ManyLayers uses a three-layer settings system that lets you bootstrap from a YAML file but manage ongoing configuration from the admin UI without restarts.

How precedence works

1

YAML seeds the database on first boot

On first startup, ManyLayers reads all UI-configurable sections from your gateway.yaml and writes them to the database. This covers: pii, firewall, cache, router, rag, async, audit, suite, deployer, oidc_mappings.
2

Admin UI changes take permanent precedence

After you save a section in the admin UI (or via PUT /admin/settings/{section}), the database value takes permanent precedence. Subsequent config reloads no longer touch that section.
3

Config reloads update untouched sections

Sections you have never changed through the admin UI continue to be updated whenever you reload the config. This lets you update defaults in your YAML and have them take effect without a restart.

Admin UI settings

Access settings at Admin UI → Settings (or GET /admin/settings). Each section maps to a card in the UI:
SectionDescriptionExample keys
piiPII detector modedetector, http_url
firewallPrompt injection firewalldefault_mode, threshold
cacheResponse cachingenabled, ttl, semantic.*
routerUpstream routing strategystrategy, session_ttl
ragKnowledge base settingsvector_store, hybrid_search, rerank_model, relevance_filter_enabled
asyncAsync inference workersworkers
auditAudit log retentionretention_days, log_bodies
suiteWorkspace featuresenabled, session_ttl, local_users_enabled
deployerModel deploymentsmode, namespace
voiceVoice STT/TTSenabled, stt_model, tts_model, tts_voice
websearchWeb search groundingprovider, api_key, base_url, top_k

Restart-only settings

These settings are never stored in the database. They can only be changed in gateway.yaml followed by a gateway restart:
  • server — listen address, max body bytes
  • database — connection URL
  • redis — address, password, db
  • queue — backend, Kafka brokers
  • connectors.encryption_key — credential encryption passphrase
  • mode — on-prem vs SaaS
Changing restart-only settings through the admin UI has no effect. Update them in gateway.yaml and restart the gateway.

Settings API

MethodPathAuthDescription
GET/admin/settingsadminRetrieve all settings sections
PUT/admin/settings/{section}adminUpdate a specific section
When you PUT a section, it is marked as UI-owned and subsequent config reloads skip it.

Live config reload

To reload models, reseed teams, and re-apply any untouched config sections without dropping active connections:
# Docker Compose
docker compose kill -s HUP gateway

# Kubernetes
kubectl rollout restart deployment/manylayers -n manylayers
This reloads without restarting the process or dropping in-flight requests.