Config
Almost no setup, here are the knobs.
Make one
sentinel config-init
sentinel config-init --profile server
sentinel config-init my.yaml --profile paranoid
Writes defaults to yaml. Edit and go. doctor lints and names bad keys.
Profiles
One word presets. Explicit keys beat the profile.
home: quiet watch, warn onlyserver: auto block, higher burstuploads: strict entropy, bigger vaultparanoid: low burst, low line, freeze rest
profile: server
response: auto
Lookup
Walks up and takes first hit:
sentinel.yaml.sentinel.yaml.sentinel/config.yaml
Force one:
sentinel watch . --config ./examples/sentinel.yaml
Flags beat file values.
Full file
burst: 25
window: 10
cooldown: 30
entropy_line: 7.5
response: warn
profile: home
vault_max_mb: 5
vault_keep: 3
quar_max_mb: 500
risk_warn: 40
risk_high: 70
serve_port: 8000
webhook: ""
notify: false
kill: false
mail_to: ""
mail_from: "sentinel@localhost"
smtp_host: "localhost"
smtp_port: 25
allow: []
ignore:
- "*.tmp"
- "*.log"
paths: []
What each does
burst,window: trip after N in M secs. Lower is louder. Runlearnif unsure.cooldown: quiet secs after a hit. Stops 500 mails for one strain.entropy_line: 7.5 stock. 7.2 strict, 7.8 chill.vault_max_mb: cap per clean copy. 5 covers docs and code, skips videos.risk_warn,risk_high: lines forcheck. 40 and 70 work for most.serve_port: forserve.webhook: Slack or Discord url. Posts{"text": ...}.notify: desktop popup ifnotify-send,osascript, or termux tool exists.response: warn, auto, paranoid. auto kills unknown writers, paranoid freezes rest too.kill: old flag for auto. Off by default.allow: proc name bits never killed. Backup tools built in plus yours.vault_keep: versions kept per file. 3 is fine.quar_max_mb: quarantine cap.prunetrims oldest first.paths: per prefix tweaks, first match wins:
paths:
- prefix: "media/"
entropy_line: 7.9
- prefix: "docs/"
entropy_line: 7.2
mail_to, smtp_*: mail via local smtp. Blank mail_to means off.
- ignore: extra globs. Merged with .sentinelignore.
Ignores
Three layers, all merge:
- built in:
.git,__pycache__,.sentinel,node_modules,.venv,dist,build .sentinelignorein root:
*.tmp
*.log
scratch/
ignore:in yaml
Check count:
python -c "from sentinel.baseline import list_files; print(len(list_files('.')))"
Per command
init,update: use ignores at hash timeverify,scan,check,report: same ignores so diffs stay cleanwatch: same plus 0.5s debounce on repeat savesprotect: same, plus size cap