127 lines
6.2 KiB
TOML
127 lines
6.2 KiB
TOML
# Copy to config.toml and edit. config.toml is gitignored (holds the link password).
|
||
|
||
[uplink]
|
||
host = "127.0.0.1"
|
||
port = 7000
|
||
password = "changeme" # must match the <link> block on the uplink IRCd
|
||
|
||
[server]
|
||
name = "services.example.net"
|
||
sid = "42S" # 3 chars, unique on the network
|
||
description = "Federated Services"
|
||
protocol = 1206 # InspIRCd link protocol version (1206 = insp4, 1205 = insp3)
|
||
|
||
# Node-to-node replication. Omit this section (and [[peer]]) to run a single node.
|
||
# [gossip]
|
||
# bind = "0.0.0.0:16700" # where peers reach us; omit for a dial-only node
|
||
# secret = "shared-secret" # both nodes must present the same secret
|
||
#
|
||
# [gossip.tls] # omit for a plaintext link; see scripts/gen-certs.sh
|
||
# cert = "certs/node.crt"
|
||
# key = "certs/node.key"
|
||
# ca = "certs/ca.crt" # a peer must present a certificate signed by this CA
|
||
#
|
||
# [[peer]] # one block per other node
|
||
# addr = "other-node:16700"
|
||
# name = "other-node" # TLS name to expect; must match the peer certificate
|
||
|
||
# Directory replication (gRPC) — lets a website mirror the account/channel
|
||
# directory (identity + metadata only, never credentials; see proto/echo.proto).
|
||
# Omit this section to run without it.
|
||
# [grpc]
|
||
# bind = "127.0.0.1:50051" # a private network hop is the expected deployment
|
||
# token = "shared-secret" # every RPC must send `authorization: Bearer <token>`
|
||
#
|
||
# [grpc.tls] # omit for plaintext (fine on a private/loopback hop)
|
||
# cert = "certs/node.crt"
|
||
# key = "certs/node.key"
|
||
|
||
# Liveness + Prometheus metrics (plain HTTP, read-only, unauthenticated). Omit to
|
||
# leave it off. Bind to localhost and point a monitor at it: GET /health for a
|
||
# liveness probe (JSON), GET /metrics for a scrape (gauges: account/channel/oper
|
||
# totals, per-service counters, and event.lamport — a monotonic log-progress gauge).
|
||
# [health]
|
||
# bind = "127.0.0.1:9099"
|
||
|
||
# Which service modules to start. Omit this section for the full standard suite
|
||
# (every service comes up by default). List names here to run a subset; add
|
||
# "example" to also start the example template service.
|
||
# [modules]
|
||
# services = ["nickserv", "chanserv"]
|
||
|
||
# Services operators, in three tiers of increasing power:
|
||
# operator — day-to-day moderation: view hidden info, network bans, kick,
|
||
# kill, session limits, ignores, mode, spam filters, log search.
|
||
# administrator — the above plus account/channel data: suspend, drop, set flags,
|
||
# forbid, global notices, defcon, memo/info/bot administration.
|
||
# root — the above plus daemon control: add/remove opers, set, rehash,
|
||
# restart, shutdown, the activity feed.
|
||
# Name a tier with `type`, or list individual privileges with `privs` (auspex,
|
||
# oper, suspend, admin, root). Omit the whole block for a network with no opers.
|
||
# [[oper]]
|
||
# account = "yournick"
|
||
# type = "root"
|
||
|
||
# Staff audit feed: notable service actions (registrations, drops, vhosts,
|
||
# suspensions, akicks, access and bot changes, oper host config) are announced
|
||
# to this channel so operators can see who did what. Private material (memo
|
||
# bodies, password/verifier data) and cosmetic self-service tweaks are never
|
||
# surfaced. Omit the section to disable the feed.
|
||
# [log]
|
||
# channel = "#services"
|
||
# Masks OperServ NOTIFY never announces, so they can't flood the feed. Three kinds:
|
||
# "#channel" mute a channel (keep a broad `#*` watch out of "#staff")
|
||
# "server:<glob>" mute everyone on a server (a relay whose users have clean
|
||
# nicks; alias "via:", matching the "via <server>" in the feed)
|
||
# anything else mute a user — nick glob, user@host, or extban ("*/*" catches
|
||
# PyLink relays that suffix nicks with /network)
|
||
# Reloadable with OperServ REHASH.
|
||
# notify_exclude = ["*/*", "server:chatnova.relay", "#staff"]
|
||
|
||
# Inactivity-expiry: accounts not identified to, and channels not joined, for
|
||
# longer than the threshold are dropped on a periodic pass (opers, live
|
||
# sessions, occupied channels, and NOEXPIRE-pinned records are spared). A zero
|
||
# or omitted field leaves that kind never expiring. Omit the section to disable
|
||
# expiry entirely.
|
||
# [expire]
|
||
# accounts_days = 90
|
||
# channels_days = 30
|
||
# warn_days sends the owner a heads-up email this many days before expiry (only
|
||
# where an address is on file and [email] is configured); 0 or omitted = no
|
||
# warning email.
|
||
# warn_days = 7
|
||
|
||
# Per-IP session limiting: the connection that puts an IP over `default_limit`
|
||
# is killed on connect. OperServ EXCEPTION entries raise or lower the allowance
|
||
# per IP-mask (an exception limit of 0 means unlimited). 0 or omitted = off.
|
||
# [session]
|
||
# default_limit = 3
|
||
|
||
# Account authority. Omit this section (the default) and Echo owns accounts
|
||
# itself: NickServ REGISTER / IDENTIFY / SET PASSWORD all work standalone, no
|
||
# external service needed. Set external = true to hand identity to an outside
|
||
# authority (e.g. your website): IRC can then only IDENTIFY — REGISTER, DROP,
|
||
# SET PASSWORD/EMAIL, RESETPASS, CONFIRM, CERT and GROUP are refused, and the
|
||
# authority pushes accounts in via the gRPC Accounts API (see [grpc]). Echo
|
||
# still owns all channel/vhost/ban data, keyed by the account name.
|
||
# [auth]
|
||
# external = true
|
||
|
||
# DictServ: dictionary / thesaurus / reference lookups over the DICT protocol
|
||
# (RFC 2229). Present = the service loads and channel bots answer !dict, !define,
|
||
# !thes, !acronym, !law, !element, !bible, and friends (DictServ LOOKUP lists them
|
||
# all); also queryable directly with /msg DictServ <cmd> <term>. Omit it and echo
|
||
# makes no outbound lookups at all — this is opt-in because it reaches the network.
|
||
# Lookups are globally rate-limited and the reply is truncated to one line. The log
|
||
# channel is unaffected; keep this off if you don't want echo talking to dict.org.
|
||
# [dictserv]
|
||
# server = "dict.org:2628"
|
||
|
||
# Registration policy. The look-alike guard refuses REGISTER of a nick or channel
|
||
# that mixes alphabets (Cyrillic "аdmin"), is built from homoglyphs or styled
|
||
# (fullwidth/math) letters imitating Latin, or hides invisible/bidi characters —
|
||
# while genuine monolingual text (including accented French) passes. It's on by
|
||
# default; turn it off for a community that legitimately uses mixed/non-Latin
|
||
# names. Reloadable with OperServ REHASH.
|
||
# [register]
|
||
# confusable_check = false
|