Every flag pion-server accepts — 70 of them, in the groups pion-server --help prints. This page is generated from the help printer in src/main.mojo at build time, so a flag is documented here exactly when the binary knows it. Defaults and profiles are explained in Configuration and profiles; the security-relevant flags (--bind, --requirepass*, --tenant) in the security model.
listen port (default 1974; binary protocol on N+1 with --kvcache)
-w, --workers N
OS-thread workers (default 1; capped at 4 on Apple Silicon). N > 1 gives each worker a PRIVATE keyspace and requires --independent-workers — see below.
--independent-workers
acknowledge that -w N > 1 runs N independent keyspaces: a connection is bound to whichever worker won accept(), so a write acked on one connection is invisible to a read on another. Safe only when every client pins one connection (or shards keys itself). Pooled clients will read stale nils.
--profile PROF
kv | vector | ai | full — KV-only / +HNSW / +AI / everything
--ns-prefix STR
multi-tenant namespace gate for KV.PREFIX. / V. (single-tenant if empty)
--requirepass STR
require AUTH <password> before serving any command (no auth if empty) NOTE: visible in ps; prefer the two below
--requirepass-file P
read the password from file P (trailing newline stripped) or set PION_REQUIREPASS in the environment
WAL segment size (default 256); rotates instead of dropping
--wal-max-segments N
sealed WAL segments to keep (default 32); 0 = never rotate
--wal-full-policy P
refuse (default) | drop — what to do with keyspace writes once the WAL is full. refuse replies -MISCONF rather than ACKing writes that cannot be persisted.
--blob-threshold N
values >= N bytes go to the file-backed blob tier (default 1048576)
--no-blob-tier
keep large values on the anonymous heap (the pre-blob-tier behaviour)