-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathconfig.example.yaml
More file actions
50 lines (41 loc) · 2.55 KB
/
Copy pathconfig.example.yaml
File metadata and controls
50 lines (41 loc) · 2.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
# pktNode configuration
# Copy to <install_dir>/config.yaml, or set PKTNODE_CONFIG=/path/to/config.yaml,
# then restart the service.
#
# install.sh generates config.yaml from this file automatically, fills in
# secret_key + credential_key, and appends install_dir — edit config.yaml
# afterwards for any further changes.
#
# install_dir is the app root. Every on-disk path below (db_path, log_file,
# ssl_dir) defaults to somewhere under install_dir and does NOT need to be
# set explicitly — only uncomment one if you need that particular path to
# live somewhere else.
#
# Most runtime settings (alert thresholds, notifications, enrollment tokens,
# etc.) are managed via the Settings page in the UI and stored in SQLite.
# This file only covers infrastructure/startup settings.
# ── Server ────────────────────────────────────────────────────────────────────
host: "0.0.0.0"
port: 8764
workers: 2
debug: false
# ── App root — install.sh appends this automatically ──────────────────────────
# install_dir: "/opt/pktnode"
# ── SQLite app database (optional override; default: <install_dir>/pktnode.db) ─
# db_path: "/opt/pktnode/pktnode.db"
# ── How long without a check-in before a node flips online -> offline/stale ───
offline_after_sec: 300
stale_after_sec: 86400
# ── JWT (generate with: openssl rand -hex 32) ─────────────────────────────────
secret_key: "CHANGE_ME_generate_with_openssl_rand_hex_32"
# ── Credential encryption key (generate with the Fernet command below) ───────
# python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
credential_key: "CHANGE_ME_generate_with_fernet_generate_key"
# ── CORS (restrict to your actual origin in production) ──────────────────────
cors_origins:
- "http://SERVER-IP:8764"
# ── Logging ───────────────────────────────────────────────────────────────────
log_level: "info"
# log_file: "/opt/pktnode/logs/pktnode.log" # optional override; default: <install_dir>/logs/pktnode.log
# ── SSL certificates (optional override; default: <install_dir>/ssl) ──────────
# ssl_dir: "/opt/pktnode/ssl"