I've been finding plain JavaScript as a very nice alternative to the many config file formats out there. It already has the trailing commas + comments bells and whistles, plus the ability to do computation to generate repetitive elements. Of course there's always the danger of the user creating a monstrosity of a 'config file' but if they're the ones using the software that consumes the config file, that's on them to keep the config file complexity down. Go already has a very useful JavaScript engine written in pure Go (goja), I recently opted for that as the config file format over templated JSON/TOML/HJSON or Starlark/Tengo because JavaScript is well defined and expressive. I'm thinking it will be a good choice for an authorization rules engine as well (over custom DSLs like OPA/Casbin) because using it is so much simpler if the user already knows JavaScript.