twins-upstream/CONFIGURATION.md

148 lines
3.5 KiB
Markdown
Raw Normal View History

2020-11-01 00:49:37 +01:00
This page is also available at [gemini://twins.rocketnine.space/configuration.gmi](gemini://twins.rocketnine.space/configuration.gmi)
2020-10-31 17:59:12 +01:00
`twins` requires a configuration file to operate. It is loaded from
`~/.config/twins/config.yaml` by default. You may specify a different location
via the `--config` argument.
2020-10-31 01:29:25 +01:00
# Configuration options
## Listen
Address to listen for connections on in the format of `interface:port`.
### Listen on localhost
`localhost:1965`
### Listen on all interfaces
`:1965`
## Hosts
Hosts are defined by their hostname followed by one or more paths to serve.
Paths may be defined as fixed strings or regular expressions (starting with `^`).
Paths are matched in the order they are defined.
Fixed string paths will match with and without a trailing slash.
When accessing a directory the file `index.gemini` or `index.gmi` is served.
### Certificates
2020-10-31 01:29:25 +01:00
A certificate and private key must be specified.
2020-10-31 01:29:25 +01:00
#### localhost certificate
2020-10-31 01:29:25 +01:00
Use `openssl` generate a certificate for localhost.
```bash
openssl req -x509 -out localhost.crt -keyout localhost.key \
-newkey rsa:2048 -nodes -sha256 \
-subj '/CN=localhost' -extensions EXT -config <( \
printf "[dn]\nCN=localhost\n[req]\ndistinguished_name = dn\n[EXT]\nsubjectAltName=DNS:localhost\nkeyUsage=digitalSignature\nextendedKeyUsage=serverAuth")
```
#### Domain certificate
2020-10-31 01:29:25 +01:00
Use [certbot](https://certbot.eff.org) to get a certificate from [Let's Encrypt](https://letsencrypt.org) for a domain.
```bash
certbot certonly --config-dir /home/www/certs \
--work-dir /home/www/certs \
--logs-dir /home/www/certs \
--webroot \
-w /home/www/gemini.rocks/public_html \
-d gemini.rocks \
-d www.gemini.rocks
```
Provide the path to the certificate file at `certs/live/$DOMAIN/fullchain.pem`
and the private key file at `certs/live/$DOMAIN/privkey.pem` to twins.
### Path
2020-10-31 01:29:25 +01:00
#### Resources
2020-10-31 01:29:25 +01:00
One resource must be defined for each path.
2020-10-31 01:29:25 +01:00
##### Root
Serve static files from specified root directory.
2020-10-31 02:31:13 +01:00
##### Proxy
2020-10-31 01:29:25 +01:00
Forward request to Gemini server at specified URL.
Use the pseudo-scheme `gemini-insecure://` to disable certificate verification.
##### Command
2020-10-30 01:17:23 +01:00
2020-10-31 01:29:25 +01:00
Serve output of system command.
2020-10-30 01:17:23 +01:00
When input is requested from the user, it is available as a pseudo-variable
`$USERINPUT` which does not require surrounding quotes. It may be used as an
argument to the command, otherwise user input is passed via standard input.
#### Attributes
Any number of attributes may be defined for a path.
##### ListDirectory
Directory listing may be enabled by adding `listdirectory: true`.
##### Input
Request text input from user.
##### SensitiveInput
Request sensitive text input from the user. Text will not be shown as it is entered.
2020-10-31 01:29:25 +01:00
# Example config.yaml
2020-10-29 21:35:48 +01:00
```yaml
# Address to listen on
2020-10-31 01:29:25 +01:00
listen: :1965
# TLS certificates
certificates:
2020-10-29 21:35:48 +01:00
-
# Hosts and paths to serve
hosts:
2020-10-30 21:36:55 +01:00
gemini.rocks:
cert: /srv/gemini.rocks/data/cert.crt
key: /srv/gemini.rocks/data/cert.key
paths:
-
path: /sites
root: /home/geminirocks/data/sites
listdirectory: true
-
path: ^/(help|info)$
root: /home/geminirocks/data/help
-
path: ^/proxy-example$
proxy: gemini://localhost:1966
-
path: ^/cmd-example$
command: uname -a
-
path: /
root: /home/geminirocks/data/home
2020-10-30 21:36:55 +01:00
twins.rocketnine.space:
cert: /srv/twins.rocketnine.space/data/cert.crt
key: /srv/twins.rocketnine.space/data/cert.key
paths:
-
path: /sites
root: /home/twins/data/sites
-
path: /
root: /home/twins/data/home
2020-10-31 17:59:12 +01:00
```