Skip to content

Reference: control

The optional control: block enables the gRPC control plane and conduitctl. Omit control: entirely when you only need DNS service and reload via SIGHUP or process restart.

The listener is created from the config present at process start. Reloading a new control: section into the snapshot does not start gRPC until you restart conduit.

FieldTypeDefaultPurpose
listen_addressstring(required when block present)gRPC bind address, e.g. 127.0.0.1:5199
reflection_enabledboolfalseRegister gRPC server reflection (dev/test)
api_keyslist of strings[]When non-empty, require Authorization: Bearer <key> on control RPCs
tlsobjectomittedWhen set, serve gRPC over TLS; see below

tls

Paths resolve relative to the config file directory (same as Rhai scripts and event sinks).

Field Purpose
cert_path Server certificate PEM
key_path Server private key PEM
client_ca_path When non-empty, require client certificates (mTLS)

Operator setup: gRPC and conduitctl, API keys, mTLS.