mirror of
https://github.com/Shik3i/KoalaSync.git
synced 2026-08-08 10:23:19 +00:00
move example configs to examples/ dir
This commit is contained in:
@@ -0,0 +1,83 @@
|
||||
# ==============================================================================
|
||||
# KoalaSync - Production Caddy Configuration Example
|
||||
# ==============================================================================
|
||||
# This file provides examples of both a lightweight "Simple" configuration
|
||||
# and a production-hardened "Advanced" configuration.
|
||||
# Replace domains, reverse proxy locations, and directories with your actual setup.
|
||||
|
||||
# ------------------------------------------------------------------------------
|
||||
# OPTION A: Simple Configuration
|
||||
# ------------------------------------------------------------------------------
|
||||
# Minimal configuration that serves the static website, enables gzip compression,
|
||||
# supports extension-less Clean URLs, and reverse proxies the relay server.
|
||||
|
||||
# sync.koalastuff.net {
|
||||
# root * /var/www/koalasync/website/www
|
||||
# encode zstd gzip
|
||||
#
|
||||
# # Clean URLs support (resolves /join to join.html, etc.)
|
||||
# try_files {path} {path}.html {path}/
|
||||
# file_server
|
||||
# }
|
||||
#
|
||||
# syncserver.koalastuff.net {
|
||||
# reverse_proxy localhost:3000
|
||||
# }
|
||||
|
||||
|
||||
# ------------------------------------------------------------------------------
|
||||
# OPTION B: Advanced Configuration (Production-Hardened)
|
||||
# ------------------------------------------------------------------------------
|
||||
# Highly secure, optimized configuration using advanced HTTP security headers,
|
||||
# aggressive static assets caching, server signature concealment, and strict
|
||||
# hardware permission access policies.
|
||||
|
||||
(security_headers) {
|
||||
header {
|
||||
# Enable HTTP Strict Transport Security (HSTS)
|
||||
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
||||
# Prevent clickjacking attacks (Sameorigin)
|
||||
X-Frame-Options "SAMEORIGIN"
|
||||
# Prevent MIME-sniffing
|
||||
X-Content-Type-Options "nosniff"
|
||||
# Enable browser XSS protection
|
||||
X-XSS-Protection "1; mode=block"
|
||||
# Control referrer information
|
||||
Referrer-Policy "strict-origin-when-cross-origin"
|
||||
# Hide Caddy server stamp signature
|
||||
-Server
|
||||
}
|
||||
}
|
||||
|
||||
sync.koalastuff.net {
|
||||
encode zstd gzip
|
||||
root * /var/www/koalasync/website/www
|
||||
|
||||
# Clean URLs: Resolves paths without .html in the URL
|
||||
try_files {path} {path}.html {path}/
|
||||
file_server
|
||||
|
||||
# Static Caching for high-performance PageSpeed (1 year with validation)
|
||||
@static {
|
||||
file
|
||||
path *.ico *.css *.js *.png *.svg *.webp *.avif
|
||||
}
|
||||
header @static Cache-Control "public, max-age=31536000, must-revalidate"
|
||||
|
||||
# Security Headers & Content Security Policy (CSP)
|
||||
import security_headers
|
||||
header {
|
||||
# CSP hardened with base-uri and form-action limits
|
||||
Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self'; img-src 'self' data:; object-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none';"
|
||||
|
||||
# Modern Permissions Policy (blocks browser hardware access for enhanced privacy)
|
||||
Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()"
|
||||
}
|
||||
}
|
||||
|
||||
syncserver.koalastuff.net {
|
||||
import security_headers
|
||||
encode zstd gzip
|
||||
reverse_proxy KoalaSync:3000
|
||||
}
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
services: # Top-level key defining all containers in this Compose file
|
||||
koala-sync: # Name of the KoalaSync service
|
||||
image: ghcr.io/shik3i/koalasync:latest # Pulls the latest KoalaSync image from GitHub Container Registry
|
||||
container_name: KoalaSync # Sets a fixed container name instead of an auto-generated one
|
||||
restart: always # Always restart the container if it stops or if Docker starts
|
||||
environment: # Environment variables passed into the container
|
||||
- TZ=Europe/Berlin # Sets the timezone inside the container
|
||||
- PORT=3000 # Port KoalaSync listens on inside the container
|
||||
- MIN_VERSION=1.0.0 # Minimum client version allowed to connect
|
||||
- MAX_ROOMS=100 # Maximum number of rooms that can exist
|
||||
- MAX_PEERS_PER_ROOM=25 # Maximum number of peers allowed per room
|
||||
- ADMIN_METRICS_TOKEN= # Optional: 32+ char random token for aggregate-only /health metrics
|
||||
pids_limit: 2048 # Limits the container to 2048 process IDs for safety
|
||||
networks: # Attaches the service to the networks listed below
|
||||
- caddy_net # Joins the pre-existing Caddy network for reverse proxying
|
||||
networks: # Top-level networks definition
|
||||
caddy_net: # Network name as referenced by the service
|
||||
external: true # Marks the network as managed outside of Compose (created by Caddy)
|
||||
@@ -0,0 +1,22 @@
|
||||
services: # Top-level key defining all containers in this Compose file
|
||||
koala-sync: # Name of the KoalaSync service
|
||||
image: ghcr.io/shik3i/koalasync:latest # Pulls the latest KoalaSync image from GitHub Container Registry
|
||||
container_name: KoalaSync # Sets a fixed container name instead of an auto-generated one
|
||||
restart: always # Always restart the container if it stops or if Docker starts
|
||||
ports: # Exposes the container port to the host
|
||||
- "3000:3000" # Maps host port 3000 to container port 3000
|
||||
environment: # Environment variables passed into the container
|
||||
- TZ=Europe/Berlin # Sets the timezone inside the container
|
||||
- PORT=3000 # Port KoalaSync listens on inside the container
|
||||
- MIN_VERSION=1.0.0 # Minimum client version allowed to connect
|
||||
- MAX_ROOMS=100 # Maximum number of rooms that can exist
|
||||
- MAX_PEERS_PER_ROOM=25 # Maximum number of peers allowed per room
|
||||
- ADMIN_METRICS_TOKEN= # Optional: 32+ char random token for aggregate-only /health metrics
|
||||
pids_limit: 2048 # Limits the container to 2048 process IDs for safety
|
||||
networks: # Attaches the service to the networks listed below
|
||||
bond0_network: # Network name as referenced by the service
|
||||
ipv4_address: 192.168.1.XXX # Static IPv4 address for the KoalaSync container
|
||||
networks: # Top-level networks definition
|
||||
bond0_network: # Network name inside Compose
|
||||
external: true # Marks the network as managed outside of Compose
|
||||
name: bond0 # Name of the pre-existing network on the Docker host
|
||||
@@ -0,0 +1,79 @@
|
||||
# Prometheus Community JSON Exporter Configuration Example
|
||||
# File: examples/json_exporter.example.yml
|
||||
#
|
||||
# Use this configuration to map KoalaSync admin health metrics (JSON)
|
||||
# to native Prometheus metrics.
|
||||
#
|
||||
# Usage:
|
||||
# 1. Rename this file to json_exporter.yml
|
||||
# 2. Replace "YOUR_ADMIN_METRICS_TOKEN" with your actual ADMIN_METRICS_TOKEN env value
|
||||
# 3. Mount it to the json-exporter docker container: /config.yml
|
||||
|
||||
modules:
|
||||
koalasync:
|
||||
http_client_config:
|
||||
bearer_token: "YOUR_ADMIN_METRICS_TOKEN"
|
||||
metrics:
|
||||
- name: koalasync_uptime_seconds
|
||||
path: '{.uptime}'
|
||||
help: "Uptime of the KoalaSync relay server in seconds"
|
||||
|
||||
- name: koalasync_rooms
|
||||
path: '{.rooms}'
|
||||
help: "Total active rooms"
|
||||
|
||||
- name: koalasync_connections
|
||||
path: '{.connections}'
|
||||
help: "Total active socket connections (sockets)"
|
||||
|
||||
- name: koalasync_peers
|
||||
path: '{.peers}'
|
||||
help: "Total connected peers across all rooms"
|
||||
|
||||
- name: koalasync_rooms_with_lobby
|
||||
path: '{.roomsWithLobby}'
|
||||
help: "Number of rooms waiting in an episode lobby"
|
||||
|
||||
- name: koalasync_avg_peers_per_room
|
||||
path: '{.avgPeersPerRoom}'
|
||||
help: "Average number of peers per room"
|
||||
|
||||
- name: koalasync_max_peers_in_room
|
||||
path: '{.maxPeersInRoom}'
|
||||
help: "Maximum number of peers in a single room"
|
||||
|
||||
- name: koalasync_memory_rss_bytes
|
||||
path: '{.memory.rss}'
|
||||
help: "Resident Set Size (RSS) memory usage in bytes"
|
||||
|
||||
- name: koalasync_memory_heap_used_bytes
|
||||
path: '{.memory.heapUsed}'
|
||||
help: "V8 engine heap used in bytes"
|
||||
|
||||
- name: koalasync_memory_heap_total_bytes
|
||||
path: '{.memory.heapTotal}'
|
||||
help: "V8 engine heap total in bytes"
|
||||
|
||||
- name: koalasync_rate_limit_connections
|
||||
path: '{.rateLimitEntries.connections}'
|
||||
help: "Number of entries tracked in the connection rate limiter"
|
||||
|
||||
- name: koalasync_rate_limit_events
|
||||
path: '{.rateLimitEntries.events}'
|
||||
help: "Number of entries in the event rate limiter"
|
||||
|
||||
- name: koalasync_rate_limit_health
|
||||
path: '{.rateLimitEntries.health}'
|
||||
help: "Number of entries in the health rate limiter"
|
||||
|
||||
- name: koalasync_rate_limit_admin_metrics_auth
|
||||
path: '{.rateLimitEntries.adminMetricsAuth}'
|
||||
help: "Number of entries in the admin metrics auth rate limiter"
|
||||
|
||||
- name: koalasync_rate_limit_auth_failures
|
||||
path: '{.rateLimitEntries.authFailures}'
|
||||
help: "Number of entries in the authentication failures cache"
|
||||
|
||||
- name: koalasync_rate_limit_room_list
|
||||
path: '{.rateLimitEntries.roomList}'
|
||||
help: "Number of entries in the room list cooldown cache"
|
||||
Reference in New Issue
Block a user