mirror of
https://github.com/openziti/ziti.git
synced 2026-10-07 21:31:16 +00:00
255 lines
11 KiB
YAML
255 lines
11 KiB
YAML
v: 3
|
|
|
|
network:
|
|
# Sets router minimum cost. Defaults to 10
|
|
minRouterCost: 10
|
|
|
|
# Sets how often a new control channel connection can take over for a router with an existing control channel connection
|
|
# Defaults to 1 minute
|
|
routerConnectChurnLimit: 1m
|
|
|
|
#trace:
|
|
# path: ctrl.trace
|
|
|
|
profile:
|
|
# cpu:
|
|
# path: /home/plorenz/tmp/ctrl.cpu.pprof
|
|
# memory:
|
|
# path: ctrl.memprof
|
|
|
|
db: ${ZITI_DATA}/db/ctrl.db
|
|
|
|
identity:
|
|
cert: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/certs/ctrl-client.cert.pem
|
|
server_cert: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/certs/ctrl-server.cert.pem
|
|
key: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/private/ctrl.key.pem
|
|
ca: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/certs/ca-chain.cert.pem
|
|
|
|
# the endpoint that routers will connect to the controller over.
|
|
ctrl:
|
|
listener: tls:127.0.0.1:6262
|
|
options:
|
|
# (optional) settings
|
|
# set the maximum number of connect requests that are buffered and waiting to be acknowledged (1 to 5000, default 1000)
|
|
#maxQueuedConnects: 50
|
|
|
|
# the maximum number of connects that have begun hello synchronization (1 to 1000, default 16)
|
|
#maxOutstandingConnects: 100
|
|
|
|
# the number of milliseconds to wait before a hello synchronization fails and closes the connection (30ms to 60000ms, default: 1000ms)
|
|
#connectTimeoutMs: 3000
|
|
|
|
# Sets the control channel write timeout. A write timeout will close the control channel, so the router will reconnect
|
|
#writeTimeout: 15s
|
|
|
|
# A listener address which will be sent to connecting routers in order to change their configured controller
|
|
# address. If defined, routers will update address configuration to immediately use the new address for future
|
|
# connections. The value of newListener must be resolvable both via DNS and validate via certificates
|
|
#newListener: tls:localhost:6262
|
|
|
|
#events:
|
|
# jsonLogger:
|
|
# subscriptions:
|
|
# - type: entityChange
|
|
# include:
|
|
# - services
|
|
# - identities
|
|
# - type: fabric.circuits
|
|
# - type: fabric.links
|
|
# - type: fabric.routers
|
|
# - type: fabric.terminators
|
|
# - type: metrics
|
|
# sourceFilter: .*
|
|
# metricFilter: .*
|
|
# - type: edge.sessions
|
|
# - type: edge.apiSessions
|
|
# - type: fabric.usage
|
|
# version: 3
|
|
# include:
|
|
# - ingress.rx
|
|
# - egress.rx
|
|
# - type: services
|
|
# - type: edge.entityCounts
|
|
# interval: 5s
|
|
# handler:
|
|
# type: file
|
|
# format: json
|
|
# path: /tmp/ziti-events.log
|
|
# usageLogger:
|
|
# subscriptions:
|
|
# - type: fabric.usage
|
|
# interval: 5s
|
|
# handler:
|
|
# type: amqp
|
|
# format: json
|
|
# url: "amqp://localhost:5672"
|
|
# queue: ziti
|
|
# durable: true //default:true
|
|
# autoDelete: false //default:false
|
|
# exclusive: false //default:false
|
|
# noWait: false //default:false
|
|
# bufferSize: 50 //default:50
|
|
|
|
# xctrl_example
|
|
#
|
|
#example:
|
|
# enabled: false
|
|
# delay: 5
|
|
|
|
healthChecks:
|
|
boltCheck:
|
|
# How often to try entering a bolt read tx. Defaults to 30 seconds
|
|
interval: 30s
|
|
# When to timeout the check. Defaults to 15 seconds
|
|
timeout: 15s
|
|
# How long to wait before starting the check. Defaults to 15 seconds
|
|
initialDelay: 15s
|
|
|
|
# By having an 'edge' section defined, the ziti-controller will attempt to parse the edge configuration. Removing this
|
|
# section, commenting out, or altering the name of the section will cause the edge to not run.
|
|
edge:
|
|
# This section allows configurating the rate limiter for auth attempts
|
|
authRateLimiter:
|
|
# if disabled, no auth rate limiting with be enforced
|
|
enabled: true
|
|
# the smallest window size for auth attempts
|
|
minSize: 5
|
|
# the largest allowed window size for auth attempts
|
|
maxSize: 100
|
|
|
|
# This section represents the configuration of the Edge API that is served over HTTPS
|
|
api:
|
|
#(optional, default 90s) Alters how frequently heartbeat and last activity values are persisted
|
|
# activityUpdateInterval: 90s
|
|
#(optional, default 250) The number of API Sessions updated for last activity per transaction
|
|
# activityUpdateBatchSize: 250
|
|
# sessionTimeout - optional, default 10m
|
|
# The number of minutes before an Edge API session will timeout. Timeouts are reset by
|
|
# API requests and connections that are maintained to Edge Routers
|
|
sessionTimeout: 30m
|
|
# address - required
|
|
# The default address (host:port) to use for enrollment for the Client API. This value must match one of the addresses
|
|
# defined in a bind point's address field for the `edge-client` API in the web section.
|
|
address: 127.0.0.1:1280
|
|
# enrollment - required
|
|
# A section containing settings pertaining to enrollment.
|
|
enrollment:
|
|
# signingCert - required
|
|
# A Ziti Identity configuration section that specifically makes use of the cert and key fields to define
|
|
# a signing certificate from the PKI that the Ziti environment is using to sign certificates. The signingCert.cert
|
|
# will be added to the /.well-known CA store that is used to bootstrap trust with the Ziti Controller.
|
|
signingCert:
|
|
cert: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/certs/intermediate.cert.pem
|
|
key: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/private/intermediate.key.decrypted.pem
|
|
# edgeIdentity - optional
|
|
# A section for identity enrollment specific settings
|
|
edgeIdentity:
|
|
# duration - optional, default 5m
|
|
# The length of time that a Ziti Edge Identity enrollment should remain valid. After
|
|
# this duration, the enrollment will expire and not longer be usable.
|
|
duration: 5m
|
|
# edgeRouter - Optional
|
|
# A section for edge router enrollment specific settings.
|
|
edgeRouter:
|
|
# duration - optional, default 5m
|
|
# The length of time that a Ziti Edge Router enrollment should remain valid. After
|
|
# this duration, the enrollment will expire and not longer be usable.
|
|
duration: 5m
|
|
|
|
|
|
# web - optional
|
|
# Defines webListeners that will be hosted by the controller. Each webListener can host many APIs and be bound to many
|
|
# bind points.
|
|
web:
|
|
# name - required
|
|
# Provides a name for this listener, used for logging output. Not required to be unique, but is highly suggested.
|
|
- name: all-apis-localhost
|
|
# bindPoints - required
|
|
# One or more bind points are required. A bind point specifies an interface (interface:port string) that defines
|
|
# where on the host machine the webListener will listen and the address (host:port) that should be used to
|
|
# publicly address the webListener(i.e. mydomain.com, localhost, 127.0.0.1). This public address may be used for
|
|
# incoming address resolution as well as used in responses in the API.
|
|
bindPoints:
|
|
#interface - required
|
|
# A host:port string on which network interface to listen on. 0.0.0.0 will listen on all interfaces
|
|
- interface: 127.0.0.1:1280
|
|
|
|
# address - required
|
|
# The public address that external incoming requests will be able to resolve. Used in request processing and
|
|
# response content that requires full host:port/path addresses.
|
|
address: 127.0.0.1:1280
|
|
|
|
# newAddress - optional
|
|
# A host:port string which will be sent out as an HTTP header "ziti-new-address" if specified. If the header
|
|
# is present, clients should update location configuration to immediately use the new address for future
|
|
# connections. The value of newAddress must be resolvable both via DNS and validate via certificates
|
|
newAddress: localhost:1280
|
|
# identity - optional
|
|
# Allows the webListener to have a specific identity instead of defaulting to the root `identity` section.
|
|
# identity:
|
|
# cert: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/certs/ctrl-client.cert.pem
|
|
# server_cert: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/certs/ctrl-server.cert.pem
|
|
# key: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/private/ctrl.key.pem
|
|
# ca: ${ZITI_SOURCE}/ziti/etc/ca/intermediate/certs/ca-chain.cert.pem
|
|
# options - optional
|
|
# Allows the specification of webListener level options - mainly dealing with HTTP/TLS settings. These options are
|
|
# used for all http servers started by the current webListener.
|
|
options:
|
|
# idleTimeout - optional, default 5000ms
|
|
# The maximum amount of idle time in milliseconds allowed for pipelined HTTP requests. Setting this too high
|
|
# can cause resources on the host to be consumed as clients remain connected and idle. Lowering this value
|
|
# will cause clients to reconnect on subsequent HTTPs requests.
|
|
idleTimeout: 5000ms #http timeouts, new
|
|
|
|
# readTimeout - optional, default 5000ms
|
|
# The maximum amount of time in milliseconds http servers will wait to read the first incoming requests. A higher
|
|
# value risks consuming resources on the host with clients that are acting bad faith or suffering from high latency
|
|
# or packet loss. A lower value can risk losing connections to high latency/packet loss clients.
|
|
|
|
readTimeout: 5000ms
|
|
# writeTimeout - optional, default 10000ms
|
|
# The total maximum time in milliseconds that the http server will wait for a single requests to be received and
|
|
# responded too. A higher value can allow long running requests to consume resources on the host. A lower value
|
|
# can risk ending requests before the server has a chance to respond.
|
|
|
|
writeTimeout: 100000ms
|
|
# minTLSVersion - optional, default TSL1.2
|
|
# The minimum version of TSL to support
|
|
|
|
minTLSVersion: TLS1.2
|
|
# maxTLSVersion - optional, default TSL1.3
|
|
# The maximum version of TSL to support
|
|
|
|
maxTLSVersion: TLS1.3
|
|
# apis - required
|
|
# Allows one or more APIs to be bound to this webListener
|
|
apis:
|
|
# binding - required
|
|
# Specifies an API to bind to this webListener. Built-in APIs are
|
|
# - health-checks
|
|
# - edge-management
|
|
# - edge-client
|
|
# - fabric-management
|
|
- binding: health-checks
|
|
options: { }
|
|
- binding: fabric
|
|
- binding: edge-management
|
|
# options - variable optional/required
|
|
# This section is used to define values that are specified by the API they are associated with.
|
|
# These settings are per API. The example below is for the `edge-api` and contains both optional values and
|
|
# required values.
|
|
options: { }
|
|
- binding: edge-client
|
|
options: { }
|
|
- binding: edge-oidc
|
|
options:
|
|
secret: 38de0de7fa283e8c8ef2a7823a6d3e727681ade50b9eb7bee2424197fb22bf18
|
|
redirectURIs:
|
|
- "http://localhost:*/auth/callback"
|
|
- "http://127.0.0.1:*/auth/callback"
|
|
- "https://oauth.pstmn.io/v1/callback"
|
|
|
|
commandRateLimiter:
|
|
enabled: true
|
|
maxQueued: 100
|