docs
// Execution Management (EEM)

Environment Variables

Every environment variable the EEM agent reads to configure itself. A command-line flag wins, then the primary environment name, then its legacy EEM_* spelling, then the YAML file at /etc/erebine/eem.yaml, then the built-in default. This page documents the environment layer.

Overview

See Config Files for the YAML companion to this reference.

Prefix Split: EREBINE_* vs EEM_*

Every variable on this page is listed under its primary name, and the agent reads that name first. Most primary names start with EREBINE_EEM_; the join key's is EREBINE_AGENT_JOIN_KEY, the name the EIM agent also reads.

Most settings also answer to a legacy EEM_* name, read only when the primary name is unset or empty. Each row names its legacy spelling, if it has one. Set the primary name: when both are set the primary wins, whichever file set it, so a legacy name in an override file loses to a primary name set anywhere else.

Rows also name the command-line flag and the eem.yaml key for the same setting, where one exists. A setting with no flag or no key is read from the environment only. The EIM inference agent uses the EREBINE_AGENT_* prefix; see EIM Agent Variables below.

Connection

Where the agent enrolls.

NameDefaultPurpose
EREBINE_EEM_ROUTER_URL required # unset HTTPS URL of the router the agent enrolls with. Flag: --router-url. YAML: router_url. Legacy: EEM_ROUTER_URL.
EREBINE_AGENT_JOIN_KEY first enrollment # unset Enrollment token issued by the router. Required only until the first enrollment succeeds: the agent writes agent-enrollment.json beside its keys and restores that identity on every later start, so the key is redeemed once and can be revoked and the variable dropped. Remove that file to enroll again, which needs a fresh key. Flag: --join-key, which shows the key to every account on the host in ps. YAML: join_key. Legacy: EEM_JOIN_KEY.

Identity

How the agent advertises itself to the router.

NameDefaultPurpose
EREBINE_EEM_REGISTRATION_NAME required # unset Stable display name the router uses to track this agent across restarts. Flag: --registration-name. YAML: registration_name. Legacy: EEM_REGISTRATION_NAME.

Runtime

Concurrency, lease, and lifecycle tuning. A numeric value that is not a whole number is skipped as if unset.

NameDefaultPurpose
EREBINE_EEM_LEASE_RENEWAL_INTERVAL_MS # 10000 Cadence (milliseconds) for lease renewal messages to the router. No flag. YAML: lease_renewal_interval_ms. Legacy: EEM_LEASE_RENEWAL_INTERVAL_MS.
EREBINE_EEM_SHUTDOWN_GRACE_SECONDS # 30 Time the agent waits for in-flight executions to finish on SIGTERM or SIGINT before forcing exit. No flag. YAML: shutdown_grace_seconds. Legacy: EEM_SHUTDOWN_GRACE_SECONDS.
EREBINE_EEM_MAX_CONCURRENT_EXECUTIONS # 20 Ceiling on simultaneous tool executions handled by the agent. No flag. YAML: max_concurrent_executions. Legacy: EEM_MAX_CONCURRENT_EXECUTIONS.
EREBINE_EEM_LOG_LEVEL # info Log verbosity. One of trace, debug, info, notice, warning, error, critical; any other value logs at info. Flag: --log-level. YAML: log_level. Legacy: EEM_LOG_LEVEL.

Filesystem Paths

Where the agent reads credentials and declared workspaces, and stores keys and queue state. Defaults are the Linux paths; on macOS /var/lib/erebine is ~/.local/state/erebine (the queue file sits directly in it) and /etc/erebine is ~/.config/erebine.

NameDefaultPurpose
EREBINE_EEM_CREDENTIALS_DIR # /var/lib/erebine/credentials Directory of per-workspace credential files referenced by credentials_ref in tool manifests. Flag: --credentials-dir. YAML: credentials_dir. Legacy: EEM_CREDENTIALS_DIR.
EREBINE_EEM_SIGNING_KEY_PATH # /var/lib/erebine/agent-signing-key.hex Persisted Ed25519 signing-key file used to sign messages to the router. Flag: --signing-key-path. YAML: signing_key_path. Legacy: EEM_SIGNING_KEY_PATH.
EREBINE_EEM_CURVE_KEY_PATH # /var/lib/erebine/agent-curve-key.hex Persisted CURVE key-agreement private-key file. Flag: --curve-key-path. YAML: curve_key_path. Legacy: EEM_CURVE_KEY_PATH.
EREBINE_EEM_QUEUE_DB_PATH # /var/lib/erebine/state/queue.sqlite SQLite file backing the outbound dispatch queue; :memory: keeps the queue for the life of the process only. No flag. YAML: queue_db_path. Legacy: EEM_QUEUE_DB_PATH.
EREBINE_EEM_WORKSPACES_FILE # /etc/erebine/workspaces.yaml The operator-declared workspaces document. No flag and no YAML key. Legacy: EEM_WORKSPACES_FILE.

Tool Domains

Which tool domains the agent registers. Both take a comma-separated list and are read from the environment only: no flag and no YAML key.

NameDefaultPurpose
EREBINE_EEM_DOMAINS # unset Tool domains to enable, for example kubernetes,openstack. When set, only these domains are registered; unset registers every domain. Legacy: EEM_DOMAINS.
EREBINE_EEM_DISABLE_DOMAINS # unset Tool domains to leave out, for example shell,database, applied after EREBINE_EEM_DOMAINS. Legacy: EEM_DISABLE_DOMAINS.

Discovery

Advisory host probes that report candidate workspaces after startup. They configure nothing. Read from the environment only: no flag and no YAML key.

NameDefaultPurpose
EREBINE_EEM_DISCOVERY_MODE # off off skips the probes; any other value runs them. Legacy: EEM_DISCOVERY_MODE.
EREBINE_EEM_DISCOVERY_ROOTS # home directory Colon-separated directories the git-repository probe searches. Legacy: EEM_DISCOVERY_ROOTS.
KUBECONFIG # ~/.kube/config Colon-separated kubeconfig files the Kubernetes probe reads.

Router Callback

Settings that let callback-dependent tools (for example, deep_think) dial back into the router. Callbacks present the token the agent receives at enrollment and refreshes on its own; there is no token to configure. Until the agent holds one, or when no project external id is set, affected tools surface router_callback_missing rather than dispatching unauthenticated.

NameDefaultPurpose
EREBINE_EEM_PROJECT_EXTERNAL_ID optional # unset External project id (ws_<hex>) attached to callbacks for project-scoped routing. No flag. YAML: project_external_id. Legacy: EEM_PROJECT_EXTERNAL_ID.

Observability

NameDefaultPurpose
EREBINE_EEM_METRICS_HOST # 127.0.0.1 Bind address for the metrics, health and readiness HTTP server. An empty value keeps the default.
EREBINE_EEM_METRICS_PORT # 9095 TCP port for the metrics, health and readiness HTTP server. A value that is not a whole number keeps the default.
EREBINE_AGENT_LOG_BUFFER_BYTES # 65536 Bytes of recent log output the agent keeps for live log streaming, clamped to 8192 through 1048576. The EIM agent reads the same name.

EIM Agent Variables (Cross-Reference)

The EIM inference agent (erebine-eim-agent) is a separate binary that hosts vLLM and uses the EREBINE_AGENT_* prefix. Subset listed here; the EIM deployment page linked under Further Reading covers the rest.

NameDefaultPurpose
EREBINE_AGENT_ALLOW_INSECURE # unset Set to 1 or true to allow non-HTTPS enrollment URLs (development only).
EREBINE_AGENT_LOG_LEVEL # info Log verbosity for the EIM agent process.
EREBINE_AGENT_MAX_CONCURRENT # auto Optional ceiling on concurrent inference requests.
EREBINE_AGENT_METRICS_PORT # 9094 Prometheus metrics port for the EIM agent.
EREBINE_AGENT_VLLM_PATH # PATH lookup Absolute path to the vLLM binary.
EREBINE_AGENT_VLLM_SOCKET_PATH # /tmp/erebine-engine.sock Unix socket path used to dial vLLM.
EREBINE_AGENT_VLLM_SALT_SECRET # unset Server secret for tenant-isolated cache keys.

Precedence

Configuration layers for the EEM agent resolve in this order (later wins):

  1. // 1 defaults Built-in constants compiled into the agent.
  2. // 2 eem.yaml File values from /etc/erebine/eem.yaml, or the file --config names.
  3. // 3 legacy EEM_* env The legacy spelling, read only when the primary name is unset or empty.
  4. // 4 primary env The names this page lists, mostly EREBINE_EEM_*.
  5. // 5 CLI flags erebine-eem-agent command-line flags.

An empty environment value counts as unset and falls through to the next layer down. Secrets such as EREBINE_AGENT_JOIN_KEY should flow through environment variables or a secrets manager, not committed YAML.

Further Reading