⟳: reloaded at runtime; without the mark: taken at restart. See Hot reload .
See Admin API and console .
Key Type Default Effect
admintable absent: no HTTP door the listener of the admin API, the file API and the file explorer
admin.listenaddress (required) listen address; 0.0.0.0 in a container; CRAFT_FILE_GATE_ADMIN_LISTEN
admin.control_listenaddress absent a separate door for /admin, the console, /metrics and the probes (except with server.probes_listen); CRAFT_FILE_GATE_ADMIN_CONTROL_LISTEN
admin.bearer_tokenstring absent token with every permission; it or a role from [[admin.roles]] is required; CRAFT_FILE_GATE_ADMIN_BEARER_TOKEN, _FILE
admin.allow_static_tokenboolean truefalse: no static token, from any source
admin.header_read_timeout_secsinteger 10seconds to send the headers of a request; 1 to 300; CRAFT_FILE_GATE_ADMIN_HEADER_READ_TIMEOUT_SECS
admin.long_request_threshold_secs ⟳ integer 30seconds after which a running REST transfer appears in the console sessions; 0: all
See Admin API and console .
Key Type Default Effect
admin.rolesarray of tables []the named admin roles
admin.roles[].namestring (required) the name an authority carries (local account or JWT); unique, distinct from the [[roles]] names
admin.roles[].permissionslist (required, not empty) among overview, sessions, kick, bans, unban, config, logs, audit, revoke
See Console sessions .
Key Type Default Effect
admin.sessiontable per-process key, 1 h, 12 h, revocations in memory the admin console session tokens, signed by the server, and their revocations
admin.session.key_filepath absent the signing key, 32 bytes at least (head -c 32 /dev/urandom), readable by the server only, the same on every instance; without it or secret_name, a key drawn for the process
admin.session.secret_namestring absent the Kubernetes Secret whose admin-session.key entry holds the key; the chart creates it empty, the first pod writes it, the others read it (feature k8s); CRAFT_FILE_GATE_ADMIN_SESSION_SECRET_NAME; not with key_file
admin.session.ttl_secsinteger 3600life of a token; 60 to 86400
admin.session.max_age_secsinteger 43200no renewal beyond this, counted from sign-in; 60 to 604800, at least ttl_secs
admin.session.persist_filepath absent the file where revocations are shared, for them alone, distinct from the ban files; neither it nor backend: in memory, one instance, lost at restart
admin.session.backendstring file with persist_file, memory otherwisefile (with persist_file) or configmap (feature k8s), a ConfigMap like the bans; CRAFT_FILE_GATE_ADMIN_SESSION_BACKEND
admin.session.revocation_configmap_namestring craft-file-gate-accessthe revocations ConfigMap, key revocations, with backend = "configmap"; the same as temporary accesses; CRAFT_FILE_GATE_ADMIN_SESSION_REVOCATION_CONFIGMAP_NAME
admin.session.reread_interval_secsinteger 5re-read of the shared revocations, in seconds; 1 to 30
Temporary accesses: a file role given to a user until a date, through POST /admin/grants (permission grant).
Key Type Default Effect
admin.grantstable in memory, 7 days at most where temporary accesses are shared, and the longest one
admin.grants.persist_filepath absent the file where accesses are shared, for them alone (no bans, no revocations); neither it nor backend: in memory, one instance, refused with [cluster]
admin.grants.backendstring file with persist_file, memory otherwisefile or configmap (feature k8s); CRAFT_FILE_GATE_ADMIN_GRANTS_BACKEND
admin.grants.grant_configmap_namestring craft-file-gate-accessthe ConfigMap, key grants, next to the revocations; CRAFT_FILE_GATE_ADMIN_GRANTS_GRANT_CONFIGMAP_NAME
admin.grants.reread_interval_secsinteger 5re-read of the shared accesses, in seconds; 1 to 30
admin.grants.max_duration_secsinteger 604800maximum duration of an access; 60 to 2592000
Key Type Default Effect
admin.tlstable absent: HTTP HTTPS on the whole listener
admin.tls.cert_filepath absent PEM certificate, re-read when the file changes; CRAFT_FILE_GATE_ADMIN_TLS_CERT
admin.tls.key_filepath absent PEM private key; CRAFT_FILE_GATE_ADMIN_TLS_KEY
admin.tls.auto_generateboolean falsegenerate a self-signed certificate (trials)
admin.tls.auto_generate_cnstring localhostits Common Name
admin.tls.auto_generate_dirpath .where to write it
admin.tls.auto_generate_validity_daysinteger 31its validity in days
Same keys as [sftp.ban]. See Bans and rate limits .
Key Type Default Effect
admin.bantable absent: no ban ban of addresses after authentication failures on the admin API; the file API has its own list, [api.ban]
admin.ban.max_failuresinteger 5failures in the window before the ban; at least 1
admin.ban.ban_duration_secsinteger 600duration of a ban in seconds, from the verdict
admin.ban.window_secsinteger 300failure counting window in seconds, fixed, opened by the first failure of a series
admin.ban.whitelist_ipslist []addresses and CIDR networks, IPv4 or IPv6, never banned by this instance
admin.ban.trusted_proxieslist []proxies whose X-Forwarded-For gives the client address; without control_listen, equal to api.ban.trusted_proxies
admin.ban.persist_filepath absent: in memory file where bans are kept and shared between instances
admin.ban.backendstring "file""file", or "configmap" to share bans between Kubernetes pods
admin.ban.ban_configmap_namestring craft-file-gate-bansthe bans ConfigMap, with backend = "configmap"
admin.ban.reread_interval_secsinteger 5re-read of the shared persist_file in seconds, on top of watching; 1 to 30
See Metrics .
Key Type Default Effect
admin.metrics_thresholdstable - alert thresholds of the console’s Metrics tab
admin.metrics_thresholds.hash_pool_percentinteger 80slots taken in the hashing pool, in %
admin.metrics_thresholds.tls_cert_daysinteger 14days left on the admin TLS certificate, below
admin.metrics_thresholds.rejections_per_minuteinteger 60SFTP refusals per minute
admin.metrics_thresholds.jwt_refusals_per_minuteinteger 60JWTs refused per minute
admin.metrics_thresholds.jwks_age_secsinteger 2 x jwks_refresh_interval_secs age of the JWKS cache
admin.metrics_thresholds.clock_skew_secsinteger 30clock skew of a storage
admin.metrics_thresholds.cpu_percentinteger 90CPU of the process, 100 = one core
See Doors .
Key Type Default Effect
apitable absent: no API the REST file API, on admin.listen
api.enabledboolean falseserve the API, on the [admin] listener; requires [admin]
api.prefixstring /api/v1/filespath under which the API is served
api.cors_originslist absent: no CORS origins allowed for CORS; "*": all (see Bans )
api.openapiboolean falseserve the Swagger UI (/api/docs) and the OpenAPI document (/api/openapi.json), without authentication; requires api.enabled
Same keys as [sftp.ban]. See Bans and rate limits .
Key Type Default Effect
api.bantable absent: no ban ban of addresses after authentication failures on the file API, its tickets and the file explorer
api.ban.max_failuresinteger 5failures in the window before the ban; at least 1
api.ban.ban_duration_secsinteger 600duration of a ban in seconds, from the verdict
api.ban.window_secsinteger 300failure counting window in seconds, fixed, opened by the first failure of a series
api.ban.whitelist_ipslist []addresses and CIDR networks, IPv4 or IPv6, never banned by this instance, nor capped in the hashing queue
api.ban.trusted_proxieslist []proxies whose X-Forwarded-For gives the client address (ban, limiter, audit); without admin.control_listen, equal to admin.ban.trusted_proxies
api.ban.persist_filepath absent: in memory file where bans are kept and shared between instances
api.ban.backendstring "file""file", or "configmap" to share bans between Kubernetes pods
api.ban.ban_configmap_namestring craft-file-gate-bansthe bans ConfigMap, with backend = "configmap"
api.ban.reread_interval_secsinteger 5re-read of the shared persist_file in seconds, on top of watching; 1 to 30
See Bans and rate limits .
Key Type Default Effect
api.rate_limittable absent: no limit token bucket per address for the API
api.rate_limit.requests_per_minuteinteger (required) sustained request rate per address; at least 1
api.rate_limit.burstinteger requests_per_minuterequests accepted in a row; at least 1
See File explorer .
Key Type Default Effect
api.uitable - the web file explorer
api.ui.enabledboolean falseserve the file explorer; requires [api]
api.ui.pathstring /fileswhere the page is served, on the API listener (admin.listen, even with control_listen); starts with /, no trailing /; neither on api.prefix, nor on a server route (/admin, /ui, /metrics, /health, /livez, /readyz, /api/docs, /api/openapi.json)