How to Configure Timeouts, Retries, and Resource Limits in Strix Scans

Set the LLM_TIMEOUT, STRIX_LLM_MAX_RETRIES, STRIX_SANDBOX_EXECUTION_TIMEOUT, and STRIX_SANDBOX_CONNECT_TIMEOUT environment variables—or persist them in ~/.strix/cli-config.json—to control wall‑clock limits, transient‑failure retries, and sandbox execution ceilings across all Strix scans.

Strix is an open‑source security scanning framework that orchestrates LLM calls and sandboxed tool execution. Tuning its timeout, retry, and resource limit settings prevents hung scans and transient failures without modifying source code. All values are runtime‑configurable via environment variables or a JSON config file, making it easy to adapt Strix to slow networks, large codebases, or restricted CI environments.

Environment Variables vs. JSON Configuration

Strix offers two mechanisms for supplying configuration:

  • Environment variables – Ideal for ad‑hoc runs and containerized deployments. Values are read via Config.get() in strix/config/config.py and applied immediately.
  • JSON config file – Located at ~/.strix/cli-config.json by default (or any path passed via --config), this file persists settings across sessions. The Config.apply_saved method injects these values during CLI startup.

Both methods feed into the same Config class, ensuring a single source of truth for all timeout and retry logic.

Configuring LLM Timeouts and Retries

LLM Request Timeout

The llm_timeout parameter defines the maximum wall‑clock time a call to the language model may take before abortion. The default is 300 seconds (5 minutes).

In strix/config/config.py line 24, the default is registered under the key llm_timeout. At runtime, strix/llm/config.py line 33 resolves this value inside the LLMConfig constructor, applying it to the underlying HTTP client.

export LLM_TIMEOUT="600"  # 10 minutes

Retry Count for Transient Failures

The strix_llm_max_retries parameter controls how many times the framework re‑attempts an LLM request after transient failures (network blips, rate limits). The default is 5 attempts.

This value is defined in strix/config/config.py line 22 and consumed in strix/llm/llm.py line 57, where the LLM.generate method implements the retry loop.

export STRIX_LLM_MAX_RETRIES="8"

Configuring Sandbox Resource Limits

Execution and Connection Timeouts

Sandboxed tools (e.g., port scanners, OS queries) run inside Docker containers governed by DockerRuntime in strix/runtime/docker_runtime.py. Two parameters control these operations:

  • strix_sandbox_execution_timeout – Hard limit on how long a tool may run inside the container (default: 120 seconds).
  • strix_sandbox_connect_timeout – Maximum time to establish a connection to the container (default: 10 seconds).

Both are defined in strix/config/config.py lines 45–46 and enforced at line 132 of strix/runtime/docker_runtime.py when the runtime creates the container.

export STRIX_SANDBOX_EXECUTION_TIMEOUT="300"  # 5 minutes

export STRIX_SANDBOX_CONNECT_TIMEOUT="20"     # 20 seconds

Practical Configuration Examples

Quick Environment Variable Setup

For a one‑off scan with extended limits, export the variables before invoking the CLI:

export LLM_TIMEOUT="600"
export STRIX_LLM_MAX_RETRIES="8"
export STRIX_SANDBOX_EXECUTION_TIMEOUT="300"
export STRIX_SANDBOX_CONNECT_TIMEOUT="20"

strix --target ./myapp

Persistent JSON Configuration

Save the following to ~/.strix/cli-config.json to apply these settings to every subsequent scan:

{
  "env": {
    "LLM_TIMEOUT": "600",
    "STRIX_LLM_MAX_RETRIES": "8",
    "STRIX_SANDBOX_EXECUTION_TIMEOUT": "300",
    "STRIX_SANDBOX_CONNECT_TIMEOUT": "20"
  }
}

Strix automatically loads this file on startup via Config.apply_saved.

CI Pipeline Overrides

For ephemeral build environments, inline the environment variables directly before the command:

STRIX_LLM_MAX_RETRIES=10 STRIX_SANDBOX_EXECUTION_TIMEOUT=600 strix \
  --target ./service \
  --scan-mode deep

Summary

  • LLM timeout defaults to 300 seconds and is configured via LLM_TIMEOUT, resolved in strix/llm/config.py.
  • LLM retries default to 5 attempts via STRIX_LLM_MAX_RETRIES, implemented in the retry loop at strix/llm/llm.py line 57.
  • Sandbox limits default to 120 seconds execution and 10 seconds connection, enforced in strix/runtime/docker_runtime.py line 132.
  • Configuration sources include environment variables or ~/.strix/cli-config.json, both handled by the central Config class.

Frequently Asked Questions

What is the default LLM timeout in Strix?

The default LLM timeout is 300 seconds (5 minutes). This value is defined in strix/config/config.py line 24 and applied to the HTTP client in strix/llm/config.py line 33.

How many times does Strix retry failed LLM requests?

By default, Strix retries failed requests 5 times. You can override this with the STRIX_LLM_MAX_RETRIES environment variable. The retry logic resides in the LLM.generate method at strix/llm/llm.py line 57.

Can I configure Strix without using environment variables?

Yes. Create a JSON file at ~/.strix/cli-config.json containing an env object with the desired keys. Strix loads this automatically on startup through Config.apply_saved, applying the settings without requiring shell exports.

Where does Strix enforce sandbox resource limits?

Sandbox limits are enforced in strix/runtime/docker_runtime.py at line 132, where the DockerRuntime class reads strix_sandbox_execution_timeout and strix_sandbox_connect_timeout to configure Docker container timeouts.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →