Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Reference: [[backends]]

⟳: reloaded at runtime; no mark: taken at restart. See Hot reload.

[[backends]]: all types

See Backends.

KeyTypeDefaultEffect
backends ⟳array of tables-the storages; also in roles_file
backends[].name ⟳string(required)the name that mounts cite; unique
backends[].type ⟳string(required)local, sftp, s3 or webhdfs, among those built into the binary
backends[].stale_partials ⟳tablethat of [uploads.stale_partials]sweep of the leftovers of interrupted uploads on this backend
backends[].stale_partials.age_check ⟳booleanthat of [uploads.stale_partials]see uploads.stale_partials.age_check
backends[].stale_partials.grace_secs ⟳integerthat of [uploads.stale_partials]see uploads.stale_partials.grace_secs
backends[].hidden_stores ⟳tablethat of [server.hidden_stores]atomic writes of this backend, key by key; not applicable on S3 and WebHDFS
backends[].hidden_stores.enabled ⟳booleanthat of [server.hidden_stores]see server.hidden_stores.enabled
backends[].hidden_stores.prefix ⟳stringthat of [server.hidden_stores]see server.hidden_stores.prefix
backends[].hidden_stores.extension ⟳stringthat of [server.hidden_stores]see server.hidden_stores.extension
backends[].refuse_upload_over_directory ⟳booleanfalseS3: refuse an upload to a key that is also a directory; not applicable elsewhere, where an upload never replaces a directory
backends[].cross_instance_reservation ⟳booleantrue (false for local on Windows)put a lock on the storage during an upload, for the other instances; false suits a single instance
backends[].lock_prefix ⟳string.craftfilegate-upload.the start of the name of these locks; 8 to 64 bytes, without /
backends[].case_insensitive ⟳booleanprobed (local), false (elsewhere)compare ACL paths ignoring case and Unicode normalization; absent on WebHDFS

[[backends]] type = “local”

See Local.

KeyTypeDefaultEffect
backends[].root ⟳path(required)local: the root directory
backends[].follow_symlinks ⟳booleanfalselocal: follow symbolic links that stay under root + the mount’s home_dir

[[backends]] type = “sftp”

See SFTP proxy.

KeyTypeDefaultEffect
backends[].host ⟳string(required)SFTP proxy: the upstream
backends[].port ⟳integer22SFTP proxy: its port; 1 to 65535
backends[].host_key_fingerprint ⟳string(required, unless accept_any_host_key)SFTP proxy: the fingerprint of the upstream host key, SHA256:<base64> (as ssh-keygen -lf) or SHA512:<base64>
backends[].accept_any_host_key ⟳booleanfalseSFTP proxy: true without a fingerprint, any host key is accepted; for a throwaway upstream (tests, mock-ups) only
backends[].auth ⟳table(required)SFTP proxy, WebHDFS: the service account
backends[].auth.type ⟳string(required)SFTP proxy: password or private_key; WebHDFS: basic
backends[].auth.username ⟳string(required)the service account; WebHDFS: without : or control characters
backends[].auth.password ⟳string-SFTP proxy, type = "password": its password
backends[].auth.private_key_pem ⟳string-SFTP proxy, type = "private_key": its PEM private key

[[backends]] type = “s3”

See S3 and compatibles.

KeyTypeDefaultEffect
backends[].bucket ⟳string(required)S3: the bucket
backends[].region ⟳string(required)S3: the region
backends[].prefix ⟳string""S3: the start of every key
backends[].endpoint_url ⟳URLAWS S3S3: the endpoint of a compatible service (MinIO, Garage…)
backends[].credentials ⟳table(required)S3: { type = "iam_role" } or { type = "static", ... }
backends[].credentials.type ⟳string(required)S3: static (a key pair) or iam_role (the environment’s chain)
backends[].credentials.access_key_id ⟳string-S3, static: the access key
backends[].credentials.secret_access_key ⟳string-S3, static: its secret

[[backends]] type = “webhdfs”

See WebHDFS (Knox). auth, auth.type and auth.username: SFTP proxy section above.

KeyTypeDefaultEffect
backends[].url ⟳URL(required)WebHDFS: the base of the Knox gateway, https://<knox>:<port>/gateway/<topology>; the backend appends /webhdfs/v1; without credentials, query or fragment
backends[].auth.password_file ⟳path(required)WebHDFS: file holding the service account password, re-read at each reload of the file that defines the backend; a trust anchor
backends[].ca_bundle ⟳pathsystem storeWebHDFS: the PEM roots that authenticate url, alone; a trust anchor
backends[].impersonate ⟳booleantrueWebHDFS: doAs=<user> on each request; false: everything goes out under the service account
backends[].read_ahead_bytes ⟳integer4194304WebHDFS: size of a read range; 65536 to 67108864
backends[].timeout_secs ⟳integer30WebHDFS: timeout of a request in seconds, body included; at least 1