Skip to content

General configuration

General fields control core runtime behavior. mode: rule is the practical daily default; global and direct are useful for temporary diagnosis. IPv6, logging, delay measurement, TCP concurrency, keep-alive, and hosts are handled by the shared Hako core on all three platforms.

Apple-platform notes

  • find-process-mode depends on process metadata supplied by the system. macOS Packet Tunnel supports process name, path, and UID; use domain, IP, port, and network-type rules on iOS and tvOS.
  • Geodata works through Hako-managed resources. iOS and tvOS prioritize memory use, and tvOS caches must be treated as rebuildable.
  • Upstream removed global-client-fingerprint; use per-outbound client-fingerprint where the protocol supports it.

36 fields shown

FieldTypeiOSmacOStvOSPlatform notes
clash-for-android.append-system-dnsboolNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
clash-for-android.ui-subtitle-patternstringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
disable-keep-aliveboolSupportedSupportedSupportedConsumed by the Hako core.
etag-supportboolSupportedSupportedSupportedConsumed by the Hako core.
external-controllerstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-controller-cors.allow-origins[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-controller-cors.allow-private-networkboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-controller-pipestringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
external-controller-routing-markintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
external-controller-tlsstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-controller-unixstringAdvancedAdvancedUnsupportedCan expose a listener or control surface. Use only with explicit access control and strong credentials. Unix-domain controller sockets are unavailable on tvOS.
external-doh-serverstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-uistringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-ui-namestringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-ui-urlstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
find-process-modeprocess.FindProcessModeUnsupportedSupportedUnsupportedRemoved or not consumed in the Apple Packet Tunnel runtime. Consumed by the Hako core.
geo-auto-updateboolManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geo-update-intervalintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
geodata-loaderstringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geodata-modeboolManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geosite-matcherstringSupportedSupportedSupportedConsumed by the Hako core.
geox-url.asnstringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geox-url.geoipstringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geox-url.geositestringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geox-url.mmdbstringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
global-client-fingerprintstringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
global-uastringSupportedSupportedSupportedConsumed by the Hako core.
hostsmap[string]anySupportedSupportedSupportedConsumed by the Hako core.
ipv6boolSupportedSupportedSupportedConsumed by the Hako core.
keep-alive-idleintSupportedSupportedSupportedConsumed by the Hako core.
keep-alive-intervalintSupportedSupportedSupportedConsumed by the Hako core.
log-levellog.LogLevelSupportedSupportedSupportedConsumed by the Hako core.
modeT.TunnelModeSupportedSupportedSupportedConsumed by the Hako core.
secretstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tcp-concurrentboolSupportedSupportedSupportedConsumed by the Hako core.
unified-delayboolSupportedSupportedSupportedConsumed by the Hako core.