# Pollux Gemini Server Configuration # # This is an example configuration file for the Pollux Gemini server. # Copy this file to /etc/pollux/config.toml and customize the values below. # # The Gemini protocol is specified in RFC 1436: https://tools.ietf.org/rfc/rfc1436.txt # For additional hostnames, add more sections like: # ["blog.example.com"] # root = "/var/gemini/blog" # cert = "/etc/pollux/tls/blog.crt" # key = "/etc/pollux/tls/blog.key" # Server network configuration # # bind_host: IP address or interface to bind the server to # - "0.0.0.0" = listen on all interfaces (default) # - "127.0.0.1" = localhost only # - "::" = IPv6 all interfaces # - Specific IP = bind to that address only bind_host = "0.0.0.0" # port: TCP port to listen on # - Default Gemini port is 1965 # - Ports below 1024 require root privileges # - Choose a different port if 1965 is in use port = 1965 # Request limiting # # max_concurrent_requests: Maximum number of requests processed at once # - Requests above the limit are answered with "41 Server unavailable" # - Must be between 1 and 1000000; the server will not start on 0 # - Typical values: 100-10000 depending on server capacity max_concurrent_requests = 1000 # max_connections: Maximum number of connections handled at once # - Connections above the limit are dropped immediately, which keeps the # listener responsive under a flood of half-open connections # - Keep this below the process file-descriptor limit (LimitNOFILE in the # systemd unit, or `ulimit -n`) # - Must be between 1 and 1000000; defaults to 512 if unset max_connections = 512 # Logging configuration # # Logging is controlled by the RUST_LOG environment variable, not this file. # In the systemd unit, set for example: # Environment=RUST_LOG=info # Levels, least to most verbose: error, warn, info, debug, trace # Host configuration # Each hostname needs its own section with root, cert, and key settings ["example.com"] # Directory containing your Gemini files (.gmi, .txt, images, etc.) # The server will serve files from this directory and its subdirectories. # Default index file is 'index.gmi' for directory requests. # # IMPORTANT: The server needs READ access to this directory. # Make sure the service user can read all files here. root = "/var/gemini" # TLS certificate and private key files # These files are required for TLS encryption (Gemini requires TLS). # # For self-signed certificates (development/testing): cert = "/etc/pollux/tls/cert.pem" key = "/etc/pollux/tls/key.pem" # # Generate self-signed certs with: # openssl req -x509 -newkey rsa:4096 -keyout /etc/pollux/tls/key.pem -out /etc/pollux/tls/cert.pem -days 365 -nodes -subj "/CN=example.com" # # For Let's Encrypt certificates, use paths under /etc/letsencrypt/live/