Configuration

Pass --config config.toml. Without it, the binary uses built-in defaults. CLI overrides are --tcp-addr, --metrics-addr, --shards and --uds-path. Unknown TOML fields and invalid combinations are rejected before trading starts.

Server

FieldDefaultMeaning
server.tcp_addr127.0.0.1:9090Trading listener
server.metrics_addr127.0.0.1:9091HTTP health, metrics and admin
server.shards0Auto CPU count; pin a count for recovery compatibility
server.uds_pathabsentOptional Unix domain socket
server.allow_plaintext_remotefalseExplicit opt-in for non-loopback plaintext TCP
server.clockcoarsesystem, coarse or rdtsc
server.pin_threadsfalseLinux CPU affinity
server.shutdown.drain_timeout_secs30Connection drain deadline
server.heartbeat.interval_ms5000Advertised heartbeat interval
server.heartbeat.timeout_ms15000Connection read timeout
server.session.replay_buffer_size1000Per-session replay frame capacity
server.session.ttl_secs60Idle lifetime for unused sessions

Configure server.tls.cert_path and key_path together; client_ca_path enables required client certificates. TLS needs the tls build feature. The HTTP listener has no native TLS.

server.admin.api_key is empty by default, disabling halt/resume routes. Configured keys require at least 16 printable, non-space ASCII characters. Status and metrics remain public; protect the HTTP listener with a private network or proxy.

Symbols and risk

Each [[symbols]] entry defines an ID, base/quote names, price/quantity scales and decimal-string limits. See trading pairs. The optional [symbols.risk] table enables these controls:

FieldMeaning
max_order_qtyMaximum order quantity, including hidden quantity
max_order_notionalConservative quote notional cap
price_band_bpsDeviation from reference price; zero disables
reference_priceInitial reference price as a decimal string
max_orders_per_secondToken-bucket limit; zero disables
max_open_ordersResting-order limit; zero disables
trading_enabledAdmission switch
self_trade_preventionReject same-session self-matches

Without a risk table, these checks do not run. Market orders subject to notional/reference checks fail closed if no reference price is available. Seed reference_price or establish a traded reference. Position limits are not supported without an external account ledger.

invariant_policy is halt_symbol by default. strict panics on internal invariant violations; continue logs and continues and should be reserved for controlled recovery.

Storage

FieldDefaultMeaning
wal.enabledtrueEnable durable recovery
wal.modeprepre or post; both persist decisions/outcomes before reply
wal.path./data/walJournal directory
wal.sync_interval100Legacy writer interval; the server syncs each decision explicitly, so this does not batch server replies
wal.snapshot_dirderivedDefaults to {wal.path}/snapshots
wal.snapshot_interval100000Commands per shard checkpoint; zero disables

Snapshot creation does not truncate decision history. Symbol/risk settings and shard topology are part of the recovery contract. See deployment and recovery for backups and upgrades.