# Kanidm server configuration. bootstrap.sh renders this into # server.toml from .env; edit the template, not the rendered file. # Reference: https://kanidm.github.io/kanidm/stable/server_configuration.html version = "2" bindaddress = "0.0.0.0:8443" # Internal self-signed pair made by bootstrap.sh; Caddy terminates the # public certificate and proxies here with verification disabled. tls_chain = "/data/chain.pem" tls_key = "/data/key.pem" db_path = "/data/kanidm.db" db_fs_type = "other" db_arc_size = 2048 log_level = "info" # domain must equal the DNS name Kanidm is served at. domain = "${ID_HOST}" origin = "https://${ID_HOST}" # Trust X-Forwarded-For from Caddy on the compose network. [http_client_address_info] x-forward-for = ["172.16.0.0/12"] [online_backup] path = "/data/backups/" schedule = "00 22 * * *" versions = 7