# /etc/overseer.yaml — installed by the overseer package.
# Mode SHOULD be 0640 root:overseer (the tmpfiles rule enforces this);
# the OIDC client_secret is sensitive.
bind_address: "unix:/run/overseer/overseer.sock"
port: 8080 # ignored when bind_address starts with "unix:"
socket_permission: "0666" # world rw — so any reverse proxy can connect
log_level: "info" # trace|debug|info|warn|error|critical
db_path: "/var/lib/overseer/overseer.db"
oidc:
issuer_url: "https://keycloak.example.com/realms/family"
client_id: "overseer"
client_secret: "REPLACE_ME"
redirect_uri: "https://overseer.example.com/oidc/callback"
session:
cookie_name: "overseer_sid"
max_age_minutes: 480