Template: jray-server/server-id Type: string Default: localhost Description: Public hostname of this JRay server: Identifies this instance in federation (SPEC section 9a) and is recorded on every manifest it originates, so peers can tell whose judgement they are replicating. . Use the name operators will reach you on, for example jray.example.org. Leaving it as "localhost" is fine for a private trial and wrong for anything federated. Template: jray-server/bind Type: string Default: 127.0.0.1:8080 Description: Address and port to listen on: The server speaks plain HTTP and expects TLS to be terminated by your reverse proxy (SPEC section 8). . Keep the default if the proxy runs on this same host. If the proxy is elsewhere - a separate container or VM, which is the common case - this must be an address that host can reach, for example 0.0.0.0:8080. Firewall the port to the proxy if you do that: the default is loopback precisely so an unconfigured install is not reachable. Template: jray-server/trusted-proxies Type: string Description: Trusted reverse proxy addresses (comma-separated): Rate limiting and abuse-report attribution both key on the client IP, so X-Forwarded-For is honoured only from addresses listed here. A header trusted unconditionally would let any client mint itself a fresh rate-limit budget and pin its reports on someone else. . If the proxy runs on this host, enter 127.0.0.1. If it runs elsewhere, enter the address it connects from - not the address you reach it on. . Leaving this empty is safe but coarse: X-Forwarded-For is then ignored entirely and every request is attributed to the proxy, so all clients share one rate-limit bucket. Template: jray-server/tmdb-api-key Type: password Description: TMDB API key: Uploaded manifests are cross-checked against the TMDB cast list before being published (SPEC section 6, stage 3). Without a key the server still serves reads normally, but every upload stays in "pending" and is never listed - the correct failure mode, but a silent one. . Leave blank to configure later with: dpkg-reconfigure jray-server If a key is already configured, leaving this blank keeps it. Template: jray-server/contact Type: string Description: Operator contact (optional): Published so other operators can arrange peering out of band. An email address or a URL. Leave blank to publish no contact. Template: jray-server/publish-peer-directory Type: boolean Default: false Description: Publish this server's peer directory? Section 9a makes this deliberately optional: publishing lists the peers you replicate from, which discloses your federation topology. A server that would rather not disclose it simply does not, and federation still works.