echo/config.example.toml

114 lines
5.5 KiB
TOML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Copy to config.toml and edit. config.toml is gitignored (holds the link password).
[uplink]
host = "127.0.0.1"
port = 7000
password = "changeme" # must match the <link> block on the uplink IRCd
[server]
name = "services.example.net"
sid = "42S" # 3 chars, unique on the network
description = "Federated Services"
protocol = 1206 # InspIRCd link protocol version (1206 = insp4, 1205 = insp3)
# Node-to-node replication. Omit this section (and [[peer]]) to run a single node.
# [gossip]
# bind = "0.0.0.0:16700" # where peers reach us; omit for a dial-only node
# secret = "shared-secret" # both nodes must present the same secret
#
# [gossip.tls] # omit for a plaintext link; see scripts/gen-certs.sh
# cert = "certs/node.crt"
# key = "certs/node.key"
# ca = "certs/ca.crt" # a peer must present a certificate signed by this CA
#
# [[peer]] # one block per other node
# addr = "other-node:16700"
# name = "other-node" # TLS name to expect; must match the peer certificate
# Directory replication (gRPC) — lets a website mirror the account/channel
# directory (identity + metadata only, never credentials; see proto/echo.proto).
# Omit this section to run without it.
# [grpc]
# bind = "127.0.0.1:50051" # a private network hop is the expected deployment
# token = "shared-secret" # every RPC must send `authorization: Bearer <token>`
#
# [grpc.tls] # omit for plaintext (fine on a private/loopback hop)
# cert = "certs/node.crt"
# key = "certs/node.key"
# Which service modules to start. Omit this section for the full standard suite
# (every service comes up by default). List names here to run a subset; add
# "example" to also start the example template service.
# [modules]
# services = ["nickserv", "chanserv"]
# Services operators: accounts granted privileges. Omit for a network with no
# opers. Privileges: "auspex" (see others' hidden info), "suspend"
# (suspend/unsuspend), "admin" (modify or drop other accounts/channels).
# [[oper]]
# account = "yournick"
# privs = ["auspex", "suspend", "admin"]
# Staff audit feed: notable service actions (registrations, drops, vhosts,
# suspensions, akicks, access and bot changes, oper host config) are announced
# to this channel so operators can see who did what. Private material (memo
# bodies, password/verifier data) and cosmetic self-service tweaks are never
# surfaced. Omit the section to disable the feed.
# [log]
# channel = "#services"
# Masks OperServ NOTIFY never announces, so they can't flood the feed. Three kinds:
# "#channel" mute a channel (keep a broad `#*` watch out of "#staff")
# "server:<glob>" mute everyone on a server (a relay whose users have clean
# nicks; alias "via:", matching the "via <server>" in the feed)
# anything else mute a user — nick glob, user@host, or extban ("*/*" catches
# PyLink relays that suffix nicks with /network)
# Reloadable with OperServ REHASH.
# notify_exclude = ["*/*", "server:chatnova.relay", "#staff"]
# Inactivity-expiry: accounts not identified to, and channels not joined, for
# longer than the threshold are dropped on a periodic pass (opers, live
# sessions, occupied channels, and NOEXPIRE-pinned records are spared). A zero
# or omitted field leaves that kind never expiring. Omit the section to disable
# expiry entirely.
# [expire]
# accounts_days = 90
# channels_days = 30
# warn_days sends the owner a heads-up email this many days before expiry (only
# where an address is on file and [email] is configured); 0 or omitted = no
# warning email.
# warn_days = 7
# Per-IP session limiting: the connection that puts an IP over `default_limit`
# is killed on connect. OperServ EXCEPTION entries raise or lower the allowance
# per IP-mask (an exception limit of 0 means unlimited). 0 or omitted = off.
# [session]
# default_limit = 3
# Account authority. Omit this section (the default) and Echo owns accounts
# itself: NickServ REGISTER / IDENTIFY / SET PASSWORD all work standalone, no
# external service needed. Set external = true to hand identity to an outside
# authority (e.g. your website): IRC can then only IDENTIFY — REGISTER, DROP,
# SET PASSWORD/EMAIL, RESETPASS, CONFIRM, CERT and GROUP are refused, and the
# authority pushes accounts in via the gRPC Accounts API (see [grpc]). Echo
# still owns all channel/vhost/ban data, keyed by the account name.
# [auth]
# external = true
# DictServ: dictionary / thesaurus / reference lookups over the DICT protocol
# (RFC 2229). Present = the service loads and channel bots answer !dict, !define,
# !thes, !acronym, !law, !element, !bible, and friends (DictServ LOOKUP lists them
# all); also queryable directly with /msg DictServ <cmd> <term>. Omit it and echo
# makes no outbound lookups at all — this is opt-in because it reaches the network.
# Lookups are globally rate-limited and the reply is truncated to one line. The log
# channel is unaffected; keep this off if you don't want echo talking to dict.org.
# [dictserv]
# server = "dict.org:2628"
# Registration policy. The look-alike guard refuses REGISTER of a nick or channel
# that mixes alphabets (Cyrillic "аdmin"), is built from homoglyphs or styled
# (fullwidth/math) letters imitating Latin, or hides invisible/bidi characters —
# while genuine monolingual text (including accented French) passes. It's on by
# default; turn it off for a community that legitimately uses mixed/non-Latin
# names. Reloadable with OperServ REHASH.
# [register]
# confusable_check = false