listeners:-name:hy-intype:hysteria2port:8443listen:0.0.0.0# routing-mark: 0 # Sets the routing-mark for the listening socket (Linux only)users:user1:password1user2:password2up:1000down:1000ignore-client-bandwidth:falseobfs:salamanderobfs-password:passwordmasquerade:""# bbr-profile: "" # Available: "standard", "conservative", "aggressive". Default: "standard"# realm-opts:# enable: true # Must be enabled manually# server-url: https://realm.hy2.io# token: public# realm-id: my-cabin-1f3a8c2e9b# stun-servers:# - stun.nextcloud.com:3478# - stun.sip.us:3478# - global.stun.twilio.com:3478# # proxy: DIRECT # Proxy used to connect to server-url# # TLS options for server-url can be configured below: sni, skip-cert-verify, name-cert-verify, fingerprint, certificate, private-key, alpn# # skip-cert-verify: false# # name-cert-verify: example.com# # ......alpn:-h3certificate:./server.crt# Certificate in PEM format or path to the certificateprivate-key:./server.key# Corresponding private key in PEM format or path to the private key# The following two options configure mTLS. client-auth-cert must be non-empty when client-auth-type is "verify-if-given" or "require-and-verify"# client-auth-type: "" # Available values: "", "request", "require-any", "verify-if-given", "require-and-verify"# client-auth-cert: string # Certificate in PEM format or path to the certificate# When filled, enables ECH. Generate it with mihomo generate ech-keypair <plaintext-domain># ech-key: |# -----BEGIN ECH KEYS-----# ACATwY30o/RKgD6hgeQxwrSiApLaCgU+HKh7B6SUrAHaDwBD/g0APwAAIAAgHjzK# madSJjYQIf9o1N5GXjkW4DEEeb17qMxHdwMdNnwADAABAAEAAQACAAEAAwAIdGVz# dC5jb20AAA==# -----END ECH KEYS-----# mux-option:# padding: true# brutal:# enabled: true# up: 1000 # Mbps by default# down: 1000