-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathseid.example.yaml
More file actions
115 lines (89 loc) · 4.31 KB
/
Copy pathseid.example.yaml
File metadata and controls
115 lines (89 loc) · 4.31 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
# Statusengine Web Interface - example configuration.
#
# Every key is optional except mysql_dsn. Precedence, for every setting:
#
# command line flag > environment variable > this file > default
#
# Environment variables are the key in upper case with an SEI_ prefix,
# for example SEI_LISTEN_ADDR.
# --- HTTP ------------------------------------------------------------------
# Loopback by default. This process holds a key that can drive the
# monitoring core, so reaching the network should be a decision.
listen_addr: 127.0.0.1:8090
# --- MySQL -----------------------------------------------------------------
# The same database the Statusengine worker writes to. The interface reads
# statusengine_* and owns the sei_* tables it creates itself.
mysql_dsn: statusengine:statusengine@tcp(127.0.0.1:3306)/statusengine?parseTime=true
mysql_max_open_conns: 25
# How long one API request may spend in the database. Without a bound, a
# query that cannot finish holds a pooled connection and a browser tab
# for as long as the server is willing to wait, which is forever. The
# live event stream is exempt - it is meant to stay open.
query_timeout: 20s
# --- Statusengine worker ---------------------------------------------------
# External commands. Without a key this is left switched off and the UI
# says so rather than offering buttons that always fail.
# Note the endpoint is /commands, plural, on its own port with its own key
# - a /ws key does not work here.
worker_command_url: http://127.0.0.1:8081/commands
worker_command_key: ""
# Live event stream. The browser never talks to this directly: the daemon
# is the only client and fans events out over SSE. Without a key the UI
# falls back to polling.
worker_events_url: ws://127.0.0.1:8080/ws
worker_events_key: ""
# --- Sessions --------------------------------------------------------------
session_ttl: 12h
# Turn this on whenever the browser reaches the interface over TLS. It
# marks the session cookie Secure and sends HSTS.
secure_cookies: false
# Failed logins allowed per address per window, which is what makes
# online guessing slow.
login_rate_limit: 10
login_rate_window: 1m
# --- Demo mode -------------------------------------------------------------
# Offers an account on the login page that signs in with one click. The
# account is created on start.
demo_mode: false
demo_user: guest
# What that account may submit. Empty means it can only read, which is
# the default and the right setting unless you decided otherwise.
#
# Allowed names: acknowledge, downtime, reschedule, submit-result,
# toggle. Each is one right - acknowledging and removing an
# acknowledgement are the same one, as are scheduling a downtime and
# cancelling it.
#
# "notify" is refused here whatever you write: a custom notification
# mails and pages the real contacts of whatever is being monitored.
#
# Read docs/security.md before turning this on for something reachable
# from the internet.
demo_commands: []
# --- Limits ----------------------------------------------------------------
# Command submissions allowed per caller per minute. Every command that
# gets through becomes work for the monitoring core, so this bounds what
# the interface can ask of it. A negative number switches it off.
command_rate_limit: 60
# The same for the demo account, which is shared by everybody trying it,
# plus a ceiling on how many objects one of its commands may address.
demo_command_rate_limit: 10
demo_max_targets: 25
# Concurrent event-stream connections. Each is cheap; the limit is there
# so one client cannot hold them until the process runs out of file
# descriptors.
max_event_clients: 500
# --- Command audit ---------------------------------------------------------
# Every submitted command is recorded in sei_command_audit, refusals
# included. These two decide what that record keeps.
# The caller's address. Right for an internal deployment, where the
# question is who did this; a public demo records strangers.
audit_client_ip: true
# Drop records older than this many days. Zero keeps them forever.
audit_retention_days: 0
# --- Performance data ------------------------------------------------------
# "mysql" reads statusengine_perfdata. "graphite" is not wired up yet.
metrics_provider: mysql
# --- Logging ---------------------------------------------------------------
log_level: info
log_format: text