How precedence works
YAML seeds the database on first boot
On first startup, ManyLayers reads all UI-configurable sections from your
gateway.yaml and writes them to the database. This covers: pii, firewall, cache, router, rag, async, audit, suite, deployer, oidc_mappings.Admin UI changes take permanent precedence
After you save a section in the admin UI (or via
PUT /admin/settings/{section}), the database value takes permanent precedence. Subsequent config reloads no longer touch that section.Admin UI settings
Access settings at Admin UI → Settings (orGET /admin/settings). Each section maps to a card in the UI:
| Section | Description | Example keys |
|---|---|---|
pii | PII detector mode | detector, http_url |
firewall | Prompt injection firewall | default_mode, threshold |
cache | Response caching | enabled, ttl, semantic.* |
router | Upstream routing strategy | strategy, session_ttl |
rag | Knowledge base settings | vector_store, hybrid_search, rerank_model, relevance_filter_enabled |
async | Async inference workers | workers |
audit | Audit log retention | retention_days, log_bodies |
suite | Workspace features | enabled, session_ttl, local_users_enabled |
deployer | Model deployments | mode, namespace |
voice | Voice STT/TTS | enabled, stt_model, tts_model, tts_voice |
websearch | Web search grounding | provider, api_key, base_url, top_k |
Restart-only settings
These settings are never stored in the database. They can only be changed ingateway.yaml followed by a gateway restart:
server— listen address, max body bytesdatabase— connection URLredis— address, password, dbqueue— backend, Kafka brokersconnectors.encryption_key— credential encryption passphrasemode— on-prem vs SaaS
Settings API
| Method | Path | Auth | Description |
|---|---|---|---|
GET | /admin/settings | admin | Retrieve all settings sections |
PUT | /admin/settings/{section} | admin | Update a specific section |
PUT a section, it is marked as UI-owned and subsequent config reloads skip it.