Config Reference¶
Auto-generated from the ShieldFileConfig model. Unknown keys are rejected at load time (extra='forbid').
Top-level keys¶
| Key | Type | Default | Description |
|---|---|---|---|
mode |
Literal | "auto" |
Firewall mode: auto selects the best available; hook forces OCI hook mode |
default_profiles |
list of string | [] |
Profiles applied when a command does not pass --profiles; an empty list applies none |
dnsmasq_path |
Path or null | — | dnsmasq binary to run; found on the current host PATH when unset |
audit:¶
| Key | Type | Default | Description |
|---|---|---|---|
enabled |
boolean | true |
Enable per-container JSON-lines audit logging |
Example¶
config.yml
# Firewall mode: auto selects the best available; hook forces OCI hook mode
mode: auto
# Profiles applied when a command does not pass --profiles; an empty list applies none
default_profiles: []
# Audit logging settings
audit:
# Enable per-container JSON-lines audit logging
enabled: true
# dnsmasq binary to run; found on the current host PATH when unset
dnsmasq_path: