Configuration
Everything here belongs to the open runtime, the part that runs on your own
machine. Most people never open this page: the file you actually edit is
memnox.policies.toml, and it lives in the repository it governs.
Where things live
Everything the runtime writes is under ~/.memnox/ or in the repository you are
standing in. Nothing else on the machine is touched, and memnox uninstall
takes all of it back out.
Path
memnox.policies.toml~/.memnox/machine.policies.toml~/.memnox/config.toml~/.memnox/policies.json~/.memnox/memnox.db~/.memnox/bin/~/.memnox/backup/~/.memnox/kept.json~/.memnox/keeper.json~/.memnox/probation.json~/.memnox/notice/~/.memnox/checkpoints.json~/.memnox/daemon.log~/.memnox/memnox.sock~/.memnox/overlays.json~/.memnox/snapshots/~/.memnox/guard/~/.memnox/pending/~/.memnox/transcripts/Milestones for memnox rewind are the exception: they are git objects under
refs/memnox/ in the repository itself, because a working tree belongs to its
repository and nowhere else. The newest twenty are kept in each repository.
The config file
Seven settings, and memnox config is the way to change them.
memnox config list
memnox config get mode
memnox config set mode enforceSetting
moderetentionDaysfailOpentelemetryapprovedAgentsnoticeUnusualnoticeWarmupDaysmemnox protect --observe and --enforce are the same setting, reachable from
the command that made you think about it.
Environment variables
Variable
MEMNOX_POLICIESMEMNOX_SESSIONMEMNOX_AGENT_NAMEMEMNOX_REAL_SHELLMEMNOX_HOMEWhich wins
A rule file named on the command line beats MEMNOX_POLICIES, which beats the
file in the working directory. Within the rules themselves the order is
precedence, not file order: deny beats
ask beats allow, and the most specific rule wins. There is no first match
wins, because a rule set whose meaning depends on line order breaks the day
somebody sorts it.

