Skip to content

Configuration file

Netronome reads its configuration from a TOML file named config.toml. Each key in this file also has an environment variable. An environment variable overrides the value in the file. For the variable names, see Environment variables.

If you start Netronome with --config <path>, it reads only that file. If you do not give --config, Netronome looks for the file in these locations, in this order:

  1. ~/.config/netronome/config.toml
  2. netronome/config.toml in the configuration directory of your operating system. On Linux, this is also ~/.config. On macOS, it is ~/Library/Application Support.
  3. config.toml in the working directory.

If Netronome finds no file, it starts with the default values and the environment variables. To write a file with the default values, run netronome generate-config. For more, see CLI.

Netronome resolves a relative database.path from the directory of the configuration file. It also reads librespeed-servers.json from that directory.

The default values in the tables below are the values that Netronome uses when a key is missing from the file. The file that generate-config writes can contain other values. For example, it sets server.host to 0.0.0.0 in a container and writes a random session_secret.

These keys go at the top of the file, before the first section header.

KeyTypeDefaultDescription
check_for_updatesbooleantrueChecks GitHub for new releases and shows a notice in the web interface. See FAQ.

Netronome uses SQLite by default. For PostgreSQL, see Database.

KeyTypeDefaultDescription
typestring"sqlite"The database type: sqlite or postgres.
pathstring"netronome.db"The SQLite database file. A relative path starts at the directory of the configuration file. SQLite only.
hoststring"localhost"The PostgreSQL host.
portinteger5432The PostgreSQL port.
userstring"postgres"The PostgreSQL user.
passwordstring""The PostgreSQL password.
dbnamestring"netronome"The PostgreSQL database name.
sslmodestring"disable"The PostgreSQL SSL mode, for example disable or require.

For base_url behind a reverse proxy, see Reverse proxy.

KeyTypeDefaultDescription
hoststring"127.0.0.1"The address that the web server listens on. See Reverse proxy.
portinteger7575The port of the web server.
base_urlstring"/"The URL path that Netronome runs under, for example /netronome.
gin_modestring""The Gin web framework mode: debug, release, or test. If empty, Netronome uses release.
KeyTypeDefaultDescription
levelstring"info"The log level: trace, debug, info, warn, error, fatal, or panic.

For login, OIDC, and the IP whitelist, see Authentication.

KeyTypeDefaultDescription
whitelistlist of strings[]Networks in CIDR notation that can use Netronome without a login, for example ["127.0.0.1/32"].
trusted_proxieslist of strings[]Proxies that Netronome trusts for the client address headers. See Behind a reverse proxy.

Before you set whitelist = ["0.0.0.0/0", "::/0"], read Turn off authentication.

Netronome turns on OpenID Connect (OIDC) login when issuer has a value. For the setup, see Authentication.

KeyTypeDefaultDescription
issuerstring""The URL of the OIDC provider.
client_idstring""The client ID from the OIDC provider.
client_secretstring""The client secret from the OIDC provider.
redirect_urlstring""The callback URL, for example https://netronome.example.com/api/auth/oidc/callback.
scopeslist of strings[]The scopes to request. If empty, Netronome requests openid and profile. See OIDC.
KeyTypeDefaultDescription
session_secretstring""The key that signs session tokens and encrypts OIDC refresh tokens. See Sessions.

For the test types, see Speed tests.

KeyTypeDefaultDescription
timeoutinteger30The time limit in seconds for a speed test. See Speed tests.
connectionsinteger0The maximum number of Speedtest.net connections. 0 keeps the library default. See Speed tests.

Before you set a high connections value, read the caution in Speed tests.

KeyTypeDefaultDescription
test_durationinteger10The length of an iperf3 test in seconds.
parallel_connsinteger4The number of parallel iperf3 streams.
timeoutinteger60The time limit in seconds for an iperf3 test.

These keys control the ping test that measures latency.

KeyTypeDefaultDescription
countinteger5The number of ping packets.
intervalinteger1000The time between packets in milliseconds.
timeoutinteger10The time limit in seconds for the ping test.
KeyTypeDefaultDescription
timeoutinteger60The time limit in seconds for a LibreSpeed test. If the file sets 0, Netronome uses 60.

These keys set the defaults for the speed test history. A request to the API can override each one.

KeyTypeDefaultDescription
default_pageinteger1The first page to show.
default_time_rangestring"1w"The time range of the history, for example 1w for one week.
default_limitinteger20The number of results on one page.

GeoIP adds country flags and ASN names to traceroute results. Both keys are empty by default, and GeoIP is off. For the setup, see GeoIP.

KeyTypeDefaultDescription
country_database_pathstring""The path to GeoLite2-Country.mmdb.
asn_database_pathstring""The path to GeoLite2-ASN.mmdb.

For packet loss monitors and MTR, see Packet loss.

KeyTypeDefaultDescription
enabledbooleantrueTurns on packet loss monitoring.
max_concurrent_monitorsinteger10Netronome reads this value but does not apply it. See Packet loss.
privileged_modebooleantrueTries ICMP first. See Privileges.
mtr_enable_dnsbooleanfalseResolves hop addresses to hostnames in MTR results.

For remote system monitoring, see Agents.

KeyTypeDefaultDescription
enabledbooleantrueTurns on the monitor service. The server uses it to collect data from agents.

The netronome agent command reads this section. The server does not use it. Each key also has a command-line flag. For the setup, see Agents.

KeyTypeDefaultDescription
hoststring"0.0.0.0"The address that the agent listens on.
portinteger8200The port of the agent.
interfacestring""The network interface that vnstat monitors. See The interface setting.
api_keystring""The API key that the server must send. If empty, the agent does not ask for a key.
disk_includeslist of strings[]Mount points that the agent always reports. See Disk filters.
disk_excludeslist of strings[]Mount points that the agent does not report. See Disk filters.
disable_system_metricsbooleanfalseStops the collection of CPU, memory, disk, and temperature data.

Tailscale connects the server and the agents over your tailnet. For the setup, see Tailscale.

KeyTypeDefaultDescription
enabledbooleanfalseTurns on the Tailscale integration.
methodstring"auto"How Netronome connects to Tailscale: auto, host, or tsnet. See Methods.
auth_keystring""The Tailscale auth key. The tsnet method must have one.
hostnamestring""The name of the tsnet node. See Tailscale.
ephemeralbooleanfalseRemoves the tsnet node from the tailnet when Netronome stops.
state_dirstring"~/.config/netronome/tsnet"The directory for the tsnet state.
control_urlstring""The URL of a different control server, for example Headscale.
agent_portinteger8200The port that the agent listens on over Tailscale. 0 uses agent.port. See tsnet mode.
auto_discoverbooleantrueThe server finds Netronome agents on the tailnet.
discovery_intervalstring"5m"The time between two discovery runs, as a Go duration, for example 5m or 1h.
discovery_portinteger8200The port that the server probes on each Tailscale peer.
discovery_prefixstring""Discovery does not read this key. The server probes every online peer.
prefer_hostbooleanfalseDeprecated. Use method = "host".

This section is deprecated. Use the keys in [tailscale].

KeyTypeDefaultDescription
enabledbooleanfalseDeprecated. If true, netronome agent starts with Tailscale, like --tailscale.
portinteger8200Deprecated. Use tailscale.agent_port.

This section is deprecated. Use the keys in [tailscale].

KeyTypeDefaultDescription
auto_discoverbooleantrueDeprecated. Use tailscale.auto_discover.
discovery_intervalstring"5m"Deprecated. Use tailscale.discovery_interval.
discovery_portinteger8200Deprecated. Use tailscale.discovery_port.
discovery_prefixstring""Deprecated. Discovery does not filter by this prefix. The server probes every online peer.

You set notifications, schedules, DNS monitors, and packet loss monitors in the web interface. Netronome keeps them in the database. See Notifications, Scheduling, and DNS.

config.toml
check_for_updates = true
[database]
type = "sqlite"
path = "netronome.db"
[server]
host = "0.0.0.0"
port = 7575
[logging]
level = "info"
[auth]
whitelist = []
trusted_proxies = []
[session]
session_secret = "<random value>"
[speedtest]
timeout = 30
connections = 0
[speedtest.iperf]
test_duration = 10
parallel_conns = 4
timeout = 60
[speedtest.iperf.ping]
count = 5
interval = 1000
timeout = 10
[speedtest.librespeed]
timeout = 60
[packetloss]
enabled = true
max_concurrent_monitors = 10
privileged_mode = true
mtr_enable_dns = false
[monitor]
enabled = true
[tailscale]
enabled = false
method = "auto"