Configuration boundary reference
| Bootstrap or deployment | Dynamic administration |
|---|---|
| Listen address, public origin, trusted proxy | Public registration policy |
| PostgreSQL, Redis and physical storage | SMTP, SMS and SSO profiles |
| TLS, cookie and token trust roots | AI Providers, BaseURLs and enabled models |
| Daemon gateway and worker deployment | Plugin registries, versions and typed config |
| Signing/envelope keys and hard ceilings | Marketplace, quotas and soft policy |
Bootstrap values determine whether a process can establish its trust and data plane and may require restart. Dynamic values are typed, revisioned, audited, validated and activated without rewriting deployment files. Dynamic policy can lower a hard limit but cannot raise or disable its security ceiling.
Panel and Registry maintain separate dynamic settings, databases, accounts and secret envelopes.