Skip to content
User Guide

Settings → System → Advanced Settings

Use Advanced Settings to configure application-wide behavior. Search by the exact key shown below, edit its value, then save that row. Settings are predefined; you can change or reset them, but cannot add or remove them.

This reference covers every setting in the tab. Tables show shipped defaults, not necessarily your current values: guided setup and administrators may have changed them. Empty means no value is configured; Generated automatically means MisterShell supplies the value. Limits use the units described in each row. Secret values are masked.

Find the right settings

Change or reset a value

  1. Open Settings → System → Advanced Settings and search for the key or a prefix, such as smtp_ or sshgw_.
  2. Edit Value. Correct any validation error before saving; the accepted ranges and choices are listed below.
  3. Click the row’s green Save icon. Each row is saved independently.
  4. To restore the shipped default, click Reset to Default and confirm. Resetting a secret or identity key can affect access; read its guidance first.

For secrets, leaving the input untouched keeps the current value; entering a new value replaces it. Local MFA must be changed through Auth Providers, even though its setting appears here.

Most settings are picked up at runtime, but application caches and component update intervals can delay the effect. Follow any explicit restart or new-session requirement below. Infrastructure connection strings and other environment variables belong in your deployment configuration; see Deployment.

Deployment identity and HTTPS

Start here when making MisterShell available to users. The public address must match the URL people browse to. For installation and reverse-proxy examples, see Deployment.

SettingDefaultAllowed valuesWhat it controls
app_base_urlhttp://localhost:90001–500 charactersPublic web URL used in password-reset, verification, report, and sign-in links. Set your real HTTPS address before enabling OpenID Connect or SAML.
licensing_emailEmpty0–320 charactersEmail address used to purchase this installation’s licenses. It must match the license. Empty leaves paid licenses inactive; the Free edition remains available.
enable_x_forwarded_for_headerfalsetrue / falseUse the client address supplied by another reverse proxy in front of MisterShell. Enable only when that proxy overwrites the forwarded-address header; the built-in proxy already reports the real client address.
nginx_tls_certificate_pemEmptyPEM textWeb-server certificate in PEM format. Configure with its matching private key. Empty does not install a custom certificate; resetting does not automatically replace the currently served certificate.
nginx_tls_private_key_pemEmptyPEM textSecret. Matching PEM private key for the web certificate. Coordinate certificate changes with any load balancer that terminates HTTPS.

Certificate handling depends on the deployment topology. Follow the TLS guidance before replacing a certificate.

Email delivery

Configure and test email before relying on email verification, password recovery, email MFA, or notifications. The global switch applies to outgoing application mail. See Auth Providers for the email-MFA activation test.

SettingDefaultAllowed valuesWhat it controls
enable_email_notificationsfalsetrue / falseEnable outgoing application email. Configure the SMTP connection before turning this on.
smtp_hostlocalhost1–255 charactersSMTP server hostname.
smtp_port5871–65,535SMTP server port. MisterShell upgrades a plain SMTP connection with STARTTLS when TLS is enabled; this is not implicit TLS on connection.
smtp_usernameEmpty0–255 charactersSMTP authentication username. Leave empty only if the mail server allows sending without authentication.
smtp_passwordEmpty0–255 charactersSecret. SMTP authentication password; used together with the username.
smtp_from_emailnoreply@example.com3–255 charactersSender address shown on MisterShell emails. Use an address your mail server permits.
smtp_use_tlstruetrue / falseRequest STARTTLS encryption for the SMTP connection.
smtp_tls_verifyfalsetrue / falseValidate the mail server’s TLS certificate against system and configured CA certificates. Enable for a trusted mail endpoint; add a private CA under CA Certificates if needed.

Accounts, passwords, and sign-in

MisterShell login names are email addresses. Local password rules apply when users set or change a local password. External providers manage their own credentials. Set MFA through Users & Roles → Auth Providers, where the activation and verification steps are available.

SettingDefaultAllowed valuesWhat it controls
enable_self_registrationfalsetrue / falseAllow people to create their own local accounts. Keep off when administrators provision accounts.
require_email_verificationfalsetrue / falseRequire local accounts to verify their email before activation. Working email delivery is required.
email_verification_token_expire_hours241–168How long an email-verification link remains usable, in hours.
local_mfaNoneManage in Auth ProvidersManaged through Auth Providers. Choose None, Email, or Authenticator app there. Direct editing and resetting on Advanced Settings are refused.
password_min_length84–128Minimum local password length.
password_min_uppercase00–10Minimum uppercase letters in a local password.
password_min_lowercase00–10Minimum lowercase letters in a local password.
password_min_digit00–10Minimum digits in a local password.
password_min_special00–10Minimum special characters in a local password.
max_failed_login_attempts51–100Failed sign-in attempts allowed before the account is temporarily locked.
lockout_duration_minutes151–1,440Duration of a temporary account lockout, in minutes.
password_reset_token_expire_minutes305–1,440How long a password-reset link remains usable, in minutes.

Password complexity counts are minimums; choose a total length that can accommodate them. A value of 0 removes that character-count requirement.

External identity providers

These settings apply to LDAP, OpenID Connect, and SAML sign-ins. Configure provider connections and group-to-role mappings under Auth Providers.

SettingDefaultAllowed valuesWhat it controls
external_auth_auto_provisiontruetrue / falseCreate a MisterShell account on the first successful external sign-in. Turn off when accounts must be prepared in advance.
external_auth_sync_attributestruetrue / falseRefresh account name and email from the external provider during sign-in.
external_auth_override_rolestruetrue / falseWhen enabled, mapped external roles replace local assignments; sign-in is refused if no group maps to a role. When disabled, mapped roles are added while existing assignments are preserved.
oidc_state_timeout_minutes101–60Time allowed to complete an OpenID Connect or SAML sign-in round trip, in minutes.

Login lifetime and API protection

Login lifetime controls how long a user stays signed in. It is separate from the idle timeout of a connection to a resource. API limits protect the service from excessive request rates.

SettingDefaultAllowed valuesWhat it controls
auth_session_max_duration_minutes7200–2,147,483,647 minutesAbsolute human sign-in lifetime. 0 disables this limit. Takes effect at the next full sign-in; activity and refresh never restart it.
jwt_access_token_expire_minutes305–1,440Lifetime of a short-lived sign-in token, in minutes. Changing this affects newly issued tokens.
jwt_refresh_token_expire_days71–30Lifetime of the credential used to renew a sign-in, in days. Changing this affects newly issued credentials.
jwt_secret_keyGenerated automaticallyAt least 32 charactersSecret. Automatically generated at initial setup. Changing it invalidates existing login tokens. Do not use Reset to rotate it: Reset clears the key instead of generating a replacement. Plan any replacement as an authentication change.
jwt_algorithmHS256HS256, HS384, HS512Login-token signing algorithm. Leave at its default unless planning a coordinated authentication change; changing it invalidates tokens using the previous algorithm.
rate_limiting_enabledtruetrue / falseEnable API request-rate protection. Keep enabled for normal operation.
api_rate_limit_per_minute60010–10,000Authenticated API requests allowed per user per minute. Includes requests made by the web UI.
public_api_rate_limit_per_minute1201–1,000Unauthenticated API requests allowed per source IP address per minute. Consider shared office addresses when choosing this value.

Five minutes before the sign-in deadline, MisterShell shows a warning. After Got it, a seconds countdown appears in the top navigation, orange below two minutes and red below one minute. Finish and save your work, then sign in again and reconnect at expiry. This does not introduce an inactivity logout. Unlimited still respects ordinary token expiration and revocation.

Interactive session capacity

These limits apply when users connect to resources. Browser and native SSH shells share the same per-user/resource quota. A worker’s session limit covers all users and connection types assigned to it.

SettingDefaultAllowed valuesWhat it controls
max_shell_sessions_per_resource31–20Maximum live shells for one user on one resource, shared across shell modes and browser/native SSH clients.
worker_max_concurrent_sessions31–20Total sessions on each worker across SSH, cloud, Kubernetes, database, RDP, VNC, Web, and Files.
session_inactivity_timeout_minutes151–240Close a resource session after this many minutes without user activity.
enable_session_resumetruetrue / falsePreserve browser sessions after an accidental disconnect, within their timeout. Applies to shell, graphical, and file sessions. Reopen an existing connection pin to reattach; changing the setting is picked up when session configuration is loaded.

Graphical sessions have a fixed limit of one per user/resource. File browsing does not consume the shell quota. Reducing a capacity limit leaves existing sessions running and restricts new connections until capacity is available; sessions awaiting reconnection or still closing continue to count.

Explicitly choosing Disconnect or confirming closure of a connection pin ends that session even when resume is enabled. Native SSH connections end their sessions when disconnected.

Native SSH access

These settings govern the SSH gateway and Text UI. Users sign in with their MisterShell account email address. Expose the configured port on the host or load balancer using the same port number.

SettingDefaultAllowed valuesWhat it controls
sshgw_enabledtruetrue / falseAccept native SSH and SFTP connections.
sshgw_port22221–65,535SSH listening and client connection port. A change restarts the listener within about 30 seconds; update the host mapping and client settings together.
sshgw_max_connections2001–10,000Maximum concurrent SSH connections per Core. Each Core enforces its own limit.
sshgw_unauth_connections_per_ip51–1,000Concurrent connections still signing in from one source IP address.
sshgw_auth_attempts_per_ip_per_10min201–10,000Sign-in attempts allowed from one source IP address in ten minutes.
sshgw_max_tabs81–32Maximum open session tabs in one Text UI connection, across all resources. Applies to newly opened Text UI connections after the setting is picked up, within about 30 seconds.
sshgw_host_keyGenerated automaticallyPEM textSecret. Automatically generated server identity key. Reset rotates the key: clients must verify and accept the new fingerprint before trusting the server.
sshgw_internal_tokenGenerated automaticallyTextSecret. Automatically managed gateway credential. Leave unchanged. If reset is necessary, restart every Core to restore native SSH sign-ins.

The Text UI tab limit is separate from the shared shell-session quota. For example, an eight-tab limit does not allow eight shells on one resource when the resource quota is three.

The server fingerprint appears in Summary → SSH bookmark on supported shell resources with a Summary tab. For resources without that menu, obtain the fingerprint from your administrator through a trusted channel.

Allow personal SSH keys for native SSH automation is a per-resource option, not an Advanced Setting. Enable it in the resource’s edit form only when needed for direct connections. The user’s registered SSH key then signs in on its own, in place of their account password and verification code; resource credentials, permissions, policy, and recording still apply. The sign-in is restricted to that resource. See direct SSH connections.

Sharing sessions and transferring files

Internal session sharing follows the user’s sharing permission. External guests additionally require the Session Proxy feature and a configured proxy. See session sharing and Files.

SettingDefaultAllowed valuesWhat it controls
enable_external_session_participantsfalsetrue / falseAllow guests without MisterShell accounts to join through one-time session invitation links.
proxy_base_urlEmpty0–500 charactersPublic HTTPS address used to build guest invitation links. Guests must be able to reach this proxy.
session_invite_ttl_hours241–720Time a one-time invitation link remains redeemable, in hours. This is the invitation’s expiry, not the session duration.
files_max_upload_bytes53687091201,048,576–1,099,511,627,776Maximum size of one catalog or resource file upload. Enter bytes; the default is 5 GiB (5,368,709,120 bytes).

Resource checks and collection

Use these settings to control collection load and connection waits. Per-resource SSH timeout values override the global SSH defaults. Collection content is selected under Manage → Configuration, and recurring collection intervals are set under Scheduled Tasks.

SettingDefaultAllowed valuesWhat it controls
facts_enabledfalsetrue / falseEnable the Facts feature and collection. Fact configuration, permissions, and licensed capabilities still determine what can be collected or displayed.
data_collection_concurrency21–100Maximum number of concurrent resource collections. Higher values increase collection load; stay within worker capacity.
dns_resolution_timeout_seconds51–30Maximum wait for hostname resolution, in seconds.
ssh_conn_timeout_seconds301–300Default wait to establish an SSH network connection, in seconds.
ssh_auth_timeout_seconds301–300Default wait for SSH authentication, in seconds.
ssh_banner_timeout_seconds151–300Default wait for the SSH server’s greeting, in seconds.
onboarding_discovery_proof_ttl_seconds14400600–86,400Maximum server-side lifetime of a resource verification result, in seconds; 14,400 is four hours. The browser’s Verify → Save countdown is separately limited to 60 seconds and is not extended by this setting.

Workers and background tasks

Worker task capacity covers collection, diagnostics, and long-running session tasks. Session-specific limits apply in addition to task capacity. Increase concurrency only when the worker has enough CPU and memory; more parallel work can overload both the worker and its targets.

SettingDefaultAllowed valuesWhat it controls
worker_max_concurrent_tasks101–100Maximum concurrent worker tasks, including long-running session tasks. New work is refused when the worker reaches this total.
local_max_concurrent_tasks41–32Maximum background tasks running locally per Core API process, such as application-side automation actions. Requires a Core restart to apply.
worker_task_max_execution_time_minutes51–60Age limit for unstarted tasks whose worker is missing or offline, and unstarted cancellation requests. Running tasks use their own execution deadlines; this does not extend snapshot or session duration.
scheduler_check_interval_seconds6010–3,600Interval between checks for due scheduled tasks, in seconds. Requires a Core restart to apply. Each scheduled task also has its own configured interval.
worker_heartbeat_interval305–300Status-report interval, in seconds. Currently changes sensor and proxy cadence; worker reports remain every 30 seconds. Keep the offline-detection timeout above the effective report interval.
gateway_heartbeat_timeout6030–300Seconds without a worker, sensor, or proxy status report before it is considered stale or offline.
gateway_ack_task_timeout_seconds51–60Seconds to wait for a worker to acknowledge a dispatched task.
worker_reconnect_interval51–60Worker retry interval in seconds. Changing it currently does not change the reconnect cadence; leave at the default.
gateway_max_result_size10485761,024–20,971,520Maximum task-result size in bytes; the default is 1 MiB. Oversized results are truncated and snapshots are marked failed. This does not control file-upload size.

AI usage

Control how much AI a user may consume. Models, agents, and their permissions are configured separately under AI Settings; this setting does not enable AI by itself.

SettingDefaultAllowed valuesWhat it controls
ai_daily_token_limit_per_user00–100,000,000Daily total AI-token budget per user. 0 means unlimited. A token budget limits usage, not a fixed currency amount; cost depends on the selected model.

Notes editing

Notes use an editing reservation to prevent simultaneous changes. These limits release an abandoned editor or bound how long one editor can hold the reservation. See Notes.

SettingDefaultAllowed valuesWhat it controls
notes_edit_lock_ttl_seconds12030–600Seconds an editing reservation remains valid without renewal from the editor.
notes_edit_lock_max_seconds60060–3,600Maximum duration of one editing reservation, in seconds, even while the editor keeps renewing it. Save before it expires.

Syslog collection and intrusion detection

These settings tune licensed Collector and IDS features; changing a limit does not grant a license. Configure actual log collectors and sensors under Fabric.

SettingDefaultAllowed valuesWhat it controls
collector_ingest_rate_per_second20001–1,000,000Sustained device-log ingestion allowance, in records per second.
collector_ingest_burst6000010,000–10,000,000Extra ingestion capacity for short bursts, in records. The minimum permits a full log batch.
collector_bucket_interval305–300Seconds between collector log shipments. Shorter intervals improve freshness but increase request frequency.
sensor_ruleset_update_modemanualauto, manualmanual uses uploaded ruleset bundles; auto fetches them through the Sensor Ruleset Update scheduled task. Configure that task’s interval under Scheduled Tasks.
sensor_suricata_version8.0.5major.minor.patchSuricata version used when preparing rulesets. Match the engine version on your sensors; changing this setting does not upgrade the sensors.

Retention for device logs and IDS alerts is listed in the next section.

History and retention

All values below are days. Shorter retention reduces storage use and removes older evidence during cleanup. Increasing it cannot recover deleted data. Plan retention for your investigation and audit needs.

Retention applies independently to each kind of data. Session recordings also follow their Recording Policy; changing session history retention is not a replacement for that policy.

SettingDefaultAllowed valuesWhat it controls
data_collection_retention_days301–365Saved resource snapshots.
health_metric_retention_days901–365Per-metric health history, independent of snapshot retention.
fact_version_retention_days901–3,650Superseded fact versions. The current version is kept.
fact_policy_retention_days901–3,650Closed compliance evaluation versions.
changelog_retention_days901–3,650Closed configuration versions. The current configuration per resource is kept.
session_log_retention_days901–3,650Session history records across all connection types.
policy_log_retention_days901–3,650Session and file-transfer policy decisions.
automation_runs_retention_days901–3,650Automation run records.
ai_usage_retention_days901–3,650AI usage records.
ai_audit_retention_days71–3,650AI audit metadata and retained request/response content.
collector_retention_days71–90Searchable device syslog.
sensor_alert_retention_days301–3,650IDS alert records.
security_log_retention_days901–3,650Security audit events.
api_log_retention_days901–3,650API request logs.
app_log_retention_days141–365Persisted application and worker logs.
task_log_retention_days301–365Scheduled-task execution logs.
worker_task_retention_days301–365Completed worker-task records.
local_tasks_retention_days901–3,650Completed or failed application-side background-task records.

Database backup destination

Configure the SFTP destination, then enable and schedule Database Backup under Scheduled Tasks. These fields alone do not schedule backups. Database backups do not include every file or recording needed for a complete recovery; follow Backup and Restore.

SettingDefaultAllowed valuesWhat it controls
backup_sftp_hostEmptyTextSFTP server hostname receiving database archives.
backup_sftp_port221–65,535SFTP server port.
backup_sftp_usernameEmptyTextAccount with permission to write archives to the destination.
backup_sftp_passwordEmptyTextSecret. Password for the backup SFTP account.
backup_sftp_remote_path/backupsTextDestination directory on the SFTP server.

Use a trusted SFTP endpoint and network path: the backup connection does not verify or pin the server’s SSH host key. Test backup and restore before relying on the schedule.

Performance and monitoring

These controls trade memory, freshness, and request load. Change one value at a time and check the effect in Fabric and Diagnostics.

SettingDefaultAllowed valuesWhat it controls
core_cache_ttl_seconds6010–3,600Seconds before cached configuration and access decisions expire. Longer values reduce repeated lookups but can delay permission revocation and token-rotation enforcement on another Core.
cache_max_memory_mb25664–16,384Cache memory budget in MiB. Older cache entries are evicted when needed; this is not a limit on total application or database memory.
fabric_sample_interval_seconds52–60Seconds between Fabric statistics samples on each Core. Smaller values produce more frequent monitoring updates.

Logging and troubleshooting

Use normal logging for day-to-day operation. More verbose worker logging can increase log volume; reduce it after troubleshooting. See Diagnostics to read the logs.

SettingDefaultAllowed valuesWhat it controls
fastapi_log_levelEmptyEmpty, DEBUG, INFO, WARNING, ERROR, CRITICALCore API log level. Empty uses the deployment’s LOG_LEVEL environment setting. Requires a Core restart to apply.
worker_log_levelINFODEBUG, INFO, WARNING, ERROR, CRITICALWorker log level, applied through worker status updates.
enable_debug_modefalsetrue / falseDevelopment-only cookie mode: permits sign-in cookies over HTTP and relaxes cross-site cookie restrictions. Keep off in production. It does not increase logging verbosity; the DEBUG_MODE environment setting can also enable it.

Maps

Choose map backgrounds for dashboards, resource summaries, location editing, and search previews.

SettingDefaultAllowed valuesWhat it controls
carto_api_keyEmpty0–4,096 charactersSecret in the settings table, but supplied to signed-in browsers to load map tiles. Empty uses OpenStreetMap; a CARTO Basemaps key enables light/dark backgrounds.

Configure map backgrounds

The optional carto_api_key setting selects the map backgrounds used throughout the application: the dashboard map, location editor, resource summary, and search location previews.

SettingLight themeDark theme
Empty (default)OpenStreetMapOpenStreetMap, with a light background
CARTO Basemaps key configuredCARTO PositronCARTO Dark Matter

To enable CARTO:

  1. Request a dedicated CARTO Basemaps API key.
  2. In CARTO’s key management, restrict the key to the website domains used to access your MisterShell deployment. Use a Basemaps key rather than a general CARTO account credential.
  3. Open Settings → System → Advanced Settings and search for carto_api_key.
  4. Enter the key in the Value cell and click Save. The setting is encrypted in storage and displayed in masked form.
  5. Open a map and switch the application theme to check the light and dark backgrounds. Markers, map position, and zoom are preserved when the background changes.

The key is shared across the deployment. Authenticated users’ browsers receive it to request tiles directly from CARTO, even when those users cannot read Advanced Settings. Encryption and masking do not hide the key from browser users; the domain restrictions limit where it can be used.

To replace the key, edit and save the same row. To remove it, click the row’s Reset to Default action and confirm. Reset clears the stored key and restores OpenStreetMap. Leaving the secret input untouched keeps the existing key.

Saving or resetting refreshes maps in your current browser session without a server restart. Other sessions pick up the change when they reopen or reactivate a map after the one-minute configuration cache expires; reloading the page also fetches the current configuration.

If maps remain light, check that the key was saved, the application is in dark mode, and the browser can reach CARTO. Failed configuration loads or CARTO tile requests fall back to OpenStreetMap. If CARTO displays an API key required watermark, check the key and its domain restrictions, then reload the page to discard an older displayed map. Watermarked images may be delivered as successful requests, so they do not automatically trigger fallback.

Setup and automatically managed values

Use System → Config for guided setup and Fabric to manage components. These rows describe setup state or credentials maintained by MisterShell; they are not everyday tuning controls.

SettingDefaultAllowed valuesWhat it controls
quickstart_completedfalsetrue / falseWhether the initial setup wizard has been completed. Resetting the flag does not undo configured values.
quickstart_sizesmallsmall, medium, largeDeployment size selected in the setup wizard. Use the wizard to apply a size preset; changing this label alone does not resize the deployment.
default_worker_tokenGenerated automaticallyTextSecret. Automatically provisioned credential for the embedded worker. Leave it managed by MisterShell; do not use it to enroll remote workers.

Permissions

  • Read Advanced Settings: app.settings.read.
  • Edit or reset values: app.settings.write.
  • MFA changes use the separate Auth Providers permissions and workflow. Feature-specific license requirements still apply, including IDS operation when changing its update mode.