How to Configure Timeouts, Retries, and Resource Limits in Strix Scans
Set the LLM_TIMEOUT, STRIX_LLM_MAX_RETRIES, STRIX_SANDBOX_EXECUTION_TIMEOUT, and STRIX_SANDBOX_CONNECT_TIMEOUT environment variables—or persist them in ~/.strix/cli-config.json—to control wall‑clock limits, transient‑failure retries, and sandbox execution ceilings across all Strix scans.
Strix is an open‑source security scanning framework that orchestrates LLM calls and sandboxed tool execution. Tuning its timeout, retry, and resource limit settings prevents hung scans and transient failures without modifying source code. All values are runtime‑configurable via environment variables or a JSON config file, making it easy to adapt Strix to slow networks, large codebases, or restricted CI environments.
Environment Variables vs. JSON Configuration
Strix offers two mechanisms for supplying configuration:
- Environment variables – Ideal for ad‑hoc runs and containerized deployments. Values are read via
Config.get()instrix/config/config.pyand applied immediately. - JSON config file – Located at
~/.strix/cli-config.jsonby default (or any path passed via--config), this file persists settings across sessions. TheConfig.apply_savedmethod injects these values during CLI startup.
Both methods feed into the same Config class, ensuring a single source of truth for all timeout and retry logic.
Configuring LLM Timeouts and Retries
LLM Request Timeout
The llm_timeout parameter defines the maximum wall‑clock time a call to the language model may take before abortion. The default is 300 seconds (5 minutes).
In strix/config/config.py line 24, the default is registered under the key llm_timeout. At runtime, strix/llm/config.py line 33 resolves this value inside the LLMConfig constructor, applying it to the underlying HTTP client.
export LLM_TIMEOUT="600" # 10 minutes
Retry Count for Transient Failures
The strix_llm_max_retries parameter controls how many times the framework re‑attempts an LLM request after transient failures (network blips, rate limits). The default is 5 attempts.
This value is defined in strix/config/config.py line 22 and consumed in strix/llm/llm.py line 57, where the LLM.generate method implements the retry loop.
export STRIX_LLM_MAX_RETRIES="8"
Configuring Sandbox Resource Limits
Execution and Connection Timeouts
Sandboxed tools (e.g., port scanners, OS queries) run inside Docker containers governed by DockerRuntime in strix/runtime/docker_runtime.py. Two parameters control these operations:
strix_sandbox_execution_timeout– Hard limit on how long a tool may run inside the container (default: 120 seconds).strix_sandbox_connect_timeout– Maximum time to establish a connection to the container (default: 10 seconds).
Both are defined in strix/config/config.py lines 45–46 and enforced at line 132 of strix/runtime/docker_runtime.py when the runtime creates the container.
export STRIX_SANDBOX_EXECUTION_TIMEOUT="300" # 5 minutes
export STRIX_SANDBOX_CONNECT_TIMEOUT="20" # 20 seconds
Practical Configuration Examples
Quick Environment Variable Setup
For a one‑off scan with extended limits, export the variables before invoking the CLI:
export LLM_TIMEOUT="600"
export STRIX_LLM_MAX_RETRIES="8"
export STRIX_SANDBOX_EXECUTION_TIMEOUT="300"
export STRIX_SANDBOX_CONNECT_TIMEOUT="20"
strix --target ./myapp
Persistent JSON Configuration
Save the following to ~/.strix/cli-config.json to apply these settings to every subsequent scan:
{
"env": {
"LLM_TIMEOUT": "600",
"STRIX_LLM_MAX_RETRIES": "8",
"STRIX_SANDBOX_EXECUTION_TIMEOUT": "300",
"STRIX_SANDBOX_CONNECT_TIMEOUT": "20"
}
}
Strix automatically loads this file on startup via Config.apply_saved.
CI Pipeline Overrides
For ephemeral build environments, inline the environment variables directly before the command:
STRIX_LLM_MAX_RETRIES=10 STRIX_SANDBOX_EXECUTION_TIMEOUT=600 strix \
--target ./service \
--scan-mode deep
Summary
- LLM timeout defaults to 300 seconds and is configured via
LLM_TIMEOUT, resolved instrix/llm/config.py. - LLM retries default to 5 attempts via
STRIX_LLM_MAX_RETRIES, implemented in the retry loop atstrix/llm/llm.pyline 57. - Sandbox limits default to 120 seconds execution and 10 seconds connection, enforced in
strix/runtime/docker_runtime.pyline 132. - Configuration sources include environment variables or
~/.strix/cli-config.json, both handled by the centralConfigclass.
Frequently Asked Questions
What is the default LLM timeout in Strix?
The default LLM timeout is 300 seconds (5 minutes). This value is defined in strix/config/config.py line 24 and applied to the HTTP client in strix/llm/config.py line 33.
How many times does Strix retry failed LLM requests?
By default, Strix retries failed requests 5 times. You can override this with the STRIX_LLM_MAX_RETRIES environment variable. The retry logic resides in the LLM.generate method at strix/llm/llm.py line 57.
Can I configure Strix without using environment variables?
Yes. Create a JSON file at ~/.strix/cli-config.json containing an env object with the desired keys. Strix loads this automatically on startup through Config.apply_saved, applying the settings without requiring shell exports.
Where does Strix enforce sandbox resource limits?
Sandbox limits are enforced in strix/runtime/docker_runtime.py at line 132, where the DockerRuntime class reads strix_sandbox_execution_timeout and strix_sandbox_connect_timeout to configure Docker container timeouts.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →