By default fedserv owns accounts itself — nothing changes, no external
service required. Set [auth] external = true and an outside authority (the
website) owns identity instead: NickServ REGISTER / DROP / SET
PASSWORD|EMAIL / RESETPASS / CONFIRM / CERT / GROUP and the IRCv3
registration relay are all refused ("managed on the website"), so IRC
can't mint or change a second identity. Login is unchanged — fedserv still
authenticates locally against the accounts the authority pushes in via the
existing gRPC Accounts API, so lookups stay in-memory fast.
fedserv keeps owning all IRC-domain data (channels, access, vhosts, bans,
memos) keyed by the account name in both modes. One config bool, off by
default, so standalone deployments are unaffected.
86 lines
3.8 KiB
TOML
86 lines
3.8 KiB
TOML
# Copy to config.toml and edit. config.toml is gitignored (holds the link password).
|
|
|
|
[uplink]
|
|
host = "127.0.0.1"
|
|
port = 7000
|
|
password = "changeme" # must match the <link> block on the uplink IRCd
|
|
|
|
[server]
|
|
name = "services.example.net"
|
|
sid = "42S" # 3 chars, unique on the network
|
|
description = "Federated Services"
|
|
protocol = 1206 # InspIRCd link protocol version (1206 = insp4, 1205 = insp3)
|
|
|
|
# Node-to-node replication. Omit this section (and [[peer]]) to run a single node.
|
|
# [gossip]
|
|
# bind = "0.0.0.0:16700" # where peers reach us; omit for a dial-only node
|
|
# secret = "shared-secret" # both nodes must present the same secret
|
|
#
|
|
# [gossip.tls] # omit for a plaintext link; see scripts/gen-certs.sh
|
|
# cert = "certs/node.crt"
|
|
# key = "certs/node.key"
|
|
# ca = "certs/ca.crt" # a peer must present a certificate signed by this CA
|
|
#
|
|
# [[peer]] # one block per other node
|
|
# addr = "other-node:16700"
|
|
# name = "other-node" # TLS name to expect; must match the peer certificate
|
|
|
|
# Directory replication (gRPC) — lets a website mirror the account/channel
|
|
# directory (identity + metadata only, never credentials; see proto/fedserv.proto).
|
|
# Omit this section to run without it.
|
|
# [grpc]
|
|
# bind = "127.0.0.1:50051" # a private network hop is the expected deployment
|
|
# token = "shared-secret" # every RPC must send `authorization: Bearer <token>`
|
|
#
|
|
# [grpc.tls] # omit for plaintext (fine on a private/loopback hop)
|
|
# cert = "certs/node.crt"
|
|
# key = "certs/node.key"
|
|
|
|
# Which service modules to start. Omit this section for the built-in NickServ +
|
|
# ChanServ. Add "example" to also start the example template service.
|
|
# [modules]
|
|
# services = ["nickserv", "chanserv"]
|
|
|
|
# Services operators: accounts granted privileges. Omit for a network with no
|
|
# opers. Privileges: "auspex" (see others' hidden info), "suspend"
|
|
# (suspend/unsuspend), "admin" (modify or drop other accounts/channels).
|
|
# [[oper]]
|
|
# account = "yournick"
|
|
# privs = ["auspex", "suspend", "admin"]
|
|
|
|
# Staff audit feed: notable service actions (registrations, drops, vhosts,
|
|
# suspensions, akicks, access and bot changes, oper host config) are announced
|
|
# to this channel so operators can see who did what. Private material (memo
|
|
# bodies, password/verifier data) and cosmetic self-service tweaks are never
|
|
# surfaced. Omit the section to disable the feed.
|
|
# [log]
|
|
# channel = "#services"
|
|
|
|
# Inactivity-expiry: accounts not identified to, and channels not joined, for
|
|
# longer than the threshold are dropped on a periodic pass (opers, live
|
|
# sessions, occupied channels, and NOEXPIRE-pinned records are spared). A zero
|
|
# or omitted field leaves that kind never expiring. Omit the section to disable
|
|
# expiry entirely.
|
|
# [expire]
|
|
# accounts_days = 90
|
|
# channels_days = 30
|
|
# warn_days sends the owner a heads-up email this many days before expiry (only
|
|
# where an address is on file and [email] is configured); 0 or omitted = no
|
|
# warning email.
|
|
# warn_days = 7
|
|
|
|
# Per-IP session limiting: the connection that puts an IP over `default_limit`
|
|
# is killed on connect. OperServ EXCEPTION entries raise or lower the allowance
|
|
# per IP-mask (an exception limit of 0 means unlimited). 0 or omitted = off.
|
|
# [session]
|
|
# default_limit = 3
|
|
|
|
# Account authority. Omit this section (the default) and fedserv owns accounts
|
|
# itself: NickServ REGISTER / IDENTIFY / SET PASSWORD all work standalone, no
|
|
# external service needed. Set external = true to hand identity to an outside
|
|
# authority (e.g. your website): IRC can then only IDENTIFY — REGISTER, DROP,
|
|
# SET PASSWORD/EMAIL, RESETPASS, CONFIRM, CERT and GROUP are refused, and the
|
|
# authority pushes accounts in via the gRPC Accounts API (see [grpc]). fedserv
|
|
# still owns all channel/vhost/ban data, keyed by the account name.
|
|
# [auth]
|
|
# external = true
|