Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
61 lines (56 loc) · 3.13 KB
/
Copy path.env.example
File metadata and controls
61 lines (56 loc) · 3.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
# --- Database (PostgreSQL only) ---------------------------------------------
# Serval is PostgreSQL-exclusive. Point this at a live PostgreSQL 16+ instance.
DATABASE_URL=postgres://serval:serval@localhost:5432/serval
# Maximum pooled connections.
DATABASE_MAX_CONNECTIONS=16
# --- Servers ----------------------------------------------------------------
# Control Plane: management API + embedded React dashboard.
CONTROL_PLANE_ADDR=0.0.0.0:8080
# Data Plane: public, extreme-throughput snippet delivery.
DATA_PLANE_ADDR=0.0.0.0:3000
# Public base URL at which the Data Plane is reachable by clients, e.g.
# https://cdn.example.com. In a typical deployment the two planes sit behind
# different domains, so the dashboard cannot assume the Data Plane shares the
# Control Plane's origin. Advertised to the dashboard so it can build correct
# "copy link" delivery URLs. When unset the dashboard falls back to guessing
# `:3000` on its own hostname (handy for local dev only). No trailing slash.
# DATA_PLANE_PUBLIC_URL=https://cdn.example.com
# --- Delivery cache ---------------------------------------------------------
# Byte budget for the in-memory moka cache (bounded by weight, not entry count).
# Entries are never time-evicted: freshness rests entirely on Control Plane
# invalidation (both planes share one in-process cache handle). Entries leave
# the cache only by that invalidation or byte-budget pressure.
CACHE_BYTE_BUDGET=33554432
# --- Route-id signing (DoS mitigation) --------------------------------------
# Deployment-wide secret salt that keys the route-id MAC. Every route id is
# `BLAKE3(prefix) || keyed-MAC`, so the Data Plane can reject forged/enumerated
# ids with a constant-time check before any cache or database lookup. REQUIRED;
# the process refuses to boot without it. Must be at least 32 characters — use a
# long, random value (e.g. `openssl rand -base64 48`). Keep it STABLE across a
# deployment: rotating it changes every snippet's id and every version address.
ID_SIGNING_SECRET=
# --- Authentication ---------------------------------------------------------
# AUTH_MODE = oauth | cloudflare | none. `none` is intended for local/dev and
# tests only.
AUTH_MODE=none
# OAuth/JWT settings (required when AUTH_MODE=oauth).
OAUTH_JWKS_URL=
OAUTH_ISSUER=
OAUTH_AUDIENCE=
OAUTH_CLIENT_ID=
OAUTH_REDIRECT_URI=
# Optional scopes requested during the browser-driven PKCE flow.
OAUTH_SCOPES=openid profile email
# Cloudflare Access settings (required when AUTH_MODE=cloudflare). Put Serval
# behind a Cloudflare Zero Trust Access application: the edge injects a signed
# `Cf-Access-Jwt-Assertion` header on every request, which Serval validates
# against the team's published certs — no token-paste step in the dashboard.
# CLOUDFLARE_TEAM_DOMAIN is your team domain (the certs live at
# `<team_domain>/cdn-cgi/access/certs`); CLOUDFLARE_AUDIENCE is the Access
# application's AUD tag.
CLOUDFLARE_TEAM_DOMAIN=
CLOUDFLARE_AUDIENCE=
# How long (seconds) to cache the Access signing certs; clamped to >= 3600.
CLOUDFLARE_CERTS_CACHE_TTL_SECS=86400
# --- Logging ----------------------------------------------------------------
RUST_LOG=serval=info,tower_http=warn