# How to Configure Timeouts, Retries, and Resource Limits in Strix Scans

> Configure Strix scans with timeouts, retries, and resource limits. Control execution ceilings and transient failure retries using environment variables or a JSON config file for robust scanning.

- Repository: [Strix/strix](https://github.com/usestrix/strix)
- Tags: how-to-guide
- Published: 2026-03-26

---

**Set the `LLM_TIMEOUT`, `STRIX_LLM_MAX_RETRIES`, `STRIX_SANDBOX_EXECUTION_TIMEOUT`, and `STRIX_SANDBOX_CONNECT_TIMEOUT` environment variables—or persist them in `~/.strix/cli-config.json`—to control wall‑clock limits, transient‑failure retries, and sandbox execution ceilings across all Strix scans.**

Strix is an open‑source security scanning framework that orchestrates LLM calls and sandboxed tool execution. Tuning its **timeout, retry, and resource limit** settings prevents hung scans and transient failures without modifying source code. All values are runtime‑configurable via environment variables or a JSON config file, making it easy to adapt Strix to slow networks, large codebases, or restricted CI environments.

## Environment Variables vs. JSON Configuration

Strix offers two mechanisms for supplying configuration:

- **Environment variables** – Ideal for ad‑hoc runs and containerized deployments. Values are read via `Config.get()` in [`strix/config/config.py`](https://github.com/usestrix/strix/blob/main/strix/config/config.py) and applied immediately.
- **JSON config file** – Located at `~/.strix/cli-config.json` by default (or any path passed via `--config`), this file persists settings across sessions. The `Config.apply_saved` method injects these values during CLI startup.

Both methods feed into the same `Config` class, ensuring a single source of truth for all timeout and retry logic.

## Configuring LLM Timeouts and Retries

### LLM Request Timeout

The `llm_timeout` parameter defines the maximum wall‑clock time a call to the language model may take before abortion. The default is **300 seconds** (5 minutes).

In [`strix/config/config.py`](https://github.com/usestrix/strix/blob/main/strix/config/config.py) line 24, the default is registered under the key `llm_timeout`. At runtime, [`strix/llm/config.py`](https://github.com/usestrix/strix/blob/main/strix/llm/config.py) line 33 resolves this value inside the `LLMConfig` constructor, applying it to the underlying HTTP client.

```bash
export LLM_TIMEOUT="600"  # 10 minutes

```

### Retry Count for Transient Failures

The `strix_llm_max_retries` parameter controls how many times the framework re‑attempts an LLM request after transient failures (network blips, rate limits). The default is **5 attempts**.

This value is defined in [`strix/config/config.py`](https://github.com/usestrix/strix/blob/main/strix/config/config.py) line 22 and consumed in [`strix/llm/llm.py`](https://github.com/usestrix/strix/blob/main/strix/llm/llm.py) line 57, where the `LLM.generate` method implements the retry loop.

```bash
export STRIX_LLM_MAX_RETRIES="8"

```

## Configuring Sandbox Resource Limits

### Execution and Connection Timeouts

Sandboxed tools (e.g., port scanners, OS queries) run inside Docker containers governed by `DockerRuntime` in [`strix/runtime/docker_runtime.py`](https://github.com/usestrix/strix/blob/main/strix/runtime/docker_runtime.py). Two parameters control these operations:

- **`strix_sandbox_execution_timeout`** – Hard limit on how long a tool may run inside the container (default: **120 seconds**).
- **`strix_sandbox_connect_timeout`** – Maximum time to establish a connection to the container (default: **10 seconds**).

Both are defined in [`strix/config/config.py`](https://github.com/usestrix/strix/blob/main/strix/config/config.py) lines 45–46 and enforced at line 132 of [`strix/runtime/docker_runtime.py`](https://github.com/usestrix/strix/blob/main/strix/runtime/docker_runtime.py) when the runtime creates the container.

```bash
export STRIX_SANDBOX_EXECUTION_TIMEOUT="300"  # 5 minutes

export STRIX_SANDBOX_CONNECT_TIMEOUT="20"     # 20 seconds

```

## Practical Configuration Examples

### Quick Environment Variable Setup

For a one‑off scan with extended limits, export the variables before invoking the CLI:

```bash
export LLM_TIMEOUT="600"
export STRIX_LLM_MAX_RETRIES="8"
export STRIX_SANDBOX_EXECUTION_TIMEOUT="300"
export STRIX_SANDBOX_CONNECT_TIMEOUT="20"

strix --target ./myapp

```

### Persistent JSON Configuration

Save the following to `~/.strix/cli-config.json` to apply these settings to every subsequent scan:

```json
{
  "env": {
    "LLM_TIMEOUT": "600",
    "STRIX_LLM_MAX_RETRIES": "8",
    "STRIX_SANDBOX_EXECUTION_TIMEOUT": "300",
    "STRIX_SANDBOX_CONNECT_TIMEOUT": "20"
  }
}

```

Strix automatically loads this file on startup via `Config.apply_saved`.

### CI Pipeline Overrides

For ephemeral build environments, inline the environment variables directly before the command:

```bash
STRIX_LLM_MAX_RETRIES=10 STRIX_SANDBOX_EXECUTION_TIMEOUT=600 strix \
  --target ./service \
  --scan-mode deep

```

## Summary

- **LLM timeout** defaults to 300 seconds and is configured via `LLM_TIMEOUT`, resolved in [`strix/llm/config.py`](https://github.com/usestrix/strix/blob/main/strix/llm/config.py).
- **LLM retries** default to 5 attempts via `STRIX_LLM_MAX_RETRIES`, implemented in the retry loop at [`strix/llm/llm.py`](https://github.com/usestrix/strix/blob/main/strix/llm/llm.py) line 57.
- **Sandbox limits** default to 120 seconds execution and 10 seconds connection, enforced in [`strix/runtime/docker_runtime.py`](https://github.com/usestrix/strix/blob/main/strix/runtime/docker_runtime.py) line 132.
- **Configuration sources** include environment variables or `~/.strix/cli-config.json`, both handled by the central `Config` class.

## Frequently Asked Questions

### What is the default LLM timeout in Strix?

The default LLM timeout is **300 seconds** (5 minutes). This value is defined in [`strix/config/config.py`](https://github.com/usestrix/strix/blob/main/strix/config/config.py) line 24 and applied to the HTTP client in [`strix/llm/config.py`](https://github.com/usestrix/strix/blob/main/strix/llm/config.py) line 33.

### How many times does Strix retry failed LLM requests?

By default, Strix retries failed requests **5 times**. You can override this with the `STRIX_LLM_MAX_RETRIES` environment variable. The retry logic resides in the `LLM.generate` method at [`strix/llm/llm.py`](https://github.com/usestrix/strix/blob/main/strix/llm/llm.py) line 57.

### Can I configure Strix without using environment variables?

Yes. Create a JSON file at `~/.strix/cli-config.json` containing an `env` object with the desired keys. Strix loads this automatically on startup through `Config.apply_saved`, applying the settings without requiring shell exports.

### Where does Strix enforce sandbox resource limits?

Sandbox limits are enforced in [`strix/runtime/docker_runtime.py`](https://github.com/usestrix/strix/blob/main/strix/runtime/docker_runtime.py) at line 132, where the `DockerRuntime` class reads `strix_sandbox_execution_timeout` and `strix_sandbox_connect_timeout` to configure Docker container timeouts.