Skip to content

Controller flags

The Controller is the shardkeep binary in the controller image. In the Compose install, flags go in the command of the controller service in compose.yml.

Flag Default Meaning
-listen :8080 HTTPS address for the web UI and API
-agent-listen :8443 Address for Agent sessions (mutual TLS)
-enroll-listen :8444 Address where Agents enroll (TLS)
-database-url $SHARDKEEP_DATABASE_URL PostgreSQL connection URL. The environment variable keeps the password out of the command line
-data-dir /var/lib/shardkeep Controller state: the CA, the generated TLS certificate, the software cache, the setup code
-public-name An extra DNS name or IP address the Controller is reached by, for its certificates. Repeatable
-tls-cert, -tls-key Your own certificate and key (PEM) for the web UI and API, instead of a self-signed one. See Your own certificate
-game-port-range 25565-25664 Host ports servers’ game ports are assigned from
-heartbeat-timeout 30s How long without a heartbeat before a Node is marked unreachable
-local-node Create a Node with this name for an Agent bundled with the Controller, and give it enrollment tokens through -local-node-token-file until it enrolls
-local-node-token-file The file only the bundled Agent shares (never inside -data-dir)
-agent-image the release’s Agent image The Agent image the web UI shows when adding Nodes
-offline off No outbound connections: no catalog sync, no downloads. See Offline installs
-catalog-url https://catalog.shardkeep.gg/v1/ Where to sync the catalog from (a mirror works too)
-catalog-trust-key An extra trusted catalog key, ed25519:<base64>, for a private catalog. Repeatable
-version Print the version and exit

shardkeep admin … runs administration commands instead of the server.