2023-09-18 12:23:13 +02:00
|
|
|
---
|
2023-10-04 12:41:41 +02:00
|
|
|
# Custom SSH accounts, should start from UID 8000.
|
|
|
|
bootstrap__active_extra_users:
|
|
|
|
- { name: ivan, uid: 8000, groups: ['docker', 'dockremap'], key: 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJBdm8y1PfWjT1pioaWJSZ2ETrUySb+dS/ifDg+VIpLY ivansete@status.im' }
|
2023-09-18 12:23:13 +02:00
|
|
|
|
2024-07-03 01:19:08 +02:00
|
|
|
# Hourly rotation to avoid disk space issue
|
2024-04-24 16:01:04 +02:00
|
|
|
bootstrap__logrotate_frequency: 'hourly'
|
2024-08-26 11:09:35 +02:00
|
|
|
bootstrap__logrotate_timer_frequency: '*:0/30'
|
2024-04-24 16:01:04 +02:00
|
|
|
|
2024-07-24 12:04:37 +02:00
|
|
|
# Tag dependent on fleet
|
2024-07-16 16:54:51 +02:00
|
|
|
nim_waku_cont_tag: 'deploy-{{ env }}-{{ stage }}'
|
2023-09-18 12:23:13 +02:00
|
|
|
nim_waku_cont_name: 'nim-waku-boot'
|
2024-03-07 11:09:56 +01:00
|
|
|
nim_waku_cont_vol: '/docker/{{ nim_waku_cont_name }}'
|
|
|
|
nim_waku_node_conf_path: '{{ nim_waku_cont_vol }}/conf'
|
2023-11-23 11:31:50 +01:00
|
|
|
nim_waku_log_level: 'debug'
|
2023-09-18 12:23:13 +02:00
|
|
|
nim_waku_protocols_enabled: ['relay', 'filter', 'lightpush', 'peer-exchange']
|
|
|
|
nim_waku_disc_v5_enabled: true
|
|
|
|
nim_waku_dns4_domain_name: '{{ dns_entry }}'
|
2024-07-03 21:47:54 +02:00
|
|
|
nim_waku_node_key: '{{lookup("bitwarden", "fleets/status/"+stage+"/nodekeys", field=hostname)}}'
|
2023-09-18 12:23:13 +02:00
|
|
|
|
|
|
|
# Topic configuration
|
2024-02-29 12:34:10 +01:00
|
|
|
nim_waku_cluster_id: 16
|
2023-09-18 12:23:13 +02:00
|
|
|
nim_waku_pubsub_topics:
|
2024-03-04 22:09:38 +01:00
|
|
|
- '/waku/2/rs/16/1'
|
2023-10-13 13:44:50 -04:00
|
|
|
- '/waku/2/rs/16/32'
|
2023-10-04 11:33:24 +02:00
|
|
|
- '/waku/2/rs/16/64'
|
2023-09-18 12:23:13 +02:00
|
|
|
- '/waku/2/rs/16/128'
|
|
|
|
- '/waku/2/rs/16/256'
|
|
|
|
nim_waku_protected_topics:
|
2024-03-04 22:09:38 +01:00
|
|
|
- '/waku/2/rs/16/1:0461747a1b31c242d5d116baec75d6c2add6335aead6092ab2fa7eeaacd8fc9af2905207ebff8eed1c52e7c67ffa31ec830448e6c91524acdde6073f7c488db7c0'
|
2023-09-18 12:23:13 +02:00
|
|
|
- '/waku/2/rs/16/128:045ced3b90fabf7673c5165f9cc3a038fd2cfeb96946538089c310b5eaa3a611094b27d8216d9ec8110bd0e0e9fa7a7b5a66e86a27954c9d88ebd41d0ab6cfbb91'
|
|
|
|
- '/waku/2/rs/16/256:049022b33f7583f34463f5b7622e5da29f99f993e6858a478465c68ee114ccf142204eff285ed922349c4b71b178a2e1a2154b99bcc2d8e91b3994626ffa9f1a6c'
|
|
|
|
|
|
|
|
# Ports
|
|
|
|
nim_waku_p2p_tcp_port: 30303
|
|
|
|
nim_waku_metrics_port: 8008
|
|
|
|
nim_waku_disc_v5_port: 9000
|
|
|
|
nim_waku_rpc_tcp_port: 8545
|
2023-12-14 10:06:00 +01:00
|
|
|
nim_waku_websock_port: 443
|
2024-01-24 15:25:34 +01:00
|
|
|
|
2023-09-18 12:23:13 +02:00
|
|
|
# Limits
|
2024-05-30 09:35:09 +02:00
|
|
|
nim_waku_max_msg_size: '1024KiB'
|
2024-09-05 18:16:31 +02:00
|
|
|
nim_waku_p2p_max_connections: 500
|
2024-01-24 15:25:34 +01:00
|
|
|
nim_waku_ip_colocation_limit: 100
|
2023-09-18 12:23:13 +02:00
|
|
|
|
|
|
|
# Store
|
|
|
|
nim_waku_store_message_retention_policy: 'time:2592000' # 30 days
|
|
|
|
|
|
|
|
# DNS Discovery
|
2023-09-21 13:01:05 +02:00
|
|
|
nim_waku_dns_disc_enabled: true
|
2023-09-28 17:01:36 +02:00
|
|
|
nim_waku_dns_disc_url_map:
|
2024-07-25 09:14:24 +02:00
|
|
|
prod: 'enrtree://AMOJVZX4V6EXP7NTJPMAYJYST2QP6AJXYW76IU6VGJS7UVSNDYZG4@boot.prod.status.nodes.status.im'
|
2024-07-03 21:47:54 +02:00
|
|
|
staging: 'enrtree://AI4W5N5IFEUIHF5LESUAOSMV6TKWF2MB6GU2YK7PU4TYUGUNOCEPW@boot.staging.status.nodes.status.im'
|
2023-09-28 17:01:36 +02:00
|
|
|
nim_waku_dns_disc_url: '{{ nim_waku_dns_disc_url_map[stage] }}'
|
2023-09-18 12:23:13 +02:00
|
|
|
|
2023-12-14 10:06:00 +01:00
|
|
|
# Websockets
|
|
|
|
nim_waku_websocket_enabled: true
|
|
|
|
nim_waku_websocket_secure_enabled: true
|
|
|
|
nim_waku_websocket_domain: '{{ dns_entry }}'
|
|
|
|
nim_waku_websocket_ssl_dir: '/etc/letsencrypt'
|
|
|
|
nim_waku_websocket_ssl_cert: '/etc/letsencrypt/live/{{ nim_waku_websocket_domain }}/fullchain.pem'
|
|
|
|
nim_waku_websocket_ssl_key: '/etc/letsencrypt/live/{{ nim_waku_websocket_domain }}/privkey.pem'
|
2023-09-18 12:23:13 +02:00
|
|
|
|
|
|
|
# Consul Service
|
2024-08-06 20:02:46 +02:00
|
|
|
nim_waku_consul_check_interval: '120s'
|
|
|
|
nim_waku_consul_check_timeout: '5s'
|
2023-09-18 12:23:13 +02:00
|
|
|
nim_waku_consul_success_before_passing: 5
|
2024-08-06 20:02:46 +02:00
|
|
|
nim_waku_consul_failures_before_warning: 5
|
2023-09-18 12:23:13 +02:00
|
|
|
nim_waku_consul_failures_before_critical: 20
|
|
|
|
|
2023-12-14 10:06:00 +01:00
|
|
|
# LetsEncrypt via Certbot
|
|
|
|
certbot_docker_enabled: true
|
|
|
|
certbot_admin_email: 'devops@status.im'
|
2024-03-07 11:09:56 +01:00
|
|
|
certbot_services_to_stop: ['nginx']
|
2024-01-08 13:35:03 +01:00
|
|
|
certbot_containers_to_stop: ['{{ nim_waku_cont_name }}']
|
2024-03-18 20:48:58 +01:00
|
|
|
certbot_certs: '{{ certbot_certs_map[stage] }}'
|
|
|
|
# FIXME: Remove once ENR records are updated without the domain.
|
|
|
|
certbot_certs_map:
|
2024-07-24 12:04:37 +02:00
|
|
|
prod:
|
2024-03-18 20:48:58 +01:00
|
|
|
- domains:
|
|
|
|
- '{{ nim_waku_websocket_domain }}'
|
2024-07-24 12:04:37 +02:00
|
|
|
- '{{ nim_waku_websocket_domain | replace("status."+stage, "shards.test") }}' # Legacy Fleet Name
|
2024-03-18 20:48:58 +01:00
|
|
|
staging:
|
|
|
|
- domains:
|
|
|
|
- '{{ nim_waku_websocket_domain }}'
|
2024-07-24 12:04:37 +02:00
|
|
|
- '{{ nim_waku_websocket_domain | replace("status."+stage, "shards.staging") }}' # Legacy Fleet Name
|
2023-12-14 10:06:00 +01:00
|
|
|
|
2024-09-12 16:40:48 +02:00
|
|
|
# Open Nim-Waku Ports
|
2023-09-18 12:23:13 +02:00
|
|
|
open_ports_list:
|
2024-09-12 16:40:48 +02:00
|
|
|
nginx:
|
|
|
|
- { comment: 'Nginx and Certbot', port: '80' }
|
|
|
|
nim-waku:
|
|
|
|
- { comment: 'Nim-Waku LibP2P', port: '{{ nim_waku_p2p_tcp_port }}' }
|
|
|
|
- { comment: 'Nim-Waku Discovery v5', port: '{{ nim_waku_disc_v5_port }}', protocol: 'udp' }
|
2024-10-18 12:49:25 +02:00
|
|
|
- { comment: 'Nim-Waku Metrics', port: '{{ nim_waku_metrics_port }}', ipset: 'hq.metrics', iifname: 'wg0' }
|
2024-09-12 16:40:48 +02:00
|
|
|
- { comment: 'Nim-Waku WebSocket', port: '{{ nim_waku_websock_port }}' }
|
2024-03-07 11:09:56 +01:00
|
|
|
|
|
|
|
# Public Config file access
|
|
|
|
nginx_sites:
|
|
|
|
nim_waku_config:
|
|
|
|
- listen 80 default_server
|
|
|
|
- location = / {
|
|
|
|
return 302 /config.toml;
|
|
|
|
}
|
|
|
|
- location = /config.toml {
|
|
|
|
root {{ nim_waku_node_conf_path }};
|
|
|
|
try_files /config.toml =404;
|
|
|
|
types { text/plain toml; }
|
|
|
|
}
|