Sharkord

Configuration

Configure Sharkord with config.ini and environment variables.

On first run, Sharkord writes a config.ini in its data directory (~/.config/sharkord/config.ini on Linux). Edit it and restart the server to apply changes.

This file covers how the process runs: ports, limits, proxies. Everything about how the community runs, from permissions to storage quotas, is in the interface instead. See Server Settings.

The file is rewritten on every start

Sharkord merges your file with its defaults on boot and writes the result back, so new options appear automatically after an update. Comments and unknown keys are removed in the process, and a file that fails validation is replaced with the defaults.

Format

It is a plain INI file with one section per group:

[server]
port=4991
debug=false
autoupdate=false
backupDatabase=true
maxRequestBodyBytes=262144
allowedOrigins[]=*
trustedProxies[]=127.0.0.1
trustedProxies[]=::1
trustedProxies[]=10.0.0.0/8
trustedProxies[]=172.16.0.0/12
trustedProxies[]=192.168.0.0/16
trustedProxies[]=fc00::/7

[oidc]
enabled=false
issuer=
clientId=
clientSecret=
redirectUri=
disableLocalLogin=false

[webRtc]
port=40000
announcedAddress=
maxBitrate=30000000

[rateLimiters.sendAndEditMessage]
maxRequests=15
windowMs=60000

List values repeat the key with [], one line per entry:

[server]
allowedOrigins[]=https://chat.example.com
allowedOrigins[]=https://www.example.com
trustedProxies[]=127.0.0.1

Server

FieldDefaultDescription
port4991Port for HTTP and WebSocket traffic.
debugfalseVerbose debug logging.
autoupdatefalseCheck for new releases every hour and install them. Ignored in Docker. See Updating.
backupDatabasetrueSnapshot the database before applying migrations. See Database Migrations.
maxRequestBodyBytes262144Maximum size of an HTTP request body, in bytes. File uploads are not affected; their limits live in the server settings.
allowedOrigins*Origins allowed to call the server from a browser. * allows any.
trustedProxiesloopback and private rangesAddresses or CIDR ranges whose forwarded headers are believed. See Behind a Proxy.

Single Sign-On

FieldDefaultDescription
enabledfalseTurn on OIDC sign-in.
issueremptyYour provider's issuer URL.
clientIdemptyClient id from your provider.
clientSecretemptyClient secret from your provider.
redirectUriemptyOverride the callback URL. Empty means it is derived from the request.
disableLocalLoginfalseRefuse password sign-in, leaving the provider as the only way in.

These live under [oidc]. See Single Sign-On for the provider side and how accounts are matched.

WebRTC

FieldDefaultDescription
port40000Port used for voice, webcam, and screen sharing media. Listens on both UDP and TCP; open both.
announcedAddressemptyPublic address clients should send media to. Set this if the server is behind NAT, Docker, or a cloud firewall.
maxBitrate30000000Maximum bitrate per connection, in bits per second.
Public IP lookup

When announcedAddress is empty, the server asks an external service (icanhazip, ipify, or ifconfig.me) for its public IP at startup. Setting announcedAddress explicitly skips that request entirely.

Rate Limiters

Each limiter takes maxRequests and windowMs. Requests are counted per user once logged in, and per client IP before that. Going over the limit returns an error to the client and logs a line when debug is on.

LimiterMax requestsWindowApplies to
sendAndEditMessage1560000Sending and editing messages
joinVoiceChannel2060000Joining voice channels
moveMembers2060000Moving members between channels
login560000Login attempts
joinServer560000Joining the server
upload3060000File uploads
search1560000Message search
signalTyping405000Typing indicators
getMessages6010000Loading message history
markAsRead6010000Marking channels as read
toggleMessageReaction6010000Adding and removing reactions
addEmoji1060000Uploading custom emojis
openDirectMessage1060000Opening direct message channels
handshake1060000Initial connection handshakes
updatePassword560000Password changes
adminCreate6060000Creating roles and invites
voiceTransport3060000Voice transport setup
voiceStream20060000Voice and video stream updates
useSecretToken560000Owner token claims
pluginExecute6060000Plugin commands and actions
pluginRoute30060000Requests to plugin HTTP routes
pluginInstall1060000Installing and updating plugins
oidc3060000Single sign-on requests

Most servers never need to touch these. Raise a limit if legitimate users hit it; lower it if you are being abused.

Environment Variables

Every option above can be set with an environment variable, which is usually easier in Docker. Environment variables win over config.ini, and empty values are ignored.

VariableOverrides
SHARKORD_PORTserver.port
SHARKORD_DEBUGserver.debug
SHARKORD_AUTOUPDATEserver.autoupdate
SHARKORD_BACKUP_DATABASEserver.backupDatabase
SHARKORD_MAX_REQUEST_BODY_BYTESserver.maxRequestBodyBytes
SHARKORD_ALLOWED_ORIGINSserver.allowedOrigins
SHARKORD_TRUSTED_PROXIESserver.trustedProxies
SHARKORD_OIDC_ENABLEDoidc.enabled
SHARKORD_OIDC_ISSUERoidc.issuer
SHARKORD_OIDC_CLIENT_IDoidc.clientId
SHARKORD_OIDC_CLIENT_SECREToidc.clientSecret
SHARKORD_OIDC_REDIRECT_URIoidc.redirectUri
SHARKORD_OIDC_DISABLE_LOCAL_LOGINoidc.disableLocalLogin
SHARKORD_WEBRTC_PORTwebRtc.port
SHARKORD_WEBRTC_ANNOUNCED_ADDRESSwebRtc.announcedAddress
SHARKORD_WEBRTC_MAX_BITRATEwebRtc.maxBitrate

List options take a comma-separated value:

SHARKORD_TRUSTED_PROXIES="127.0.0.1,::1,10.0.0.0/8"

Rate limiters cannot be set through environment variables. Use config.ini for those.

There is one more variable, SHARKORD_DATA_PATH, which moves the whole data directory. See Data Directory.

Running Behind a Proxy

trustedProxies defaults to loopback and every private range:

[server]
trustedProxies[]=127.0.0.1
trustedProxies[]=::1
trustedProxies[]=10.0.0.0/8
trustedProxies[]=172.16.0.0/12
trustedProxies[]=192.168.0.0/16
trustedProxies[]=fc00::/7

So a proxy on the same machine, in another container, or elsewhere on your network is believed without any configuration. Public addresses are not, which is why a CDN such as Cloudflare has to be added by hand. Setting the option replaces the list rather than extending it.

Behind a Proxy covers this in full, including how the client address is resolved, when to narrow the default, and what the proxy itself has to pass through.

On this page