Commands

jackin❯ config

View and modify operator configuration

Synopsis

jackin config <SUBCOMMAND>

Manage global operator configuration — mounts, agent trust, and agent authentication forwarding.

config mount

Manage global mounts that apply to all (or scoped) agent launches.

Global mounts are best for caches, shared read-only reference material, or team-wide directories that should be available everywhere.

config mount add

jackin config mount add <NAME> --src <PATH> --dst <PATH> [OPTIONS]

Register a new global mount.

If a global mount resolves to the same container destination as a workspace mount or load-time mount, jackin❯ raises a conflict error at load time instead of silently overriding one of them.

OptionDescription
--src <PATH>Path on the host machine
--dst <PATH>Path inside the container
--readonlyMake this mount read-only
--scope <PATTERN>Only apply to matching roles (glob pattern)
# Mount Gradle cache for all roles
jackin config mount add gradle-cache \
  --src ~/.gradle/caches \
  --dst /home/agent/.gradle/caches \
  --readonly

# Mount secrets only for chainargos roles
jackin config mount add secrets \
  --src ~/.chainargos/secrets \
  --dst /secrets \
  --readonly \
  --scope "chainargos/*"

config mount list

jackin config mount list

Show all registered global mounts with their source, destination, read-only status, and scope.

config mount remove

jackin config mount remove <NAME> [OPTIONS]

Unregister a global mount.

OptionDescription
--scope <PATTERN>Only remove from this scope (leave other scopes untouched)
jackin config mount remove gradle-cache
jackin config mount remove secrets --scope "chainargos/*"

Agent accounts

Agent credentials are managed with jackin account and jackin workspace account. The old config auth policy command has been removed. See Agent Accounts for discovery, profile folders, provider keys, and workspace authorization.

config env

Manage operator env vars at global and per-role scope.

Values are stored verbatim — whatever you type is what jackin❯ resolves at launch time. No editor-side validation of key names or value shape. op://... 1Password references, $VAR / ${VAR} shell-style interpolations, and literal strings all work.

Without --role, writes and reads target the global scope (applies to every agent launch). With --role <SELECTOR>, they target the per-role scope (applies only when that role is loaded). The role selector is not pre-validated — the value is recorded even if the role is not registered.

config env set

jackin config env set <KEY> <VALUE> [OPTIONS]

Set or overwrite an env var at the chosen scope.

OptionDescription
--role <SELECTOR>Apply to the per-role scope instead of the global scope
--comment <TEXT>Attach an inline comment to the key
--on-demandInject the value at jackin-exec time instead of at launch
# Global scope — 1Password reference
jackin config env set API_TOKEN "op://Personal/api/token"

# Per-role override
jackin config env set LOG_LEVEL debug --role agent-smith

# Attach a comment (useful for rotation reminders)
jackin config env set OPENAI_KEY "op://Work/OpenAI/key" --comment "rotate quarterly"

# On-demand credential: never resolved at launch, approved per use
jackin config env set OP_TOKEN "op://Work/svc-account/credential" --on-demand

An --on-demand value is left out of the launch environment entirely. Only its name reaches the container; the agent asks for the value through jackin-exec, and the host resolves it after the operator approves that use. Use it for credentials that must not sit in a long-lived container's environment.

config env unset

jackin config env unset <KEY> [OPTIONS]

Remove an env var from the chosen scope. Idempotent: if the key is not present, prints <KEY> not set. and exits 0 without changing anything.

OptionDescription
--role <SELECTOR>Unset from the per-role scope instead of the global scope
jackin config env unset API_TOKEN
jackin config env unset LOG_LEVEL --role agent-smith

config env list

jackin config env list [OPTIONS]

Show the env vars registered at the chosen scope as a table with Key, Value, and On demand columns. Prints No env vars set. when the scope is empty. Values are shown as-stored (no resolution, no masking); On demand is yes for a value that is resolved at jackin-exec time rather than injected at launch.

OptionDescription
--role <SELECTOR>List vars from the per-role scope instead of the global scope
jackin config env list
jackin config env list --role agent-smith

config git

Manage git-related global settings.

config git coauthor-trailer enable|disable

jackin config git coauthor-trailer enable
jackin config git coauthor-trailer disable

Enable or disable automatic Co-authored-by trailer injection for agent commits. When enabled, jackin❯ installs a prepare-commit-msg hook inside every container at launch. The hook appends the running agent's Co-authored-by trailer whenever Git prepares a commit message, preserving existing agent trailers and deduplicating matching lines so the trailer appears in Git's final trailer block.

Supported agents and their trailers:

AgentTrailer
Claude (Claude Code)Co-authored-by: Claude <noreply@anthropic.com>
CodexCo-authored-by: Codex <codex@openai.com>
AmpCo-authored-by: Amp <amp@ampcode.com>
OpenCodeCo-authored-by: opencode-agent[bot] <opencode-agent[bot]@users.noreply.github.com>

This setting can also be toggled in jackin console via the General tab in the Settings panel (S from the workspace list).

jackin config git coauthor-trailer enable
# → coauthor_trailer: enabled

jackin config git coauthor-trailer disable
# → coauthor_trailer: disabled

config git dco enable|disable

jackin config git dco enable
jackin config git dco disable

Enable or disable automatic Signed-off-by (DCO) trailer injection for agent commits. When enabled, the same prepare-commit-msg hook that config git coauthor-trailer installs also appends a Signed-off-by trailer whenever Git prepares a commit message, deduplicating matching lines so the trailer appears in Git's final trailer block. The trailer uses the git identity (user.name and user.email) forwarded from the host by jackin. If either is unset inside the container at commit time, the trailer is skipped with a warning.

The two flags are independent — you can enable either or both.

This setting can also be toggled in jackin console via the General tab in the Settings panel (S from the workspace list).

jackin config git dco enable
# → dco: enabled

jackin config git dco disable
# → dco: disabled

On this page