Document every route, encrypted URLs and the config file search (closes #75)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
README.md "Routes" lists every route pixa registers with its method, purpose, what it needs and the status codes it answers with, read from the handlers, says q and fit are part of what is cached, and says the login and generator forms need HTTPS unless debug is on. A new "Encrypted URLs" section covers logging in with the signing key, making a URL on the generator page, how long it lasts, and the 410 once it has expired. "Configuration" gives the order in which pixa looks for its config file. config.example.yml now lists db_url and env and gives every key's default. scripts/manual-test.sh is left to #97. Model: opus-5-5
This commit was merged in pull request #174.
This commit is contained in:
+27
-9
@@ -12,27 +12,38 @@
|
||||
# Durations are Go duration strings such as 30s or 2m and must be
|
||||
# positive; a bare number has no unit and aborts startup. Sizes are a
|
||||
# whole number of bytes.
|
||||
#
|
||||
# A key left out takes the default its comment gives.
|
||||
|
||||
# Server settings
|
||||
# Port to listen on (default: 8080)
|
||||
port: 8080
|
||||
|
||||
# Debug logging and plain-HTTP local development (default: false)
|
||||
debug: false
|
||||
|
||||
# While true, the image routes (/v1/image/ and /v1/e/) answer every request
|
||||
# with 503 and a Retry-After header. The health check keeps answering 200 and
|
||||
# reports maintenance_mode as true. It stays 200 because the image's Docker
|
||||
# HEALTHCHECK requests it: a 503 there would make the container unhealthy, and
|
||||
# upaas marks a deploy failed when its container is unhealthy.
|
||||
# for an image with 503 and a Retry-After header. The health check keeps
|
||||
# answering 200 and reports maintenance_mode as true. It stays 200 because
|
||||
# the image's Docker HEALTHCHECK requests it: a 503 there would make the
|
||||
# container unhealthy, and upaas marks a deploy failed when its container is
|
||||
# unhealthy. (default: false)
|
||||
maintenance_mode: false
|
||||
|
||||
# Data directory for SQLite database and cache files
|
||||
# (default: /var/lib/pixa)
|
||||
state_dir: ./data
|
||||
|
||||
# SQLite database URL (default:
|
||||
# file:<state_dir>/state.sqlite3?_journal_mode=WAL). An empty value aborts
|
||||
# startup; leave the key out to use the default.
|
||||
# db_url: "file:./data/state.sqlite3?_journal_mode=WAL"
|
||||
|
||||
# Image proxy settings
|
||||
# HMAC signing key for URL signatures (required, at least 32 characters)
|
||||
# Generate with: openssl rand -base64 32
|
||||
signing_key: "CHANGE_ME_generate_with_openssl_rand_base64_32"
|
||||
|
||||
# Hosts that don't require signatures
|
||||
# Hosts that don't require signatures (default: none)
|
||||
# Use "." prefix for wildcard subdomain matching (e.g., ".example.com" matches "cdn.example.com")
|
||||
allowlist_hosts:
|
||||
- s3.sneak.cloud
|
||||
@@ -45,7 +56,7 @@ allowlist_hosts:
|
||||
# SSRF protection. These are added to the always-enforced built-in ranges
|
||||
# (loopback, RFC 1918 private, link-local, CGNAT, benchmark, NAT64, and
|
||||
# similar), never replacing them. Each entry must be a valid CIDR in IPv4
|
||||
# or IPv6 form; an invalid entry aborts startup.
|
||||
# or IPv6 form; an invalid entry aborts startup. (default: none)
|
||||
# blocked_networks:
|
||||
# - 100.64.0.0/10
|
||||
# - 2001:db8::/32
|
||||
@@ -72,6 +83,7 @@ allowlist_hosts:
|
||||
# - 2001:db8::/32
|
||||
|
||||
# Allow HTTP upstream (only for testing, always use HTTPS in production)
|
||||
# (default: false)
|
||||
allow_http: false
|
||||
|
||||
# Maximum concurrent connections per upstream host (default: 20)
|
||||
@@ -121,10 +133,16 @@ access_control_allow_origin: "*"
|
||||
# with a minimum of 500 MiB.
|
||||
# cache_max_bytes: 10737418240
|
||||
|
||||
# Sentry error reporting (optional)
|
||||
# Sentry DSN for error reporting (default: empty, which turns it off)
|
||||
sentry_dsn: ""
|
||||
|
||||
# Metrics endpoint authentication (optional)
|
||||
# Username and password for /metrics, set together (default: unset). Metrics
|
||||
# are measured and /metrics is served only when both are set.
|
||||
# metrics:
|
||||
# username: "admin"
|
||||
# password: "secret"
|
||||
|
||||
# Environment variables set while this file loads, as described at the top
|
||||
# (default: none)
|
||||
# env:
|
||||
# PIXA_DEBUG: "true"
|
||||
|
||||
Reference in New Issue
Block a user