config

package
v1.3.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 9, 2026 License: AGPL-3.0 Imports: 20 Imported by: 0

Documentation

Overview

Package config provides configuration loading and validation.

Index

Constants

View Source
const (
	DefaultOutboundTimeoutMS             = 10000
	DefaultOutboundConnectTimeoutMS      = 2000
	DefaultOutboundMaxRedirects          = 1
	DefaultMaxResponseBytes              = 1 << 20
	DefaultOutboundMaxIdleConns          = 10
	DefaultOutboundMaxConnsPerHost       = 10
	DefaultOutboundIdleConnTimeout       = 30 * time.Second
	DefaultOutboundResponseHeaderTimeout = 10 * time.Second
)

Outbound HTTP defaults (production strict preset baseline).

View Source
const (
	DefaultServerReadTimeout          = 30 * time.Second
	DefaultServerReadHeaderTimeout    = 10 * time.Second
	DefaultServerWriteTimeout         = 30 * time.Second
	DefaultServerIdleTimeout          = 60 * time.Second
	DefaultChallengeReadTimeout       = 10 * time.Second
	DefaultChallengeReadHeaderTimeout = 10 * time.Second
	DefaultChallengeWriteTimeout      = 10 * time.Second
	DefaultChallengeIdleTimeout       = 60 * time.Second
	DefaultServerShutdownTimeout      = 2 * time.Second
)

Server HTTP listener defaults.

View Source
const (
	DefaultPeerTrustCacheTTLSeconds      = 21600  // 6 hours
	DefaultPeerTrustCacheMaxStaleSeconds = 604800 // 7 days
)

Peer trust membership cache defaults (seconds, TOML-facing).

View Source
const (
	DefaultSignatureLabel          = sigparams.SignatureLabelOCM
	DefaultSignatureKidFragment    = "key1"
	DefaultSignatureCreatedMaxAge  = 300
	DefaultSignatureCreatedMaxSkew = 60
	DefaultMinRSAModulusBits       = 2048
)

HTTP signature defaults (https://www.rfc-editor.org/rfc/rfc9421.html; OCM Appendix B, informative: https://github.com/cs3org/OCM-API/blob/6a0586183cbef10ecae9dedc42561806447eb2f5/IETF-OCM.md#L2136).

View Source
const (
	TestOutboundTimeoutMS = 5000
	TestOutboundConnectMS = 2000
)

Test-oriented outbound and wait defaults (integration harness + unit tests).

View Source
const (
	BackendMemory = "memory"
	BackendJSON   = "json"
	BackendSQLite = "sqlite"
	BackendMirror = "mirror"
)

Persistence backend name constants. These are the only valid values for PersistenceConfig.Backend. Unknown values are rejected at validation time; there is no silent fallback to memory.

View Source
const (

	// TLSModeOff disables in-process TLS; the HTTP server listens in plain HTTP.
	TLSModeOff = "off"
	// TLSModeTerminated terminates TLS upstream; forwarded headers from trusted proxies carry scheme.
	TLSModeTerminated = "terminated"
)

URL scheme, mode, and strict-preset port constants for config loading and validation.

View Source
const (
	// ScanPublicRatelimitProfile is the public scan ratelimit profile name.
	// Configured at [http.interceptors.ratelimit.profiles.scan_public].
	ScanPublicRatelimitProfile = "scan_public"

	// StartPublicRatelimitBucket is the create-session bucket under scan_public.
	// Configured at [http.interceptors.ratelimit.profiles.scan_public.start_public].
	StartPublicRatelimitBucket = "start_public"

	// DefaultValidatorProbeEmail is the preset [validator.probe] email.
	DefaultValidatorProbeEmail = "probe@localhost"

	// DefaultValidatorProbeDisplayName is the preset [validator.probe] display name.
	DefaultValidatorProbeDisplayName = "Probe User"
)
View Source
const DefaultContentDir = ".ocm/files"

DefaultContentDir is the CWD-relative managed content root, sibling of the default data directory under .ocm/.

View Source
const DefaultPersistenceDataDir = ".ocm/data"

DefaultPersistenceDataDir is the CWD-relative data directory the strict preset uses for its durable sqlite backend.

View Source
const DefaultTestShutdownWait = 5 * time.Second

DefaultTestShutdownWait is the standard bounded wait for server shutdown and async test synchronization.

View Source
const DefaultValidatorPersistenceDataDir = ".ocm/validator-data"

DefaultValidatorPersistenceDataDir is the CWD-relative data directory the validator preset uses for its durable sqlite backend.

View Source
const EnvOutboundHTTPUseEnvFallback = "OCM_CONFIG_OUTBOUND_HTTP_USE_ENV_FALLBACK"

EnvOutboundHTTPUseEnvFallback is the environment-variable name that overrides the outbound_http.use_env_fallback TOML key at load time via applyEnvOverrides. use_env_fallback has no CLI flag, so the env override sits directly above the TOML value in the precedence order. Exported so callers that scrub or set the environment (for example the integration harness hermetic blocklist) reuse the single canonical name instead of duplicating the raw literal.

View Source
const SeedContentFileName = "hello-ocm.txt"

SeedContentFileName is the demo file created idempotently under the content root.

Variables

View Source
var DefaultValidatorTrustedProxies = []string{
	"127.0.0.0/8",
	"::1/128",
	"10.0.0.0/8",
	"172.16.0.0/12",
	"192.168.0.0/16",
}

DefaultValidatorTrustedProxies includes loopback and common Docker bridge ranges.

Functions

func IsTLSModeTerminated added in v1.3.0

func IsTLSModeTerminated(cfg *Config) bool

IsTLSModeTerminated reports whether TLS terminates at an upstream reverse proxy.

func IsValidatorMode added in v1.3.0

func IsValidatorMode(cfg *Config) bool

IsValidatorMode reports whether cfg runs in federation validator mode.

func NormalizeSignatureAllowedAlgorithms added in v1.2.0

func NormalizeSignatureAllowedAlgorithms(algorithms []string) ([]string, error)

NormalizeSignatureAllowedAlgorithms canonicalizes JOSE/native aliases, rejects empty/whitespace/symmetric/unknown entries, and dedupes while preserving first-seen order.

func PublicSchemeFromOrigin added in v1.1.0

func PublicSchemeFromOrigin(publicOrigin string) string

PublicSchemeFromOrigin returns "http" or "https" derived from a public origin string. Returns "https" if the origin is empty or unparseable. Use this for callers that want a usable default scheme (config-aware callers and the token handler). Callers that must leave the scheme empty when the origin is empty or unparseable should use SchemeFromOrigin.

func ResolveContentDir added in v1.2.0

func ResolveContentDir(dir string) (string, error)

ResolveContentDir returns the absolute path for the managed content root. Empty dir falls back to DefaultContentDir relative to the current working directory.

func SchemeFromOrigin added in v1.1.0

func SchemeFromOrigin(publicOrigin string) string

SchemeFromOrigin returns the lowercased scheme ("http" or "https") derived from a public origin string, or an empty string when the origin is empty or unparseable. Unlike PublicSchemeFromOrigin it never substitutes a default scheme, preserving callers that intentionally treat an empty or unparseable origin as an empty scheme during hostport normalization.

func SessionConfigFromValidator added in v1.3.0

func SessionConfigFromValidator(cfg *Config) validatorcore.SessionConfig

SessionConfigFromValidator returns validatorcore session limits from cfg.

func StartPublicRatelimitProfile added in v1.3.0

func StartPublicRatelimitProfile(cfg *Config) (map[string]any, error)

StartPublicRatelimitProfile returns the start_public bucket under scan_public.

func ValidateStrictModeStartupGuardrails added in v1.2.0

func ValidateStrictModeStartupGuardrails(cfg *Config) error

ValidateStrictModeStartupGuardrails applies the same strict-mode startup guardrails that Load enforces. It is exported so in-memory config callers that build a Config without going through Load (for example the in-process test harness) reject the same impossible startup states the real binary rejects. Load reaches this logic via validateEnums.

func ValidateValidatorModeStartupGuardrails added in v1.3.0

func ValidateValidatorModeStartupGuardrails(cfg *Config) error

ValidateValidatorModeStartupGuardrails applies the same validator-mode startup guardrails that Load enforces. It is exported so in-memory config callers that build a Config without going through Load (for example the in-process test harness) reject the same impossible startup states the real binary rejects. Load reaches this logic via validateEnums.

Types

type ACMEConfig

type ACMEConfig struct {
	// Email for ACME registration
	Email string `toml:"email"`

	// Domain is the domain to obtain a certificate for
	Domain string `toml:"domain"`

	// Directory is the ACME server URL (default: Let's Encrypt production)
	Directory string `toml:"directory"`

	// StorageDir is where ACME certificates and account info are stored
	StorageDir string `toml:"storage_dir"`

	// UseStaging uses Let's Encrypt staging (for testing)
	UseStaging bool `toml:"use_staging"`
}

ACMEConfig holds ACME/Let's Encrypt settings.

type BootstrapAdminConfig

type BootstrapAdminConfig struct {
	// Username for the super admin. Default: "admin"
	Username string `toml:"username"`

	// Password for the super admin. If empty on first boot, a random password is generated.
	Password string `toml:"password"`

	// CredentialFile is where an auto-generated bootstrap password is written.
	// Relative paths resolve against the process working directory.
	CredentialFile string `toml:"password_file"`
}

BootstrapAdminConfig holds bootstrap admin credentials.

type CacheConfig

type CacheConfig struct {
	// Driver is the cache driver name: "memory" (default). Other drivers may fail validation.
	Driver string `toml:"driver"`

	// Drivers holds per-driver configuration (Reva-style).
	// Example: [cache.drivers.memory] ...
	Drivers map[string]any `toml:"drivers"`
}

CacheConfig holds cache settings.

type CodeFlowConfig added in v1.2.0

type CodeFlowConfig struct {
	IncludesTokenExchangeRequirement *bool `toml:"includes_token_exchange_requirement"`
	RequiresTokenExchangeRequirement *bool `toml:"requires_token_exchange_requirement"`
	RequiresHTTPRequestSignatures    *bool `toml:"requires_http_request_signatures"`
}

CodeFlowConfig holds relaxable OCM code-flow knobs under [ocm.code_flow]. Unset (nil) means inherit/strict default; false relaxes; true enforces.

type CompatibilityScope added in v1.2.0

type CompatibilityScope string

CompatibilityScope selects how peer-compat leniency is applied. This is an ocmgo-internal policy axis, not an OCM specification concept.

const (
	// CompatibilityScopeGlobal applies peer_compat relaxations globally (current behavior).
	CompatibilityScopeGlobal CompatibilityScope = "global"
	// CompatibilityScopeScoped limits leniency to explicitly mapped peers only.
	CompatibilityScopeScoped CompatibilityScope = "scoped"
)

func ParseCompatibilityScope added in v1.2.0

func ParseCompatibilityScope(s string) (CompatibilityScope, error)

ParseCompatibilityScope parses a compatibility_scope string.

type Config

type Config struct {
	// Mode selects a preset bundle: strict, dev, or validator.
	Mode string `toml:"mode"`

	// PublicOrigin is the public origin (scheme + host + port) for this instance.
	// Example: "https://localhost:9200"
	PublicOrigin string `toml:"public_origin"`

	// ExternalBasePath is the optional path prefix for app endpoints.
	// The root-only well-known discovery endpoint (/.well-known/ocm) is
	// never under this path; the local JWKS route (<endPoint>/jwks) is
	// mounted under the OCM service and does move with this path.
	// Example: "/ocm" or empty string
	ExternalBasePath string `toml:"external_base_path"`

	// ListenAddr is the address to listen on.
	// Example: ":9200"
	ListenAddr string `toml:"listen_addr"`

	// Server holds server-level settings.
	Server ServerConfig `toml:"server"`

	// TLS configuration
	TLS TLSConfig `toml:"tls"`

	// OutboundHTTP configuration
	OutboundHTTP OutboundHTTPConfig `toml:"outbound_http"`

	// Signature configuration
	Signature SignatureConfig `toml:"signature"`

	// Cache configuration
	Cache CacheConfig `toml:"cache"`

	// Peer trust configuration
	PeerTrust PeerTrustConfig `toml:"peer_trust"`

	// Logging configuration
	Logging LoggingConfig `toml:"logging"`

	// TokenExchange configuration
	TokenExchange TokenExchangeConfig `toml:"token_exchange"`

	// HTTP holds per-service HTTP configuration (Reva-style).
	HTTP HTTPConfig `toml:"http"`

	// Persistence holds persistence backend settings.
	Persistence PersistenceConfig `toml:"persistence"`

	// OCM holds OCM-specific settings.
	OCM OCMConfig `toml:"ocm"`

	// Statistics holds federation validator statistics settings.
	Statistics StatisticsConfig `toml:"statistics"`

	// Validator holds federation validator session, probe, and active settings.
	Validator ValidatorSection `toml:"validator"`
}

Config holds the server configuration.

func DevConfig

func DevConfig() *Config

DevConfig returns development mode defaults as an overlay on StrictConfig, so the strict preset stays the single source of shared defaults.

DevConfig relaxes dev-only transport and operational settings (TLS off, SSRF off, insecure skip verify, ACME staging, debug logging) and overrides persistence to the ephemeral memory backend so dev runs never touch the strict data dir.

func Load

func Load(opts LoaderOptions) (*Config, error)

Load reads, merges, and validates configuration from the given loader options.

func StrictConfig

func StrictConfig() *Config

StrictConfig returns production-safe strict defaults.

func ValidatorConfig added in v1.3.0

func ValidatorConfig() *Config

ValidatorConfig returns federation validator defaults as an overlay on StrictConfig.

func (*Config) BuildServiceConfig

func (c *Config) BuildServiceConfig(serviceName string) map[string]any

BuildServiceConfig returns the raw service config map for a given service name. Returns nil if the service is not configured in [http.services.<name>].

func (*Config) PublicScheme

func (c *Config) PublicScheme() string

PublicScheme returns "http" or "https" from PublicOrigin. Returns "https" if PublicOrigin is empty or unparseable.

func (*Config) Redacted

func (c *Config) Redacted() string

Redacted returns a string representation of the config with secrets redacted.

type DiscoveryConfig added in v1.2.0

type DiscoveryConfig struct {
	// PeerAPIVersionPolicy selects accept policy: accept-any, exact, at-least-1.4.
	PeerAPIVersionPolicy string `toml:"peer_api_version_policy"`

	// PeerAPIVersionWarn selects warning behavior: any-diff, lower-only, none.
	PeerAPIVersionWarn string `toml:"peer_api_version_warn"`
}

DiscoveryConfig holds inbound peer discovery validation settings.

func DefaultDiscoveryConfig added in v1.2.0

func DefaultDiscoveryConfig() DiscoveryConfig

DefaultDiscoveryConfig returns inbound peer discovery validation defaults.

type FlagOverrides

type FlagOverrides struct {
	ListenAddr        *string
	PublicOrigin      *string
	ExternalBasePath  *string
	AdminUsername     *string
	AdminPassword     *string
	LoggingLevel      *string
	TokenExchangePath *string
}

FlagOverrides holds CLI flag values that override config file values.

type HTTPConfig

type HTTPConfig struct {
	// Services maps service names to their raw config maps.
	// Each service decodes its own config via cfg.Decode() with Setter interface.
	Services map[string]map[string]any `toml:"services"`

	// Interceptors maps interceptor names to their raw config maps.
	// Ratelimit profiles live at [http.interceptors.ratelimit.profiles.<name>].
	// Per-service opt-in is [http.services.<svc>.ratelimit] with profile = "<name>".
	Interceptors map[string]map[string]any `toml:"interceptors"`
}

HTTPConfig holds per-service HTTP configuration. Services are configured under [http.services.<svcname>]. Interceptors are configured under [http.interceptors.<name>].

type InviteConfig added in v1.2.0

type InviteConfig struct {
	// EnforceMustInvite requires an exchanged invite before accepting a share
	// creation notification (IETF-OCM:
	// https://github.com/cs3org/OCM-API/blob/6a0586183cbef10ecae9dedc42561806447eb2f5/IETF-OCM.md#L763-L765).
	// Nil means enabled (the default); explicit false is the legacy opt-out.
	EnforceMustInvite *bool `toml:"enforce_must_invite"`
}

InviteConfig holds invite-exchange enforcement settings under [ocm.invite]. This is independent of peer_trust.enabled: must-invite gates inbound share creation on an exchanged invite, not on peer-trust membership.

type LoaderOptions

type LoaderOptions struct {
	// ConfigPath is the path to a TOML config file (optional).
	// If provided but file is missing or invalid, loading fails.
	ConfigPath string

	// ModeFlag is the --mode flag value (overrides config file mode).
	ModeFlag string

	// FlagOverrides are CLI flag values that override config file values.
	FlagOverrides FlagOverrides

	// Logger is accepted but not read by Load.
	Logger *slog.Logger
}

LoaderOptions controls how configuration is loaded.

type LoggingConfig

type LoggingConfig struct {
	// Level is the minimum log level: trace, debug, info, warn, error.
	// Default: info in strict mode, debug in dev mode.
	Level string `toml:"level"`
}

LoggingConfig holds logging settings.

type Mode

type Mode string

Mode represents the server operating mode.

const (
	// ModeStrict is the strict server operating mode.
	ModeStrict Mode = "strict"
	// ModeDev is the development server operating mode.
	ModeDev Mode = "dev"
	// ModeValidator is the federation validator operating mode.
	ModeValidator Mode = "validator"
)

func ParseMode

func ParseMode(s string) (Mode, error)

ParseMode parses a mode string, returning an error for invalid values.

type OCMConfig added in v1.2.0

type OCMConfig struct {
	// CompatibilityScope selects global vs scoped peer-compat leniency.
	// Default: global. This is ocmgo-internal policy, not an OCM spec field.
	CompatibilityScope CompatibilityScope `toml:"compatibility_scope"`

	Discovery   DiscoveryConfig   `toml:"discovery"`
	CodeFlow    CodeFlowConfig    `toml:"code_flow"`
	PeerMapping PeerMappingConfig `toml:"peer_compat"`
	Invite      *InviteConfig     `toml:"invite"`
}

OCMConfig holds OCM-specific settings.

func (OCMConfig) MustInviteEnforced added in v1.2.0

func (c OCMConfig) MustInviteEnforced() bool

MustInviteEnforced reports whether inbound shares require an exchanged invite. Unset configuration evaluates to enabled.

type OutboundHTTPConfig

type OutboundHTTPConfig struct {
	// SSRF holds SSRF protection settings.
	// Configure via [outbound_http.ssrf] in TOML.
	SSRF SSRFConfig `toml:"ssrf"`

	// TimeoutMS is the overall request timeout in milliseconds
	TimeoutMS int `toml:"timeout_ms"`

	// ConnectTimeoutMS is the connection timeout in milliseconds
	ConnectTimeoutMS int `toml:"connect_timeout_ms"`

	// MaxRedirects is the maximum number of redirects to follow
	MaxRedirects int `toml:"max_redirects"`

	// MaxResponseBytes is the maximum response body size
	MaxResponseBytes int64 `toml:"max_response_bytes"`

	// InsecureSkipVerify disables TLS verification (dev-only)
	InsecureSkipVerify bool `toml:"insecure_skip_verify"`

	// TLSRootCAFile is a PEM file of root CAs for outbound TLS verification.
	TLSRootCAFile string `toml:"tls_root_ca_file"`

	// TLSRootCADir is a directory of .pem/.crt files for outbound TLS root CAs.
	TLSRootCADir string `toml:"tls_root_ca_dir"`

	// ProxyURL is an optional HTTP/HTTPS proxy for all outbound requests.
	// Must be an absolute http or https URL with no userinfo.
	// When set, the proxy host is operator-trusted; private and loopback
	// addresses are permitted.
	// When set, proxy_url takes precedence over use_env_fallback; the
	// explicit URL is used and environment variables are not consulted.
	ProxyURL string `toml:"proxy_url"`

	// UseEnvFallback (config key use_env_fallback) enables reading
	// HTTP_PROXY/HTTPS_PROXY/NO_PROXY from the environment when proxy_url is
	// not set. Default: false in all presets. Set to true to opt in to
	// ambient proxy discovery, or set the
	// OCM_CONFIG_OUTBOUND_HTTP_USE_ENV_FALLBACK environment variable.
	UseEnvFallback bool `toml:"use_env_fallback"`
}

OutboundHTTPConfig holds settings for outbound HTTP requests.

func DefaultOutboundHTTP added in v1.1.0

func DefaultOutboundHTTP() OutboundHTTPConfig

DefaultOutboundHTTP returns the strict preset outbound HTTP baseline. use_env_fallback defaults to false: ambient HTTP_PROXY/HTTPS_PROXY/NO_PROXY are ignored unless the operator explicitly opts in via the config field or its environment-variable override. The returned config is already non-ambient, so callers do not need a separate strict variant to avoid env proxy discovery.

func OutboundHTTPConfigStrict

func OutboundHTTPConfigStrict() OutboundHTTPConfig

OutboundHTTPConfigStrict returns strict outbound HTTP config for production. UseEnvFallback (use_env_fallback) is false so programmatic callers do not inherit ambient env proxy settings unless explicitly configured.

func TestHarnessOutboundHTTP added in v1.1.0

func TestHarnessOutboundHTTP() *OutboundHTTPConfig

TestHarnessOutboundHTTP returns the integration-harness outbound baseline.

type PeerMappingConfig added in v1.2.0

type PeerMappingConfig struct {
	IncludesTokenExchangeRequirement *bool `toml:"includes_token_exchange_requirement"`
	RequiresTokenExchangeRequirement *bool `toml:"requires_token_exchange_requirement"`
	RequiresHTTPRequestSignatures    *bool `toml:"requires_http_request_signatures"`

	HostPlatform map[string]string              `toml:"host_platform"`
	Platform     map[string]PeerPlatformOverlay `toml:"platform"`
	// contains filtered or unexported fields
}

PeerMappingConfig holds the hierarchical [ocm.peer_compat] overlay. Empty TOML leaves all *bool knobs nil, which defaults to strict (true). Maps are normalized at load time so host lookup is scheme-aware.

func (*PeerMappingConfig) GlobalKnobs added in v1.2.0

func (cfg *PeerMappingConfig) GlobalKnobs() (includes, requires, http *bool)

GlobalKnobs returns the global tier knobs.

func (*PeerMappingConfig) HostPlatformFor added in v1.2.0

func (cfg *PeerMappingConfig) HostPlatformFor(host string) (string, bool)

HostPlatformFor returns the platform mapped to host, if any.

func (*PeerMappingConfig) InstanceKnobs added in v1.2.0

func (cfg *PeerMappingConfig) InstanceKnobs(platform, host string) (includes, requires *bool, ok bool)

InstanceKnobs returns the instance-level knobs for a platform and host, if both are defined.

func (*PeerMappingConfig) PlatformInstanceBinding added in v1.2.0

func (cfg *PeerMappingConfig) PlatformInstanceBinding(host string) (string, bool)

PlatformInstanceBinding returns the platform that has an explicit instance binding for host, if any.

func (*PeerMappingConfig) PlatformKnobs added in v1.2.0

func (cfg *PeerMappingConfig) PlatformKnobs(platform string) (includes, requires *bool, ok bool)

PlatformKnobs returns the platform-level knobs, if the platform is defined.

func (*PeerMappingConfig) PublicScheme added in v1.2.0

func (cfg *PeerMappingConfig) PublicScheme() string

PublicScheme returns the scheme used to normalize host keys. It defaults to "https" when the config has not been loaded.

func (*PeerMappingConfig) Scheme added in v1.2.0

func (cfg *PeerMappingConfig) Scheme() string

Scheme returns the scheme for host-key normalization.

type PeerMappingInstanceOverlay added in v1.2.0

type PeerMappingInstanceOverlay struct {
	IncludesTokenExchangeRequirement *bool `toml:"includes_token_exchange_requirement"`
	RequiresTokenExchangeRequirement *bool `toml:"requires_token_exchange_requirement"`
}

PeerMappingInstanceOverlay holds instance-level knob overrides. HTTP request signature admission is governed by the must-use-http-sig criterion and Applicability rules, not by per-peer compatibility knobs.

type PeerPlatformOverlay added in v1.2.0

type PeerPlatformOverlay struct {
	IncludesTokenExchangeRequirement *bool `toml:"includes_token_exchange_requirement"`
	RequiresTokenExchangeRequirement *bool `toml:"requires_token_exchange_requirement"`

	Instance map[string]PeerMappingInstanceOverlay `toml:"instance"`
}

PeerPlatformOverlay holds platform-level knobs and per-instance overrides. HTTP request signature admission is governed by the must-use-http-sig criterion and Applicability rules, not by per-peer compatibility knobs.

type PeerTrustConfig

type PeerTrustConfig struct {
	// Enabled enables peer trust features. Default: false.
	Enabled bool `toml:"enabled"`

	// ConfigPaths is a list of paths to JSON trust group config files.
	// Required when enabled.
	ConfigPaths []string `toml:"config_paths"`

	// Policy contains trust policy settings.
	Policy PeerTrustPolicyConfig `toml:"policy"`

	// MembershipCache contains membership cache settings.
	MembershipCache PeerTrustMembershipCacheConfig `toml:"membership_cache"`
}

PeerTrustConfig holds peer trust settings.

type PeerTrustMembershipCacheConfig

type PeerTrustMembershipCacheConfig struct {
	// TTLSeconds is the cache TTL in seconds. Default: 21600 (6 hours).
	TTLSeconds int `toml:"ttl_seconds"`

	// MaxStaleSeconds is the max staleness before treating as unavailable. Default: 604800 (7 days).
	MaxStaleSeconds int `toml:"max_stale_seconds"`
}

PeerTrustMembershipCacheConfig holds membership cache settings.

func DefaultPeerTrustMembershipCache added in v1.1.0

func DefaultPeerTrustMembershipCache() PeerTrustMembershipCacheConfig

DefaultPeerTrustMembershipCache returns preset peer-trust cache TTL defaults.

type PeerTrustPolicyConfig

type PeerTrustPolicyConfig struct {
	// AllowList is a list of always-allowed hosts.
	AllowList []string `toml:"allow_list"`

	// DenyList is a list of always-denied hosts.
	DenyList []string `toml:"deny_list"`
}

PeerTrustPolicyConfig holds peer trust policy settings.

type PersistenceConfig added in v1.1.0

type PersistenceConfig struct {
	// Backend selects the persistence backend: memory, json, sqlite, mirror.
	// Preset default: strict uses sqlite; dev uses memory (see presets.go).
	Backend string `toml:"backend"`

	// DataDir is the data directory for durable backends (json, sqlite, mirror).
	// Required when backend is json, sqlite, or mirror.
	DataDir string `toml:"data_dir"`

	// ContentDir is the managed local content root for demo shares.
	ContentDir string `toml:"content_dir"`
}

PersistenceConfig holds persistence backend settings.

type SSRFConfig added in v1.1.0

type SSRFConfig struct {
	// Mode is one of: strict, off.
	Mode string `toml:"mode"`

	// RoutePolicy names the active route policy from RoutePolicies.
	// When set the named policy must exist in RoutePolicies.
	RoutePolicy string `toml:"route_policy"`

	// RoutePolicies maps policy names to their definitions.
	RoutePolicies map[string]SSRFRoutePolicyConfig `toml:"route_policies"`
}

SSRFConfig holds SSRF protection settings for outbound HTTP requests.

type SSRFRoutePolicyConfig added in v1.1.0

type SSRFRoutePolicyConfig struct {
	// AllowPrivateHostSuffixes lists host suffixes permitted for private routing.
	AllowPrivateHostSuffixes []string `toml:"allow_private_host_suffixes"`

	// AllowPrivateCIDRs lists CIDR ranges permitted for private routing.
	// Catch-all CIDRs (0.0.0.0/0, ::/0) are rejected by route-policy validation.
	AllowPrivateCIDRs []string `toml:"allow_private_cidrs"`

	// AllowedPorts restricts which destination ports are permitted.
	AllowedPorts []int `toml:"allowed_ports"`

	// AllowIPLiterals permits direct IP address targets when true.
	AllowIPLiterals bool `toml:"allow_ip_literals"`
}

SSRFRoutePolicyConfig defines a named SSRF route policy with explicit allow-lists for private destinations.

type ServerConfig

type ServerConfig struct {
	// TrustedProxies is a list of CIDR ranges for trusted reverse proxies.
	// X-Forwarded-* headers are only honored from these addresses.
	// Default: ["127.0.0.0/8", "::1/128"]
	TrustedProxies []string `toml:"trusted_proxies"`

	// BootstrapAdmin holds super admin bootstrap configuration.
	BootstrapAdmin BootstrapAdminConfig `toml:"bootstrap_admin"`
}

ServerConfig holds server-level settings.

type SignatureConfig

type SignatureConfig struct {
	// KeyPath is where the signing private key is stored
	KeyPath string `toml:"key_path"`

	// Label is the RFC 9421 signature dictionary label (default: ocm).
	Label string `toml:"label"`

	// KidFragment is the host#fragment suffix for local JWKS kid (default: key1).
	KidFragment string `toml:"kid_fragment"`

	// CreatedMaxAgeSeconds is the maximum signature age verifiers accept.
	CreatedMaxAgeSeconds int `toml:"created_max_age_seconds"`

	// CreatedMaxSkewSeconds is the maximum clock skew into the future verifiers accept.
	CreatedMaxSkewSeconds int `toml:"created_max_skew_seconds"`

	// AllowedAlgorithms lists permitted asymmetric RFC 9421 algorithms for
	// inbound verification and outbound SignRequest. The local private key
	// (default Ed25519) still performs signing; this list must include that
	// key's algorithm or SignRequest fails before the request is sent.
	AllowedAlgorithms []string `toml:"allowed_algorithms"`

	// JwksURI optionally overrides the local JWKS URL advertised in
	// discovery. Empty derives it from the route inventory as
	// <endPoint>/jwks.
	JwksURI string `toml:"jwks_uri"`

	// MinRSAModulusBits is the local minimum RSA modulus size for inbound
	// signature verification. Zero means use the default (2048).
	MinRSAModulusBits int `toml:"min_rsa_modulus_bits"`
}

SignatureConfig holds HTTP signature settings.

func DefaultSignatureConfig added in v1.1.0

func DefaultSignatureConfig() SignatureConfig

DefaultSignatureConfig returns RFC 9421 / OCM IETF signature defaults.

type StatisticsConfig added in v1.3.0

type StatisticsConfig struct {
	// Enabled turns on statistics host hashing and related exports.
	Enabled bool `toml:"enabled"`
}

StatisticsConfig holds federation validator statistics settings under [statistics]. The shared 32-byte redaction salt is minted at startup into persistence.data_dir/redaction.salt (mode 0600); it is not stored in TOML.

type TLSConfig

type TLSConfig struct {
	// Mode is one of: off, static, selfsigned, acme
	Mode string `toml:"mode"`

	// CertFile and KeyFile for static mode
	CertFile string `toml:"cert_file"`
	KeyFile  string `toml:"key_file"`

	// HTTPPort for HTTP listener (used for ACME challenges and redirects)
	HTTPPort int `toml:"http_port"`

	// HTTPSPort for HTTPS listener
	HTTPSPort int `toml:"https_port"`

	// SelfSignedDir is where self-signed certs are stored
	SelfSignedDir string `toml:"self_signed_dir"`

	// TLSDir optionally re-roots default paths (self_signed_dir, acme.storage_dir, signature.key_path).
	// When set, paths are derived unless explicitly defined in TOML. Default: empty (unset).
	TLSDir string `toml:"tls_dir"`

	// ACME configuration
	ACME ACMEConfig `toml:"acme"`
}

TLSConfig holds TLS-related settings.

type TokenExchangeConfig

type TokenExchangeConfig struct {
	// Path is the token exchange endpoint path (relative to /ocm/).
	// Default: "token"
	Path string `toml:"path"`
}

TokenExchangeConfig holds token exchange settings.

type ValidatorActiveConfig added in v1.3.0

type ValidatorActiveConfig struct {
	// Enabled turns on active-session legs. Nil means enabled (the default);
	// explicit false is the passive-only opt-out.
	Enabled *bool `toml:"enabled"`
}

ValidatorActiveConfig holds the optional [validator.active] knobs.

type ValidatorProbeConfig added in v1.3.0

type ValidatorProbeConfig struct {
	Email       string `toml:"email"`
	DisplayName string `toml:"display_name"`
}

ValidatorProbeConfig holds the local probe party fields under [validator.probe].

type ValidatorSection added in v1.3.0

type ValidatorSection struct {
	Session ValidatorSessionConfig `toml:"session"`
	Probe   ValidatorProbeConfig   `toml:"probe"`
	Active  ValidatorActiveConfig  `toml:"active"`
}

ValidatorSection holds federation-validator-specific config knobs.

func (ValidatorSection) ActiveEnabled added in v1.3.0

func (s ValidatorSection) ActiveEnabled() bool

ActiveEnabled reports whether active-session legs should be built. Unset configuration evaluates to enabled.

type ValidatorSessionConfig added in v1.3.0

type ValidatorSessionConfig struct {
	InFlightPassiveLimit       int `toml:"in_flight_passive_limit"`
	CreatedTTLSeconds          int `toml:"created_ttl_seconds"`
	PassiveRunningTTLSeconds   int `toml:"passive_running_ttl_seconds"`
	PassiveCompleteTTLSeconds  int `toml:"passive_complete_ttl_seconds"`
	TerminalRetentionDays      int `toml:"terminal_retention_days"`
	StallTimeoutSeconds        int `toml:"stall_timeout_seconds"`
	ReverseShareTimeoutSeconds int `toml:"reverse_share_timeout_seconds"`
	MaxDriveIdleSeconds        int `toml:"max_drive_idle_seconds"`
	ReapIntervalSeconds        int `toml:"reap_interval_seconds"`
	SessionLimit               int `toml:"session_limit"`
	MaxDispatchAttempts        int `toml:"max_dispatch_attempts"`
	BackoffBaseSeconds         int `toml:"backoff_base_seconds"`
	BackoffCapSeconds          int `toml:"backoff_cap_seconds"`
}

ValidatorSessionConfig holds optional session limits under [validator.session].

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL