Run the server process with seikan-server run (systemd uses ExecStart=seikan-server run); the bare command prints help. Flags go after run (seikan-server run --admin-host …), and every flag has an SEIKAN_* env equivalent.
| Flag | Env var | Default | Description |
|---|---|---|---|
--state-dir |
SEIKAN_STATE_DIR |
/var/lib/seikan |
bbolt DB + autocert cache. |
--admin-host |
SEIKAN_ADMIN_HOST |
— | Reserved hostname for the admin API on :443. |
| — | SEIKAN_SETUP_KEY |
— | One-time key authorizing creation of the first administrator. Unset: the server generates one at first start, prints it, and keeps it in <state-dir>/setup-key. Accepted only until an administrator exists. |
--acme-email |
SEIKAN_ACME_EMAIL |
— | Let's Encrypt contact email. |
--acme-staging |
SEIKAN_ACME_STAGING |
false |
Use the LE staging directory. |
--self-signed |
SEIKAN_SELF_SIGNED |
false |
Dev: serve self-signed certs instead of ACME. |
--skip-admin-host-check |
SEIKAN_SKIP_ADMIN_HOST_CHECK |
false |
Skip the startup check that --admin-host's DNS resolves to this machine (needed behind Docker/NAT/a reverse proxy, where that's expected rather than a misconfiguration). Has no effect with --self-signed, which always skips the check. |
--verbose |
SEIKAN_VERBOSE |
false |
Start with per-request access logging on (toggle live with verbose on/off). |
--http-addr |
SEIKAN_HTTP_ADDR |
:80 |
ACME HTTP-01 + redirect listener. |
--https-addr |
SEIKAN_HTTPS_ADDR |
:443 |
Public HTTPS — frontends, admin API, and the client tunnels (ALPN seikan-tunnel). |
--tcp-range |
SEIKAN_TCP_RANGE |
10000-20000 |
Public ports assigned to TCP frontends, and the range from which a client may request a specific one. |
--metrics-addr |
SEIKAN_METRICS_ADDR |
127.0.0.1:9090 |
Metrics + pprof endpoint ("" disables). |
--perf-profile |
SEIKAN_PERF_PROFILE |
balanced |
Performance preset (see Performance). |
| — | SEIKAN_MAX_CONNS |
8192 |
Max concurrent public HTTPS connections (0 = unlimited). |
| — | SEIKAN_MAX_TUNNELS |
1024 |
Max concurrent client tunnels (0 = unlimited). |
| — | SEIKAN_MAX_FRONTENDS |
0 |
Max total frontends (0 = unlimited). |
| — | SEIKAN_APIKEY_PREFIX |
sk_ |
Prefix on generated client keys. |
| — | SEIKAN_TOKEN_PREFIX |
sk_t_ |
Prefix on generated per-frontend connect tokens. |
| — | SEIKAN_AFFINITY_COOKIE |
sk_aff |
Sticky-session affinity cookie name. |
| — | SEIKAN_KEEPALIVE |
profile | Reuse tunnel streams across HTTP requests. |
| — | SEIKAN_FLUSH_INTERVAL |
profile | ReverseProxy flush interval (-1/immediate or a duration). |
| — | SEIKAN_STREAM_WINDOW |
profile | yamux per-stream window in bytes (min 262144). |
| — | SEIKAN_COPY_BUFFER |
profile | Pipe copy buffer in bytes. |
| — | LOG_LEVEL |
info |
debug | info | warn | error. |
seikan-server install writes every setting above to /etc/seikan-server.env at its effective value (the perf knobs commented, since they default from the profile). Edit it with seikan-server configure; upgrades backfill any newly-added settings.