Configuration
Config options and convars for Nexra Overwatch.
Configuration
config.lua controls the local resource options. The browser panel is configured with convars in server.cfg.
Resource config
| Option | Default | Description |
|---|---|---|
Config.Debug | false | Extra debug logging |
Config.Locale | 'en' | Locale file from locales/ |
Config.Framework | 'auto' | auto, none, qbx_core, qb-core, es_extended, or custom |
Set Config.Framework = 'none' if you want Overwatch to run without framework bridging. Player session names still show, but framework character names may be unavailable.
Panel access
| Convar | Default | Description |
|---|---|---|
overwatch_enabled | "true" | Set to "false" to disable the panel HTTP server |
overwatch_bind_host | "0.0.0.0" | Address the panel server binds to |
overwatch_port | "3848" | Browser panel TCP port |
overwatch_trust_proxy | "false" | Trust X-Forwarded-For when behind a reverse proxy |
overwatch_allowed_ips | "" | Comma-separated IP allowlist for the browser panel |
overwatch_token_ttl_ms | "28800000" | Login session lifetime in milliseconds |
Use overwatch_allowed_ips to restrict which IP addresses can open the panel.
set overwatch_allowed_ips ""An empty value means IP allowlisting is disabled. Anyone who can reach the panel port can see the login page, but they still need valid panel credentials.
To allow only specific IPs, list them with commas:
set overwatch_allowed_ips "XXX.XXX.XXX.10,XXX.XXX.XXX.25"Do not add spaces between IPs. Localhost (127.0.0.1) is always allowed.
Login and staff users
| Convar | Default | Description |
|---|---|---|
overwatch_user | "admin" | Built-in config username |
overwatch_pass | "change-me" | Built-in config password |
overwatch_admin_username | "admin" | Username allowed to manage panel users and watch logs |
overwatch_admin_local_only | "true" | Restrict the admin username to localhost |
overwatch_rate_limit_max_attempts | "3" | Failed login attempts before the IP is blocked |
Staff users created in the panel are saved to data/users.json with hashed passwords. The built-in convar user is not written to that file.
Streaming
| Convar | Default | Description |
|---|---|---|
overwatch_max_streams | "16" | Global cap and max per-user cap. Hard-limited to 16 |
overwatch_max_viewers_per_target | "3" | Max staff viewers watching the same player |
overwatch_signal_poll_ms | "300" | Browser polling interval for WebRTC signaling |
overwatch_default_quality | "medium" | Default quality preset: low, medium, high, or ultra |
overwatch_default_voice_range | "18.0" | Default voice range used for telemetry |
Each staff user also has a per-account max stream count, clamped to overwatch_max_streams.
Watch logging
| Convar | Default | Description |
|---|---|---|
overwatch_watch_logging | "false" | Enable start / stop watch activity logging |
overwatch_watch_log_file | "watch_log.txt" | Log filename inside data/ |
When enabled, the admin account can view the watch activity of other approved staff members.
Reverse proxy
When using Nginx, Cloudflare Tunnel, or another reverse proxy:
setr overwatch_bind_host "0.0.0.0"
setr overwatch_port "3848"
setr overwatch_trust_proxy "true"Make sure your proxy forwards WebRTC/API traffic to the same panel origin. If you use overwatch_allowed_ips, include the real staff IPs or the proxy IPs depending on your proxy setup.
