All Products
Search
Document Center

Alibaba Cloud Linux:Manage configuration

Last Updated:Sep 10, 2026

Alibaba Cloud Linux 4 Agentic Edition (Agentic OS) manages certification, model, tool and other settings through a hierarchical configuration system, supporting multi-layer coverage of project-level and user-level configuration files. This article introduces the access methods of multiple authentication methods, model switching operations, as well as the hierarchical priority and core configuration item descriptions of configuration files.

1 Authentication method

The first startup of Agentic OS requires authentication to connect to the large language model service. Can be used later /authCommand to switch authentication mode.

Currently the following authentication methods are supported.

Alibaba Cloud Certification

Select "Aliyun Authentication" on the interactive interface to get a certain amount of free credit.

  • In an ECS environment, the terminal displays the authorization URL and QR code. Open the URL in the browser or scan the QR code with your mobile phone to complete the Alibaba Cloud account login and authorization

  • In non-ECS environments, use Alibaba Cloud AK/SK authentication

    • Get AK/SK:

      1. Log in to the Alibaba Cloud console

      2. exist AccessKey Management page creation Key

Users who are authenticated by Alibaba Cloud can use a free API call quota, which is suitable for individual development and testing.

Note: Alibaba Cloud authentication method only supports the use of Qianwen series text models and does not support multi-modal models.

Bailian certification

Bailian Certification has pre-made Base Url, you can choose Coding Plan, Token Plan, and custom model authentication method, and provide API Key for authentication.

OpenAI Compatible Endpoint API Key Authentication

Select "OpenAI Compatible" on the interactive interface and prepare the API Key. Supported OpenAI compatible endpoints include:

  • Custom Base URL: locally deployed models (such as vLLM, Ollama), third-party API proxy services, etc.

Certification management

operate

Order

View current certification status

/auth

Switch authentication method

/auth(Select in interactive menu)

FAQ: When authentication fails, check whether the API Key is correct (note the spaces before and after) and whether the network can access the corresponding API endpoint. Agentic OS supports configuring multiple authentications at the same time. It will be selected according to priority. It can also be configured through /auth Manual switching.

2 Model configuration

Switch model

use /auth The command switches the model used by the current session, selects the configured authentication configuration, and then selects "Set as active provider".

3 configuration files

Configuration levels and priorities

Agentic OS's system Shell entrance cosh uses JSON format configuration files to manage settings, with priority from high to low:

Command line parameters > Environment variables > Project configuration > User configuration > Default value

Configuration file location

type

path

illustrate

System settings

/etc/copilot-shell/config.toml

Administrator defaults

User settings

~/.copilot-shell/config.toml

Personal global configuration

Project settings

.copilot-shell/config.toml(project root directory)

Project-level configuration can be shared by the team

Configuration file location

type

path

illustrate

System settings

/etc/copilot-shell/config.toml

Administrator defaults

User settings

~/.copilot-shell/config.toml

Personal global configuration

Project settings

.copilot-shell/config.toml(project root directory)

Project-level configuration can be shared by the team

cosh-core merges configurations in the order system → user → project. Project configuration can set Agent, Hook, Skill, session,active_model and answer language preference, but ignored active_provider, Provider definition, MCP server and project audit settings.cosh-shell Only user files are read, not system or project files.

Core configuration items

ai --- AI and model settings

Configuration items

type

default value

illustrate

active_provider

string

---

Currently active Provider

active_model

string

---

The name of the model currently in use

output_language

string

---

Answer language preference

thinking

string

---

thinking mode preference

ai.providers. --- Provider definition

Configuration items

type

default value

illustrate

type

string

---

Provider type, such as dashscope、openai_compat、aliyun

base_url

string

---

API base URL

api_key

string

---

API key, recommended ${VAR_NAME} Environment variable expansion

model

string

---

The Provider's default model

auth_source

string

---

Authentication source such as ecs_ram_role

access_key_id

string

---

Alibaba Cloud Access Key ID

access_key_secret

string

---

Alibaba Cloud Access Key Secret

security_token

string

---

Alibaba Cloud Security Token

explicit_cache

boolean

false

Whether to enable explicit caching

agent --- Agent behavior settings

Configuration items

type

default value

illustrate

approval_mode

string

"recommend"

Core approval mode:recommend、auto、trust

max_turns

number

50

The maximum number of rounds for a single Agent request

max_tool_calls_per_turn

number

10

Maximum number of tool calls per round

session_token_limit

number

128000

Session token restrictions

allowed_tools

array

[]

List of tools exempt from approval

session --- session management

Configuration items

type

default value

illustrate

auto_persist

boolean

true

Whether to automatically persist sessions

persist_dir

string

"~/.copilot-shell/cosh-core/sessions"

Session persistence directory

session.compaction --- session compression

Configuration items

type

default value

illustrate

enabled

boolean

true

Enable compression

auto

boolean

true

automatic compression

trigger_ratio

number

0.70

The context ratio that triggers normal compression

emergency_ratio

number

0.90

The proportion of contexts that trigger emergency protection

target_ratio

number

0.30

Compressed target context ratio

preserve_recent_runs

number

2

Number of recent complete Agent runs retained

auto_compact_token_limit

number

---

Optional absolute trigger token limit

model_context_window

number

---

Model context window override value

model_max_output_tokens

number

---

Model maximum output token coverage value

must be maintained target_ratio <= trigger_ratio <= emergency_ratio。

shell --- Shell interactive settings

Configuration items

type

default value

illustrate

default

string

"auto"

default shell

adapter_default

string

"cosh-core"

default adapter

analysis_mode

string

"smart"

Analysis mode:smart、auto、manual

approval_mode

string

"auto"

Shell approval mode:recommend、auto、trust

integration

string

"enhanced"

Shell integration mode: enhanced (default; enables marker hooks for AI routing and command events, and lets you press Shift+Tab to switch between Assisted and Shell-only modes) or native (no hooks; the shell handles all input).

input_wait_timeout_secs

number

120

Enter the wait timeout seconds,0 Indicates disabled

trusted_commands

array

[]

Trusted command list

trusted_project_roots

array

[]

List of trusted project roots

shell.recommendations --- Shell recommendations

Configuration items

type

default value

illustrate

enabled

boolean

true

Whether to enable shell suggestions

bash_history

boolean

false

Whether to use Bash history to generate suggestions

ui --- interface settings

Configuration items

type

default value

illustrate

language

string

"auto"

UI language

startup_banner

boolean

true

launch banner

startup_hooks

boolean

false

start hook

debug

boolean

false

debug mode

log_level

string

"warn"

UI log level

skills --- skill settings

Configuration items

type

default value

illustrate

enabled

boolean

false

Whether to enable custom skills

custom_paths

array

[]

Custom skill path list

logging --- log settings

Configuration items

type

default value

illustrate

level

string

"warn"

Log level

mcp.servers. --- MCP servers

MCP client can only be defined in system or user configuration. Each server uses command(stdio) or urlOne of (Streamable HTTP); omitted allowed_tools Indicates exposing all tools,[ ] Indicates that the tool is not exposed.

Configuration items

type

default value

illustrate

command

string

---

stdio server executable file path

url

string

---

Streamable HTTP endpoint

args

array

[]

Command line parameters

env

table

{}

environment variables

timeout_ms

number

10000

Request timeout in milliseconds

startup_timeout_ms

number

30000

Start timeout in milliseconds

allowed_tools

array

---

List of tools allowed to be exposed

health --- health check

Configuration items

type

default value

illustrate

enabled

boolean

true

Whether to enable health checks

role

string

---

Role ID

memory_sensitive

boolean

false

memory sensitive mode

critical_mounts

array

["/"]

List of key mount points

verbose

boolean

false

Verbose output mode

health.services Use TOML array table definition:

[[health.services]]
name = "nginx"
expected = "active"

audit --- Audit settings

System files include [audit] In the table, the system settings shall prevail; otherwise, the user settings shall be used. Project audit tables are ignored.

Configuration items

type

default value

illustrate

mode

string

"best_effort"

Audit mode:best_effort or required

retention_days

number

30

Number of days to retain audit data

max_disk_bytes

number

1073741824

Maximum disk usage of audit data in bytes