Documentation
¶
Overview ¶
Package config provides configuration loading and validation.
Index ¶
- Constants
- Variables
- func IsTLSModeTerminated(cfg *Config) bool
- func IsValidatorMode(cfg *Config) bool
- func NormalizeSignatureAllowedAlgorithms(algorithms []string) ([]string, error)
- func PublicSchemeFromOrigin(publicOrigin string) string
- func ResolveContentDir(dir string) (string, error)
- func SchemeFromOrigin(publicOrigin string) string
- func SessionConfigFromValidator(cfg *Config) validatorcore.SessionConfig
- func StartPublicRatelimitProfile(cfg *Config) (map[string]any, error)
- func ValidateStrictModeStartupGuardrails(cfg *Config) error
- func ValidateValidatorModeStartupGuardrails(cfg *Config) error
- type ACMEConfig
- type BootstrapAdminConfig
- type CacheConfig
- type CodeFlowConfig
- type CompatibilityScope
- type Config
- type DiscoveryConfig
- type FlagOverrides
- type HTTPConfig
- type InviteConfig
- type LoaderOptions
- type LoggingConfig
- type Mode
- type OCMConfig
- type OutboundHTTPConfig
- type PeerMappingConfig
- func (cfg *PeerMappingConfig) GlobalKnobs() (includes, requires, http *bool)
- func (cfg *PeerMappingConfig) HostPlatformFor(host string) (string, bool)
- func (cfg *PeerMappingConfig) InstanceKnobs(platform, host string) (includes, requires *bool, ok bool)
- func (cfg *PeerMappingConfig) PlatformInstanceBinding(host string) (string, bool)
- func (cfg *PeerMappingConfig) PlatformKnobs(platform string) (includes, requires *bool, ok bool)
- func (cfg *PeerMappingConfig) PublicScheme() string
- func (cfg *PeerMappingConfig) Scheme() string
- type PeerMappingInstanceOverlay
- type PeerPlatformOverlay
- type PeerTrustConfig
- type PeerTrustMembershipCacheConfig
- type PeerTrustPolicyConfig
- type PersistenceConfig
- type SSRFConfig
- type SSRFRoutePolicyConfig
- type ServerConfig
- type SignatureConfig
- type StatisticsConfig
- type TLSConfig
- type TokenExchangeConfig
- type ValidatorActiveConfig
- type ValidatorProbeConfig
- type ValidatorSection
- type ValidatorSessionConfig
Constants ¶
const ( DefaultOutboundTimeoutMS = 10000 DefaultOutboundConnectTimeoutMS = 2000 DefaultOutboundMaxRedirects = 1 DefaultMaxResponseBytes = 1 << 20 DefaultOutboundMaxIdleConns = 10 DefaultOutboundMaxConnsPerHost = 10 DefaultOutboundIdleConnTimeout = 30 * time.Second DefaultOutboundResponseHeaderTimeout = 10 * time.Second )
Outbound HTTP defaults (production strict preset baseline).
const ( DefaultServerReadTimeout = 30 * time.Second DefaultServerReadHeaderTimeout = 10 * time.Second DefaultServerWriteTimeout = 30 * time.Second DefaultServerIdleTimeout = 60 * time.Second DefaultChallengeReadTimeout = 10 * time.Second DefaultChallengeReadHeaderTimeout = 10 * time.Second DefaultChallengeWriteTimeout = 10 * time.Second DefaultChallengeIdleTimeout = 60 * time.Second DefaultServerShutdownTimeout = 2 * time.Second )
Server HTTP listener defaults.
const ( DefaultPeerTrustCacheTTLSeconds = 21600 // 6 hours DefaultPeerTrustCacheMaxStaleSeconds = 604800 // 7 days )
Peer trust membership cache defaults (seconds, TOML-facing).
const ( DefaultSignatureLabel = sigparams.SignatureLabelOCM DefaultSignatureKidFragment = "key1" DefaultSignatureCreatedMaxAge = 300 DefaultSignatureCreatedMaxSkew = 60 DefaultMinRSAModulusBits = 2048 )
HTTP signature defaults (https://www.rfc-editor.org/rfc/rfc9421.html; OCM Appendix B, informative: https://github.com/cs3org/OCM-API/blob/6a0586183cbef10ecae9dedc42561806447eb2f5/IETF-OCM.md#L2136).
const ( TestOutboundTimeoutMS = 5000 TestOutboundConnectMS = 2000 )
Test-oriented outbound and wait defaults (integration harness + unit tests).
const ( BackendMemory = "memory" BackendJSON = "json" BackendSQLite = "sqlite" BackendMirror = "mirror" )
Persistence backend name constants. These are the only valid values for PersistenceConfig.Backend. Unknown values are rejected at validation time; there is no silent fallback to memory.
const ( // TLSModeOff disables in-process TLS; the HTTP server listens in plain HTTP. TLSModeOff = "off" // TLSModeTerminated terminates TLS upstream; forwarded headers from trusted proxies carry scheme. TLSModeTerminated = "terminated" )
URL scheme, mode, and strict-preset port constants for config loading and validation.
const ( // ScanPublicRatelimitProfile is the public scan ratelimit profile name. // Configured at [http.interceptors.ratelimit.profiles.scan_public]. ScanPublicRatelimitProfile = "scan_public" // StartPublicRatelimitBucket is the create-session bucket under scan_public. // Configured at [http.interceptors.ratelimit.profiles.scan_public.start_public]. StartPublicRatelimitBucket = "start_public" // DefaultValidatorProbeEmail is the preset [validator.probe] email. DefaultValidatorProbeEmail = "probe@localhost" // DefaultValidatorProbeDisplayName is the preset [validator.probe] display name. DefaultValidatorProbeDisplayName = "Probe User" )
const DefaultContentDir = ".ocm/files"
DefaultContentDir is the CWD-relative managed content root, sibling of the default data directory under .ocm/.
const DefaultPersistenceDataDir = ".ocm/data"
DefaultPersistenceDataDir is the CWD-relative data directory the strict preset uses for its durable sqlite backend.
const DefaultTestShutdownWait = 5 * time.Second
DefaultTestShutdownWait is the standard bounded wait for server shutdown and async test synchronization.
const DefaultValidatorPersistenceDataDir = ".ocm/validator-data"
DefaultValidatorPersistenceDataDir is the CWD-relative data directory the validator preset uses for its durable sqlite backend.
const EnvOutboundHTTPUseEnvFallback = "OCM_CONFIG_OUTBOUND_HTTP_USE_ENV_FALLBACK"
EnvOutboundHTTPUseEnvFallback is the environment-variable name that overrides the outbound_http.use_env_fallback TOML key at load time via applyEnvOverrides. use_env_fallback has no CLI flag, so the env override sits directly above the TOML value in the precedence order. Exported so callers that scrub or set the environment (for example the integration harness hermetic blocklist) reuse the single canonical name instead of duplicating the raw literal.
const SeedContentFileName = "hello-ocm.txt"
SeedContentFileName is the demo file created idempotently under the content root.
Variables ¶
var DefaultValidatorTrustedProxies = []string{
"127.0.0.0/8",
"::1/128",
"10.0.0.0/8",
"172.16.0.0/12",
"192.168.0.0/16",
}
DefaultValidatorTrustedProxies includes loopback and common Docker bridge ranges.
Functions ¶
func IsTLSModeTerminated ¶ added in v1.3.0
IsTLSModeTerminated reports whether TLS terminates at an upstream reverse proxy.
func IsValidatorMode ¶ added in v1.3.0
IsValidatorMode reports whether cfg runs in federation validator mode.
func NormalizeSignatureAllowedAlgorithms ¶ added in v1.2.0
NormalizeSignatureAllowedAlgorithms canonicalizes JOSE/native aliases, rejects empty/whitespace/symmetric/unknown entries, and dedupes while preserving first-seen order.
func PublicSchemeFromOrigin ¶ added in v1.1.0
PublicSchemeFromOrigin returns "http" or "https" derived from a public origin string. Returns "https" if the origin is empty or unparseable. Use this for callers that want a usable default scheme (config-aware callers and the token handler). Callers that must leave the scheme empty when the origin is empty or unparseable should use SchemeFromOrigin.
func ResolveContentDir ¶ added in v1.2.0
ResolveContentDir returns the absolute path for the managed content root. Empty dir falls back to DefaultContentDir relative to the current working directory.
func SchemeFromOrigin ¶ added in v1.1.0
SchemeFromOrigin returns the lowercased scheme ("http" or "https") derived from a public origin string, or an empty string when the origin is empty or unparseable. Unlike PublicSchemeFromOrigin it never substitutes a default scheme, preserving callers that intentionally treat an empty or unparseable origin as an empty scheme during hostport normalization.
func SessionConfigFromValidator ¶ added in v1.3.0
func SessionConfigFromValidator(cfg *Config) validatorcore.SessionConfig
SessionConfigFromValidator returns validatorcore session limits from cfg.
func StartPublicRatelimitProfile ¶ added in v1.3.0
StartPublicRatelimitProfile returns the start_public bucket under scan_public.
func ValidateStrictModeStartupGuardrails ¶ added in v1.2.0
ValidateStrictModeStartupGuardrails applies the same strict-mode startup guardrails that Load enforces. It is exported so in-memory config callers that build a Config without going through Load (for example the in-process test harness) reject the same impossible startup states the real binary rejects. Load reaches this logic via validateEnums.
func ValidateValidatorModeStartupGuardrails ¶ added in v1.3.0
ValidateValidatorModeStartupGuardrails applies the same validator-mode startup guardrails that Load enforces. It is exported so in-memory config callers that build a Config without going through Load (for example the in-process test harness) reject the same impossible startup states the real binary rejects. Load reaches this logic via validateEnums.
Types ¶
type ACMEConfig ¶
type ACMEConfig struct {
// Email for ACME registration
Email string `toml:"email"`
// Domain is the domain to obtain a certificate for
Domain string `toml:"domain"`
// Directory is the ACME server URL (default: Let's Encrypt production)
Directory string `toml:"directory"`
// StorageDir is where ACME certificates and account info are stored
StorageDir string `toml:"storage_dir"`
// UseStaging uses Let's Encrypt staging (for testing)
UseStaging bool `toml:"use_staging"`
}
ACMEConfig holds ACME/Let's Encrypt settings.
type BootstrapAdminConfig ¶
type BootstrapAdminConfig struct {
// Username for the super admin. Default: "admin"
Username string `toml:"username"`
// Password for the super admin. If empty on first boot, a random password is generated.
Password string `toml:"password"`
// CredentialFile is where an auto-generated bootstrap password is written.
// Relative paths resolve against the process working directory.
CredentialFile string `toml:"password_file"`
}
BootstrapAdminConfig holds bootstrap admin credentials.
type CacheConfig ¶
type CacheConfig struct {
// Driver is the cache driver name: "memory" (default). Other drivers may fail validation.
Driver string `toml:"driver"`
// Drivers holds per-driver configuration (Reva-style).
// Example: [cache.drivers.memory] ...
Drivers map[string]any `toml:"drivers"`
}
CacheConfig holds cache settings.
type CodeFlowConfig ¶ added in v1.2.0
type CodeFlowConfig struct {
IncludesTokenExchangeRequirement *bool `toml:"includes_token_exchange_requirement"`
RequiresTokenExchangeRequirement *bool `toml:"requires_token_exchange_requirement"`
RequiresHTTPRequestSignatures *bool `toml:"requires_http_request_signatures"`
}
CodeFlowConfig holds relaxable OCM code-flow knobs under [ocm.code_flow]. Unset (nil) means inherit/strict default; false relaxes; true enforces.
type CompatibilityScope ¶ added in v1.2.0
type CompatibilityScope string
CompatibilityScope selects how peer-compat leniency is applied. This is an ocmgo-internal policy axis, not an OCM specification concept.
const ( // CompatibilityScopeGlobal applies peer_compat relaxations globally (current behavior). CompatibilityScopeGlobal CompatibilityScope = "global" // CompatibilityScopeScoped limits leniency to explicitly mapped peers only. CompatibilityScopeScoped CompatibilityScope = "scoped" )
func ParseCompatibilityScope ¶ added in v1.2.0
func ParseCompatibilityScope(s string) (CompatibilityScope, error)
ParseCompatibilityScope parses a compatibility_scope string.
type Config ¶
type Config struct {
// Mode selects a preset bundle: strict, dev, or validator.
Mode string `toml:"mode"`
// PublicOrigin is the public origin (scheme + host + port) for this instance.
// Example: "https://localhost:9200"
PublicOrigin string `toml:"public_origin"`
// ExternalBasePath is the optional path prefix for app endpoints.
// The root-only well-known discovery endpoint (/.well-known/ocm) is
// never under this path; the local JWKS route (<endPoint>/jwks) is
// mounted under the OCM service and does move with this path.
// Example: "/ocm" or empty string
ExternalBasePath string `toml:"external_base_path"`
// ListenAddr is the address to listen on.
// Example: ":9200"
ListenAddr string `toml:"listen_addr"`
// Server holds server-level settings.
Server ServerConfig `toml:"server"`
// TLS configuration
TLS TLSConfig `toml:"tls"`
// OutboundHTTP configuration
OutboundHTTP OutboundHTTPConfig `toml:"outbound_http"`
// Signature configuration
Signature SignatureConfig `toml:"signature"`
// Cache configuration
Cache CacheConfig `toml:"cache"`
// Peer trust configuration
PeerTrust PeerTrustConfig `toml:"peer_trust"`
// Logging configuration
Logging LoggingConfig `toml:"logging"`
// TokenExchange configuration
TokenExchange TokenExchangeConfig `toml:"token_exchange"`
// HTTP holds per-service HTTP configuration (Reva-style).
HTTP HTTPConfig `toml:"http"`
// Persistence holds persistence backend settings.
Persistence PersistenceConfig `toml:"persistence"`
// OCM holds OCM-specific settings.
OCM OCMConfig `toml:"ocm"`
// Statistics holds federation validator statistics settings.
Statistics StatisticsConfig `toml:"statistics"`
// Validator holds federation validator session, probe, and active settings.
Validator ValidatorSection `toml:"validator"`
}
Config holds the server configuration.
func DevConfig ¶
func DevConfig() *Config
DevConfig returns development mode defaults as an overlay on StrictConfig, so the strict preset stays the single source of shared defaults.
DevConfig relaxes dev-only transport and operational settings (TLS off, SSRF off, insecure skip verify, ACME staging, debug logging) and overrides persistence to the ephemeral memory backend so dev runs never touch the strict data dir.
func Load ¶
func Load(opts LoaderOptions) (*Config, error)
Load reads, merges, and validates configuration from the given loader options.
func StrictConfig ¶
func StrictConfig() *Config
StrictConfig returns production-safe strict defaults.
func ValidatorConfig ¶ added in v1.3.0
func ValidatorConfig() *Config
ValidatorConfig returns federation validator defaults as an overlay on StrictConfig.
func (*Config) BuildServiceConfig ¶
BuildServiceConfig returns the raw service config map for a given service name. Returns nil if the service is not configured in [http.services.<name>].
func (*Config) PublicScheme ¶
PublicScheme returns "http" or "https" from PublicOrigin. Returns "https" if PublicOrigin is empty or unparseable.
type DiscoveryConfig ¶ added in v1.2.0
type DiscoveryConfig struct {
// PeerAPIVersionPolicy selects accept policy: accept-any, exact, at-least-1.4.
PeerAPIVersionPolicy string `toml:"peer_api_version_policy"`
// PeerAPIVersionWarn selects warning behavior: any-diff, lower-only, none.
PeerAPIVersionWarn string `toml:"peer_api_version_warn"`
}
DiscoveryConfig holds inbound peer discovery validation settings.
func DefaultDiscoveryConfig ¶ added in v1.2.0
func DefaultDiscoveryConfig() DiscoveryConfig
DefaultDiscoveryConfig returns inbound peer discovery validation defaults.
type FlagOverrides ¶
type FlagOverrides struct {
ListenAddr *string
PublicOrigin *string
ExternalBasePath *string
AdminUsername *string
AdminPassword *string
LoggingLevel *string
TokenExchangePath *string
}
FlagOverrides holds CLI flag values that override config file values.
type HTTPConfig ¶
type HTTPConfig struct {
// Services maps service names to their raw config maps.
// Each service decodes its own config via cfg.Decode() with Setter interface.
Services map[string]map[string]any `toml:"services"`
// Interceptors maps interceptor names to their raw config maps.
// Ratelimit profiles live at [http.interceptors.ratelimit.profiles.<name>].
// Per-service opt-in is [http.services.<svc>.ratelimit] with profile = "<name>".
Interceptors map[string]map[string]any `toml:"interceptors"`
}
HTTPConfig holds per-service HTTP configuration. Services are configured under [http.services.<svcname>]. Interceptors are configured under [http.interceptors.<name>].
type InviteConfig ¶ added in v1.2.0
type InviteConfig struct {
// EnforceMustInvite requires an exchanged invite before accepting a share
// creation notification (IETF-OCM:
// https://github.com/cs3org/OCM-API/blob/6a0586183cbef10ecae9dedc42561806447eb2f5/IETF-OCM.md#L763-L765).
// Nil means enabled (the default); explicit false is the legacy opt-out.
EnforceMustInvite *bool `toml:"enforce_must_invite"`
}
InviteConfig holds invite-exchange enforcement settings under [ocm.invite]. This is independent of peer_trust.enabled: must-invite gates inbound share creation on an exchanged invite, not on peer-trust membership.
type LoaderOptions ¶
type LoaderOptions struct {
// ConfigPath is the path to a TOML config file (optional).
// If provided but file is missing or invalid, loading fails.
ConfigPath string
// ModeFlag is the --mode flag value (overrides config file mode).
ModeFlag string
// FlagOverrides are CLI flag values that override config file values.
FlagOverrides FlagOverrides
// Logger is accepted but not read by Load.
Logger *slog.Logger
}
LoaderOptions controls how configuration is loaded.
type LoggingConfig ¶
type LoggingConfig struct {
// Level is the minimum log level: trace, debug, info, warn, error.
// Default: info in strict mode, debug in dev mode.
Level string `toml:"level"`
}
LoggingConfig holds logging settings.
type OCMConfig ¶ added in v1.2.0
type OCMConfig struct {
// CompatibilityScope selects global vs scoped peer-compat leniency.
// Default: global. This is ocmgo-internal policy, not an OCM spec field.
CompatibilityScope CompatibilityScope `toml:"compatibility_scope"`
Discovery DiscoveryConfig `toml:"discovery"`
CodeFlow CodeFlowConfig `toml:"code_flow"`
PeerMapping PeerMappingConfig `toml:"peer_compat"`
Invite *InviteConfig `toml:"invite"`
}
OCMConfig holds OCM-specific settings.
func (OCMConfig) MustInviteEnforced ¶ added in v1.2.0
MustInviteEnforced reports whether inbound shares require an exchanged invite. Unset configuration evaluates to enabled.
type OutboundHTTPConfig ¶
type OutboundHTTPConfig struct {
// SSRF holds SSRF protection settings.
// Configure via [outbound_http.ssrf] in TOML.
SSRF SSRFConfig `toml:"ssrf"`
// TimeoutMS is the overall request timeout in milliseconds
TimeoutMS int `toml:"timeout_ms"`
// ConnectTimeoutMS is the connection timeout in milliseconds
ConnectTimeoutMS int `toml:"connect_timeout_ms"`
// MaxRedirects is the maximum number of redirects to follow
MaxRedirects int `toml:"max_redirects"`
// MaxResponseBytes is the maximum response body size
MaxResponseBytes int64 `toml:"max_response_bytes"`
// InsecureSkipVerify disables TLS verification (dev-only)
InsecureSkipVerify bool `toml:"insecure_skip_verify"`
// TLSRootCAFile is a PEM file of root CAs for outbound TLS verification.
TLSRootCAFile string `toml:"tls_root_ca_file"`
// TLSRootCADir is a directory of .pem/.crt files for outbound TLS root CAs.
TLSRootCADir string `toml:"tls_root_ca_dir"`
// ProxyURL is an optional HTTP/HTTPS proxy for all outbound requests.
// Must be an absolute http or https URL with no userinfo.
// When set, the proxy host is operator-trusted; private and loopback
// addresses are permitted.
// When set, proxy_url takes precedence over use_env_fallback; the
// explicit URL is used and environment variables are not consulted.
ProxyURL string `toml:"proxy_url"`
// UseEnvFallback (config key use_env_fallback) enables reading
// HTTP_PROXY/HTTPS_PROXY/NO_PROXY from the environment when proxy_url is
// not set. Default: false in all presets. Set to true to opt in to
// ambient proxy discovery, or set the
// OCM_CONFIG_OUTBOUND_HTTP_USE_ENV_FALLBACK environment variable.
UseEnvFallback bool `toml:"use_env_fallback"`
}
OutboundHTTPConfig holds settings for outbound HTTP requests.
func DefaultOutboundHTTP ¶ added in v1.1.0
func DefaultOutboundHTTP() OutboundHTTPConfig
DefaultOutboundHTTP returns the strict preset outbound HTTP baseline. use_env_fallback defaults to false: ambient HTTP_PROXY/HTTPS_PROXY/NO_PROXY are ignored unless the operator explicitly opts in via the config field or its environment-variable override. The returned config is already non-ambient, so callers do not need a separate strict variant to avoid env proxy discovery.
func OutboundHTTPConfigStrict ¶
func OutboundHTTPConfigStrict() OutboundHTTPConfig
OutboundHTTPConfigStrict returns strict outbound HTTP config for production. UseEnvFallback (use_env_fallback) is false so programmatic callers do not inherit ambient env proxy settings unless explicitly configured.
func TestHarnessOutboundHTTP ¶ added in v1.1.0
func TestHarnessOutboundHTTP() *OutboundHTTPConfig
TestHarnessOutboundHTTP returns the integration-harness outbound baseline.
type PeerMappingConfig ¶ added in v1.2.0
type PeerMappingConfig struct {
IncludesTokenExchangeRequirement *bool `toml:"includes_token_exchange_requirement"`
RequiresTokenExchangeRequirement *bool `toml:"requires_token_exchange_requirement"`
RequiresHTTPRequestSignatures *bool `toml:"requires_http_request_signatures"`
HostPlatform map[string]string `toml:"host_platform"`
Platform map[string]PeerPlatformOverlay `toml:"platform"`
// contains filtered or unexported fields
}
PeerMappingConfig holds the hierarchical [ocm.peer_compat] overlay. Empty TOML leaves all *bool knobs nil, which defaults to strict (true). Maps are normalized at load time so host lookup is scheme-aware.
func (*PeerMappingConfig) GlobalKnobs ¶ added in v1.2.0
func (cfg *PeerMappingConfig) GlobalKnobs() (includes, requires, http *bool)
GlobalKnobs returns the global tier knobs.
func (*PeerMappingConfig) HostPlatformFor ¶ added in v1.2.0
func (cfg *PeerMappingConfig) HostPlatformFor(host string) (string, bool)
HostPlatformFor returns the platform mapped to host, if any.
func (*PeerMappingConfig) InstanceKnobs ¶ added in v1.2.0
func (cfg *PeerMappingConfig) InstanceKnobs(platform, host string) (includes, requires *bool, ok bool)
InstanceKnobs returns the instance-level knobs for a platform and host, if both are defined.
func (*PeerMappingConfig) PlatformInstanceBinding ¶ added in v1.2.0
func (cfg *PeerMappingConfig) PlatformInstanceBinding(host string) (string, bool)
PlatformInstanceBinding returns the platform that has an explicit instance binding for host, if any.
func (*PeerMappingConfig) PlatformKnobs ¶ added in v1.2.0
func (cfg *PeerMappingConfig) PlatformKnobs(platform string) (includes, requires *bool, ok bool)
PlatformKnobs returns the platform-level knobs, if the platform is defined.
func (*PeerMappingConfig) PublicScheme ¶ added in v1.2.0
func (cfg *PeerMappingConfig) PublicScheme() string
PublicScheme returns the scheme used to normalize host keys. It defaults to "https" when the config has not been loaded.
func (*PeerMappingConfig) Scheme ¶ added in v1.2.0
func (cfg *PeerMappingConfig) Scheme() string
Scheme returns the scheme for host-key normalization.
type PeerMappingInstanceOverlay ¶ added in v1.2.0
type PeerMappingInstanceOverlay struct {
IncludesTokenExchangeRequirement *bool `toml:"includes_token_exchange_requirement"`
RequiresTokenExchangeRequirement *bool `toml:"requires_token_exchange_requirement"`
}
PeerMappingInstanceOverlay holds instance-level knob overrides. HTTP request signature admission is governed by the must-use-http-sig criterion and Applicability rules, not by per-peer compatibility knobs.
type PeerPlatformOverlay ¶ added in v1.2.0
type PeerPlatformOverlay struct {
IncludesTokenExchangeRequirement *bool `toml:"includes_token_exchange_requirement"`
RequiresTokenExchangeRequirement *bool `toml:"requires_token_exchange_requirement"`
Instance map[string]PeerMappingInstanceOverlay `toml:"instance"`
}
PeerPlatformOverlay holds platform-level knobs and per-instance overrides. HTTP request signature admission is governed by the must-use-http-sig criterion and Applicability rules, not by per-peer compatibility knobs.
type PeerTrustConfig ¶
type PeerTrustConfig struct {
// Enabled enables peer trust features. Default: false.
Enabled bool `toml:"enabled"`
// ConfigPaths is a list of paths to JSON trust group config files.
// Required when enabled.
ConfigPaths []string `toml:"config_paths"`
// Policy contains trust policy settings.
Policy PeerTrustPolicyConfig `toml:"policy"`
// MembershipCache contains membership cache settings.
MembershipCache PeerTrustMembershipCacheConfig `toml:"membership_cache"`
}
PeerTrustConfig holds peer trust settings.
type PeerTrustMembershipCacheConfig ¶
type PeerTrustMembershipCacheConfig struct {
// TTLSeconds is the cache TTL in seconds. Default: 21600 (6 hours).
TTLSeconds int `toml:"ttl_seconds"`
// MaxStaleSeconds is the max staleness before treating as unavailable. Default: 604800 (7 days).
MaxStaleSeconds int `toml:"max_stale_seconds"`
}
PeerTrustMembershipCacheConfig holds membership cache settings.
func DefaultPeerTrustMembershipCache ¶ added in v1.1.0
func DefaultPeerTrustMembershipCache() PeerTrustMembershipCacheConfig
DefaultPeerTrustMembershipCache returns preset peer-trust cache TTL defaults.
type PeerTrustPolicyConfig ¶
type PeerTrustPolicyConfig struct {
// AllowList is a list of always-allowed hosts.
AllowList []string `toml:"allow_list"`
// DenyList is a list of always-denied hosts.
DenyList []string `toml:"deny_list"`
}
PeerTrustPolicyConfig holds peer trust policy settings.
type PersistenceConfig ¶ added in v1.1.0
type PersistenceConfig struct {
// Backend selects the persistence backend: memory, json, sqlite, mirror.
// Preset default: strict uses sqlite; dev uses memory (see presets.go).
Backend string `toml:"backend"`
// DataDir is the data directory for durable backends (json, sqlite, mirror).
// Required when backend is json, sqlite, or mirror.
DataDir string `toml:"data_dir"`
// ContentDir is the managed local content root for demo shares.
ContentDir string `toml:"content_dir"`
}
PersistenceConfig holds persistence backend settings.
type SSRFConfig ¶ added in v1.1.0
type SSRFConfig struct {
// Mode is one of: strict, off.
Mode string `toml:"mode"`
// RoutePolicy names the active route policy from RoutePolicies.
// When set the named policy must exist in RoutePolicies.
RoutePolicy string `toml:"route_policy"`
// RoutePolicies maps policy names to their definitions.
RoutePolicies map[string]SSRFRoutePolicyConfig `toml:"route_policies"`
}
SSRFConfig holds SSRF protection settings for outbound HTTP requests.
type SSRFRoutePolicyConfig ¶ added in v1.1.0
type SSRFRoutePolicyConfig struct {
// AllowPrivateHostSuffixes lists host suffixes permitted for private routing.
AllowPrivateHostSuffixes []string `toml:"allow_private_host_suffixes"`
// AllowPrivateCIDRs lists CIDR ranges permitted for private routing.
// Catch-all CIDRs (0.0.0.0/0, ::/0) are rejected by route-policy validation.
AllowPrivateCIDRs []string `toml:"allow_private_cidrs"`
// AllowedPorts restricts which destination ports are permitted.
AllowedPorts []int `toml:"allowed_ports"`
// AllowIPLiterals permits direct IP address targets when true.
AllowIPLiterals bool `toml:"allow_ip_literals"`
}
SSRFRoutePolicyConfig defines a named SSRF route policy with explicit allow-lists for private destinations.
type ServerConfig ¶
type ServerConfig struct {
// TrustedProxies is a list of CIDR ranges for trusted reverse proxies.
// X-Forwarded-* headers are only honored from these addresses.
// Default: ["127.0.0.0/8", "::1/128"]
TrustedProxies []string `toml:"trusted_proxies"`
// BootstrapAdmin holds super admin bootstrap configuration.
BootstrapAdmin BootstrapAdminConfig `toml:"bootstrap_admin"`
}
ServerConfig holds server-level settings.
type SignatureConfig ¶
type SignatureConfig struct {
// KeyPath is where the signing private key is stored
KeyPath string `toml:"key_path"`
// Label is the RFC 9421 signature dictionary label (default: ocm).
Label string `toml:"label"`
// KidFragment is the host#fragment suffix for local JWKS kid (default: key1).
KidFragment string `toml:"kid_fragment"`
// CreatedMaxAgeSeconds is the maximum signature age verifiers accept.
CreatedMaxAgeSeconds int `toml:"created_max_age_seconds"`
// CreatedMaxSkewSeconds is the maximum clock skew into the future verifiers accept.
CreatedMaxSkewSeconds int `toml:"created_max_skew_seconds"`
// AllowedAlgorithms lists permitted asymmetric RFC 9421 algorithms for
// inbound verification and outbound SignRequest. The local private key
// (default Ed25519) still performs signing; this list must include that
// key's algorithm or SignRequest fails before the request is sent.
AllowedAlgorithms []string `toml:"allowed_algorithms"`
// JwksURI optionally overrides the local JWKS URL advertised in
// discovery. Empty derives it from the route inventory as
// <endPoint>/jwks.
JwksURI string `toml:"jwks_uri"`
// MinRSAModulusBits is the local minimum RSA modulus size for inbound
// signature verification. Zero means use the default (2048).
MinRSAModulusBits int `toml:"min_rsa_modulus_bits"`
}
SignatureConfig holds HTTP signature settings.
func DefaultSignatureConfig ¶ added in v1.1.0
func DefaultSignatureConfig() SignatureConfig
DefaultSignatureConfig returns RFC 9421 / OCM IETF signature defaults.
type StatisticsConfig ¶ added in v1.3.0
type StatisticsConfig struct {
// Enabled turns on statistics host hashing and related exports.
Enabled bool `toml:"enabled"`
}
StatisticsConfig holds federation validator statistics settings under [statistics]. The shared 32-byte redaction salt is minted at startup into persistence.data_dir/redaction.salt (mode 0600); it is not stored in TOML.
type TLSConfig ¶
type TLSConfig struct {
// Mode is one of: off, static, selfsigned, acme
Mode string `toml:"mode"`
// CertFile and KeyFile for static mode
CertFile string `toml:"cert_file"`
KeyFile string `toml:"key_file"`
// HTTPPort for HTTP listener (used for ACME challenges and redirects)
HTTPPort int `toml:"http_port"`
// HTTPSPort for HTTPS listener
HTTPSPort int `toml:"https_port"`
// SelfSignedDir is where self-signed certs are stored
SelfSignedDir string `toml:"self_signed_dir"`
// TLSDir optionally re-roots default paths (self_signed_dir, acme.storage_dir, signature.key_path).
// When set, paths are derived unless explicitly defined in TOML. Default: empty (unset).
TLSDir string `toml:"tls_dir"`
// ACME configuration
ACME ACMEConfig `toml:"acme"`
}
TLSConfig holds TLS-related settings.
type TokenExchangeConfig ¶
type TokenExchangeConfig struct {
// Path is the token exchange endpoint path (relative to /ocm/).
// Default: "token"
Path string `toml:"path"`
}
TokenExchangeConfig holds token exchange settings.
type ValidatorActiveConfig ¶ added in v1.3.0
type ValidatorActiveConfig struct {
// Enabled turns on active-session legs. Nil means enabled (the default);
// explicit false is the passive-only opt-out.
Enabled *bool `toml:"enabled"`
}
ValidatorActiveConfig holds the optional [validator.active] knobs.
type ValidatorProbeConfig ¶ added in v1.3.0
type ValidatorProbeConfig struct {
Email string `toml:"email"`
DisplayName string `toml:"display_name"`
}
ValidatorProbeConfig holds the local probe party fields under [validator.probe].
type ValidatorSection ¶ added in v1.3.0
type ValidatorSection struct {
Session ValidatorSessionConfig `toml:"session"`
Probe ValidatorProbeConfig `toml:"probe"`
Active ValidatorActiveConfig `toml:"active"`
}
ValidatorSection holds federation-validator-specific config knobs.
func (ValidatorSection) ActiveEnabled ¶ added in v1.3.0
func (s ValidatorSection) ActiveEnabled() bool
ActiveEnabled reports whether active-session legs should be built. Unset configuration evaluates to enabled.
type ValidatorSessionConfig ¶ added in v1.3.0
type ValidatorSessionConfig struct {
InFlightPassiveLimit int `toml:"in_flight_passive_limit"`
CreatedTTLSeconds int `toml:"created_ttl_seconds"`
PassiveRunningTTLSeconds int `toml:"passive_running_ttl_seconds"`
PassiveCompleteTTLSeconds int `toml:"passive_complete_ttl_seconds"`
TerminalRetentionDays int `toml:"terminal_retention_days"`
StallTimeoutSeconds int `toml:"stall_timeout_seconds"`
MaxDriveIdleSeconds int `toml:"max_drive_idle_seconds"`
ReapIntervalSeconds int `toml:"reap_interval_seconds"`
SessionLimit int `toml:"session_limit"`
MaxDispatchAttempts int `toml:"max_dispatch_attempts"`
BackoffBaseSeconds int `toml:"backoff_base_seconds"`
BackoffCapSeconds int `toml:"backoff_cap_seconds"`
}
ValidatorSessionConfig holds optional session limits under [validator.session].