulted by the top-level --host flag to re-exec ov commands on another machine over SSH. See /ov:ssh. |
# Switch to podman for both build and run
ov settings set engine.build podman
ov settings set engine.run podman
# Check current engine
ov settings get engine.build
# Change volume storage to NAS
ov settings set volumes_path /mnt/nas/ov-volumes
# Change encrypted storage location
ov settings set encrypted_storage_path /mnt/encrypted/ov
# Force KeePass backend
ov settings set secret_backend kdbx
# Migrate plaintext secrets from settings.yml to keyring
ov settings migrate-secrets
# Preview migration without changes
ov settings migrate-secrets --dry-run
Settings resolve in this order: environment variable > settings.yml > default value.
/ov:config -- deployment configuration (uses settings)/ov:secrets -- credential management/ov:doctor -- diagnose settings and secret storage health/ov:enc -- encrypted volume pathstools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).