RE:NODE

Guides14 min read

Squad Server.cfg, admins and bans

Run a Squad server's staff and rules properly: the ServerConfig folder file by file, admin groups and permissions, bans, reserved slots, remote lists and rotations.

0 readers

A Squad server is configured through a folder of small text files in SquadGame/ServerConfig/, and the two that decide how your community actually runs are Server.cfg (identity, slots, team rules, rotation mode) and Admins.cfg (who can do what). Define a handful of groups in Admins.cfg with only the permissions each role needs, assign SteamID64s to them, hold reserved slots for members through the reserve permission, keep bans in Bans.cfg or a shared remote list, and pick LayerList as the rotation mode so the night plays the way you planned. Edit with the server stopped, restart, and read the log to confirm every file was loaded.

This guide is the operations half of running Squad: the staff structure, the permission list explained one flag at a time, bans and appeals, remote admin and ban lists for communities with more than one server, and the rotation files. Installing the server, ports, the licence and tick rate are covered in Squad server hosting, and mods and layer naming in depth are in Squad mods and layers.

The ServerConfig folder, file by file#

Everything in this guide lives in one directory. The exact set of files changes between major Squad versions - files get renamed, merged or retired - so treat the list below as a map and the folder on your own server as the territory.

FileWhat it holdsWho edits it
Server.cfgName, slots, queue, team rules, rotation mode, team-kill rulesOwner
Admins.cfgPermission groups and the SteamIDs in eachOwner, head admin
Bans.cfgLocal bans, appended by the ban commandsThe server, admins
RemoteAdminListHosts.cfgURLs of admin lists to pull at startOwner
RemoteBanListHosts.cfgURLs of ban lists to pull at startOwner
LayerRotation.cfgThe ordered list of layers for LayerList modeOwner, map team
LevelRotation.cfgThe list of maps for LevelList modeOwner
ExcludedLayers.cfg, ExcludedLevels.cfg, ExcludedFactions.cfgThings never to pickOwner
VoteConfig.cfgEnd-of-round voting rulesOwner
ServerMessages.cfgLines broadcast on a timerAnyone trusted
Motd.cfgMessage of the dayAnyone trusted
Rcon.cfgRCON password and portOwner only
License.cfgLicence ID and key, if licensedOwner only

Three rules apply to all of them. Comments start with //. A file the server does not recognise is ignored without complaint, so a misspelled file name is indistinguishable from an empty one. And the server reads most of these at start-up, so the reliable workflow is stop, edit, start, then check the log. Some versions can reload parts of the configuration with an admin command, but a restart is the only method that behaves the same on every build.

On a panel host the whole folder is reachable from the browser editor and over SFTP. The useful habit is to keep a copy of the folder outside the server and diff against it after every update, because a Squad update can ship a new default file that quietly sits beside yours. SFTP and the file manager covers getting the folder down to your own machine.

Server.cfg: the settings that shape a community#

The full key list is in the shipped file and in the hosting guide. What follows is the subset that decides what kind of server you are running, grouped by the decision it represents.

SquadGame/ServerConfig/Server.cfg
ServerName="Longshot Tactical | EU | Comms Required"ShouldAdvertise=trueMaxPlayers=80NumReservedSlots=6PublicQueueLimit=25MapRotationMode=LayerListRandomizeAtStart=falseUseVoteLevel=falseUseVoteLayer=falseUseVoteFactions=falseAllowTeamChanges=truePreventTeamChangeIfUnbalanced=trueNumPlayersDiffForTeamChanges=3RejoinSquadDelayAfterKick=180TKAutoKickEnabled=trueAutoTKBanNumberTKs=7AutoTKBanTime=300AllowCommunityAdminAccess=true

Slots and the queue. MaxPlayers is the total, and NumReservedSlots is carved out of it rather than added to it. An 80-slot server with six reserved slots lets 74 members of the public in; when it fills, the next public player waits in a queue of up to PublicQueueLimit, while anyone holding the reserve permission takes one of the six held places. If you have more regulars online at peak than reserved slots, members will sit in the public queue, so size NumReservedSlots against your real peak rather than your roster. The startup parameter FIXEDMAXPLAYERS is a hard ceiling above all of this: if it is lower than MaxPlayers, it wins.

Team rules. PreventTeamChangeIfUnbalanced with NumPlayersDiffForTeamChanges=3 stops stacking without banning switching. RejoinSquadDelayAfterKick is how long a squad leader's kick sticks; 180 seconds is enough to end an argument without punishing the kicked player for the rest of the round.

Team kills. TKAutoKickEnabled turns on the automatic handling, AutoTKBanNumberTKs is the number of team kills in a round before it acts, and AutoTKBanTime is the ban length in minutes. Seven is forgiving on an armour-heavy rotation where friendly fire from vehicles is common; drop it on an infantry server.

Community admin access. AllowCommunityAdminAccess lets Offworld's own community admins act on your server. It is one of the settings marked as required for licensed servers. On an unlicensed server it is your choice, and leaving it on costs nothing.

Admins.cfg: groups first, people second#

Admins.cfg has two kinds of line. A Group= line names a role and the comma-separated permissions it carries. An Admin= line puts a SteamID64 into one group. The trailing // comment is optional and worth using, because in six months nobody will remember whose ID 76561198087654321 is.

SquadGame/ServerConfig/Admins.cfg
Group=Owner:changemap,pause,cheat,private,balance,chat,kick,ban,config,cameraman,immune,manageserver,reserve,demos,teamchange,forceteamchange,canseeadminchatGroup=SeniorAdmin:changemap,balance,chat,kick,ban,cameraman,immune,reserve,teamchange,forceteamchange,canseeadminchatGroup=Admin:chat,kick,ban,cameraman,reserve,teamchange,forceteamchange,canseeadminchatGroup=Moderator:chat,kick,reserve,canseeadminchatGroup=Member:reserveAdmin=76561198012345678:Owner // Mira, server ownerAdmin=76561198087654321:SeniorAdmin // DaxAdmin=76561198011112222:Admin // TheoAdmin=76561198033334444:Moderator // Kel, trialAdmin=76561198055556666:Member // patron

The permission names, and what each one actually grants. The shipped file lists them in its header comments, and that list is the authority for your version - Offworld adds and retires flags.

PermissionWhat it allows
changemapChange the current or next layer, end the match
pausePause gameplay
cheatServer cheat commands. Nobody on a live server needs this
privatePassword-protect the server
balanceIgnore team-balance restrictions when switching
chatAdmin chat and server-wide broadcasts
kickKick players
banBan players
configChange server configuration from in game
cameramanThe admin spectator camera
immuneCannot be kicked or banned, including by vote
manageserverShut the server down and other server-state commands
reserveUse a reserved slot
demos, clientdemosRecord demos server-side or client-side
debugDebug and admin statistics output
teamchangeSwitch teams without the timer
forceteamchangeMove other players between teams
canseeadminchatSee admin chat and team-kill and admin-join notices
featuretestDeveloper test features. Leave it out

A few decisions here deserve thought rather than copy-paste:

  • `cheat`, `config` and `manageserver` belong to the owner group only. A trial moderator who can end the server or change its configuration from in game is a moderator who can take the server down by accident, or on purpose on the day they leave.
  • `immune` is a trust statement. It also means nobody else on staff can remove that person in a hurry. Give it to as few people as you can.
  • `private` changes the server. On a licensed server a password breaks the conditions of the licence. Leave it out of every group on a licensed server.
  • `canseeadminchat` is the cheapest useful permission. Even moderators without ban rights should see team-kill notices and admin chat, because that is how staff coordinate on a live round.

The structure above - owner, senior admin, admin, moderator, member - maps onto how most Squad communities run staff, and the principle behind it is the same as subusers and least privilege on the panel side: give people the smallest set of powers that lets them do their job, and widen it when they have earned it.

Getting the right SteamID

Every Admin= line wants a SteamID64, the 17-digit number starting 7656119. Not a custom profile URL, not the short Steam3 format. The reliable source is the server itself: have the person join once, then run ListPlayers over RCON or read the join line in the log. A wrong ID fails silently - the person simply has no powers - so if a new admin reports nothing works, check the digits before anything else.

Reserved slots and member whitelists#

When a community says it wants a whitelist on Squad, it nearly always means one of two different things, and the server handles them differently.

  1. Priority for members. Members skip the public queue when the server is full. This is reserve in a Member group plus NumReservedSlots in Server.cfg, exactly as shown above. No plugin, no external tool.
  2. Members only. Nobody without a listed ID may join at all. Squad has no native allow-list switch for this. A password does it crudely (and is incompatible with a licence); a tool such as SquadJS can kick non-members on join through RCON. On a licensed server this is not allowed at all, since the server must stay public.

For the first, the operational trap is size. Patrons and members accumulate, nobody prunes the list, and two years later Admins.cfg holds four hundred Member lines for people who stopped playing. It does no harm to the server, but it makes the file unreadable and the staff lines easy to miss. Keep members in a separate remote list, described below, and staff in the local file.

Bans, appeals and the ban file#

Bans issued in game or over RCON with AdminBan or AdminBanById are appended to Bans.cfg. Each line holds the banned SteamID64 and an expiry, with 0 meaning permanent, followed by a // comment that the command fills in with the reason and, on recent versions, who issued it. Look at a line the server wrote before you hand-write one, because the exact layout has shifted between versions and a malformed line is skipped.

Ban lengths on the commands accept a number with a unit; 0 is permanent. Prefer the ById forms with the numeric id from ListPlayers:

code
ListPlayersAdminBanById 17 7d Repeated teamkilling after warningsAdminKickById 23 AFK in squad leadAdminWarnById 31 Stop mic-spamming in command chat

A ban system that works for a community, as opposed to one that merely exists, has three properties:

  • The reason is specific. "Toxic" is not a reason anyone can review in three weeks. "Repeated teamkilling at main, three warnings" is.
  • There is an appeal route. A Discord channel or form, with the ban reason visible to whoever reviews it. Most bans should be temporary, and permanent ones should need a second admin.
  • There is evidence. Squad can record demos (RecordDemos and the demos permission), and SquadJS or a log parser can keep a record of kills, team kills and admin actions. Server rules, moderation and staff goes through building the rest of that process.

To lift a ban, delete its line from Bans.cfg with the server stopped, or use the unban command your version provides over RCON. Then restart and confirm the line is gone, because the server rewrites the file on shutdown.

Remote admin and ban lists for multi-server communities#

Once a community runs two servers, two copies of Admins.cfg drift apart within a month. Squad's answer is the remote list files: each line in RemoteAdminListHosts.cfg is a URL serving a plain-text file in Admins.cfg format, and each line in RemoteBanListHosts.cfg is a URL serving a ban list. The server fetches them at start-up and merges them with the local files.

SquadGame/ServerConfig/RemoteAdminListHosts.cfg
https://lists.example-community.org/squad/admins.cfghttps://lists.example-community.org/squad/members.cfg
publishesHTTPS fetchHTTPS fetchStaff tooledits the listStatic file hostadmins.cfg, bansSquad server 1pulls at startSquad server 2pulls at start
One staff list, many Squad servers

What to know before relying on it:

  • It is fetched at start-up. Adding an admin to the remote list does nothing until each server restarts, so pair it with a scheduled daily restart.
  • The URL is the security boundary. Anyone who can change the file at that address can make themselves an owner on every server you run. Host it somewhere only the owner can write to, over HTTPS, and do not use a paste site.
  • Split the lists by purpose. One file for staff, one for members. The staff file changes rarely and is reviewed carefully; the members file changes weekly and can be generated by a script from your Discord roles or patron list.
  • If the host is down, the servers start without it. Keep the owner group in the local Admins.cfg on every server so a dead list host never locks you out of your own server.

A small static site is all the list host needs to be. The same files can be generated from a bot or a database and written out on a schedule - Discord webhooks for server status shows the general shape of tying a game server to the tools your community already uses.

Rotations, votes and the messages players see#

MapRotationMode picks which rotation file is used:

ValueReadsBehaviour
LayerListLayerRotation.cfgExactly the layers you listed, in order
LayerList_RandomizedLayerRotation.cfgYour layers, shuffled
LevelListLevelRotation.cfgYou name maps, the game picks the layer
LevelList_RandomizedLevelRotation.cfgShuffled maps, game-picked layers

For a community server, LayerList with RandomizeAtStart=false is the mode that gives you control. You can alternate heavy armour layers with infantry ones, which plays better and keeps tick rate steadier across an evening, and you can put the map your regulars love at peak time. Recent versions also accept two faction tags after a layer name to fix the matchup for that entry; check the comments in your shipped LayerRotation.cfg for the exact form before using it, and see Squad mods and layers for naming rules and the silent-skip trap.

Voting is controlled by the UseVote* switches in Server.cfg and the rules in VoteConfig.cfg, which replaced the older faction-setup exclusion file. Voting is popular and has one predictable effect: a rotation slowly collapses to the three layers that win every vote. If you switch it on, use ExcludedLayers.cfg to keep the layers you never want offered out of the vote entirely.

ServerMessages.cfg holds one message per line, broadcast in order every ServerMessageInterval seconds. Keep it to three or four lines: the rules link, the Discord invite, the one rule people break most. Motd.cfg is shown on join and can be longer. Both are read at start-up.

RCON, admin tools and change control#

Rcon.cfg holds the RCON password and port. RCON is TCP and has the full powers of the console behind a password that crosses the wire in the clear, so use a long random password used nowhere else, and restrict the port by source address where you can. RCON safely is the longer version.

Most established Squad communities run SquadJS, an open-source framework that connects over RCON and tails the server log to provide Discord logging, automatic team balancing, seeding rules, admin camera logs and similar plugins. It is worth having for one reason above the rest: it gives you a durable record of what admins did, which is what makes ban appeals fair. Give it its own RCON password if your version supports more than one, and treat its configuration file as a secret.

Change control sounds bureaucratic for a game server and saves real arguments:

  1. Keep the ServerConfig folder in a private Git repository or at least in dated copies.
  2. Make one change at a time, restart, and confirm in the log that each file loaded.
  3. Note in your staff channel what changed and why.
  4. Back up the folder before every Squad update and every rotation overhaul. Backups that actually restore explains why the restore test matters more than the copy.

On a panel, the Schedules tab is where the daily restart lives, which is also what makes remote lists and new admins take effect without anyone logging in. Subusers with file access only are the right way to let a map team edit LayerRotation.cfg without handing them Rcon.cfg.

Troubleshooting#

A new admin has no powers. The SteamID64 is wrong, the group name on the Admin= line does not match a Group= line exactly, or the server has not restarted since the edit. Group names are case-sensitive.

Reserved slots do not work. The player's group lacks reserve, or NumReservedSlots is 0. Also check that the server is actually full - reserve only matters at capacity.

Bans disappear after a restart. The file was edited while the server was running and was overwritten on shutdown, or the hand-written line does not match the format the server expects.

Remote admins never load. The URL redirects, serves HTML instead of plain text, or needs authentication. Fetch it with curl from a shell and read exactly what comes back.

The rotation plays two maps on repeat. Layer names in LayerRotation.cfg no longer exist after an update and were skipped. Compare against the current layer list.

Server messages never appear. ServerMessageInterval is 0 or the file is empty, or saved with an encoding the server cannot read. Save it as plain UTF-8.

FAQ#

How do I add an admin to my Squad server?

Add a line Admin=<SteamID64>:<GroupName> to SquadGame/ServerConfig/Admins.cfg, where the group is defined by a Group= line in the same file, then restart. Get the SteamID64 from ListPlayers or the server log rather than from a profile URL.

What is the difference between a moderator and an admin group?

Nothing built in - the server only knows permissions. A moderator group is whatever set you give it; a sensible one has chat, kick, reserve and canseeadminchat but not ban, changemap or immune.

Can I make my Squad server members only?

Not with a native switch. You can give members priority with reserve and reserved slots, or use a password, or have an RCON tool kick non-members on join. A licensed server must stay public, so members-only is not an option there.

Do Admins.cfg changes need a restart?

Plan on yes. Most of the ServerConfig files are read at start-up, and the restart is the only method that behaves identically across versions. Remote lists are also fetched at start-up.

How do I share bans between two Squad servers?

Host a ban list file at an HTTPS URL only you can write to, and list that URL in RemoteBanListHosts.cfg on both servers. Each server pulls it at start-up and merges it with its local Bans.cfg.

Why can my moderator end the round?

Their group includes changemap or manageserver. Remove both from any group below senior admin, restart, and test with the moderator's account.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000