check / check (push) Successful in 4m3s
max_concurrent_processing (default: the number of CPUs Go uses) bounds the images processed at once, and upstream_connections (default 64) the fetches from all upstream hosts together, beside the per-host limit. A request that finds either full waits up to 10 seconds, then gets 503 "server busy, try again later". The processor holds its slot from before it reads the input until it returns, and takes a free slot even after the request context has ended; a fetch holds its connection until the response body is closed, after its image is processed. libvips now starts with one worker thread per image and no operation cache. Both settings have PIXA_ variables and are in README.md and config.example.yml. Model: opus-5-5
90 lines
3.6 KiB
YAML
90 lines
3.6 KiB
YAML
# Pixa Example Configuration
|
|
#
|
|
# Every key can also be set by an environment variable, which wins over
|
|
# this file: PIXA_ plus the key in upper case, with "." written as "_"
|
|
# (state_dir is PIXA_STATE_DIR, metrics.username is
|
|
# PIXA_METRICS_USERNAME). The one exception is port, which is set by
|
|
# PORT. In a variable, a list is comma-separated. A variable named in
|
|
# this file's env: section is set while the file loads, so it overrides
|
|
# both the environment the process was started with and this file's own
|
|
# key.
|
|
|
|
# Server settings
|
|
port: 8080
|
|
debug: false
|
|
maintenance_mode: false
|
|
|
|
# Data directory for SQLite database and cache files
|
|
state_dir: ./data
|
|
|
|
# Image proxy settings
|
|
# HMAC signing key for URL signatures (required, at least 32 characters)
|
|
# Generate with: openssl rand -base64 32
|
|
signing_key: "CHANGE_ME_generate_with_openssl_rand_base64_32"
|
|
|
|
# Hosts that don't require signatures
|
|
# Use "." prefix for wildcard subdomain matching (e.g., ".example.com" matches "cdn.example.com")
|
|
allowlist_hosts:
|
|
- s3.sneak.cloud
|
|
- static.sneak.cloud
|
|
- sneak.berlin
|
|
- github.com
|
|
- user-images.githubusercontent.com
|
|
|
|
# Additional CIDR ranges to refuse when fetching upstream, extending the
|
|
# SSRF protection. These are added to the always-enforced built-in ranges
|
|
# (loopback, RFC 1918 private, link-local, CGNAT, benchmark, NAT64, and
|
|
# similar), never replacing them. Each entry must be a valid CIDR in IPv4
|
|
# or IPv6 form; an invalid entry aborts startup.
|
|
# blocked_networks:
|
|
# - 100.64.0.0/10
|
|
# - 2001:db8::/32
|
|
|
|
# CIDR ranges of the reverse proxies in front of pixa. X-Forwarded-For
|
|
# is believed only when the direct peer is inside one of these ranges;
|
|
# the client address in the access log and login records is then the
|
|
# rightmost forwarded entry that is not itself a trusted proxy. A client
|
|
# connecting directly (peer outside these ranges) cannot spoof its
|
|
# address: the header is ignored and the peer address is used. When
|
|
# omitted, this defaults to the RFC 1918 private ranges (10.0.0.0/8,
|
|
# 172.16.0.0/12, 192.168.0.0/16), since pixa is deployed behind a proxy on
|
|
# a private network. An explicitly empty list ([]) trusts no one; an
|
|
# explicit list replaces the default. An invalid CIDR aborts startup.
|
|
# Uncomment to override the defaults with your proxy's address range.
|
|
# trusted_proxies:
|
|
# - 10.0.0.0/8
|
|
# - 2001:db8::/32
|
|
|
|
# Allow HTTP upstream (only for testing, always use HTTPS in production)
|
|
allow_http: false
|
|
|
|
# Maximum concurrent connections per upstream host (default: 20)
|
|
upstream_connections_per_host: 20
|
|
|
|
# Maximum concurrent connections to all upstream hosts together, on top of
|
|
# the per-host limit (default: 64). A fetch holds its connection until its
|
|
# image has been processed. A fetch that finds none free waits up to 10
|
|
# seconds for one, and if none frees up the request is answered 503.
|
|
upstream_connections: 64
|
|
|
|
# Maximum number of images decoded and encoded at once (default: the
|
|
# number of CPUs pixa can use, which follows a container's CPU limit). A
|
|
# request that finds none free waits up to 10 seconds for one, and if none
|
|
# frees up it is answered 503.
|
|
# max_concurrent_processing: 4
|
|
|
|
# Maximum disk cache size in bytes. Explicit values are used exactly as
|
|
# given; 0 disables the disk cache entirely (every request fetches and
|
|
# processes uncached). When omitted, the default is 75% of the free
|
|
# space on the filesystem containing <state_dir>/cache/ at startup,
|
|
# with a minimum of 500 MiB.
|
|
# cache_max_bytes: 10737418240
|
|
|
|
# Sentry error reporting (optional)
|
|
sentry_dsn: ""
|
|
|
|
# Metrics endpoint authentication (optional)
|
|
# metrics:
|
|
# username: "admin"
|
|
# password: "secret"
|