Configuration
Controller process settings live in /opt/templass/config.yaml. Organizations, groups, prefixes, thresholds, flow sources, whitelist, users, license and white-label live in Postgres and the GUI. Secrets live in /opt/templass/.env.
YAML
collectors:
netflow_listen: "[::]:2055"
sflow_listen: "[::]:6343"
http:
listen: "127.0.0.1:9410"
bgp:
asn: 64500
router_id: 192.0.2.1
peers:
- address: 192.0.2.2
asn: 64501
families: [ipv4-unicast, ipv6-unicast, ipv4-flowspec, ipv6-flowspec]
extra_communities: []
mitigation:
host_mode: scrub
subnet_mode: flowspec
flowspec_action: drop
detection:
carpet_bomb:
min_hosts: 8
| Key | Role |
|---|---|
collectors.netflow_listen | NetFlow v5/v9 and IPFIX (default UDP 2055) |
collectors.sflow_listen | sFlow v5 (default UDP 6343) |
http.listen | API bind (dashboard is 9411 by default) |
bgp.asn | Local ASN |
bgp.router_id | BGP router-id |
bgp.peers[] | address, asn, families |
mitigation.host_mode | Default host mode: rtbh, flowspec, both, scrub, none |
mitigation.subnet_mode | Default subnet mode, same values |
mitigation.flowspec_action | drop, rate-limit, or redirect |
detection.carpet_bomb.min_hosts | Distinct hosts in a /24 or /48 (default 8) |
Changing bgp.asn, bgp.router_id or bgp.peers requires a restart. The GUI shows peer state.
Per-group policy (host mode, subnet mode, FlowSpec action, fallback order, customer self-mitigation) is also edited in the policy editor. Group values apply to that group's prefixes.
GUI and Postgres
| Area | Where |
|---|---|
| Organizations, groups, prefixes | GUI |
| Thresholds (pps, bps, flow rate, per vector) | GUI |
| Flow sources | GUI |
| Never-blackhole whitelist | GUI |
| Scrub nodes, drain, disable | GUI |
| Users, invites, API tokens | GUI |
| License, white-label, Public URL, SMTP, webhook allowlist, scrub restore window | System |
| Audit log | GUI |
RTBH defaults
Announcements use community 65535:666 and NO_EXPORT. Add extra_communities globally or per peer in YAML.