site.rst 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545
  1. Site configuration
  2. ==================
  3. The ``site`` consists of the files ``site.conf`` and ``site.mk``.
  4. In the first community based values are defined, which both are processed
  5. during the build process and runtime.
  6. The last is directly included in the make process of Gluon.
  7. Configuration
  8. -------------
  9. The ``site.conf`` is a lua dictionary with the following defined keys.
  10. hostname_prefix
  11. A string which shall prefix the default hostname of a device.
  12. site_name
  13. The name of your community.
  14. site_code
  15. The code of your community. It is good practice to use the TLD of
  16. your community here.
  17. prefix4 \: optional
  18. The IPv4 Subnet of your community mesh network in CIDR notation, e.g.
  19. ::
  20. prefix4 = '10.111.111.0/18'
  21. Required if ``next_node.ip4`` is set.
  22. prefix6
  23. The IPv6 subnet of your community mesh network, e.g.
  24. ::
  25. prefix6 = 'fdca::ffee:babe:1::/64'
  26. timezone
  27. The timezone of your community live in, e.g.
  28. ::
  29. -- Europe/Berlin
  30. timezone = 'CET-1CEST,M3.5.0,M10.5.0/3'
  31. ntp_server
  32. List of NTP servers available in your community or used by your community, e.g.:
  33. ::
  34. ntp_servers = {'1.ntp.services.ffac','2.ntp.services.ffac'}
  35. This NTP servers must be reachable via IPv6 from the nodes. If you don't want to set an IPv6 address
  36. explicitly, but use a hostname (which is recommended), see also the :ref:`FAQ <faq-dns>`.
  37. opkg \: optional
  38. ``opkg`` package manager configuration.
  39. There are two optional fields in the ``opkg`` section:
  40. - ``lede`` overrides the default LEDE repository URL. The default URL would
  41. correspond to ``http://downloads.lede-project.org/snapshots/packages/%A``
  42. and usually doesn't need to be changed when nodes are expected to have IPv6
  43. internet connectivity.
  44. - ``extra`` specifies a table of additional repositories (with arbitrary keys)
  45. ::
  46. opkg = {
  47. lede = 'http://opkg.services.ffac/lede/snapshots/packages/%A',
  48. extra = {
  49. gluon = 'http://opkg.services.ffac/modules/gluon-%GS-%GR/%S',
  50. },
  51. }
  52. There are various patterns which can be used in the URLs:
  53. - ``%n`` is replaced by the LEDE version codename
  54. - ``%v`` is replaced by the LEDE version number (e.g. "17.01")
  55. - ``%S`` is replaced by the target board (e.g. "ar71xx/generic")
  56. - ``%A`` is replaced by the target architecture (e.g. "mips_24kc")
  57. - ``%GS`` is replaced by the Gluon site code (as specified in ``site.conf``)
  58. - ``%GV`` is replaced by the Gluon version
  59. - ``%GR`` is replaced by the Gluon release (as specified in ``site.mk``)
  60. regdom \: optional
  61. The wireless regulatory domain responsible for your area, e.g.:
  62. ::
  63. regdom = 'DE'
  64. Setting ``regdom`` is mandatory if ``wifi24`` or ``wifi5`` is defined.
  65. wifi24 \: optional
  66. WLAN configuration for 2.4 GHz devices.
  67. ``channel`` must be set to a valid wireless channel for your radio.
  68. There are currently three interface types available. You many choose to
  69. configure any subset of them:
  70. - ``ap`` creates a master interface where clients may connect
  71. - ``mesh`` creates an 802.11s mesh interface with forwarding disabled
  72. - ``ibss`` creates an ad-hoc interface
  73. Each interface may be disabled by setting ``disabled`` to ``true``.
  74. This will only affect new installations.
  75. Upgrades will not change the disabled state.
  76. Additionally it is possible to configure the ``supported_rates`` and ``basic_rate``
  77. of each radio. Both are optional, by default hostapd/driver dictate the rates.
  78. If ``supported_rates`` is set, ``basic_rate`` is required, because ``basic_rate``
  79. has to be a subset of ``supported_rates``.
  80. The example below disables 802.11b rates.
  81. ``ap`` requires a single parameter, a string, named ``ssid`` which sets the
  82. interface's ESSID. This is the WiFi the clients connect to.
  83. ``mesh`` requires a single parameter, a string, named ``id`` which sets the
  84. mesh id, also visible as an open WiFi in some network managers. Usually you
  85. don't want users to connect to this mesh-SSID, so use a cryptic id that no
  86. one will accidentally mistake for the client WiFi.
  87. ``ibss`` requires two parametersr: ``ssid`` (a string) and ``bssid`` (a MAC).
  88. An optional parameter ``vlan`` (integer) is supported.
  89. Both ``mesh`` and ``ibss`` accept an optional ``mcast_rate`` (kbit/s) parameter for
  90. setting the multicast bitrate. Increasing the default value of 1000 to something
  91. like 12000 is recommended.
  92. ::
  93. wifi24 = {
  94. channel = 11,
  95. supported_rates = {6000, 9000, 12000, 18000, 24000, 36000, 48000, 54000},
  96. basic_rate = {6000, 9000, 18000, 36000, 54000},
  97. ap = {
  98. ssid = 'alpha-centauri.freifunk.net',
  99. },
  100. mesh = {
  101. id = 'ueH3uXjdp',
  102. mcast_rate = 12000,
  103. },
  104. ibss = {
  105. ssid = 'ff:ff:ff:ee:ba:be',
  106. bssid = 'ff:ff:ff:ee:ba:be',
  107. mcast_rate = 12000,
  108. },
  109. },
  110. wifi5 \: optional
  111. Same as `wifi24` but for the 5Ghz radio.
  112. next_node \: package
  113. Configuration of the local node feature of Gluon
  114. ::
  115. next_node = {
  116. ip4 = '10.23.42.1',
  117. ip6 = 'fdca:ffee:babe:1::1',
  118. mac = '16:41:95:40:f7:dc'
  119. }
  120. All values of this section are optional. If the IPv4 or IPv6 address is
  121. omitted, there will be no IPv4 or IPv6 anycast address. The MAC address
  122. defaults to ``16:41:95:40:f7:dc``; this value usually doesn't need to be
  123. changed, but it can be adjusted to match existing deployments that use a
  124. different value.
  125. mesh \: optional
  126. Options specific to routing protocols.
  127. At the moment, only the ``batman_adv`` routing protocol has such options:
  128. The optional value ``gw_sel_class`` sets the gateway selection class. The default
  129. class 20 is based on the link quality (TQ) only, class 1 is calculated from
  130. both the TQ and the announced bandwidth.
  131. ::
  132. mesh = {
  133. batman_adv = {
  134. gw_sel_class = 1,
  135. },
  136. }
  137. mesh_vpn
  138. Remote server setup for the mesh VPN.
  139. The `enabled` option can be set to true to enable the VPN by default. `mtu`
  140. defines the MTU of the VPN interface.
  141. The `fastd` section configures settings specific to the *fastd* VPN
  142. implementation.
  143. If `configurable` is set to `false` or unset, the method list will be replaced on updates
  144. with the list from the site configuration. Setting `configurable` to `true` will allow the user to
  145. add the method ``null`` to the beginning of the method list or remove ``null`` from it,
  146. and make this change survive updates. Setting `configurable` is necessary for the
  147. package `gluon-web-mesh-vpn-fastd`, which adds a UI for this configuration.
  148. In any case, the ``null`` method should always be the first method in the list
  149. if it is supported at all. You should only set `configurable` to `true` if the
  150. configured peers support both the ``null`` method and methods with encryption.
  151. You can set syslog_level from verbose (default) to warn to reduce syslog output.
  152. The `tunneldigger` section is used to define the *tunneldigger* broker list.
  153. **Note:** It doesn't make sense to include both `fastd` and `tunneldigger`
  154. sections in the same configuration file, as only one of the packages *gluon-mesh-vpn-fastd*
  155. and *gluon-mesh-vpn-tunneldigger* should be installed with the current
  156. implementation.
  157. ::
  158. mesh_vpn = {
  159. -- enabled = true,
  160. mtu = 1280,
  161. fastd = {
  162. methods = {'salsa2012+umac'},
  163. -- configurable = true,
  164. -- syslog_level = 'warn',
  165. groups = {
  166. backbone = {
  167. -- Limit number of connected peers from this group
  168. limit = 1,
  169. peers = {
  170. peer1 = {
  171. key = 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX',
  172. -- Having multiple domains prevents SPOF in freifunk.net
  173. remotes = {
  174. 'ipv4 "vpn1.alpha-centauri.freifunk.net" port 10000',
  175. 'ipv4 "vpn1.alpha-centauri-freifunk.de" port 10000',
  176. },
  177. },
  178. peer2 = {
  179. key = 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX',
  180. -- You can also omit the ipv4 to allow both connection via ipv4 and ipv6
  181. remotes = {'"vpn2.alpha-centauri.freifunk.net" port 10000'},
  182. },
  183. peer3 = {
  184. key = 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX',
  185. -- In addition to domains you can also add ip addresses, which provides
  186. -- resilience in case of dns outages
  187. remotes = {
  188. '"vpn3.alpha-centauri.freifunk.net" port 10000',
  189. '[2001:db8::3:1]:10000',
  190. '192.0.2.3:10000',
  191. },
  192. },
  193. },
  194. -- Optional: nested peer groups
  195. -- groups = {
  196. -- lowend_backbone = {
  197. -- limit = 1,
  198. -- peers = ...
  199. -- },
  200. -- },
  201. },
  202. -- Optional: additional peer groups, possibly with other limits
  203. -- peertopeer = {
  204. -- limit = 10,
  205. -- peers = { ... },
  206. -- },
  207. },
  208. },
  209. tunneldigger = {
  210. brokers = {'vpn1.alpha-centauri.freifunk.net'}
  211. },
  212. bandwidth_limit = {
  213. -- The bandwidth limit can be enabled by default here.
  214. enabled = false,
  215. -- Default upload limit (kbit/s).
  216. egress = 200,
  217. -- Default download limit (kbit/s).
  218. ingress = 3000,
  219. },
  220. }
  221. mesh_on_wan \: optional
  222. Enables the mesh on the WAN port (``true`` or ``false``).
  223. ::
  224. mesh_on_wan = true,
  225. mesh_on_lan \: optional
  226. Enables the mesh on the LAN port (``true`` or ``false``).
  227. ::
  228. mesh_on_lan = true,
  229. poe_passthrough \: optional
  230. Enable PoE passthrough by default on hardware with such a feature.
  231. autoupdater \: package
  232. Configuration for the autoupdater feature of Gluon.
  233. The mirrors are checked in random order until the manifest could be downloaded
  234. successfully or all mirrors have been tried.
  235. ::
  236. autoupdater = {
  237. branch = 'stable',
  238. branches = {
  239. stable = {
  240. name = 'stable',
  241. mirrors = {
  242. 'http://[fdca:ffee:babe:1::fec1]/firmware/stable/sysupgrade/',
  243. 'http://autoupdate.alpha-centauri.freifunk.net/firmware/stable/sysupgrade/',
  244. },
  245. -- Number of good signatures required
  246. good_signatures = 2,
  247. pubkeys = {
  248. 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX', -- someguy
  249. 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX', -- someother
  250. }
  251. }
  252. }
  253. }
  254. All configured mirrors must be reachable from the nodes via IPv6. If you don't want to set an IPv6 address
  255. explicitly, but use a hostname (which is recommended), see also the :ref:`FAQ <faq-dns>`.
  256. roles \: optional
  257. Optional role definitions. Nodes will announce their role inside the mesh.
  258. This will allow in the backend to distinguish between normal, backbone and
  259. service nodes or even gateways (if they advertise that role). It is up to
  260. the community which roles to define. See the section below as an example.
  261. ``default`` takes the default role which is set initially. This value should be
  262. part of ``list``. If you want node owners to change the role via config mode add
  263. the package ``gluon-web-node-role`` to ``site.mk``.
  264. The strings to display in the web interface are configured per language in the
  265. ``i18n/en.po``, ``i18n/de.po``, etc. files of the site repository using message IDs like
  266. ``gluon-web-node-role:role:node`` and ``gluon-web-node-role:role:backbone``.
  267. ::
  268. roles = {
  269. default = 'node',
  270. list = {
  271. 'node',
  272. 'test',
  273. 'backbone',
  274. 'service',
  275. },
  276. },
  277. setup_mode \: package
  278. Allows skipping setup mode (config mode) at first boot when attribute
  279. ``skip`` is set to ``true``. This is optional and may be left out.
  280. ::
  281. setup_mode = {
  282. skip = true,
  283. },
  284. legacy \: package
  285. Configuration for the legacy upgrade path.
  286. This is only required in communities upgrading from Lübeck's LFF-0.3.x.
  287. ::
  288. legacy = {
  289. version_files = {'/etc/.freifunk_version_keep', '/etc/.eff_version_keep'},
  290. old_files = {'/etc/config/config_mode', '/etc/config/ffac', '/etc/config/freifunk'},
  291. config_mode_configs = {'config_mode', 'ffac', 'freifunk'},
  292. fastd_configs = {'ffac_mesh_vpn', 'mesh_vpn'},
  293. mesh_ifname = 'freifunk',
  294. tc_configs = {'ffki', 'freifunk'},
  295. wifi_names = {'wifi_freifunk', 'wifi_freifunk5', 'wifi_mesh', 'wifi_mesh5'},
  296. }
  297. Packages
  298. --------
  299. The ``site.mk`` is a Makefile which should define constants
  300. involved in the build process of Gluon.
  301. GLUON_SITE_PACKAGES
  302. Defines a list of packages which should be installed additionally
  303. to the ``gluon-core`` package.
  304. GLUON_RELEASE
  305. The current release version Gluon should use.
  306. GLUON_PRIORITY
  307. The default priority for the generated manifests (see the autoupdater documentation
  308. for more information).
  309. GLUON_REGION
  310. Region code to build into images where necessary. Valid values are the empty string,
  311. ``us`` and ``eu``.
  312. GLUON_LANGS
  313. List of languages (as two-letter-codes) to be included in the web interface. Should always contain
  314. ``en``.
  315. .. _site-config-mode-texts:
  316. Config mode texts
  317. -----------------
  318. The community-defined texts in the config mode are configured in PO files in the ``i18n`` subdirectory
  319. of the site configuration. The message IDs currently defined are:
  320. gluon-config-mode:welcome
  321. Welcome text on the top of the config wizard page.
  322. gluon-config-mode:pubkey
  323. Information about the public VPN key on the reboot page.
  324. gluon-config-mode:novpn
  325. Information shown on the reboot page, if the mesh VPN was not selected.
  326. gluon-config-mode:altitude-label
  327. Label for the ``altitude`` field
  328. gluon-config-mode:altitude-help
  329. Description for the usage of the ``altitude`` field
  330. gluon-config-mode:reboot
  331. General information shown on the reboot page.
  332. There is a POT file in the site example directory which can be used to create templates
  333. for the language files. The command ``msginit -l en -i ../../docs/site-example/i18n/gluon-site.pot``
  334. can be used from the ``i18n`` directory to create an initial PO file called ``en.po`` if the ``gettext``
  335. utilities are installed.
  336. .. note::
  337. An empty ``msgstr``, as is the default after running ``msginit``, leads to
  338. the ``msgid`` being printed as-is. It does *not* hide the whole text, as
  339. might be expected.
  340. Depending on the context, you might be able to use comments like
  341. ``<!-- empty -->`` as translations to effectively hide the text.
  342. Site modules
  343. ------------
  344. The file ``modules`` in the site repository is completely optional and can be used
  345. to supply additional package feeds from which packages are built. The git repositories
  346. specified here are retrieved in addition to the default feeds when ``make update``
  347. it called.
  348. This file's format is very similar to the toplevel ``modules`` file of the Gluon
  349. tree, with the important different that the list of feeds must be assigned to
  350. the variable ``GLUON_SITE_FEEDS``. Multiple feed names must be separated by spaces,
  351. for example::
  352. GLUON_SITE_FEEDS='foo bar'
  353. The feed names may only contain alphanumerical characters, underscores and slashes.
  354. For each of the feeds, the following variables are used to specify how to update
  355. the feed:
  356. PACKAGES_${feed}_REPO
  357. The URL of the git repository to clone (usually ``git://`` or ``http(s)://``)
  358. PACKAGES_${feed}_COMMIT
  359. The commit ID of the repository to use
  360. PACKAGES_${feed}_BRANCH
  361. Optional: The branch of the repository the given commit ID can be found in.
  362. Defaults to the default branch of the repository (usually ``master``)
  363. These variables are always all uppercase, so for an entry ``foo`` in GLUON_SITE_FEEDS,
  364. the corresponding configuration variables would be ``PACKAGES_FOO_REPO``,
  365. ``PACKAGES_FOO_COMMIT`` and ``PACKAGES_FOO_BRANCH``. Slashes in feed names are
  366. replaced by underscores to get valid shell variable identifiers.
  367. Examples
  368. --------
  369. site.mk
  370. ^^^^^^^
  371. .. literalinclude:: ../site-example/site.mk
  372. :language: makefile
  373. site.conf
  374. ^^^^^^^^^
  375. .. literalinclude:: ../site-example/site.conf
  376. :language: lua
  377. i18n/en.po
  378. ^^^^^^^^^^
  379. .. literalinclude:: ../site-example/i18n/en.po
  380. :language: po
  381. i18n/de.po
  382. ^^^^^^^^^^
  383. .. literalinclude:: ../site-example/i18n/de.po
  384. :language: po
  385. modules
  386. ^^^^^^^
  387. .. literalinclude:: ../site-example/modules
  388. :language: makefile
  389. site-repos in the wild
  390. ^^^^^^^^^^^^^^^^^^^^^^
  391. This is a non-exhaustive list of site-repos from various communities:
  392. * `site-ffa <https://github.com/tecff/site-ffa>`_ (Altdorf, Landshut & Umgebung)
  393. * `site-ffac <https://github.com/ffac/site>`_ (Regio Aachen)
  394. * `site-ffbs <https://github.com/ffbs/site-ffbs>`_ (Braunschweig)
  395. * `site-ffhb <https://github.com/FreifunkBremen/gluon-site-ffhb>`_ (Bremen)
  396. * `site-ffda <https://github.com/freifunk-darmstadt/site-ffda>`_ (Darmstadt)
  397. * `site-ffeh <https://github.com/freifunk-ehingen/site-ffeh>`_ (Ehingen)
  398. * `site-fffl <https://github.com/freifunk-flensburg/site-fffl>`_ (Flensburg)
  399. * `site-ffgoe <https://github.com/freifunk-goettingen/site-ffgoe>`_ (Göttingen)
  400. * `site-ffgt-rhw <https://github.com/ffgtso/site-ffgt-rhw>`_ (Guetersloh)
  401. * `site-ffhh <https://github.com/freifunkhamburg/site-ffhh>`_ (Hamburg)
  402. * `site-ffho <https://git.ffho.net/freifunkhochstift/ffho-site>`_ (Hochstift)
  403. * `site-ffhgw <https://github.com/lorenzo-greifswald/site-ffhgw>`_ (Greifswald)
  404. * `site-ffka <https://github.com/ffka/site-ffka>`_ (Karlsruhe)
  405. * `site-ffki <http://git.freifunk.in-kiel.de/ffki-site/>`_ (Kiel)
  406. * `site-fflz <https://github.com/freifunk-lausitz/site-fflz>`_ (Lausitz)
  407. * `site-ffl <https://github.com/freifunk-leipzig/freifunk-gluon-leipzig>`_ (Leipzig)
  408. * `site-ffhl <https://github.com/freifunk-luebeck/site-ffhl>`_ (Lübeck)
  409. * `site-fflg <https://github.com/kartenkarsten/site-fflg>`_ (Lüneburg)
  410. * `site-ffmd <https://github.com/FreifunkMD/site-ffmd>`_ (Magdeburg)
  411. * `site-ffmwu <https://github.com/freifunk-mwu/sites-ffmwu>`_ (Mainz, Wiesbaden & Umgebung)
  412. * `site-ffmyk <https://github.com/FreifunkMYK/site-ffmyk>`_ (Mayen-Koblenz)
  413. * `site-ffmo <https://github.com/ffruhr/site-ffmo>`_ (Moers)
  414. * `site-ffmg <https://github.com/ffruhr/site-ffmg>`_ (Mönchengladbach)
  415. * `site-ffm <https://github.com/freifunkMUC/site-ffm>`_ (München)
  416. * `site-ffhmue <https://github.com/Freifunk-Muenden/site-conf>`_ (Münden)
  417. * `site-ffms <https://github.com/FreiFunkMuenster/site-ffms>`_ (Münsterland)
  418. * `site-neuss <https://github.com/ffne/site-neuss>`_ (Neuss)
  419. * `site-ffniers <https://github.com/ffruhr/site-ffniers>`_ (Niersufer)
  420. * `site-ffnw <https://git.nordwest.freifunk.net/ffnw-firmware/siteconf/tree/master>`_ (Nordwest)
  421. * `site-ffrgb <https://github.com/ffrgb/site-ffrgb>`_ (Regensburg)
  422. * `site-ffrn <https://github.com/Freifunk-Rhein-Neckar/site-ffrn>`_ (Rhein-Neckar)
  423. * `site-ffruhr <https://github.com/ffruhr?utf8=✓&query=site>`_ (Ruhrgebiet, Multi-Communities)
  424. * `site-ffs <https://github.com/freifunk-stuttgart/site-ffs>`_ (Stuttgart)
  425. * `site-fftr <https://github.com/freifunktrier/site-fftr>`_ (Trier)