Skip to content
Castellan
Toller's icon

Reference · Toller

Read as

The Toller's settings, files and commands

Every setting with its default, where the Toller keeps its files, its command line, and its local API.

Article
1703
Applies to
Toller 0.1.1
Last reviewed
For
For developers
Written for Toller 0.1.1. Toller is at 0.1.2 now (1 small release since: what changed).

Settings#

On its page, under Settings in the title bar. Each shows its value, its default and a line on what it does, with Reset to default. They're kept in %USERPROFILE%\.toller\settings.json.

SettingDefaultWhat it does
What entered your projectsOnNew and changed dependencies in your repositories.
What entered your toolsOnExtensions, global tools, PATH, git hooks and git settings.
Dev servers open to your networkOnDeveloper runtimes listening on every network.
Secrets left in the openOnKeys, tokens and private keys.
Where it looks for secretsAll threeYour repositories, PowerShell and bash histories, Text and JSON files in Downloads.
More folders with repositoriesNoneA folder holding repositories, or one repository's folder, beyond what Castellan and Reeve know and the usual folders. Up to 30.
Projects it doesn't look atNoneTheir names as the page shows them, or their folders.
A round every60 minutes15 minutes to a day. Run now runs one at any time.
Changes kept (Advanced)30 days7 to 365. A change it reported is let go after this long, unless you mark it seen sooner. What's still there, a secret or an open server, stays while it's there.

Files#

All in %USERPROFILE%\.toller:

FileWhat's in it
settings.jsonIts settings.
state.jsonThe findings, the ones marked seen, the changes of the last rounds, the last round's outcome, and this PC's fingerprint key.
baseline.jsonWhat it saw at the last look, to tell what's new: each project's lockfiles, extensions, tools, PATH, hooks and git settings.
cache.jsonThe files already read for secrets (their size, time, and what was found, by kind, line and fingerprint), so a round reads only what changed.
server.json, serve.logThe running page's process, port and token, and its log.

None of them holds a secret's value.

Commands#

Run with node $HOME\.toller\app\src\cli.ts <command>:

CommandWhat it does
runOne round now, and what it found: counts by kind, never a secret's value.
findingsWhat's on the page now, by area: kind, where, and why.
startOn duty: a round every hour, and its page up. Castellan's Start.
stopOff duty: no rounds. The page stays up. Castellan's Stop.
openMakes sure its page is up, without changing duty.
shutdownEnds its page's process.
statusOn duty or not. --json prints what Castellan reads.
uninstallRemoves it and its sign-in task. --purge removes its data too; --dry-run says what it would do.

It starts at sign-in from the scheduled task \Toller\Home page.

Local API#

At http://toller.localhost:21818/, answering only this PC:

AddressWhat it answers
GET /api/pingIts version and duty, with busy (a round under way) and toLookAt (findings not marked seen).

Its buttons, Seen and the fixes among them, need the token from its own page.

Is this page right?

If something on it is wrong or out of date, tell us and we'll fix the page.

Still stuck? Write to support@castellan-software.com and mention article 1703. Every version of Toller, and what changed in it, is in its release notes.