Configuration
Access
Every field in access.yaml: bind address, password, and remote access.
access.yaml sets the address Kraft binds to and the password that protects it.
bind: 127.0.0.1
port: 8765
password_hash: null
session_expiry_days: 7
allowed_hosts: []
| Field | Default | Means |
|---|---|---|
bind | 127.0.0.1 | The address kraft admin start binds. --host overrides KRAFT_HOST, which overrides this file. A non-loopback value is refused unless password_hash is set. |
port | 8765 | The port kraft admin start binds. --port overrides KRAFT_PORT, which overrides this file. |
password_hash | null | The login password's hash, written by Settings → Access. Required for any non-loopback bind. |
session_expiry_days | 7 | How long a browser session cookie stays valid after logging in. |
allowed_hosts | [] | Host header allowlist checked on a non-loopback bind — a password alone does not authorize an arbitrary hostname. See Remote access. |