Runtime and configuration
Cadder derives one runtime identity from the directory containing its executables. Keep cadder, cadderd, and caddy together. Separate installation directories remain independent; there is no profile selector.
The runtime writes effective-caddy.json and the owner-protected data/cadder.sqlite3 database beneath the installation directory. SQLite stores desired activation and bounded redacted logs. Live leases and process ownership remain memory-only.
Trusted configuration
Section titled “Trusted configuration”The daemon loads one immutable configuration snapshot at startup. Selection order is an explicit foreground daemon override, cadder.toml beside the executables, standard per-user configuration, standard system configuration, then safe native PATH discovery.
[caddy]real_path = "/usr/local/bin/caddy-real"Use real_command instead when needed. Unknown keys, conflicting selectors, unsafe configuration files, and non-native executable targets fail before readiness. Changes take effect after Restart.