Where Does Hysteria Store Its Config?
Hysteria 2 reads config.yaml for listen, TLS, auth, and masquerade. The install script pins it at /etc/hysteria on servers.
Last updated
Hysteria 2 configures through config.yaml: listen address, ACME or certificate TLS, auth password, bandwidth, obfuscation, and masquerade for camouflage. The official install script writes an example to /etc/hysteria/config.yaml and creates hysteria-server.service (plus a templated @ variant for multi-instance) around it. Edit that file and restart the service.
Manual runs default to ./config.yaml in the working directory, overridable with -c. Clients use the same filename with server, auth, and proxy keys instead. The password in either file is the whole access control, so permissions of 600 and a fresh value per server are worth the minute they take.
Where Hysteria stores this, by platform
/etc/hysteria/config.yaml
Listen, TLS/ACME, auth, bandwidth, masquerade. Written by the install script; edit then systemctl restart hysteria-server. Multi-instance units read /etc/hysteria/<name>.yaml via the @ template.
config.yaml (working dir)
Server address, auth, TLS verify, SOCKS/HTTP listeners. Place beside the executable and double-click or run hysteria -c. Keep client and server files in separate folders; the schemas differ.
Frequently asked questions
how do i migrate a hysteria server
Copy config.yaml plus certificate files to /etc/hysteria on the new host and restart hysteria-server.service. ACME setups reissue on their own; bring-your-own-cert setups need the key files copied too. Rotate the auth password after moving.
where is the hysteria client config
Same directory, same name. The client defaults to ./config.yaml beside the binary (double-click works on Windows with that layout). Server and client files share YAML format but different top-level keys, so keep them in separate folders.
Notice an outdated path? Let us know.