Skip to content
File

Blob: tun/client/config.example.yaml

yaml93 lines
1# Example Specter client configuration
2#
3# Copy this file to something like client.yaml and tweak it for your own
4# machine. In most cases you only need to:
5# 1) point `apex` at your Specter server, and
6# 2) add or edit entries under `tunnels`.
7 
8# Config format version. Always use 2.
9version: 2
10 
11# Address of the Specter server you connect to (host:port).
12# You usually get this from whoever runs the Specter server.
13# Examples:
14# specter.im:443
15# gateway.your-domain.com:443
16apex: specter.im:443
17 
18# After the first successful run of `specter client tunnel`, Specter will
19# write your client certificate and private key into this file.
20# Leave these commented out when starting from this example.
21#
22# certificate: |
23# -----BEGIN CERTIFICATE-----
24# ...
25# -----END CERTIFICATE-----
26#
27# privKey: |
28# -----BEGIN PRIVATE KEY-----
29# ...
30# -----END PRIVATE KEY-----
31 
32# Each item under `tunnels` exposes one local service to the outside world.
33# Hostnames are usually either generated for you, or a custom domain you own
34# that you have validated via ACME.
35#
36# Minimum you need:
37# - target : where traffic should go
38# (http://, https://, tcp://, unix://, or \\.\pipe\... )
39# - hostname : optional
40# * leave empty to have Specter generate a random name under the default
41# domain
42# * or set to your own domain (for example app.example.com) after you've
43# set up ACME / custom hostname
44#
45# Advanced HTTP options (you can usually ignore these):
46# - insecure : for https targets; skip TLS verification (useful in dev).
47# - headerTimeout : how long to wait for upstream HTTP response headers
48# (for example 10s, 30s).
49# - headerMode : how to set the HTTP Host header:
50# "" : default; use target host:port unless headerHost is set.
51# "hostname" : use this tunnel's hostname (or hostname.apex).
52# "custom" : always use headerHost.
53# "target" : use target host:port (not valid for unix/pipe targets).
54# - headerHost : custom Host value used with headerMode "custom",
55# or to override the default Host when headerMode is empty.
56#
57# Unix sockets / Windows named pipes:
58# - use target: unix:///path/to/socket or \\.\pipe\name
59# - do not use headerMode: "target" for these; prefer "hostname" or "custom".
60 
61tunnels:
62 # Local HTTP server; Specter will pick a random public hostname.
63 - target: http://127.0.0.1:8080
64 # hostname: "" # leave out or empty to let Specter generate one
65 # headerMode: target # send 127.0.0.1:8080 as the Host header
66 # headerTimeout: 15s # wait up to 15s for upstream headers
67 
68 # HTTP API reachable as api.<apex> (for example api.specter.im).
69 - target: http://127.0.0.1:9000
70 hostname: api
71 headerMode: hostname # use api.<apex> as Host header
72 
73 # HTTPS service with self-signed certificate (development only).
74 - target: https://127.0.0.1:9443
75 hostname: web
76 insecure: true # skip TLS verification to this upstream
77 headerMode: hostname
78 
79 # HTTP service behind a custom domain you've validated via ACME.
80 - target: http://127.0.0.1:3000
81 hostname: app.custom.example.com
82 headerMode: hostname
83 
84 # HTTP service on a Unix socket with a custom Host header.
85 - target: unix:///var/run/app.sock
86 hostname: app-sock
87 headerMode: custom
88 headerHost: app.internal # Host header sent to the upstream
89 
90 # Raw TCP service (for example SSH). HTTP-only options do not apply.
91 - target: tcp://127.0.0.1:22
92 # hostname omitted => random name will be generated under the apex