Repository navigation
Expand file tree
/
Copy pathconfig.example.yaml
More file actions
55 lines (46 loc) · 2.47 KB
/
Copy pathconfig.example.yaml
File metadata and controls
55 lines (46 loc) · 2.47 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
# pktPCAP configuration
# Copy to <install_dir>/config.yaml, or set PKTPCAP_CONFIG=/path/to/config.yaml,
# then restart the service.
#
# install.sh generates config.yaml from this file automatically, fills in
# secret_key + credential_key, and appends install_dir — edit config.yaml
# afterwards for any further changes.
#
# install_dir is the app root. Every on-disk path below (db_path, log_file,
# ssl_dir, storage_path) defaults to somewhere under install_dir and does NOT
# need to be set explicitly — only uncomment one if you need that particular
# path to live somewhere else.
#
# Feature settings (capture storage/retention, notification channels,
# keys, SAML config, suite integrations, per-user lookup API keys) are all
# managed via the Settings UI and stored in SQLite. This file only covers
# infrastructure/startup settings.
# -- Server --------------------------------------------------------------------
host: "0.0.0.0"
port: 8765
# workers MUST stay 1 — live capture feed sessions are held in this process's
# memory (app/capture/feed_sessions.py). A multi-worker deployment would
# silently split feed ingest/list/download across separate processes and
# lose in-progress captures. Do not raise this without redesigning feed
# storage to be shared across workers (e.g. moving buffers to disk/Redis).
workers: 1
debug: false
# -- App root — install.sh appends this automatically --------------------------
# install_dir: "/opt/pktpcap"
# -- SQLite app database (optional override; default: <install_dir>/pktpcap.db) --
# db_path: "/opt/pktpcap/pktpcap.db"
# -- JWT (generate with: openssl rand -hex 32) ----------------------------------
secret_key: "CHANGE_ME_generate_with_openssl_rand_hex_32"
# -- Credential encryption key (generate with the Fernet command below) --------
# python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
credential_key: "CHANGE_ME_generate_with_fernet_generate_key"
# -- CORS (restrict to your actual origin in production) -----------------------
cors_origins:
- "http://SERVER-IP:8765"
# -- Logging ---------------------------------------------------------------------
log_level: "info"
# log_file: "/opt/pktpcap/logs/pktpcap.log" # optional override; default: <install_dir>/logs/pktpcap.log
# -- SSL certificates (optional override; default: <install_dir>/ssl) ------------
# ssl_dir: "/opt/pktpcap/ssl"
# -- Capture storage (optional override; default: <install_dir>/captures) -------
# storage_path: "/opt/pktpcap/captures"