⟳: reloaded at runtime; no mark: taken at restart. See Hot reload .
See Logs , Audit .
Key Type Default Effect
logtable - the logs and the audit trail
log.level ⟳ string infotrace, debug, info, warn, error or off; CRAFT_FILE_GATE_LOG_LEVEL (or RUST_LOG), if set, wins, on reload too; see Log level
log.formatstring jsonjson (one JSON line per event) or pretty (readable)
log.audit ⟳ string allvolume of the trail: all, changes or failures; refusals and errors always written
log.dirpath absent: stdout only directory of the log and audit files, rotated and compressed; CRAFT_FILE_GATE_LOG_DIR
log.stdoutboolean truealso write to stdout; false requires dir
log.max_file_size_mbinteger 100rotation before this size, in MiB; 1 to 1048576
log.retention_daysinteger 7days the archives of the application log are kept; 1 to 36500
log.audit_retention_daysinteger 90days the archives of the audit trail are kept; 1 to 36500
log.refusal_summary_threshold ⟳ integer 10identical refusals written per window before a summary line; 1 to 1000000
log.refusal_summary_window_secs ⟳ integer 60duration of that window; 1 to 86400
log.refusal_summary_max_addresses ⟳ integer 10000distinct refusals tracked at once; 1 to 1000000
See Telemetry .
Key Type Default Effect
telemetrytable absent the OpenTelemetry (OTLP) export
telemetry.enabledboolean falseexport traces
telemetry.otlp_endpointURL http://localhost:4317the OTLP collector, an http:// or https:// URL
telemetry.service_namestring craft-file-gatethe service.name attribute; service.version is the binary’s version
telemetry.protocolstring grpcgrpc (OTLP/gRPC, port 4317) or http (OTLP/HTTP protobuf, port 4318)
telemetry.metricsboolean falsealso export metrics over OTLP, to the same collector
telemetry.metrics_interval_secsinteger 60period of that export, in seconds; 1 to 3600
telemetry.on_exporter_errorstring refusean exporter that cannot be built: refuse (startup refused) or warn (startup without that signal)
See Timeouts .
Key Type Default Effect
uploadstable - upload timeouts, on all doors
uploads.idle_timeout_secsinteger 30upload abandoned after this time without a byte; 1 to 86400; CRAFT_FILE_GATE_UPLOAD_IDLE_TIMEOUT_SECS
uploads.min_rate_bytes_per_secinteger 0: disabledminimum average rate of an upload since its start, required once the grace has passed; at most 1073741824
uploads.min_rate_grace_secsinteger 60wait before requiring that rate; 1 to 86400
uploads.takeover_idle_secs ⟳ integer 10an upload with no byte for this time is taken over by a new upload from the same account to the same file, on this instance; acts only below idle_timeout_secs (otherwise WARN); 0: never; 0 to 86400; on reload, an out-of-bounds value keeps the one in force
See Atomic writes .
Key Type Default Effect
uploads.stale_partialstable - sweep of the leftovers of interrupted uploads
uploads.stale_partials.age_checkboolean truemeasure age on the storage clock (a probe file in the same directory), not on the server’s
uploads.stale_partials.grace_secsinteger 2 x idle_timeout_secs + max(300, idle_timeout_secs), i.e. 360 sage from which a leftover is deleted; more than 2 x idle_timeout_secs + 60, at most 2592000 (30 days)
Key Type Default Effect
tcp_keepalivetable - TCP keepalive of every accepted connection
tcp_keepalive.enabledboolean trueenable SO_KEEPALIVE
tcp_keepalive.idle_secsinteger 30silence before the first probe; 1 to 32767
tcp_keepalive.interval_secsinteger 10gap between two probes; 1 to 32767
tcp_keepalive.countinteger 3unanswered probes before closing; 1 to 127
tcp_keepalive.user_timeout_secsinteger 0: derived from idle_timeout_secsLinux: how long sent bytes can stay unacknowledged, then the connection is closed; 5 to 86400
Key Type Default Effect
reloadtable - how a modified file is noticed
reload.watchstring autoauto: inotify, and periodic re-reading if inotify cannot be used; inotify: inotify required; poll: periodic re-reading only, no inotify instance
reload.poll_interval_secsinteger 5period of the periodic re-reading, in seconds; 1 to 60
See Security .
Key Type Default Effect
securitytable - how trust files are judged
security.allow_group_writable_trust_anchorsboolean falsea trust file writable by the server’s group: WARN instead of a refusal; never the configuration file