# sish configuration (keys mirror the CLI flags, see `sish --help`). # Cluster-specific values (domain, bind-hosts) are injected as SISH_* env vars # from the `sish-env` ConfigMap in each overlay. Env takes precedence over this file. # Listeners ssh-address: ":2222" http-address: ":80" https: false # sish never terminates TLS; :443 is an SNI passthrough listener # SNI passthrough + multiple connectors per hostname sni-proxy: true sni-load-balancer: true tcp-load-balancer: true http-load-balancer: true # Connectors get exactly what they ask for, or the bind fails bind-random-ports: false bind-random-subdomains: false bind-random-aliases: false force-requested-subdomains: true force-requested-ports: true bind-wildcards: true # Ports connectors may claim. Must match the sish-public rule in # talos/patches/firewall.yaml, otherwise a claimed port is silently unreachable. # 22 gitea ssh, 443 SNI, 20000-20099 reserved for raw tcp forwards. # Ports below 80 also need talos/patches/unprivileged-ports.yaml. port-bind-range: "22,443,20000-20099" # PROXY header version for connectors that request it (sish-client default: v2) proxy-protocol: true proxy-protocol-version: "2" # Default is 5s, which kills idle websockets/SSE/slow uploads idle-connection-timeout: 1h # Auth: public keys only authentication: true authentication-keys-directory: /pubkeys private-keys-directory: /keys # No web UI / consoles redirect-root: false admin-console: false service-console: false load-templates: false # Default -1 makes the HTTP muxer io.ReadAll() every request/response body into memory # (for the console), even with consoles disabled: large uploads OOM-kill sish. # 0 = never buffer, stream bodies through. service-console-max-content-length: 0 log-to-stdout: true log-to-file: false