# Pixa Example Configuration # # Every key can also be set by an environment variable, which wins over # this file: PIXA_ plus the key in upper case, with "." written as "_" # (state_dir is PIXA_STATE_DIR, metrics.username is # PIXA_METRICS_USERNAME). The one exception is port, which is set by # PORT. In a variable, a list is comma-separated. A variable named in # this file's env: section is set while the file loads, so it overrides # both the environment the process was started with and this file's own # key. # # Durations are Go duration strings such as 30s or 2m and must be # positive; a bare number has no unit and aborts startup. Sizes are a # whole number of bytes. # Server settings port: 8080 debug: false maintenance_mode: false # Data directory for SQLite database and cache files state_dir: ./data # Image proxy settings # HMAC signing key for URL signatures (required, at least 32 characters) # Generate with: openssl rand -base64 32 signing_key: "CHANGE_ME_generate_with_openssl_rand_base64_32" # Hosts that don't require signatures # Use "." prefix for wildcard subdomain matching (e.g., ".example.com" matches "cdn.example.com") allowlist_hosts: - s3.sneak.cloud - static.sneak.cloud - sneak.berlin - github.com - user-images.githubusercontent.com # Additional CIDR ranges to refuse when fetching upstream, extending the # SSRF protection. These are added to the always-enforced built-in ranges # (loopback, RFC 1918 private, link-local, CGNAT, benchmark, NAT64, and # similar), never replacing them. Each entry must be a valid CIDR in IPv4 # or IPv6 form; an invalid entry aborts startup. # blocked_networks: # - 100.64.0.0/10 # - 2001:db8::/32 # CIDR ranges of the reverse proxies in front of pixa. X-Forwarded-For # is believed only when the direct peer is inside one of these ranges; # the client address in the access log and login records is then the # rightmost forwarded entry that is not itself a trusted proxy. A client # connecting directly (peer outside these ranges) cannot spoof its # address: the header is ignored and the peer address is used. When # omitted, this defaults to the RFC 1918 private ranges (10.0.0.0/8, # 172.16.0.0/12, 192.168.0.0/16), since pixa is deployed behind a proxy on # a private network. An explicitly empty list ([]) trusts no one; an # explicit list replaces the default. An invalid CIDR aborts startup. # Uncomment to override the defaults with your proxy's address range. # trusted_proxies: # - 10.0.0.0/8 # - 2001:db8::/32 # Allow HTTP upstream (only for testing, always use HTTPS in production) allow_http: false # Maximum concurrent connections per upstream host (default: 20) upstream_connections_per_host: 20 # Time allowed for one fetch from an upstream host (default: 30s) upstream_fetch_timeout: 30s # Largest upstream response accepted, in bytes, at most 1073741824 # (1 GiB) (default: 52428800, 50 MiB) upstream_max_response_size: 52428800 # Time allowed for answering one client request, the upstream fetch # included, so keep it longer than upstream_fetch_timeout (default: 60s) downstream_timeout: 60s # The origin a browser lets read pixa's responses, sent as the CORS # Access-Control-Allow-Origin header: "*" (the default) is any site; # otherwise one origin, scheme and host only, such as https://example.com access_control_allow_origin: "*" # Maximum disk cache size in bytes. Explicit values are used exactly as # given; 0 disables the disk cache entirely (every request fetches and # processes uncached). When omitted, the default is 75% of the free # space on the filesystem containing /cache/ at startup, # with a minimum of 500 MiB. # cache_max_bytes: 10737418240 # Sentry error reporting (optional) sentry_dsn: "" # Metrics endpoint authentication (optional) # metrics: # username: "admin" # password: "secret"