forked from michaelhart/meshcore-mqtt-broker
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
85 lines (70 loc) · 3.2 KB
/
Copy path.env.example
File metadata and controls
85 lines (70 loc) · 3.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
# MeshCore MQTT Broker Configuration
# Copy this file to .env and fill in your values
# MQTT Server Settings
MQTT_WS_PORT=8883
MQTT_HOST=0.0.0.0
# Authentication Settings
# Expected audience claim in JWT tokens (e.g., mqtt.yourdomain.com)
# Leave empty to skip audience validation
# NOTE: a browser-based publisher sets the JWT audience to the hostname it
# connects to, so this MUST equal that hostname or every such publisher is
# rejected while the broker looks healthy.
AUTH_EXPECTED_AUDIENCE=mqtt.yourdomain.com
# Where a plain (non-WebSocket) browser request to the broker is 302-redirected.
# This broker only speaks MQTT-over-WS, so a human who opens the URL is sent to
# the front-end. Defaults to https://observers.dutchmeshcore.nl/.
HTTP_REDIRECT_URL=https://observers.dutchmeshcore.nl/
# Non-IATA stream-region labels publishers may use in the topic region slot
# (meshcore/{REGION}/{PUBKEY}/...), in addition to real IATA codes and "test".
# Comma-separated, lowercase. The wardrive collector publishes under the
# "wardriver" (and "hunter") stream label to keep that traffic separable.
# Unset defaults to "wardriver,hunter"; set explicitly (even empty) to override.
# These streams are gated as sensitive on the subscribe side (LIMITED role never
# receives /wardriver/* topics).
PUBLISH_EXTRA_REGIONS=wardriver,hunter
# Subscribe-Only Users (one per line, format: username:password:role:maxConnections)
# Role: 1=admin (full access + can delete retained), 2=full_access (no hidden data), 3=limited (filtered data)
# Default role is 3 (limited) if not specified
# maxConnections: number for override, D or omit to use default (SUBSCRIBER_MAX_CONNECTIONS_DEFAULT)
# Add as many as you need by incrementing the number
SUBSCRIBER_MAX_CONNECTIONS_DEFAULT=2
SUBSCRIBER_1=viewer1:your-secure-password-here:2
SUBSCRIBER_2=admin:admin-password-here:1:10
SUBSCRIBER_3=limited:limited-password:3:D
# ... add more as needed
# Abuse Detection - Enforcement
ABUSE_ENFORCEMENT_ENABLED=false
# Abuse Detection - Duplicate Detection
ABUSE_DUPLICATE_WINDOW_SIZE=100
ABUSE_DUPLICATE_WINDOW_MS=300000
ABUSE_DUPLICATE_THRESHOLD=10
ABUSE_MAX_DUPLICATES_PER_PACKET=5
ABUSE_DUPLICATE_RATE_THRESHOLD=0.3
ABUSE_DUPLICATE_RATE_WINDOW_MS=300000
# Abuse Detection - Rate Limiting
ABUSE_BUCKET_CAPACITY=20
ABUSE_BUCKET_REFILL_RATE=3
# Abuse Detection - Anomaly Detection
ABUSE_MAX_PACKET_SIZE=255
ABUSE_MAX_TOPICS_PER_DAY=3
ABUSE_ANOMALY_THRESHOLD=10
# Abuse Detection - IATA Change Limiting
ABUSE_MAX_IATA_CHANGES_24H=3
# Abuse Detection - Topic Tracking
ABUSE_TOPIC_HISTORY_SIZE=50
ABUSE_TOPIC_HISTORY_WINDOW_MS=86400000
# Abuse Detection - Persistence
ABUSE_PERSISTENCE_PATH=/data/abuse-detection.db
ABUSE_PERSISTENCE_INTERVAL_MS=300000
# Evict trust state for clients with no activity within this window (default 7 days).
# Keeps the persisted store bounded by active clients rather than every client ever seen.
ABUSE_STATE_RETENTION_MS=604800000
# Cloudflare Tunnel (used by docker-compose.prod.yml only)
# Get this from: Cloudflare Zero Trust -> Networks -> Tunnels -> your tunnel -> Install connector
TUNNEL_TOKEN=
# for publishing collector stats
COLLECTOR_NAME=
STATS_TOPIC_PREFIX=stats
STATS_INTERVAL_MS=30000
STATS_INCLUDE_TOKEN_CLIENT_DETAILS=false
STATS_RETAIN=true