# Copy to config.toml and edit. config.toml is gitignored (holds the link password). [uplink] host = "127.0.0.1" port = 7000 password = "changeme" # must match the block on the uplink IRCd [server] name = "services.example.net" sid = "42S" # 3 chars, unique on the network description = "Federated Services" protocol = 1206 # InspIRCd link protocol version (1206 = insp4, 1205 = insp3) # Node-to-node replication. Omit this section (and [[peer]]) to run a single node. # [gossip] # bind = "0.0.0.0:16700" # where peers reach us; omit for a dial-only node # secret = "shared-secret" # both nodes must present the same secret # # [gossip.tls] # omit for a plaintext link; see scripts/gen-certs.sh # cert = "certs/node.crt" # key = "certs/node.key" # ca = "certs/ca.crt" # a peer must present a certificate signed by this CA # # [[peer]] # one block per other node # addr = "other-node:16700" # name = "other-node" # TLS name to expect; must match the peer certificate # Directory replication (gRPC) — lets a website mirror the account/channel # directory (identity + metadata only, never credentials; see proto/echo.proto). # Omit this section to run without it. # [grpc] # bind = "127.0.0.1:50051" # a private network hop is the expected deployment # token = "shared-secret" # every RPC must send `authorization: Bearer ` # # [grpc.tls] # omit for plaintext (fine on a private/loopback hop) # cert = "certs/node.crt" # key = "certs/node.key" # Which service modules to start. Omit this section for the full standard suite # (every service comes up by default). List names here to run a subset; add # "example" to also start the example template service. # [modules] # services = ["nickserv", "chanserv"] # Services operators, in three tiers of increasing power: # operator — day-to-day moderation: view hidden info, network bans, kick, # kill, session limits, ignores, mode, spam filters, log search. # administrator — the above plus account/channel data: suspend, drop, set flags, # forbid, global notices, defcon, memo/info/bot administration. # root — the above plus daemon control: add/remove opers, set, rehash, # restart, shutdown, the activity feed. # Name a tier with `type`, or list individual privileges with `privs` (auspex, # oper, suspend, admin, root). Omit the whole block for a network with no opers. # [[oper]] # account = "yournick" # type = "root" # Staff audit feed: notable service actions (registrations, drops, vhosts, # suspensions, akicks, access and bot changes, oper host config) are announced # to this channel so operators can see who did what. Private material (memo # bodies, password/verifier data) and cosmetic self-service tweaks are never # surfaced. Omit the section to disable the feed. # [log] # channel = "#services" # Masks OperServ NOTIFY never announces, so they can't flood the feed. Three kinds: # "#channel" mute a channel (keep a broad `#*` watch out of "#staff") # "server:" mute everyone on a server (a relay whose users have clean # nicks; alias "via:", matching the "via " in the feed) # anything else mute a user — nick glob, user@host, or extban ("*/*" catches # PyLink relays that suffix nicks with /network) # Reloadable with OperServ REHASH. # notify_exclude = ["*/*", "server:chatnova.relay", "#staff"] # Inactivity-expiry: accounts not identified to, and channels not joined, for # longer than the threshold are dropped on a periodic pass (opers, live # sessions, occupied channels, and NOEXPIRE-pinned records are spared). A zero # or omitted field leaves that kind never expiring. Omit the section to disable # expiry entirely. # [expire] # accounts_days = 90 # channels_days = 30 # warn_days sends the owner a heads-up email this many days before expiry (only # where an address is on file and [email] is configured); 0 or omitted = no # warning email. # warn_days = 7 # Per-IP session limiting: the connection that puts an IP over `default_limit` # is killed on connect. OperServ EXCEPTION entries raise or lower the allowance # per IP-mask (an exception limit of 0 means unlimited). 0 or omitted = off. # [session] # default_limit = 3 # Account authority. Omit this section (the default) and Echo owns accounts # itself: NickServ REGISTER / IDENTIFY / SET PASSWORD all work standalone, no # external service needed. Set external = true to hand identity to an outside # authority (e.g. your website): IRC can then only IDENTIFY — REGISTER, DROP, # SET PASSWORD/EMAIL, RESETPASS, CONFIRM, CERT and GROUP are refused, and the # authority pushes accounts in via the gRPC Accounts API (see [grpc]). Echo # still owns all channel/vhost/ban data, keyed by the account name. # [auth] # external = true # DictServ: dictionary / thesaurus / reference lookups over the DICT protocol # (RFC 2229). Present = the service loads and channel bots answer !dict, !define, # !thes, !acronym, !law, !element, !bible, and friends (DictServ LOOKUP lists them # all); also queryable directly with /msg DictServ . Omit it and echo # makes no outbound lookups at all — this is opt-in because it reaches the network. # Lookups are globally rate-limited and the reply is truncated to one line. The log # channel is unaffected; keep this off if you don't want echo talking to dict.org. # [dictserv] # server = "dict.org:2628" # Registration policy. The look-alike guard refuses REGISTER of a nick or channel # that mixes alphabets (Cyrillic "аdmin"), is built from homoglyphs or styled # (fullwidth/math) letters imitating Latin, or hides invisible/bidi characters — # while genuine monolingual text (including accented French) passes. It's on by # default; turn it off for a community that legitimately uses mixed/non-Latin # names. Reloadable with OperServ REHASH. # [register] # confusable_check = false