Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Shutdown

[server]
shutdown_grace_period_secs = 30   # wait for work in progress, all doors
docker stop -t 90 craft-file-gate                  # Docker
# Kubernetes: terminationGracePeriodSeconds: 90

The steps

SIGTERM or SIGINT (Ctrl-C) trigger the shutdown, even when the server is PID 1.

StepWhat happensBound
1the SFTP door stops accepting; /readyz answers 503; no password check is admitted any more-
2the ban lists ([sftp.ban], [api.ban], [admin.ban]) are written to their persist_file5 s per list
3server shutting down sent to every SFTP session; the admin/API door stops accepting and closes its streams-
4sessions without a transfer in progress are cut-
5wait for transfers in progress, if any; ends with the last oneshutdown_grace_period_secs
6any session still there is cut-
7wait for the cut sessions to end (spans, last audit lines)rest of the delay
8wait for REST and admin requests in progressrest of the delay
9S3 multipart uploads still open are aborted5 s
10quota cleanups and upload lock removals5 s
11last OTLP export (metrics, spans)5 s
12graceful shutdown complete, exit 0-

Steps 5, 7 and 8 share a single delay, counted from the announcement. Without a transfer in progress, the shutdown does not wait for it.

Tuning the orchestrator

The worst case of a shutdown:

ComponentDefault
shutdown_grace_period_secs30 s
ban writes5 s per list ([sftp.ban], [api.ban], [admin.ban])
backend work5 s
cleanups and locks5 s
OTLP export5 s
total50 s with one ban list, 60 s with all three

The orchestrator’s shutdown delay must exceed it: docker stop -t 90, terminationGracePeriodSeconds: 90, which the chart sets (grace period plus 60 s). A SIGKILL before the end cuts transfers without an audit line, leaves S3 multipart uploads open and loses unexported spans.

What you will see

Each step writes its INFO line: shutdown signal received, ban files written out before the shutdown sequence, idle sessions disconnected (idle_kicked), waiting for active transfers to complete (only if there are any), remaining sessions disconnected (force_kicked, 0 included), graceful shutdown complete. Cut sessions end with session_end reason=shutdown_idle (step 4) or shutdown (step 6).