Skip to content

Configuration

Bifröst will be configured in the YAML language.

By default, the configuration is taken from the following location:

  • Linux: /etc/engity/bifroest/configuration.yaml
  • macOS: /Library/Application Support/Engity/Bifroest/configuration.yaml
  • Windows: C:\ProgramData\Engity\Bifroest\configuration.yaml

This location can be changed by the --configuration=<path> flag when executing:

bifroest run --configuration=/my/config.yaml

Properties

ssh

SSH

Defines how the SSH connections itself will behave.

session

Defines where and how the sessions inside Bifröst are handled.

flows

[]Flow

Defines which flows are evaluated for user sessions.

auditlog

Defines named audit logs that flows can use for security-relevant actions. If omitted or empty, it contains one disabled audit log named default.

housekeeping

Defines how Bifröst will clean up its sessions and connections.

alternatives

Defines how the imp (if needed) behaves to help to bridge context boundaries, for example to enable port-forwarding into an OCI container.

startMessage

string Core = ""

If defined this message will be displayed in the log files of Bifröst on startup.

Examples

  1. Simple:

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    ssh:
      addresses: [ ":22" ]
      # ...
    session:
      type: fs
      # ...
    flows:
      - name: local
        # ...
    housekeeping:
      # ...
    alternatives:
      # ...
    startMessage: ""
    

  2. Local-account host configuration
     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
    ## Host service for an existing local account on Linux, Windows or macOS.
    ## Local authentication uses the platform default.
    flows:
      - name: local
        authorization:
          type: local
        environment:
          type: local
          name: "{{.authorization.user.name}}"
          ## If you only want to allow user with group "ssh" to log in, uncomment the following lines:
          ## Unix only: Windows users have no primary group.
          #loginAllowed: |
          #  {{ or
          #    (.authorization.user.group.name | eq "ssh" )
          #    (.authorization.user.groups     | firstMatching `{{.name | eq "ssh" }}` )
          #  }}
    
  3. Docker environment with OpenID Connect authorization

    This example is using the Docker environment with OpenID Connection authorization.

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    flows:
      - name: docker
        authorization:
          type: oidcDeviceAuth
          issuer: https://login.microsoftonline.com/my-great-tenant-uuid/v2.0
          clientId: my-great-client-uuid
          clientSecret: very-secret-secret
          scopes:
            - openid
            - email
            - profile
            - offline_access
        environment:
          type: docker
          image: alpine