Files
nx9-auth/config.example.toml
T
2026-07-22 19:36:22 +05:30

59 lines
1.8 KiB
TOML

# nx9-auth Configuration Reference
# Copy this file to /etc/nx9-auth/config.toml and adjust for your environment.
[server]
# Interface to bind on. Use 127.0.0.1 if running behind a reverse proxy.
host = "0.0.0.0"
# Port the service listens on.
port = 8655
# Session cookie Secure flag.
# false = works over plain HTTP (typical self-hosted / LAN).
# true = required when the UI is served over HTTPS (or a TLS reverse proxy).
# If Secure=true on plain HTTP, browsers drop the cookie and login/password
# reset will appear broken (subsequent API calls return 401).
cookie_secure = false
# Production mode: refuses cookie_secure=false and enables HSTS headers.
# TLS is usually terminated at a reverse proxy; set cookie_secure=true there.
production = false
[database]
# Absolute path to the SQLite database file.
# The directory must be writable by the nx9-auth user.
path = "/var/lib/nx9-auth/auth.db"
[security]
# Session idle timeout in hours. Sessions unused for longer than this are expired.
session_ttl_hours = 24
# Session absolute lifetime in days. Sessions older than this are always expired,
# regardless of activity.
session_absolute_ttl_days = 30
# Default API token lifetime in days (365 = 1 year).
token_ttl_days = 365
# Argon2id memory cost in KiB. Higher = more secure but slower.
# Minimum recommended: 65536 (64 MiB)
argon2_memory = 65536
# Argon2id iteration count. Higher = more secure but slower.
argon2_iterations = 3
# Argon2id parallelism (number of threads).
argon2_parallelism = 1
[audit]
# Enable structured audit logging to the database.
# Disable only in development environments.
enabled = true
[shutdown]
# Maximum time in seconds to wait for active HTTP requests and background workers to drain.
graceful_timeout_secs = 30
# Hard timeout in seconds after which task cancellation is forced. Must be > graceful_timeout_secs.
force_timeout_secs = 35