Reference: [[backends]]
⟳: reloaded at runtime; no mark: taken at restart. See Hot reload.
[[backends]]: all types
See Backends.
| Key | Type | Default | Effect |
|---|---|---|---|
backends ⟳ | array of tables | - | the storages; also in roles_file |
backends[].name ⟳ | string | (required) | the name that mounts cite; unique |
backends[].type ⟳ | string | (required) | local, sftp, s3 or webhdfs, among those built into the binary |
backends[].stale_partials ⟳ | table | that of [uploads.stale_partials] | sweep of the leftovers of interrupted uploads on this backend |
backends[].stale_partials.age_check ⟳ | boolean | that of [uploads.stale_partials] | see uploads.stale_partials.age_check |
backends[].stale_partials.grace_secs ⟳ | integer | that of [uploads.stale_partials] | see uploads.stale_partials.grace_secs |
backends[].hidden_stores ⟳ | table | that of [server.hidden_stores] | atomic writes of this backend, key by key; not applicable on S3 and WebHDFS |
backends[].hidden_stores.enabled ⟳ | boolean | that of [server.hidden_stores] | see server.hidden_stores.enabled |
backends[].hidden_stores.prefix ⟳ | string | that of [server.hidden_stores] | see server.hidden_stores.prefix |
backends[].hidden_stores.extension ⟳ | string | that of [server.hidden_stores] | see server.hidden_stores.extension |
backends[].refuse_upload_over_directory ⟳ | boolean | false | S3: refuse an upload to a key that is also a directory; not applicable elsewhere, where an upload never replaces a directory |
backends[].cross_instance_reservation ⟳ | boolean | true (false for local on Windows) | put a lock on the storage during an upload, for the other instances; false suits a single instance |
backends[].lock_prefix ⟳ | string | .craftfilegate-upload. | the start of the name of these locks; 8 to 64 bytes, without / |
backends[].case_insensitive ⟳ | boolean | probed (local), false (elsewhere) | compare ACL paths ignoring case and Unicode normalization; absent on WebHDFS |
[[backends]] type = “local”
See Local.
| Key | Type | Default | Effect |
|---|---|---|---|
backends[].root ⟳ | path | (required) | local: the root directory |
backends[].follow_symlinks ⟳ | boolean | false | local: follow symbolic links that stay under root + the mount’s home_dir |
[[backends]] type = “sftp”
See SFTP proxy.
| Key | Type | Default | Effect |
|---|---|---|---|
backends[].host ⟳ | string | (required) | SFTP proxy: the upstream |
backends[].port ⟳ | integer | 22 | SFTP proxy: its port; 1 to 65535 |
backends[].host_key_fingerprint ⟳ | string | (required, unless accept_any_host_key) | SFTP proxy: the fingerprint of the upstream host key, SHA256:<base64> (as ssh-keygen -lf) or SHA512:<base64> |
backends[].accept_any_host_key ⟳ | boolean | false | SFTP proxy: true without a fingerprint, any host key is accepted; for a throwaway upstream (tests, mock-ups) only |
backends[].auth ⟳ | table | (required) | SFTP proxy, WebHDFS: the service account |
backends[].auth.type ⟳ | string | (required) | SFTP proxy: password or private_key; WebHDFS: basic |
backends[].auth.username ⟳ | string | (required) | the service account; WebHDFS: without : or control characters |
backends[].auth.password ⟳ | string | - | SFTP proxy, type = "password": its password |
backends[].auth.private_key_pem ⟳ | string | - | SFTP proxy, type = "private_key": its PEM private key |
[[backends]] type = “s3”
See S3 and compatibles.
| Key | Type | Default | Effect |
|---|---|---|---|
backends[].bucket ⟳ | string | (required) | S3: the bucket |
backends[].region ⟳ | string | (required) | S3: the region |
backends[].prefix ⟳ | string | "" | S3: the start of every key |
backends[].endpoint_url ⟳ | URL | AWS S3 | S3: the endpoint of a compatible service (MinIO, Garage…) |
backends[].credentials ⟳ | table | (required) | S3: { type = "iam_role" } or { type = "static", ... } |
backends[].credentials.type ⟳ | string | (required) | S3: static (a key pair) or iam_role (the environment’s chain) |
backends[].credentials.access_key_id ⟳ | string | - | S3, static: the access key |
backends[].credentials.secret_access_key ⟳ | string | - | S3, static: its secret |
[[backends]] type = “webhdfs”
See WebHDFS (Knox). auth, auth.type and auth.username: SFTP proxy section above.
| Key | Type | Default | Effect |
|---|---|---|---|
backends[].url ⟳ | URL | (required) | WebHDFS: the base of the Knox gateway, https://<knox>:<port>/gateway/<topology>; the backend appends /webhdfs/v1; without credentials, query or fragment |
backends[].auth.password_file ⟳ | path | (required) | WebHDFS: file holding the service account password, re-read at each reload of the file that defines the backend; a trust anchor |
backends[].ca_bundle ⟳ | path | system store | WebHDFS: the PEM roots that authenticate url, alone; a trust anchor |
backends[].impersonate ⟳ | boolean | true | WebHDFS: doAs=<user> on each request; false: everything goes out under the service account |
backends[].read_ahead_bytes ⟳ | integer | 4194304 | WebHDFS: size of a read range; 65536 to 67108864 |
backends[].timeout_secs ⟳ | integer | 30 | WebHDFS: timeout of a request in seconds, body included; at least 1 |