1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
|
# MeshBay Hub — example configuration.
#
# Copy to /etc/meshbay/hub.toml and edit. The package deliberately does not
# install a working config: it would either ship a placeholder secret that
# somebody runs in production, or overwrite yours on upgrade.
#
# Read from the first of these that exists:
# /etc/meshbay/hub.toml <- where a packaged hub looks
# ~/.config/meshbay/hub.toml <- a development hub, run as yourself
#
# Every value below can also come from the environment, which is what the
# systemd unit's EnvironmentFile (/etc/meshbay/hub.env) is for. Secrets belong
# there rather than in an `Environment=` line: `systemctl cat` shows a unit to
# any user on the machine.
[hub]
# This hub's identity, as members and nodes know it. Changing it after anyone
# has joined invalidates what they trust.
id = "hub.example.org"
# Ed25519 private key. Generate with:
# meshbay-hub --help (see the key subcommands)
# The packaged service runs as `meshbay`, so:
# chown meshbay:meshbay /etc/meshbay/hub_private.pem && chmod 600 it
private_key_path = "/etc/meshbay/hub_private.pem"
# Accounts granted the admin role at creation. Everything else is set in the UI.
admin_usernames = []
[database]
# PostgreSQL in production. The default without this key is an in-memory
# SQLite, which is a test fixture and loses everything on restart.
# Prefer MESHBAY_DATABASE_URL in /etc/meshbay/hub.env — it carries a password.
url = "postgresql+asyncpg://meshbay:CHANGEME@localhost/meshbay_hub"
[server]
# Loopback: TLS is Caddy's job, and the hub should not be reachable directly.
host = "127.0.0.1"
port = 8000
workers = 1
[jwt]
# The access token is not the session — the refresh token is, and the SPA
# renews against it long before this runs out. What this bounds is a token
# that leaks.
access_token_ttl = 14400 # 4 h
refresh_token_ttl = 2592000 # 30 j
[captcha]
# reCAPTCHA v2 on registration and password reset, so no mail is ever sent
# before a human has been seen. Absent, or either key empty, disables it
# entirely — which is right for development and for a hub nobody can reach.
# See docs/captcha.md.
site_key = ""
secret_key = ""
# Hostnames a solved captcha may have been solved on, checked against the one
# `siteverify` reports — what Google observed, not what the client claims.
#
# Leave empty while the reCAPTCHA key does its own origin check: it is then
# already done, one layer up. Set it when you turn that check off in the
# reCAPTCHA console, and the two go together — turning the console check off
# without setting this leaves no origin check anywhere.
#
# The desktop client is why it exists. Its interface ships inside the package
# and is served from `app://meshbay`, so the hostname Google sees is not this
# hub's and never can be; with the console check on, the widget shows
# "Invalid domain for site key" and nothing client-side reaches that decision.
# Add the client's own host only if you distribute it — it is the weak entry,
# since any Electron application can claim the same scheme and host.
#
# allowed_hosts = ["hub.example.org", "localhost", "meshbay"]
allowed_hosts = []
|