echoIRCd/echoircd.conf.example

82 lines
3.5 KiB
Text

# echoIRCd config — simple key = value (repeat `motd` for extra lines).
# Copy this file to `echoircd.conf` and fill in your own values.
# NOTE: echoircd.conf is gitignored because it holds secrets (oper password,
# cloak key, link password). Never commit your real config.
servername = irc.example.net
network = ExampleNet
bind = 0.0.0.0:6667
# TLS listener. Generate a cert/key first, e.g.:
# openssl req -x509 -newkey rsa:2048 -keyout tls/key.pem -out tls/cert.pem \
# -days 3650 -nodes -subj "/CN=irc.example.net"
bind_tls = 0.0.0.0:6697
tls_cert = ./tls/cert.pem
tls_key = ./tls/key.pem
motd = Welcome to echoIRCd — a from-scratch IRC daemon in Rust.
motd = Edit the MOTD in your echoircd.conf.
# --- server-to-server linking ---
sid = 0AA
serverdesc = echoIRCd server
bind_server = 0.0.0.0:7000
# link = <name> <ip> <port> <password> [autoconnect] (the password is a shared secret)
# link = peer.example.net 203.0.113.5 7000 CHANGE_THIS_LINK_SECRET autoconnect
# services: the linked server that handles SASL (client AUTHENTICATE is relayed to
# it). Leave unset to disable SASL. SASL EXTERNAL additionally needs the client on
# TLS with a client certificate (its fingerprint is sent to services).
# sasl_server = services.example.net
# trusted web gateways (CGI:IRC / kiwiirc-style): they send WEBIRC to declare the
# real client's host+ip. webirc = <password> [gateway-name] [ip-mask]; the ip-mask
# restricts which source IP may use the password (recommended). Repeat for more.
# webirc = CHANGE_THIS_WEBIRC_SECRET mygateway 203.0.113.9
# IRC operators — oper = <name> <password>
oper = admin CHANGE_THIS_PASSWORD
# host-cloaking secret (+x). Use a long random hex string; keep it private.
# Changing it re-cloaks everyone.
cloak_key = CHANGE_THIS_TO_A_LONG_RANDOM_HEX_STRING
# reverse-DNS clients on connect (the "*** Looking up your hostname..." notices).
# on (default) performs the lookup and reports the result; off skips it (bare IP).
resolve_hosts = on
# whether a resolved hostname is used in the hostmask (nick!user@host). on (default)
# shows the domain; off keeps the IP in the mask even though the lookup still runs
# and reports "Found your hostname". Only matters when resolve_hosts = on.
use_resolved_host = on
# DNS blocklist (DNSBL) checks on connect, like InspIRCd's m_dnsbl. Repeat `dnsbl`
# for multiple zones. On a listing, `dnsbl_action` decides what happens:
# mark = just show the "*** ... LISTED" notice, let them in (default, safe)
# kill = disconnect them (no persistent ban)
# kline / gline / zline = add a 1-day ban and disconnect
# (leave commented to disable DNSBL entirely)
# dnsbl = dnsbl.dronebl.org
# dnsbl = rbl.efnetrbl.org
# dnsbl_action = mark
# dnsbl_reason = Your host is listed in a DNS blocklist
# antimixedutf8 — block spam that mixes look-alike scripts within words.
# action = block | kill | gline | kline | zline ; target = both | channel | private
antimixedutf8 = off
amu_threshold = 8
amu_minlen = 10
amu_action = block
amu_target = both
# +G censor words: `badword = <find> [replacement]` (omit replacement to block).
# badword = examplebadword ***
# --- OPERMOTD: message shown to opers via /OPERMOTD (one line per entry) ---
# opermotd = Welcome to the staff team.
# --- self-service vhosts: /VHOST <user> <pass> sets your displayed host ---
# vhost = alice s3cret alice.staff.example
# --- command aliases: /NS ... -> PRIVMSG <target> :... (services shortcuts) ---
# alias = NS NickServ
# alias = CS ChanServ