forked from github-starred/komodo
* modularize openapi structs * most of execute openapi * server / stack exec openapi * most of write openapi * more write openapi * add the write openapi definitions * fmt and bump mogh auth * gen types * remove user api, mogh auth handles api keys * clean up * cache latest image digests and use this for image update alerting / auto update * deploy 2.0.0-dev-108 * deploy 2.0.0-dev-109 * add back legacy Action "exec" method calling convention * typegen * improve config quick links styling * improve config styling a bit more * deploy 2.0.0-dev-110 * finish version upgrades page, and use prism theme oneLight and oneDark * stack level terminal page * fix Action import from terminal * clean up dangling action api keys on startup * improve swarm service / stack state inference * deploy 2.0.0-dev-111 * add api docs link * bump ts types and fix SwarmConfig type name conflict * use mogh auth for passkey conversion * align dashboard icon with sidebar * bump frontend node version * bump node version in all the dockerfiles * fix tailwind config module * fix require to import * skip auto update for images with pinned digest * dev 112 * cleanup * batch check for updates, add check to table multi select actions * dev-113 * mogh_server = "1.2.0" * serve static ui index.html with ETag / no-cache * check update available against all digests for image * deploy 2.0.0-dev-114 * bump rust to 1.93.0 * bump mogh server and auth * configure session allow cross site * deploy 2.0.0-dev-115 * add new config value to example config * Stack check for update prefers check against deployed service image * deploy 2.0.0-dev-116 * only send auto updated alert after verifying the deploy was successful * 2.0.0 UI (#1220) * new ui using mantine * resources page * prog on resource page * resources and resource layouts * confirm button and modal * tweaks * update details * topbar updates * add skeletons for resource implementations * add resource tables * add tags to recents cards * resource page table scrolling * table component + tags filter * export toml * New Resource button * Fix update details capture closing * tweaks * omni search * refine config * config tweaks * implement more configs / resource selector * add profile page * provider / account selectors * container table page * build config * deployment config * fix deployment build version selector * fix secrets selector * resource sync config * mobile topbar and updates * update details fz sm * stack config * terminals page * create terminal in prog * create terminal menu * finish create terminal menu * terminal pages working * stack tabs / info * add executions * add server header info * confirm pubkey modal * improve resource header styling * FileSource component * stack service table, move icons.ts * basic procedure config * tweak procedure config * container / image pages * network / volume pages * clean up docker resource pages * basic log / terminal ui * reusable log section * styling * clean up resource components * delete in resource header * log auto select stderr * fix some bgs * stack logs with service selector * stack terminals * add deployment executions * use correct icon * useResource hooks * build info * build info * tweaks * server tabs * fix terminal section target * prog on server tabs * server stats * light theme * start on historical stats * stack service page * resource sync tabs * sync tabs * more topbar icons * add settings basic * add topbar alerts * tweak stream selector behavior * tweak alert icon topbar * improve styling smaller screen * schedules page and other progress * onboarding keys * improve schedule page descriptions * improve update notifications * schedule timezone selector * tag color selector * finish settings / providers * use shared-text-update component so settings tables aren't janky * updates page * refine updates page * alert page * standardize borders * theme and swarm * swarm tabs * swarm node page * swarm config page * swarm pages * swarm task and secret pages * swarm stack page * fix stack log service selector in swarm mode * standard inspect section * swarm inspect tab * server and swarm resources tab * add disable confirm dialog (modal) option for executions * stack update available indicator * deployment update available * add template switch to resource headers * ResourceHeader + rename * set editing name onclick * repo tabs * server stats table * refine a bit * refine deployment / stack header info * show server stats dashboard. dashboard tables * action last run in config * SettingsUsers page * user page etc * manage api key * user base permissions * color the table multi select * user group page * UserAddUserGroup * active includes deployments / stacks * improve small screen view * fix docker pages execution showing * clean up * rename frontend to UI * align profile page styling * config maintenance windows * finish maintenance windows * builder config * add batch execute dropdown / confirm menu * batch execute styling * deploy 2.0.0-dev-117 * improve stats card light theme * add update page * improve mobile * terminal group nowrap * mobile improvements * allow unused again * improve mobile font sizing * improve mobile updates / alerts * mobile tabs * alert page * add server version mismatch color * new resource, clearable selector * Fix build show info tab * copy resources * keyboard shortcuts * server resource header version mismatch * fix type errors * container page server multi select * confirm button clear timeout * hash compare force uses first 8 for short hash * fix log height * copy webhooks * responsive tweaks * add icons to server stat sections * add historical server stats charts * server stat current card shows usage numbers * refine current stats more * fix shortcuts interfering with monaco brave * clean up unused * remove v1 frontend * bump rust version to 1.93.1 and dep versions * deploy 2.0.0-dev-118 * bump chef rust version * improve login no auth configured and passkey pending * Load Average is first historical stat * procedure / action webhook branch mobile style * dashboard active styling * hide actions when none * Select Template * execution buttons disabled when loading * Fix config input issue * improve tab styling * rename ConfigSwitch onChange -> onCheckedChange * ensure section headers consistent spacing * edit swarm join command * fix batch executions width * stack stopped and deployment exited warning instead of critical * smaller more consistent gaps * add close button to update / alert details drawer * stack and deployment state color include update available. Ensure server version mismatch color applied everywhere * deploy 2.0.0-dev-120 * topbar user dropdown shows user avatar if available * post link redirect should be to profile * deploy 2.0.0-dev-121 * improve profile delete styling * standard api key modal size * improve login styling * fix login github / google icon color * fix some wrapping stuff in tables and tag text disappear * fix terminal height - same as logs * single delete terminal * Update / Alert table filter selector formatted * tweaks for lg size * taller data table and blue omnisearch * refine lg screen size view * fix sidebar margin right * "never" -> "Never" * Add hoverable disk info * improve disk usage hover card styling * rename for clarity * thinner topbar * config sidebar save * setters use maps instead of mutations * notification green contents written success * fmt * read request are trace * deploy 2.0.0-dev-122 * debug level core <> periphery auth identifiers logs * mogh auth server 1.2.10 * mogh auth 1.2.11 * deploy 2.0.0-dev-123 * Deploy / DeployStack updates invalidate corresponding list query * confirm action / save modals don't need ConfirmButton * deploy 2.0.0-dev-124 * proper base64url decode * fix init admin user * improve mobile friendly tabs width, and onboardng key copy * rename resource invalidates * better maxheight for mobile friendly tabs * km cli needs to install crypto provider for tls ws * better responsive confirm save width * confirm modal better responsiveness * Fix api key modal too thin * better api key create * improve batch execs * improve tabs * sidebar more compact * add missing Repo header Info * Fix Pull repo * fix repo Links config * improve procedure config UI including run stack service * improve deployment network, restart, termination signal config * fix confirm update showing entries which have not changed * example execute terminal uses bash * Update deployments description * move build server * [Docs] Update connect-servers.mdx (#1256) * Update connect-servers.mdx * Update connect-servers.mdx * clean up connect servers * feat(ci): build (#1018) * fmt * fix: more verbose logging (#1017) * use .with_context for stack run directory canonicalize log * fix failing doc test * Improve server resource header hover info * service selector support swarm stack icon * fix stack terminals sometimes not disabled when it should be * add terminal create and delete messages * bump packages and add Mogh Tech copyright * revamp docsite * soften the borders * clean up stack config * fix config group header too much gap * procedure stage menu easier to reach * deploy 2.0.0-dev-125 * increase universal resource polling * improve server stats * fix data table * down node is critical * cli add print core info * add docker swarm feature card * improve toml resource repetition using macros, and fix Swarm toml support * swarm config: configure alerting options * add swarm header info * Implement New Swarm Config and New Swarm Secret * brighten tag colors * continue docs revamp * fmt * set more refetch intervals to keep display data fresh * fix copy not showing copy source when there are no templates * rename onboarding key fix_existing_servers to privileged * fix Privileged spelling * fmt * more docs improvement * improve docs intro * update the curl instructions with easier call method * fix clippy lints * refresh the server cache after every server connection successful login * deploy 2.0.0-dev-126 * add polling to dashboard summary data * tweak tag opacity * improve server stat table disk hover * fix change historical stat length collapse stats * KOMODO_DISABLE_INIT_RESOURCES * stack Project Missing should be red * Fix files on host stacks showing down after reboot until refresh cache * silence user level write logs SetLastSeenUpdate and PushRecentlyViewed * See the v2 migration guide * Improve api logging using more fields * deploy 2.0.0-dev-127 * cli create api key on database, can use with docker exec into core container * deploy 2.0.0-dev-128 * advanced km create api-key options * create onboarding key with cli * tweak * onboarding keys use tag name * deploy 2.0.0-dev-129 * stack procedure stages can select specific services to apply to (default all services) * docsite dockerfile * ./docusaurus.config.ts * need to yarn build * fix broken link * improve alert (dropdown) icons * fix docs sidebar collapse * add local search functionality * docs search nice * homepage features navigate to docs * only show build cancel when canCancel * more confirm button confirmprops red * fix docsite buttons and list more features * fix sidebar cmd click opens in new tab (is a link) * execute withBorder * cleaner execute section * swap docker compose and deploy containers * make docs logo align with app * better mobile button layout * linked logins / 2fa confirm red styling * bump rust version to 1.94.0 * move bollard::secret to bollard::config * deploy 2.0.0-dev-130 * feat: add compose_cmd_wrapper_include for selective command wrapping (#1124) - Add compose_cmd_wrapper_include field to StackConfig. - Fix wrapper placeholder text not displaying in MonacoEditor. * align configuration by removing bold label stuff * confirm update monaco readonly * dockerfile binaries / ui images default to :2 * fmt * refresh server cache lint * fmt * disabling send alerts should also disable in UI * clean up disabled alerting * deploy 2.0.0-dev-131 * mogh_pki 1.1.3 safer copy from slice * fix dev container issues on 2.0.0 (#1238) * fix node version and yarn build in dev container * ensure keys directories exist and are writable in dev container * update dev container image (necessary to fix compiler error) * fix CORS error in dev container * more dev container fixes KOMODO_SESSION_ALLOW_CROSS_SITE: true needed to properly run on Firefox * fix devcontainer port * update config pages to use "Webhooks" consistently and fix acronym casing (#1239) Co-authored-by: Maxwell Becker <49575486+mbecker20@users.noreply.github.com> * update local dev setup instructions (#1240) * example mongo deploy dev * check binary URL (#1116) * install script improve failed download binary log * align cli installer with periphery installer * improve terminal page create experience * deploy 2.0.0-dev-132 * improve mobile updates with full size query * fix some internal table wrapping * fix schedule expression examples * Add swarm updates / alerts filter * filter by update available uses location hash instead of localstorage * sync commit preserve meta "deploy" and "after" * UI fixes and tweaks * deploy 2.0.0-dev-133 * add error to warn log * Stack / deployment should inherit specific Swarm permissions * Fix inline span formatting (used in logs / errors) * refactor resource sync pending deploy for better display * deploy 2.0.0-dev-134 * improve terminal error handling * deploy 2.0.0-dev-135 * dedicated docs page for v2 * warning about failing to include init: true * Limit Periphery IPs in Advanced config * refine setup guide * 2.0.0 --------- Co-authored-by: Shlee <github@shl.ee> Co-authored-by: Yujia Qiao <code@rapiz.me> Co-authored-by: ChanningHe <52875777+ChanningHe@users.noreply.github.com> Co-authored-by: Steven Loria <sloria1@pm.me> Co-authored-by: Andreas Brett <andreasbrett@users.noreply.github.com>
294 lines
9.6 KiB
TOML
294 lines
9.6 KiB
TOML
################################
|
|
# 🦎 KOMODO PERIPHERY CONFIG 🦎 #
|
|
################################
|
|
|
|
## This is the offical "Default" config file for Komodo Periphery.
|
|
## It serves as documentation for the meaning of the fields.
|
|
## It is located at `https://github.com/moghtech/komodo/blob/main/config/periphery.config.toml`.
|
|
|
|
## All fields with a "Default" provided are optional. If they are
|
|
## left out of the file, the "Default" value will be used.
|
|
|
|
## If Periphery was installed on the host (systemd install script), this
|
|
## file will be located either in `/etc/komodo/periphery.config.toml`,
|
|
## or for user installs, `$HOME/.config/komodo/periphery.config.toml`.
|
|
|
|
## Most fields can also be configured using environment variables.
|
|
## Environment variables will override values set in this file.
|
|
|
|
## You can also use JSON or YAML if preferred. You can convert here:
|
|
## - YAML: https://it-tools.tech/toml-to-yaml
|
|
## - JSON: https://it-tools.tech/toml-to-json
|
|
|
|
###########
|
|
# GENERAL #
|
|
###########
|
|
|
|
## Specify the root directory used by Periphery agent.
|
|
## All your compose files and repos need to be inside this directory
|
|
## for Periphery to interact with them.
|
|
## - ROOT_DIRECTORY (/etc/komodo)
|
|
## --- ./stacks
|
|
## ------ ./my_stack_1
|
|
## ------ ./my_stack_2
|
|
## --- ./repos
|
|
## ------ ./my_repo_1
|
|
## Each specific sub-directory (like ./stacks) can be overridden below.
|
|
## Env: PERIPHERY_ROOT_DIRECTORY
|
|
## Default: /etc/komodo
|
|
root_directory = "/etc/komodo"
|
|
|
|
## Optional. Override the directory periphery will use to manage repos.
|
|
## The periphery user must have write access to this directory.
|
|
## Env: PERIPHERY_REPO_DIR
|
|
## Default: ${root_directory}/repos
|
|
# repo_dir = "/etc/komodo/repos"
|
|
|
|
## Optional. Override the directory periphery will use to manage stacks.
|
|
## The periphery user must have write access to this directory.
|
|
## Env: PERIPHERY_STACK_DIR
|
|
## Default: ${root_directory}/stacks
|
|
# stack_dir = "/etc/komodo/stacks"
|
|
|
|
## Optional. Override the directory periphery will use to manage builds.
|
|
## The periphery user must have write access to this directory.
|
|
## Env: PERIPHERY_BUILD_DIR
|
|
## Default: ${root_directory}/builds
|
|
# build_dir = "/etc/komodo/builds"
|
|
|
|
## Set the default terminal command used to init the shell.
|
|
## For example, `bash` or `zsh`.
|
|
## Env: PERIPHERY_DEFAULT_TERMINAL_COMMAND
|
|
## Default: bash
|
|
default_terminal_command = "bash"
|
|
|
|
## Disable the terminal APIs and disallow remote shell access through Periphery.
|
|
## Env: PERIPHERY_DISABLE_TERMINALS
|
|
## Default: false
|
|
disable_terminals = false
|
|
|
|
## Disable the container exec / attach APIs and disallow remote container shell access through Periphery.
|
|
## This can be left enabled while general terminal access is disabled.
|
|
## Env: PERIPHERY_DISABLE_CONTAINER_TERMINALS
|
|
## Default: false
|
|
disable_container_terminals = false
|
|
|
|
## How often Periphery polls the host for system stats, like CPU / memory usage.
|
|
## To effectively disable polling, set this to something like 1-hr.
|
|
## Env: PERIPHERY_STATS_POLLING_RATE
|
|
## Options: https://docs.rs/komodo_client/latest/komodo_client/entities/enum.Timelength.html
|
|
## Default: 5-sec
|
|
stats_polling_rate = "5-sec"
|
|
|
|
## How often Periphery polls the host for container stats,
|
|
## Env: PERIPHERY_CONTAINER_STATS_POLLING_RATE
|
|
## Options: https://docs.rs/komodo_client/latest/komodo_client/entities/enum.Timelength.html
|
|
## Default: 30-sec
|
|
container_stats_polling_rate = "30-sec"
|
|
|
|
## Whether stack actions should use `docker-compose ...`
|
|
## instead of `docker compose ...`.
|
|
## Env: PERIPHERY_LEGACY_COMPOSE_CLI
|
|
## Default: false
|
|
legacy_compose_cli = false
|
|
|
|
## Optional. Only include mounts at specific paths in the disk report.
|
|
## Example: include_disk_mounts = ["/mnt/include/1", "/mnt/include/2"]
|
|
## Env: PERIPHERY_INCLUDE_DISK_MOUNTS
|
|
## Default: empty, which won't filter down the disks.
|
|
include_disk_mounts = []
|
|
|
|
## Optional. Don't include these mounts in the disk report.
|
|
## Example: exclude_disk_mounts = ["/mnt/exclude/1", "/mnt/exclude/2"]
|
|
## Env: PERIPHERY_EXCLUDE_DISK_MOUNTS
|
|
## Default: empty, which won't exclude any disks.
|
|
exclude_disk_mounts = []
|
|
|
|
########
|
|
# AUTH #
|
|
########
|
|
|
|
## The private key used with the Noise handshake.
|
|
## If using `file:/path/to/file` and the file doesn't exist yet,
|
|
## Periphery will generate and write new key to the path.
|
|
## Env: PERIPHERY_PRIVATE_KEY or PERIPHERY_PRIVATE_KEY_FILE
|
|
## Default: "file:${root_directory}/keys/periphery.key"
|
|
## Image Default: "file:/config/keys/periphery.key" (matching Core image)
|
|
# private_key = "file:/path/to/file"
|
|
|
|
## Accepted public keys to allow Core(s) to connect.
|
|
## Periphery gains knowledge of the Core public key through the noise handshake.
|
|
## If neither these nor passkeys provided, inbound connections will not be authenticated.
|
|
## Accepts Spki base64 DER directly and PEM file. Use `file:/path/to/core.pub` to load from file.
|
|
## Env: PERIPHERY_CORE_PUBLIC_KEYS
|
|
## Optional, no default.
|
|
# core_public_keys = "MCowBQYDK2VuAyEATZgrjGHeF0KJUe0+n77+qAWOg3YzEzXOmQWaRgO3OGQ=, file:/path/to/key2.pub"
|
|
|
|
## Deprecated. Legacy v1 compatibility.
|
|
## Users should upgrade to private / public key authentication.
|
|
## Env: PERIPHERY_PASSKEYS
|
|
# passkeys = ["default-passkey"]
|
|
|
|
#################
|
|
# OUTBOUND MODE #
|
|
#################
|
|
|
|
## The address of Komodo Core. Must be reachable from this host.
|
|
## If provided, Periphery will operate in outbound mode.
|
|
## Env: PERIPHERY_CORE_ADDRESS
|
|
## Default: None
|
|
# core_address = "demo.komo.do"
|
|
|
|
## The Server this Periphery agent should connect as.
|
|
## Must match an existing Server name or id.
|
|
## Env: PERIPHERY_CONNECT_AS
|
|
## Default: None
|
|
# connect_as = "server-name"
|
|
|
|
## Make Onboarding Keys in Server settings.
|
|
## Not needed if connecting as Server that already exists.
|
|
## Env: PERIPHERY_ONBOARDING_KEY
|
|
# onboarding_key = "MC4CAQAwBQYDK2VuBCIEIHPHNA/0M9ejFviE2y4dpyczAvnAwPWDQtGGGhEJ2G6K"
|
|
|
|
################
|
|
# INBOUND MODE #
|
|
################
|
|
|
|
## Enable the inbound connection server for
|
|
## Core -> Periphery connection.
|
|
## Env: PERIHERY_SERVER_ENABLED
|
|
## Default: If 'core_addresses' are defined, false, otherwise true.
|
|
# server_enabled = true
|
|
|
|
## Optional. The port the server runs on.
|
|
## Env: PERIPHERY_PORT
|
|
## Default: 8120
|
|
port = 8120
|
|
|
|
## The IP address the periphery server will bind to.
|
|
## The default will allow it to accept external IPv4 and IPv6 connections.
|
|
## Env: PERIPHERY_BIND_IP
|
|
## Default: [::]
|
|
bind_ip = "[::]"
|
|
|
|
## Optional. Limit the ip addresses which can connect to Periphery.
|
|
## Supports Ipv4 / Ipv6 addresses and subnets.
|
|
## Examples: allowed_ips = ["::ffff:12.34.56.78", "10.0.10.0/24"]
|
|
## Env: PERIPHERY_ALLOWED_IPS
|
|
## Default: empty, which will not block any request by ip.
|
|
allowed_ips = []
|
|
|
|
## Enable HTTPS server using the given key and cert.
|
|
## If true and a key / cert at the given paths are not found,
|
|
## self signed keys will be generated using openssl.
|
|
## Env: PERIPHERY_SSL_ENABLED
|
|
## Default: true
|
|
ssl_enabled = true
|
|
|
|
## Path to the ssl key.
|
|
## Env: PERIPHERY_SSL_KEY_FILE
|
|
## Default: ${root_directory}/ssl/key.pem
|
|
# ssl_key_file = "/etc/komodo/ssl/key.pem"
|
|
|
|
## Path to the ssl cert.
|
|
## Env: PERIPHERY_SSL_CERT_FILE
|
|
## Default: ${root_directory}/ssl/cert.pem
|
|
# ssl_cert_file = "/etc/komodo/ssl/cert.pem"
|
|
|
|
###########
|
|
# LOGGING #
|
|
###########
|
|
|
|
## Specify the logging verbosity
|
|
## Options: off, error, warn, info, debug, trace
|
|
## Default: info
|
|
## Env: PERIPHERY_LOGGING_LEVEL
|
|
logging.level = "info"
|
|
|
|
## Specify the logging format for stdout / stderr.
|
|
## Env: PERIPHERY_LOGGING_STDIO
|
|
## Options: standard, json, none
|
|
## Default: standard
|
|
logging.stdio = "standard"
|
|
|
|
## Specify a opentelemetry otlp endpoint to send traces to.
|
|
## Example: http://localhost:4317.
|
|
## Env: PERIPHERY_LOGGING_OTLP_ENDPOINT
|
|
## Optional, no default
|
|
logging.otlp_endpoint = ""
|
|
|
|
## Set the opentelemetry service name attached to the telemetry Periphery will send.
|
|
## Env: PERIPHERY_LOGGING_OPENTELEMETRY_SERVICE_NAME
|
|
## Default: "Komodo"
|
|
logging.opentelemetry_service_name = "Periphery"
|
|
|
|
## Set the opentelemetry scope name.
|
|
## This will be attached to the telemetry Komodo will send.
|
|
## Env: PERIPHERY_LOGGING_OPENTELEMETRY_SCOPE_NAME
|
|
## Default: "Komodo"
|
|
logging.opentelemetry_scope_name = "Komodo"
|
|
|
|
## Specify whether logging is more human readable.
|
|
## Note. Single logs will span multiple lines.
|
|
## Env: PERIPHERY_LOGGING_PRETTY
|
|
## Default: false
|
|
logging.pretty = false
|
|
|
|
## Specify whether startup config log
|
|
## is more human readable (multi-line)
|
|
## Env: PERIPHERY_PRETTY_STARTUP_CONFIG
|
|
## Default: false
|
|
pretty_startup_config = false
|
|
|
|
#################
|
|
# GIT PROVIDERS #
|
|
#################
|
|
|
|
## configure Periphery based git providers
|
|
# [[git_provider]]
|
|
# domain = "github.com"
|
|
# accounts = [
|
|
# { username = "mbecker20", token = "access_token_for_account" },
|
|
# { username = "moghtech", token = "access_token_for_other_account" },
|
|
# ]
|
|
|
|
# [[git_provider]]
|
|
# domain = "git.mogh.tech" # use a custom provider, like self-hosted gitea
|
|
# accounts = [
|
|
# { username = "mbecker20", token = "access_token_for_account" },
|
|
# ]
|
|
|
|
# [[git_provider]]
|
|
# domain = "localhost:8000" # use a custom provider, like self-hosted gitea
|
|
# https = false # use http://localhost:8000 as base-url for clone
|
|
# accounts = [
|
|
# { username = "mbecker20", token = "access_token_for_account" },
|
|
# ]
|
|
|
|
######################
|
|
# REGISTRY PROVIDERS #
|
|
######################
|
|
|
|
## Configure Periphery based docker registries
|
|
# [[docker_registry]]
|
|
# domain = "docker.io"
|
|
# accounts = [
|
|
# { username = "mbecker2020", token = "access_token_for_account" }
|
|
# ]
|
|
# organizations = ["DockerhubOrganization"]
|
|
|
|
# [[docker_registry]]
|
|
# domain = "git.mogh.tech" # use a custom provider, like self-hosted gitea
|
|
# accounts = [
|
|
# { username = "mbecker20", token = "access_token_for_account" },
|
|
# ]
|
|
# organizations = ["Mogh"] # These become available in the UI
|
|
|
|
###########
|
|
# SECRETS #
|
|
###########
|
|
|
|
## Provide periphery-based secrets
|
|
# [secrets]
|
|
# SECRET_1 = "value_1"
|
|
# SECRET_2 = "value_2" |