Configuration

Controller process settings live in /opt/templass/config.yaml. Organizations, groups, prefixes, thresholds, flow sources, whitelist, users, license and white-label live in Postgres and the GUI. Secrets live in /opt/templass/.env.

YAML

collectors:
  netflow_listen: "[::]:2055"
  sflow_listen: "[::]:6343"

http:
  listen: "127.0.0.1:9410"

bgp:
  asn: 64500
  router_id: 192.0.2.1
  peers:
    - address: 192.0.2.2
      asn: 64501
      families: [ipv4-unicast, ipv6-unicast, ipv4-flowspec, ipv6-flowspec]
  extra_communities: []

mitigation:
  host_mode: scrub
  subnet_mode: flowspec
  flowspec_action: drop

detection:
  carpet_bomb:
    min_hosts: 8
KeyRole
collectors.netflow_listenNetFlow v5/v9 and IPFIX (default UDP 2055)
collectors.sflow_listensFlow v5 (default UDP 6343)
http.listenAPI bind (dashboard is 9411 by default)
bgp.asnLocal ASN
bgp.router_idBGP router-id
bgp.peers[]address, asn, families
mitigation.host_modeDefault host mode: rtbh, flowspec, both, scrub, none
mitigation.subnet_modeDefault subnet mode, same values
mitigation.flowspec_actiondrop, rate-limit, or redirect
detection.carpet_bomb.min_hostsDistinct hosts in a /24 or /48 (default 8)

Changing bgp.asn, bgp.router_id or bgp.peers requires a restart. The GUI shows peer state.

Per-group policy (host mode, subnet mode, FlowSpec action, fallback order, customer self-mitigation) is also edited in the policy editor. Group values apply to that group's prefixes.

GUI and Postgres

AreaWhere
Organizations, groups, prefixesGUI
Thresholds (pps, bps, flow rate, per vector)GUI
Flow sourcesGUI
Never-blackhole whitelistGUI
Scrub nodes, drain, disableGUI
Users, invites, API tokensGUI
License, white-label, Public URL, SMTP, webhook allowlist, scrub restore windowSystem
Audit logGUI

RTBH defaults

Announcements use community 65535:666 and NO_EXPORT. Add extra_communities globally or per peer in YAML.