OriginGate

Configuration

Every config.yml setting, its default, and example setups.

config.yml is in plugins/origingate/. Run origingate reload after editing. A file with a mistake is refused, the old settings stay active, and the reply names the setting, for example lookup.wait-millis must be a whole number from 1000 to 20000. Unknown settings are refused too, so typos are caught.

Updates keep your file. New settings are not added automatically; compare with the default config after an update.

Settings

SettingDefaultNotes
dry-runfalseLog decisions, never kick
console-logmatchesnone, kicks, matches, all, or debug. See logging
lookup.skip-private-addressestrueNo lookup for loopback, LAN, link-local, and unique local addresses
lookup.on-lookup-failureallowallow or deny
lookup.wait-millis50001000 to 20000. Longest time a login is held
lookup.country-from[proxycheck]Providers asked for the country, in order. See providers
lookup.vpn-from[proxycheck]Providers asked for the VPN check, in order: proxycheck, iphub, ip-api. [] for none; then the vpn and proxy rules must be off, and lookups are kept in memory only
lookup.proxycheck.base-urlhttps://proxycheck.io/v3/Change only for testing
lookup.proxycheck.api-keys[]Up to 32 keys, used in turn
lookup.iphub.api-keys[]Up to 32 keys, used in turn. At least one when IPHub is listed
lookup.ip-api.api-key""Pro key. Empty uses the free service (plain HTTP, no commercial use)
lookup.ipinfo.token""Needed when IPinfo is listed
lookup.*.request-timeout-millis3500500 to 20000, per request, for each web provider
lookup.maxmind.filedata/GeoLite2-Country.mmdbInside the plugin folder
lookup.maxmind.editionGeoLite2-CountryGeoLite2-Country or GeoLite2-City, for downloads
lookup.maxmind.account-id, license-key0, ""Both set: download and update the file automatically. Both empty: place the file yourself
storage.typesqlitesqlite or mysql (also MariaDB)
storage.max-age-days301 to 365. Lookups older than this are looked up again
storage.keep-days300, or max-age-days to 3650. Lookups older than this are deleted. 0 keeps them forever. Each IP keeps only its latest lookup
storage.memory-cache-size10000100 to 1,000,000 lookups kept in memory
storage.sqlite.filedata/origingate.dbInside the plugin folder
storage.mysql.*See storage
bypass.permissions[]Any of these skips every check
bypass.players[]Names (any case) or UUIDs
bypass.addresses[]IPs or CIDR ranges
rules.deny-addressesofflist of IPs or CIDR ranges, bypass-permissions
rules.vpnonbypass-permissions: [origingate.bypass.vpn]
rules.proxyonallowed-countries (codes), bypass-permissions: [origingate.bypass.proxy]
rules.countryoffmode: allowlist or denylist, countries (codes), bypass-permissions: [origingate.bypass.country]
alerts.permissions[origingate.alerts]Staff who see kick and bypass alerts
log-filetrueDaily log files of kicks, bypasses, and lookup failures
log-file-keep-days300 to 3650. Log files older than this are deleted. 0 keeps them forever

Country codes are ISO 3166-1 two-letter codes such as US, GB, ID, in any case, plus XK for Kosovo. Unknown codes are refused.

Changing storage.type takes effect on reload. Saved lookups are not copied between storage types.

Examples

Each example shows only the settings that change. Each provider block needs all of its settings, so if your config.yml is from before these settings existed, copy the iphub, ip-api, ipinfo, and maxmind blocks from the default config first.

Allow only some countries

rules:
  country:
    enabled: true
    mode: allowlist
    countries: [US, CA]
    bypass-permissions: ["origingate.bypass.country"]

Country from MaxMind, VPN check from proxycheck.io

lookup:
  country-from: [maxmind, proxycheck]
  vpn-from: [proxycheck, iphub]
  iphub:
    api-keys: ["your-iphub-key"]
  maxmind:
    account-id: 123456
    license-key: "your_license_key"

The country comes from the local file, so proxycheck.io is only asked for the VPN check. If proxycheck.io fails, IPHub is asked.

Country rules only, no web requests

lookup:
  country-from: [maxmind]
  vpn-from: []
rules:
  vpn:
    enabled: false
  proxy:
    enabled: false