Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Reference: [log], [telemetry] and the rest

⟳: reloaded at runtime; no mark: taken at restart. See Hot reload.

[log]

See Logs, Audit.

KeyTypeDefaultEffect
logtable-the logs and the audit trail
log.level ⟳stringinfotrace, debug, info, warn, error or off; CRAFT_FILE_GATE_LOG_LEVEL (or RUST_LOG), if set, wins, on reload too; see Log level
log.formatstringjsonjson (one JSON line per event) or pretty (readable)
log.audit ⟳stringallvolume of the trail: all, changes or failures; refusals and errors always written
log.dirpathabsent: stdout onlydirectory of the log and audit files, rotated and compressed; CRAFT_FILE_GATE_LOG_DIR
log.stdoutbooleantruealso write to stdout; false requires dir
log.max_file_size_mbinteger100rotation before this size, in MiB; 1 to 1048576
log.retention_daysinteger7days the archives of the application log are kept; 1 to 36500
log.audit_retention_daysinteger90days the archives of the audit trail are kept; 1 to 36500
log.refusal_summary_threshold ⟳integer10identical refusals written per window before a summary line; 1 to 1000000
log.refusal_summary_window_secs ⟳integer60duration of that window; 1 to 86400
log.refusal_summary_max_addresses ⟳integer10000distinct refusals tracked at once; 1 to 1000000

[telemetry]

See Telemetry.

KeyTypeDefaultEffect
telemetrytableabsentthe OpenTelemetry (OTLP) export
telemetry.enabledbooleanfalseexport traces
telemetry.otlp_endpointURLhttp://localhost:4317the OTLP collector, an http:// or https:// URL
telemetry.service_namestringcraft-file-gatethe service.name attribute; service.version is the binary’s version
telemetry.protocolstringgrpcgrpc (OTLP/gRPC, port 4317) or http (OTLP/HTTP protobuf, port 4318)
telemetry.metricsbooleanfalsealso export metrics over OTLP, to the same collector
telemetry.metrics_interval_secsinteger60period of that export, in seconds; 1 to 3600
telemetry.on_exporter_errorstringrefusean exporter that cannot be built: refuse (startup refused) or warn (startup without that signal)

[uploads]

See Timeouts.

KeyTypeDefaultEffect
uploadstable-upload timeouts, on all doors
uploads.idle_timeout_secsinteger30upload abandoned after this time without a byte; 1 to 86400; CRAFT_FILE_GATE_UPLOAD_IDLE_TIMEOUT_SECS
uploads.min_rate_bytes_per_secinteger0: disabledminimum average rate of an upload since its start, required once the grace has passed; at most 1073741824
uploads.min_rate_grace_secsinteger60wait before requiring that rate; 1 to 86400
uploads.takeover_idle_secs ⟳integer10an upload with no byte for this time is taken over by a new upload from the same account to the same file, on this instance; acts only below idle_timeout_secs (otherwise WARN); 0: never; 0 to 86400; on reload, an out-of-bounds value keeps the one in force

[uploads.stale_partials]

See Atomic writes.

KeyTypeDefaultEffect
uploads.stale_partialstable-sweep of the leftovers of interrupted uploads
uploads.stale_partials.age_checkbooleantruemeasure age on the storage clock (a probe file in the same directory), not on the server’s
uploads.stale_partials.grace_secsinteger2 x idle_timeout_secs + max(300, idle_timeout_secs), i.e. 360 sage from which a leftover is deleted; more than 2 x idle_timeout_secs + 60, at most 2592000 (30 days)

[tcp_keepalive]

KeyTypeDefaultEffect
tcp_keepalivetable-TCP keepalive of every accepted connection
tcp_keepalive.enabledbooleantrueenable SO_KEEPALIVE
tcp_keepalive.idle_secsinteger30silence before the first probe; 1 to 32767
tcp_keepalive.interval_secsinteger10gap between two probes; 1 to 32767
tcp_keepalive.countinteger3unanswered probes before closing; 1 to 127
tcp_keepalive.user_timeout_secsinteger0: derived from idle_timeout_secsLinux: how long sent bytes can stay unacknowledged, then the connection is closed; 5 to 86400

[reload]

KeyTypeDefaultEffect
reloadtable-how a modified file is noticed
reload.watchstringautoauto: inotify, and periodic re-reading if inotify cannot be used; inotify: inotify required; poll: periodic re-reading only, no inotify instance
reload.poll_interval_secsinteger5period of the periodic re-reading, in seconds; 1 to 60

[security]

See Security.

KeyTypeDefaultEffect
securitytable-how trust files are judged
security.allow_group_writable_trust_anchorsbooleanfalsea trust file writable by the server’s group: WARN instead of a refusal; never the configuration file