Skip to content

Config Reference

Auto-generated from the ShieldFileConfig model. Unknown keys are rejected at load time (extra='forbid').

Top-level keys

Key Type Default Description
mode Literal "auto" Firewall mode: auto selects the best available; hook forces OCI hook mode
default_profiles list of string [] Profiles applied when a command does not pass --profiles; an empty list applies none
dnsmasq_path Path or null — dnsmasq binary to run; found on the current host PATH when unset

audit:

Key Type Default Description
enabled boolean true Enable per-container JSON-lines audit logging

Example

config.yml
# Firewall mode: auto selects the best available; hook forces OCI hook mode
mode: auto
# Profiles applied when a command does not pass --profiles; an empty list applies none
default_profiles: []
# Audit logging settings
audit:
  # Enable per-container JSON-lines audit logging
  enabled: true

# dnsmasq binary to run; found on the current host PATH when unset
dnsmasq_path: