--- # Headscale configuration with OIDC enabled for testing server_url: http://localhost:8180 listen_addr: 0.0.0.0:8080 metrics_listen_addr: 0.0.0.0:9090 grpc_listen_addr: 0.0.0.0:50443 grpc_allow_insecure: true # IP prefixes for the tailnet prefixes: v4: 100.64.0.0/10 v6: fd7a:115c:a1e0::/48 ip_allocation: sequential # Database configuration database: type: sqlite sqlite: path: /var/lib/headscale/db.sqlite # OIDC Configuration for testing with Keycloak oidc: issuer: "http://keycloak:8080/realms/headscale" client_id: "headscale-client" client_secret: "your-client-secret" scope: ["openid", "profile", "email", "groups"] extra_params: {} allowed_domains: [] allowed_groups: [] allowed_users: [] expiry: 180d use_expiry_from_token: false pkce: enabled: true method: "S256" # DNS Configuration dns: override_local_dns: true nameservers: global: ["1.1.1.1", "1.0.0.1", "8.8.8.8"] domains: [] extra_records: [] magic_dns: true base_domain: headscale.net # TLS disabled for local testing disable_check_updates: true ephemeral_node_inactivity_timeout: 30m # Policy configuration policy: mode: file path: "/etc/headscale/acl.hujson" # Log configuration log: format: text level: info