// Copyright (c) 2026 Petr BalvĂ­n (https://petrbalvin.org) // SPDX-License-Identifier: PolyForm-Noncommercial-1.0.0 package config // Template is the commented configuration file every deployment starts // from: an operator copies it to the config path and edits it. The // committed config.toml.example is this constant, unchanged, and a test // asserts that; the release pipeline ships that file as an asset. // // The root keys come first, before any table header: a key written below // a header belongs to that table, and the loader refuses a root key that // a header swallowed rather than silently falling back to the default. // Every key this file accepts is listed here, and docs/CONFIGURATION.md // is the reference for its type, default and rules. const Template = `# volumen configuration. # # Every key this file accepts is listed here. Copy it to # /etc/volumen/config.toml (or ~/.config/volumen/config.toml for a # per-user installation), then edit. # # Keys that belong to no table come first, because a key written below a # [table] header belongs to that table. # Directory of the Markdown posts (.md with TOML frontmatter). content_dir = "/var/lib/volumen/posts" # File holding the admin accounts (managed from the admin Settings page). users_file = "/var/lib/volumen/users.toml" # How many previous versions of each post to keep in .revisions/ # (0 keeps none, which also makes deleting a post permanent). revision_limit = 10 # Where the audit log is appended, or "" to disable auditing. Records # who changed what, and when, in JSON lines. audit_log = "" [server] # Address to bind, as an IP address: "::" is every interface, "::1" is # loopback only, which is what a reverse proxy needs. host = "::" port = 9091 # Environment label: "development" or "production". It decides the # startup safety checks (session key length, cookie flags, password # policy). env = "development" # Set true ONLY when a trusted reverse proxy terminates TLS in front of # volumen. Client addresses are then taken from X-Forwarded-For and # cookies are marked Secure. trust_proxy = false # Addresses whose X-Forwarded-For may be believed, as addresses or CIDR # prefixes. An empty list never reads the header and always uses the # connection address; list the proxy so its clients each rate-limit # under their own address. trusted_proxies = [] # Set true in production to force the Secure flag on session cookies. cookie_secure = false # Log output format: "text" (human readable) or "json" (structured). log_format = "text" [site] title = "Volumen" description = "Powered by Volumen." # Absolute URL of the public site, without a trailing slash. base_url = "https://example.com" language = "en" author = "Anonymous" # Fediverse handle surfaced as the author in feeds and meta tags. # Leave empty to disable. fediverse_creator = "" [admin] # Secret that signs session cookies (at least 64 bytes in production). # Leave empty: the server generates one and keeps it in secret.key next # to users.toml. A value here overrides that file. session_key = "" # Session lifetime in seconds (24 hours by default). session_ttl = 86400 # Minimum password length enforced when a password is set in the admin UI. min_password_length = 10 # Maximum password length, to bound the scrypt work. max_password_length = 1024 # Maximum upload size in bytes (10 MB by default). max_upload_bytes = 10485760 [api] # Public API rate limit: requests allowed per window per client address. # 0 disables rate limiting. rate_limit = 60 # Rate-limit window length in seconds. rate_limit_window = 60 # Scheduled publishing, for a post whose frontmatter carries publish_at. # [scheduler] # enabled = false # interval = 300 # Outgoing webhooks: POST a signed JSON payload on post changes so a # front-end can rebuild its cache or static pages. Repeat the block for # more endpoints; events may be omitted to receive every event. # [[webhooks]] # url = "https://example.com/hooks/rebuild" # secret = "a-long-random-string" # HMAC-SHA256 signing key # events = ["post.created", "post.updated", "post.deleted", "post.published"] # enabled = true `