Configuration config¶
The config file lives at <user_config_dir>/iq/iq.toml. IQ_CONFIG points
it elsewhere, and --config overrides both for one run (precedence:
--config > IQ_CONFIG > default). It holds the saved sources and the stored option
defaults below. iq config location prints the resolved path.
iq writes the config file with mode 0600, so only you can read it. A source
saved with --store inline (the default) keeps its password in this file. If
the file holds an inline password and other users can access it, for example
after an edit or a copy, every command prints a warning to stderr with the fix
(chmod 600 <path>) and then runs as usual. Windows has no such mode, so there
is no warning there. iq config keyring migrate moves inline passwords into the
OS keyring.
Inspect the config file and manage stored option defaults. Persist a flag's
value once so you need not retype it. Set an option globally, or scope it to
one source with --src.
At query time, the precedence is explicit flag > per-source option > base option > built-in default. As a result, a saved default fills any flag you leave unset. An explicit flag on the command line always takes precedence.
Persistable options
Persistable options are the flags whose default it is reasonable to persist:
--format,--format.decimal,--compact--timeout--monochrome,--color,--no-progress--no-cache,--no-cache-index--verbose,--log*,--error*
Per-invocation flags are not storable:
--src--explain--unbounded--no-compile--reveal,--expand--debug.pprof
An iq combine query has no single source, so it uses the base options
only, never a per-source override.
Logging options
The log* options are the one place where a stored default and the
environment overlap. A stored log* value fills an unset flag. But an
$IQ_LOG* environment variable still wins over it (the flag > env > default chain
for logging applies before a stored default is treated as "set").
An explicit --log* flag beats both. No other option reads the
environment, so this interaction is unique to the logging family.
Edit edit¶
Open the config file in $IQ_EDITOR (then $VISUAL, $EDITOR, else vi).
Get get¶
Print an option's effective value at that scope.
Keyring keyring¶
Manage the OS-keyring secrets that back --store keyring sources.
List ls¶
List keyring-backed sources, each marked present or missing (-j/-y for
machine-readable output).
Get get¶
Print a source's secret, redacted unless --reveal is used.
Set set¶
Write or update a secret (reads stdin/prompt when the value is omitted). A
source with an inline password is left untouched. Use migrate for it.
Remove rm¶
Delete a source's secret and mark it inline again.
Migrate migrate¶
Move an inline password into the keyring, rewriting the stored URI to its password-less form.
Prune prune¶
Delete stale entries left for non-keyring sources. The keyring cannot be enumerated, so entries whose source was deleted are undetectable and are not pruned.
Location location¶
Print the resolved config file path.
List ls¶
List the options set at that scope. -v lists every persistable option with
its effective value, built-in default, and help.
Set set¶
Validate and store a value (base, or per source). The value is checked exactly as the flag checks it, so an invalid value is refused.
With -D or --delete it removes a stored value instead.
View view¶
Dump the whole config as TOML, source URIs redacted like iq ls.