Configuration lives in config/tasksultan.config.ts. The file is dependency-free and side-effect-free at import
time, so the Studio, the CLI, tests and the generator can all import it safely. It derives projectRoot from its
own location and everything else hangs off that.
#The config file
The exported config object has five parts: projectRoot, demo, retry, artifactsRoot and dataDir, plus
the mailbox and actionCentre blocks. automationsDir names where the Studio scans for automation sources.
import { config } from '../config/tasksultan.config';
config.projectRoot; // resolved from the module's own directory
config.automationsDir; // <projectRoot>/automations
config.artifactsRoot; // <projectRoot>/artifacts
config.dataDir; // <projectRoot>/data
#Target and demo
config.demo.defaultUrl is the URL an automation points at by default. It resolves from TS_TARGET_URL first, then
the legacy DEMO_URL, then http://127.0.0.1:4100. The local demo application serves on host 127.0.0.1 and port
4100 with a demo username and password, which exist only because the demo application defines them.
#Retry policy
config.retry is the default policy for system failures, in the UiPath "retry, then fail" shape: maxAttempts is 3
(one try and two retries), baseDelayMs is 800, maxDelayMs is 8000 and backoffFactor is 2. An automation can
declare its own policy on its definition.
#The mailbox
The mailbox block is the watching exercise. mode is idle (react to arrivals over IMAP IDLE), interval (poll
on the scheduler shape) or manual. With idle, intervalMinutes is a backstop rather than the trigger, so a dead
watcher degrades to slow instead of silent. credential is the vault asset holding the username and app password;
account overrides the account and empty means take username from the vault. The remaining fields are host,
port, rejectUnauthorized, folder, maxMessagesPerRun, attachmentsDir and idleRefreshMs.
#The Action Centre
actionCentre names the continuation a completed human decision dispatches: resumePackage, resumeVersion,
resumeQueue and resumeEnvironment. There is deliberately no default. An empty block means the Action Centre is
not armed for this deployment and the mailbox ingest then refuses to consume an invoice that needs a human rather
than approving it or dropping it.
#Environment variables
Values resolve from the environment when present. The variables below are grouped by the area that reads them.
| Area | Variables |
|---|---|
| Paths and identity | TS_ORCHESTRATOR_ROOT, TS_DATA_DIR, TS_ARTIFACTS_DIR, TS_ORCH_ARTIFACTS_DIR, TS_PACKAGES_DIR, TS_ENVIRONMENT, TS_ROBOT_ID, TS_CONSOLE_LOGS, TS_TARGET_URL, DEMO_URL |
| Vault | TS_VAULT_MASTER_KEY, TS_VAULT_KEY_FILE, TS_CRED_<NAME> |
| Queue | TS_QUEUE_PROVIDER; empty or file is the default, sqlite swaps the substrate |
| Schedule and lock | TS_ORCH_LOCK_STALE_MS, TS_ORCH_SCHEDULER_TIMER |
| Server | TS_ORCHESTRATOR_PORT (default 4377), TS_ORCHESTRATOR_URL |
| Principals and approvals | TS_PRINCIPAL_TOKEN, TS_APPROVAL_THRESHOLD |
| HTTP | TS_API_TIMEOUT_MS (default 15000) |
| Database | TS_DB_<NAME>_CONNECTION_STRING, TS_DB_<NAME>_* |
| Desktop | TS_DESKTOP_UIA_HELPER, TS_DESKTOP_UIA_TIMEOUT_MS |
| Mailbox | TS_MAILBOX_MODE, TS_MAILBOX_INTERVAL_MINUTES, TS_MAILBOX_CREDENTIAL, TS_MAILBOX_ACCOUNT, TS_MAILBOX_HOST, TS_MAILBOX_PORT, TS_MAILBOX_TLS_REJECT_UNAUTHORIZED, TS_MAILBOX_FOLDER, TS_MAILBOX_MAX_PER_RUN, TS_MAILBOX_ATTACHMENTS_DIR, TS_MAILBOX_IDLE_REFRESH_MS |
| Action continuation | TS_ACTION_RESUME_PACKAGE, TS_ACTION_RESUME_VERSION, TS_ACTION_RESUME_QUEUE, TS_ACTION_RESUME_ENVIRONMENT |
| Remote model | TS_MODEL_API_BASE, TS_MODEL_API_KEY, TS_MODEL_NAME |
| Licence | TS_LICENCE_ENFORCE, TS_LICENCE_PUBLIC_KEY |
The vault resolves its wrapping key from TS_VAULT_MASTER_KEY (64 hex characters, or the base64 of 32 raw bytes)
or from a key file named by TS_VAULT_KEY_FILE. Nothing here carries a credential value into source.
#Things that catch people out
config/is a protected path. The database connection an automation needs is declared on the automation itself and resolved fromTS_DB_*, not written here.- Setting
TS_MAILBOX_TLS_REJECT_UNAUTHORIZED=falseis printed by the monitor, because a connection whose identity was not checked must not look identical in the log to one that was. - The Action Centre's absence is a fact, not a broken default. The ingest fails closed and the mail stays new.