FloodgateSurface/docs/configuration
DocumentationConfiguration

Configuration

Exactly one variable is required to boot: FLOODGATE_JWT_SECRET. Everything else has a working default, shown in [brackets] below. [(required)] means there is none; [(unset)] means the feature stays off until you set it. Each variable name is a link you can share.

boot

network

admin sign-in (github oauth)

admin surface

token mint

storage

limits

FLOODGATE_ALLOWED_ORIGINS applies to both socket endpoints. Non-browser clients (including the official Fluid drivers) send no Origin and are admitted under the default same-origin policy; the allow-list is only needed for browser clients served from another origin.

Set any limit to 0 to disable it. Defaults are deliberately generous: the conformance suites open several concurrent sockets from one address and burst ops during sync tests. The per-IP limit uses the real socket peer address and deliberately ignores X-Forwarded-For, which a client can set freely; behind a proxy every connection shares the proxy's address, so enforce per-client limits there instead.