- talos/: generated base config (gitignored) + patches for control-plane scheduling, unprivileged ports and the ingress firewall - kubernetes/: sish base and cirrus-dev overlay, applied with kubectl - READMEs incl. production rollout plan Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
53 lines
1.8 KiB
YAML
53 lines
1.8 KiB
YAML
# sish configuration (keys mirror the CLI flags, see `sish --help`).
|
|
# Cluster-specific values (domain, bind-hosts) are injected as SISH_* env vars
|
|
# from the `sish-env` ConfigMap in each overlay. Env takes precedence over this file.
|
|
|
|
# Listeners
|
|
ssh-address: ":2222"
|
|
http-address: ":80"
|
|
https: false # sish never terminates TLS; :443 is an SNI passthrough listener
|
|
|
|
# SNI passthrough + multiple connectors per hostname
|
|
sni-proxy: true
|
|
sni-load-balancer: true
|
|
tcp-load-balancer: true
|
|
http-load-balancer: true
|
|
|
|
# Connectors get exactly what they ask for, or the bind fails
|
|
bind-random-ports: false
|
|
bind-random-subdomains: false
|
|
bind-random-aliases: false
|
|
force-requested-subdomains: true
|
|
force-requested-ports: true
|
|
bind-wildcards: true
|
|
# Ports connectors may claim. Must match the sish-public rule in
|
|
# talos/patches/firewall.yaml, otherwise a claimed port is silently unreachable.
|
|
# 22 gitea ssh, 443 SNI, 20000-20099 reserved for raw tcp forwards.
|
|
# Ports below 80 also need talos/patches/unprivileged-ports.yaml.
|
|
port-bind-range: "22,443,20000-20099"
|
|
|
|
# PROXY header version for connectors that request it (sish-client default: v2)
|
|
proxy-protocol: true
|
|
proxy-protocol-version: "2"
|
|
|
|
# Default is 5s, which kills idle websockets/SSE/slow uploads
|
|
idle-connection-timeout: 1h
|
|
|
|
# Auth: public keys only
|
|
authentication: true
|
|
authentication-keys-directory: /pubkeys
|
|
private-keys-directory: /keys
|
|
|
|
# No web UI / consoles
|
|
redirect-root: false
|
|
admin-console: false
|
|
service-console: false
|
|
load-templates: false
|
|
# Default -1 makes the HTTP muxer io.ReadAll() every request/response body into memory
|
|
# (for the console), even with consoles disabled: large uploads OOM-kill sish.
|
|
# 0 = never buffer, stream bodies through.
|
|
service-console-max-content-length: 0
|
|
|
|
log-to-stdout: true
|
|
log-to-file: false
|