-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclaws.example.yaml
More file actions
36 lines (36 loc) · 1.79 KB
/
Copy pathclaws.example.yaml
File metadata and controls
36 lines (36 loc) · 1.79 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
# Copy to claws.yaml and fill in. claws.yaml is gitignored.
# Runs on the NAS VM and owns the database.
claws:
bind:
# The kiosk reaches this across the tailnet while the bot talks to it over
# loopback on this same VM, so it has to answer on both. "::" is every
# interface on both address families; 0.0.0.0 is IPv4 only, which breaks
# MagicDNS names since tailnet hosts resolve to an IPv6 address too.
# On the closet laptop, bind the tailnet address specifically instead --
# that network is not ours.
host: "::"
port: 8080
token: # shared bearer token, must match the frontend's config
# Keep this OUTSIDE the git checkout. The database is gitignored, and
# `git clean -xdf` exists to delete ignored files, so a cleanup during a bad
# deploy would take the inventory with it.
database_location: /home/illusion/inventory.db
# The fleet `about` reports on. A fixed set, so this is static config rather
# than service discovery -- and it is what lets `about` survive a claws
# restart, which would otherwise forget everything that had announced itself.
fleet:
illusion-bot: http://127.0.0.1:8090
lipgloss: http://eer-inventory:8081
illusion-kiosk: http://eer-inventory:8082
# Note: when digikey is enabled, claws rewrites THIS FILE to store refreshed
# tokens, so it must be writable by the service user, as must its directory
# (the write is a temp file plus a rename). A root-owned config would fail on
# the first refresh, roughly half an hour in, not at startup.
digikey:
enabled: false
client_id:
client_secret:
tokens:
access_token: # written by digikey_client, leave blank
refresh_token: # written by digikey_client, leave blank
expires_at: # written by digikey_client, leave blank