Docs / Configuration Build
Advanced Configuration
Opt-in LLM stages, architecture overrides, security extensions and limits.
Opt-in LLM stages
| Section | Stage | Cost shape |
|---|---|---|
[document-semantics] enabled, max-sections |
LLM extraction per document section | one call per section — thousands for a large corpus; cap with max-sections |
[architecture-reasoning] enabled |
crate-role classification | one batched call per recover |
[llm-description] enabled, scope |
ai_overview / ai_usage per object after commit |
~900 calls at modules, ~5× at all |
[binary-reconstruction] |
LLM business-rule drafts from binary slices (extension) | one call per slice; max-slices ceiling |
Every LLM-produced description is stored as a labelled, evidence-grounded property or a reviewable claim — never merged silently with deterministic facts.
Security extensions
[security]
extra-excluded-globs = ["**/customer-exports/**"]
[[security.extra-patterns]]
label = "internal-token"
regex = "corp_[A-Za-z0-9]{32}"
These extend the built-in redaction baseline; nothing can disable it.
Architecture overrides
[[architecture.system-decomposition.overrides]] lets you assign layers when the automatic decomposition is wrong.
Parallelism
ekos recover --parallel runs DAG-independent passes concurrently.