Files
cirrus/kubernetes/base/sish/config.yml
T
traberphandClaude Opus 5.5 3d3ddc98e9 initial commit: cirrus edge (Talos + sish)
- talos/: generated base config (gitignored) + patches for control-plane
  scheduling, unprivileged ports and the ingress firewall
- kubernetes/: sish base and cirrus-dev overlay, applied with kubectl
- READMEs incl. production rollout plan

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 12:16:27 +02:00

53 lines
1.8 KiB
YAML

# sish configuration (keys mirror the CLI flags, see `sish --help`).
# Cluster-specific values (domain, bind-hosts) are injected as SISH_* env vars
# from the `sish-env` ConfigMap in each overlay. Env takes precedence over this file.
# Listeners
ssh-address: ":2222"
http-address: ":80"
https: false # sish never terminates TLS; :443 is an SNI passthrough listener
# SNI passthrough + multiple connectors per hostname
sni-proxy: true
sni-load-balancer: true
tcp-load-balancer: true
http-load-balancer: true
# Connectors get exactly what they ask for, or the bind fails
bind-random-ports: false
bind-random-subdomains: false
bind-random-aliases: false
force-requested-subdomains: true
force-requested-ports: true
bind-wildcards: true
# Ports connectors may claim. Must match the sish-public rule in
# talos/patches/firewall.yaml, otherwise a claimed port is silently unreachable.
# 22 gitea ssh, 443 SNI, 20000-20099 reserved for raw tcp forwards.
# Ports below 80 also need talos/patches/unprivileged-ports.yaml.
port-bind-range: "22,443,20000-20099"
# PROXY header version for connectors that request it (sish-client default: v2)
proxy-protocol: true
proxy-protocol-version: "2"
# Default is 5s, which kills idle websockets/SSE/slow uploads
idle-connection-timeout: 1h
# Auth: public keys only
authentication: true
authentication-keys-directory: /pubkeys
private-keys-directory: /keys
# No web UI / consoles
redirect-root: false
admin-console: false
service-console: false
load-templates: false
# Default -1 makes the HTTP muxer io.ReadAll() every request/response body into memory
# (for the console), even with consoles disabled: large uploads OOM-kill sish.
# 0 = never buffer, stream bodies through.
service-console-max-content-length: 0
log-to-stdout: true
log-to-file: false