⟳: reloaded at runtime; no mark: taken at restart. See Hot reload.
See Authentication, Password hashing.
| Key | Type | Default | Effect |
auth | table | (required) | authentication and the role sources |
auth.jwt_sentinel_username | string | jwt | the SSH name that requests JWT authentication (the token as password) |
auth.timeout_secs | integer | 5 | timeout of a call to the authorization service |
auth.authz_base_url | URL | absent | service that translates authorities into role names (POST /authz/resolve); without it, only authorities that are role names count |
auth.roles_file | path | roles.toml next to it, if it exists | file of [[roles]] and [[backends]]; its content is reloaded at runtime |
auth.users_file | path | users.toml next to it, if it exists | file of [[users]]; its content is reloaded at runtime |
auth.hash_workers | integer | the CPUs seen (cgroup quota included), at most 2 | threads that verify passwords, concurrently; each holds the argon2 m of its hash; 1 to 1024; CRAFT_FILE_GATE_HASH_WORKERS |
auth.hash_queue | integer | 1024 | verifications that can wait for a thread; 1 to 65536; CRAFT_FILE_GATE_HASH_QUEUE |
auth.hash_per_address | integer | 4 | verifications in flight or queued for one address; 1 to 66560; no cap for an address in the whitelist_ips of the door’s ban list |
auth.users ⟳ | array of tables | - | [[auth.users]], like [[users]]; the root wins |
auth.roles ⟳ | array of tables | - | [[auth.roles]], like [[roles]]; the root wins |
auth.backends ⟳ | array of tables | - | [[auth.backends]], like [[backends]]; the root wins |
| Key | Type | Default | Effect |
auth.methods | table | - | the active identity sources |
auth.methods.jwt | table | - | the JWT method |
auth.methods.jwt.enabled | boolean | true | accept JWTs (SFTP under the sentinel name, REST as Bearer); requires [auth.jwt] |
auth.methods.local | table | - | the local user store |
auth.methods.local.enabled | boolean | false | enable the local store ([[users]] or users_file) |
auth.methods.local.password | boolean | true | accept a password as proof |
auth.methods.local.pubkey | boolean | true | accept an SSH public key as proof |
auth.methods.local.allow_sha512_crypt | boolean | false | also accept sha512-crypt hashes, $6$ (migration) |
auth.methods.local.allow_bcrypt | boolean | false | also accept bcrypt hashes, $2a$, $2b$, $2y$ (migration) |
auth.methods.local.users_file | path | absent | users file, like auth.users_file |
auth.methods.local.max_argon2_memory_kib | integer | absent: nothing is checked | memory budget of one verification, in KiB; a hash that exceeds it is named at load time; at least 1 |
| Key | Type | Default | Effect |
auth.jwt | table | absent: no JWT verified | JWT verification: a key source, and the claims |
auth.jwt.secret | string | absent | HMAC secret (HS256/384/512); CRAFT_FILE_GATE_JWT_SECRET or _FILE |
auth.jwt.public_key_file | path | absent | PEM public key (RS*, ES*) |
auth.jwt.jwks_url | URL | absent | JWKS endpoint of the identity provider; exclusive with secret and public_key_file |
auth.jwt.jwks_refresh_interval_secs | integer | 3600 | JWKS refresh period; at least 1 |
auth.jwt.algorithm | string | HS256 | HS256, HS384, HS512, RS256, RS384, RS512, ES256 or ES384 |
auth.jwt.username_path | string | /sub | JSON Pointer to the user name in the token |
auth.jwt.authorities_path | string | /groups | JSON Pointer to the user’s authorities (roles) |
auth.jwt.issuer | string | absent | if set, iss is required and compared |
auth.jwt.audience | string | absent | if set, aud is required and compared |
| Key | Type | Default | Effect |
users ⟳ | array of tables | - | the local users; also in users_file |
users[].username ⟳ | string | (required) | the name; unique |
users[].password_hash ⟳ | string | (required) | argon2 hash (craft-file-gate hash-password); never in clear text |
users[].authorized_keys ⟳ | list | [] | SSH public keys, one authorized_keys line each |
users[].authorities ⟳ | list | [] | the names of the user’s roles |
See Users, roles and mounts.
| Key | Type | Default | Effect |
roles ⟳ | array of tables | (required), here or in roles_file | the roles; also in roles_file |
roles[].name ⟳ | string | (required) | the role name, unique; it is what authorities cite |
roles[].user_key_algorithms ⟳ | list | [] | SSH key signature algorithms additionally allowed to the local users of this role, by name (see The SFTP door) |
roles[].mounts ⟳ | array of tables | (required) | the role’s mounts, [[roles.mounts]]; at least one |
| Key | Type | Default | Effect |
roles[].mounts[].backend ⟳ | string | (required) | the mounted backend, by the name of a [[backends]] |
roles[].mounts[].mount_path ⟳ | path | / | where the mount appears to the user: absolute, without ., .., // or a trailing / |
roles[].mounts[].home_dir ⟳ | path | / | where the mount starts on the storage; {username} there becomes the user’s name |
roles[].mounts[].create_home ⟳ | boolean | false | create home_dir at login if missing; local backend only, see Local |
roles[].mounts[].max_file_mb ⟳ | integer | absent: no cap | maximum size of an uploaded file, in MB (1,048,576 bytes); 0: no upload |
roles[].mounts[].acl ⟳ | array of tables | []: everything refused | the mount’s rights, [[roles.mounts.acl]], see ACL |
roles[].mounts[].hidden_stores ⟳ | table | the backend’s | atomic writes of this mount, key by key (see Atomic writes) |
roles[].mounts[].hidden_stores.enabled ⟳ | boolean | the backend’s | see server.hidden_stores.enabled |
roles[].mounts[].hidden_stores.prefix ⟳ | string | the backend’s | see server.hidden_stores.prefix |
roles[].mounts[].hidden_stores.extension ⟳ | string | the backend’s | see server.hidden_stores.extension |
| Key | Type | Default | Effect |
roles[].mounts[].acl[].path ⟳ | path | (required) | governed path, relative to the mount |
roles[].mounts[].acl[].rights ⟳ | list | (required) | among read, write, list, delete, rename |
roles[].mounts[].acl[].recursive ⟳ | boolean | false | true: the entry also governs everything under path |