# MeshBay Hub — example configuration. # # Copy to /etc/meshbay/hub.toml and edit. The package deliberately does not # install a working config: it would either ship a placeholder secret that # somebody runs in production, or overwrite yours on upgrade. # # Read from the first of these that exists: # /etc/meshbay/hub.toml <- where a packaged hub looks # ~/.config/meshbay/hub.toml <- a development hub, run as yourself # # Every value below can also come from the environment, which is what the # systemd unit's EnvironmentFile (/etc/meshbay/hub.env) is for. Secrets belong # there rather than in an `Environment=` line: `systemctl cat` shows a unit to # any user on the machine. [hub] # This hub's identity, as members and nodes know it. Changing it after anyone # has joined invalidates what they trust. id = "hub.example.org" # Ed25519 private key. Generate with: # meshbay-hub --help (see the key subcommands) # The packaged service runs as `meshbay`, so: # chown meshbay:meshbay /etc/meshbay/hub_private.pem && chmod 600 it private_key_path = "/etc/meshbay/hub_private.pem" # Accounts granted the admin role at creation. Everything else is set in the UI. admin_usernames = [] [database] # PostgreSQL in production. The default without this key is an in-memory # SQLite, which is a test fixture and loses everything on restart. # Prefer MESHBAY_DATABASE_URL in /etc/meshbay/hub.env — it carries a password. url = "postgresql+asyncpg://meshbay:CHANGEME@localhost/meshbay_hub" [server] # Loopback: TLS is Caddy's job, and the hub should not be reachable directly. host = "127.0.0.1" port = 8000 workers = 1 [jwt] # The access token is not the session — the refresh token is, and the SPA # renews against it long before this runs out. What this bounds is a token # that leaks. access_token_ttl = 14400 # 4 h refresh_token_ttl = 2592000 # 30 j [captcha] # reCAPTCHA v2 on registration and password reset, so no mail is ever sent # before a human has been seen. Absent, or either key empty, disables it # entirely — which is right for development and for a hub nobody can reach. # See docs/captcha.md. site_key = "" secret_key = "" # Hostnames a solved captcha may have been solved on, checked against the one # `siteverify` reports — what Google observed, not what the client claims. # # Leave empty while the reCAPTCHA key does its own origin check: it is then # already done, one layer up. Set it when you turn that check off in the # reCAPTCHA console, and the two go together — turning the console check off # without setting this leaves no origin check anywhere. # # The desktop client is why it exists. Its interface ships inside the package # and is served from `app://meshbay`, so the hostname Google sees is not this # hub's and never can be; with the console check on, the widget shows # "Invalid domain for site key" and nothing client-side reaches that decision. # Add the client's own host only if you distribute it — it is the weak entry, # since any Electron application can claim the same scheme and host. # # allowed_hosts = ["hub.example.org", "localhost", "meshbay"] allowed_hosts = []