sing-box — Config Layout
sing-box reads a single JSON document at startup. The root object maps to Go struct _Options at option/options.go:14 (exported as Options via a type alias whose UnmarshalJSONContext enforces strict unknown-field checking — typos in your config produce a startup error, not silent ignoring).
Root keys
| Key | Go field | Type | Page | Description |
|---|---|---|---|---|
$schema | Schema | string | (none) | JSON Schema URI for editor completion / validation; no runtime effect. sing-box schema generates one matching the current build. |
log | Log | *LogOptions | Log | Severity, output, timestamp, disable toggle. |
dns | DNS | *DNSOptions | DNS | DNS servers, rules, hosts, fakeip. |
ntp | NTP | *NTPOptions | NTP | Optional embedded NTP client. |
certificate | Certificate | *CertificateOptions | Certificate | Root-CA bundle source for TLS verification. |
certificate_providers | CertificateProviders | []CertificateProvider | TLS | Reusable certificate providers (acme, tailscale, cloudflare-origin-ca), referenced by tag from inbound TLS certificate_provider. |
http_clients | HTTPClients | []HTTPClient | (none) | Reusable HTTP clients (engine, version, dialer, TLS, HTTP/2 / QUIC parameters) for remote rule-sets, certificate providers and DERP verify_client_url. |
network_namespaces | NetworkNamespaces | []NetworkNamespace | TUN | Linux network namespaces (default, unshare), referenced by tag from the TUN, listen and dial netns fields. |
endpoints | Endpoints | []Endpoint | Endpoints | Endpoint inbound/outbound (WireGuard, Tailscale, OpenVPN client / server, OpenConnect). |
inbounds | Inbounds | []Inbound | Inbounds | List of listening services. |
outbounds | Outbounds | []Outbound | Outbounds | List of upstream targets. |
route | Route | *RouteOptions | Route | Routing rules, rule-set, default outbound. |
services | Services | []Service | Services | Background services (resolved, derp, ssm-api, api, hysteria-realm, usbip-server / usbip-client). |
experimental | Experimental | *ExperimentalOptions | Experimental | Cache file, Clash API, V2Ray API, pprof debug. |
Each DNS server declares a type; the untyped "address": "tls://…" format is not supported (see DNS).
At a glance
json
{
"log": { "level": "info", "timestamp": true },
"dns": { "servers": [{ "type": "tls", "tag": "google", "server": "8.8.8.8" }] },
"ntp": { "enabled": true, "server": "time.cloudflare.com" },
"certificate": { "store": "system" },
"inbounds": [],
"outbounds": [],
"route": { "final": "direct" },
"experimental": {
"cache_file": { "enabled": true },
"clash_api": { "external_controller": "127.0.0.1:9090" }
}
}Source: option/options.go:14-31 · v1.14.2 (af6e64c)
