Settings & policy files
Project defaults#
Use vylocore.json. Options override it; relative policy paths start beside it.
{
"version": 1,
"project": "my-app",
"configuration": { "engine_version": 2, "preset_key": "balanced" },
"policy": "protection.json"
}
Omitted settings use refreshed project defaults. Explicit choices survive uploads. --project-config selects another file.
File exclusion#
{
"version": 1,
"defaults": { "action": "inherit", "protections": {} },
"rules": [
{ "scope": "file", "path": "game/render.js", "action": "disabled" }
],
"build": { "mode": "fresh" }
}
Export function rules after scanning. Folder rules use subsystem and a folder path.
Validate and apply#
vylocore policy export --project my-app --output protection.json
vylocore policy validate --policy protection.json
vylocore scan --project my-app --policy protection.json
vylocore protect --project my-app --policy protection.json --wait
vylocore policy import --project my-app --policy protection.json
Export refuses overwrites. Validation checks structure; Vylocore checks permissions and compatibility. --policy affects one request. Import saves defaults and needs policy permission.
Repeatable builds#
Fresh mode varies output. Pinned repeats supported builds with the same seed, source and settings. It adds no security and excludes online builds. Keep private values out.