{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://nats.io/schemas/server-config.json", "title": "NATS Server Configuration", "description": "JSON Schema for NATS server configuration including network settings, authentication, clustering, JetStream, and security options.", "type": "object", "properties": { "host": { "type": "string", "description": "Host address for client connections", "default": "0.0.0.0" }, "port": { "type": "integer", "description": "Port for client connections", "default": 4222, "minimum": 1, "maximum": 65535 }, "listen": { "type": "string", "description": "Listen specification in host:port format" }, "client_advertise": { "type": "string", "description": "Client advertise address for NAT environments" }, "server_name": { "type": "string", "description": "Unique name for this server" }, "max_connections": { "type": "integer", "description": "Maximum number of client connections", "default": 65536, "minimum": 0 }, "max_control_line": { "type": "integer", "description": "Maximum control line size in bytes", "default": 4096 }, "max_payload": { "type": "integer", "description": "Maximum message payload size in bytes", "default": 1048576, "minimum": 0 }, "max_pending": { "type": "integer", "description": "Maximum pending bytes per client connection", "default": 67108864 }, "max_subscriptions": { "type": "integer", "description": "Maximum subscriptions per client connection", "default": 0, "minimum": 0 }, "ping_interval": { "type": "string", "description": "Interval between pings to clients", "default": "2m" }, "ping_max": { "type": "integer", "description": "Maximum outstanding pings before closing connection", "default": 2, "minimum": 0 }, "write_deadline": { "type": "string", "description": "Maximum time to write to a client connection", "default": "10s" }, "no_header_support": { "type": "boolean", "description": "Disable message header support", "default": false }, "disable_sublist_cache": { "type": "boolean", "description": "Disable subscription list cache", "default": false }, "authorization": { "type": "object", "description": "Authorization configuration", "properties": { "user": { "type": "string", "description": "Username for single-user authentication" }, "password": { "type": "string", "description": "Password for single-user authentication" }, "token": { "type": "string", "description": "Token for token-based authentication" }, "timeout": { "type": "number", "description": "Authorization timeout in seconds", "default": 2 }, "users": { "type": "array", "description": "List of authorized users", "items": { "type": "object", "properties": { "user": { "type": "string" }, "password": { "type": "string" }, "nkey": { "type": "string", "description": "NKey public key" }, "permissions": { "$ref": "#/$defs/permissions" }, "allowed_connection_types": { "type": "array", "items": { "type": "string", "enum": ["STANDARD", "WEBSOCKET", "LEAFNODE", "MQTT"] } } } } } } }, "accounts": { "type": "object", "description": "Multi-tenancy account configuration", "additionalProperties": { "type": "object", "properties": { "users": { "type": "array", "items": { "type": "object", "properties": { "user": { "type": "string" }, "password": { "type": "string" }, "nkey": { "type": "string" }, "permissions": { "$ref": "#/$defs/permissions" } } } }, "jetstream": { "oneOf": [ { "type": "boolean" }, { "type": "object", "properties": { "max_mem": { "type": "integer", "description": "Maximum memory for this account" }, "max_store": { "type": "integer", "description": "Maximum storage for this account" }, "max_streams": { "type": "integer", "description": "Maximum number of streams" }, "max_consumers": { "type": "integer", "description": "Maximum number of consumers" }, "max_ack_pending": { "type": "integer", "description": "Maximum pending acks per consumer" }, "mem_max_stream_bytes": { "type": "integer", "description": "Maximum bytes per memory stream" }, "disk_max_stream_bytes": { "type": "integer", "description": "Maximum bytes per disk stream" }, "max_bytes_required": { "type": "boolean", "description": "Require max_bytes on stream creation" } } } ] }, "exports": { "type": "array", "description": "Services and streams exported by this account", "items": { "type": "object", "properties": { "stream": { "type": "string" }, "service": { "type": "string" }, "accounts": { "type": "array", "items": { "type": "string" } } } } }, "imports": { "type": "array", "description": "Services and streams imported from other accounts", "items": { "type": "object", "properties": { "stream": { "type": "object", "properties": { "account": { "type": "string" }, "subject": { "type": "string" } } }, "service": { "type": "object", "properties": { "account": { "type": "string" }, "subject": { "type": "string" } } } } } } } } }, "tls": { "type": "object", "description": "TLS configuration for client connections", "properties": { "cert_file": { "type": "string", "description": "Path to server certificate file" }, "key_file": { "type": "string", "description": "Path to server private key file" }, "ca_file": { "type": "string", "description": "Path to CA certificate file for client verification" }, "verify": { "type": "boolean", "description": "Require and verify client certificates", "default": false }, "verify_and_map": { "type": "boolean", "description": "Verify client certs and map to users", "default": false }, "cipher_suites": { "type": "array", "description": "Allowed TLS cipher suites", "items": { "type": "string" } }, "curve_preferences": { "type": "array", "description": "Preferred elliptic curves", "items": { "type": "string" } }, "timeout": { "type": "number", "description": "TLS handshake timeout in seconds", "default": 2 }, "pinned_certs": { "type": "array", "description": "List of pinned certificate hex-encoded SHA256 fingerprints", "items": { "type": "string" } } } }, "cluster": { "type": "object", "description": "Cluster configuration for server-to-server communication", "properties": { "name": { "type": "string", "description": "Cluster name" }, "host": { "type": "string", "description": "Cluster listen host" }, "port": { "type": "integer", "description": "Cluster listen port", "default": 6222 }, "listen": { "type": "string", "description": "Cluster listen specification" }, "routes": { "type": "array", "description": "List of route URLs to other servers", "items": { "type": "string", "format": "uri" } }, "connect_retries": { "type": "integer", "description": "Number of connect retries for implicit routes", "default": 0 }, "authorization": { "type": "object", "properties": { "user": { "type": "string" }, "password": { "type": "string" }, "timeout": { "type": "number" } } }, "tls": { "$ref": "#/properties/tls" }, "no_advertise": { "type": "boolean", "description": "Do not advertise cluster to clients", "default": false }, "pool_size": { "type": "integer", "description": "Number of routes per remote server", "default": 3 } } }, "gateway": { "type": "object", "description": "Gateway configuration for super-cluster communication", "properties": { "name": { "type": "string", "description": "Gateway cluster name" }, "host": { "type": "string", "description": "Gateway listen host" }, "port": { "type": "integer", "description": "Gateway listen port", "default": 7222 }, "listen": { "type": "string", "description": "Gateway listen specification" }, "reject_unknown_cluster": { "type": "boolean", "description": "Reject connections from unknown clusters", "default": false }, "gateways": { "type": "array", "description": "List of remote gateway configurations", "items": { "type": "object", "properties": { "name": { "type": "string", "description": "Remote gateway cluster name" }, "urls": { "type": "array", "items": { "type": "string", "format": "uri" } } }, "required": ["name"] } }, "authorization": { "type": "object", "properties": { "user": { "type": "string" }, "password": { "type": "string" }, "timeout": { "type": "number" } } }, "tls": { "$ref": "#/properties/tls" } } }, "leafnodes": { "type": "object", "description": "Leaf node configuration for extending NATS networks", "properties": { "host": { "type": "string", "description": "Leaf node listen host" }, "port": { "type": "integer", "description": "Leaf node listen port", "default": 7422 }, "listen": { "type": "string", "description": "Leaf node listen specification" }, "no_advertise": { "type": "boolean", "description": "Do not advertise leaf node connections", "default": false }, "authorization": { "type": "object", "properties": { "user": { "type": "string" }, "password": { "type": "string" }, "timeout": { "type": "number" }, "users": { "type": "array", "items": { "type": "object", "properties": { "user": { "type": "string" }, "password": { "type": "string" }, "account": { "type": "string" } } } } } }, "remotes": { "type": "array", "description": "Remote leaf node server connections", "items": { "type": "object", "properties": { "urls": { "type": "array", "items": { "type": "string", "format": "uri" } }, "account": { "type": "string", "description": "Local account for this remote connection" }, "credentials": { "type": "string", "description": "Path to credentials file" }, "tls": { "$ref": "#/properties/tls" } } } }, "tls": { "$ref": "#/properties/tls" } } }, "jetstream": { "description": "JetStream persistent messaging configuration", "oneOf": [ { "type": "boolean" }, { "type": "object", "properties": { "store_dir": { "type": "string", "description": "Directory for JetStream storage" }, "max_mem": { "type": "integer", "description": "Maximum memory for JetStream in bytes" }, "max_store": { "type": "integer", "description": "Maximum disk storage for JetStream in bytes" }, "max_file_store": { "type": "integer", "description": "Alias for max_store" }, "max_memory_store": { "type": "integer", "description": "Alias for max_mem" }, "domain": { "type": "string", "description": "JetStream domain for isolation" }, "sync_interval": { "type": "string", "description": "Interval for syncing JetStream data to disk", "default": "2m" }, "compression": { "type": "string", "description": "Compression algorithm for storage", "enum": ["none", "s2"] }, "unique_tag": { "type": "string", "description": "Unique tag for placement constraints" } } } ] }, "websocket": { "type": "object", "description": "WebSocket configuration", "properties": { "host": { "type": "string", "description": "WebSocket listen host" }, "port": { "type": "integer", "description": "WebSocket listen port" }, "listen": { "type": "string", "description": "WebSocket listen specification" }, "advertise": { "type": "string", "description": "WebSocket advertise address" }, "no_tls": { "type": "boolean", "description": "Disable TLS for WebSocket connections", "default": false }, "same_origin": { "type": "boolean", "description": "Enforce same origin policy", "default": false }, "allowed_origins": { "type": "array", "description": "List of allowed origins for CORS", "items": { "type": "string" } }, "compression": { "type": "boolean", "description": "Enable per-message compression", "default": false }, "handshake_timeout": { "type": "string", "description": "WebSocket handshake timeout" }, "tls": { "$ref": "#/properties/tls" } } }, "mqtt": { "type": "object", "description": "MQTT protocol support configuration", "properties": { "host": { "type": "string", "description": "MQTT listen host" }, "port": { "type": "integer", "description": "MQTT listen port", "default": 1883 }, "listen": { "type": "string", "description": "MQTT listen specification" }, "no_auth_user": { "type": "string", "description": "Default user for unauthenticated MQTT connections" }, "ack_wait": { "type": "string", "description": "Duration to wait for QoS1 acknowledgments", "default": "30s" }, "max_ack_pending": { "type": "integer", "description": "Maximum pending QoS1 messages", "default": 100 }, "tls": { "$ref": "#/properties/tls" } } }, "http_port": { "type": "integer", "description": "HTTP monitoring port", "default": 8222, "minimum": 1, "maximum": 65535 }, "https_port": { "type": "integer", "description": "HTTPS monitoring port", "minimum": 1, "maximum": 65535 }, "http_base_path": { "type": "string", "description": "Base path for HTTP monitoring endpoints" }, "prof_port": { "type": "integer", "description": "Profiling port for pprof", "minimum": 1, "maximum": 65535 }, "pid_file": { "type": "string", "description": "Path to PID file" }, "log_file": { "type": "string", "description": "Path to log file" }, "log_size_limit": { "type": "integer", "description": "Maximum log file size before rotation" }, "max_traced_msg_len": { "type": "integer", "description": "Maximum traced message length", "default": 0 }, "syslog": { "type": "boolean", "description": "Enable syslog output", "default": false }, "remote_syslog": { "type": "string", "description": "Remote syslog address" }, "debug": { "type": "boolean", "description": "Enable debug logging", "default": false }, "trace": { "type": "boolean", "description": "Enable trace logging", "default": false }, "logtime": { "type": "boolean", "description": "Include timestamps in log output", "default": true }, "connect_error_reports": { "type": "integer", "description": "Number of failed connections before reporting", "default": 3600 }, "reconnect_error_reports": { "type": "integer", "description": "Number of failed reconnects before reporting", "default": 1 }, "system_account": { "type": "string", "description": "Name of the system account" }, "no_sys_acc": { "type": "boolean", "description": "Disable the system account", "default": false }, "operator": { "type": "string", "description": "Path to operator JWT or inline JWT" }, "resolver": { "oneOf": [ { "type": "string" }, { "type": "object", "properties": { "type": { "type": "string", "enum": ["full", "cache", "mem"] }, "dir": { "type": "string", "description": "Directory for account JWTs" }, "limit": { "type": "integer", "description": "Cache limit for resolver" }, "ttl": { "type": "string", "description": "TTL for cached entries" }, "timeout": { "type": "string", "description": "Lookup timeout" } } } ], "description": "Account resolver configuration" } }, "$defs": { "permissions": { "type": "object", "description": "Subject-based publish/subscribe permissions", "properties": { "publish": { "oneOf": [ { "type": "object", "properties": { "allow": { "type": "array", "items": { "type": "string" } }, "deny": { "type": "array", "items": { "type": "string" } } } }, { "type": "array", "items": { "type": "string" } } ] }, "subscribe": { "oneOf": [ { "type": "object", "properties": { "allow": { "type": "array", "items": { "type": "string" } }, "deny": { "type": "array", "items": { "type": "string" } }, "max_queue_groups": { "type": "integer", "description": "Maximum queue groups allowed" } } }, { "type": "array", "items": { "type": "string" } } ] }, "allow_responses": { "oneOf": [ { "type": "boolean" }, { "type": "object", "properties": { "max": { "type": "integer" }, "ttl": { "type": "string" } } } ], "description": "Allow request-reply responses" } } } } }