Reference: [server] and [cluster]
⟳: reloaded at runtime; no mark: taken at restart. See Hot reload.
What all doors share, and the channel between instances. [server] can be missing: each key has its default.
[server]
See Shutdown, Kubernetes.
| Key | Type | Default | Effect |
|---|---|---|---|
server | table | - | the settings common to all doors |
server.shutdown_grace_period_secs | integer | 30 | seconds left to the work in progress of each door at shutdown, one deadline for all; at least 1 |
server.max_sessions_per_user | integer | unlimited | concurrent sessions per user, on a door with sessions (SFTP); with [cluster], those of each reachable instance add up |
server.probes_listen | address | absent: probes on [admin] | CRAFT_FILE_GATE_PROBES_LISTEN replaces it; a separate port for /livez, /readyz, /health and /metrics, served only there, over HTTP, without authentication; without [admin], the only HTTP listener |
[server.hidden_stores]
See Atomic writes.
| Key | Type | Default | Effect |
|---|---|---|---|
server.hidden_stores | table | - | atomic writes, for every backend and every mount that says nothing |
server.hidden_stores.enabled | boolean | false | write to an in-transfer file, published by a rename at the end |
server.hidden_stores.prefix | string | .in. | the start of that file’s name |
server.hidden_stores.extension | string | . | the end of that file’s name |
[server.backend_probe]
See Backends.
| Key | Type | Default | Effect |
|---|---|---|---|
server.backend_probe | table | - | the availability probe of each backend, in the background, never on the path of an operation |
server.backend_probe.enabled | boolean | true | false: no probe, each backend stays unknown |
server.backend_probe.interval_secs | integer | 15 | seconds between two visits to a backend, from 5 to 3600 |
server.backend_probe.timeout_secs | integer | 5 | maximum duration of a visit, from 1 to 60, below interval_secs (otherwise startup is refused) |
server.backend_probe.failures_before_down | integer | 2 | failed visits in a row before down, from 1 to 10; one successful visit is enough to go back up. Worst-case detection: interval_secs × failures_before_down + timeout_secs, 35 s by default |
[cluster]
See Cluster.
| Key | Type | Default | Effect |
|---|---|---|---|
cluster | table | absent: each instance is alone | the channel between the instances of a deployment; CRAFT_FILE_GATE_CLUSTER_LISTEN creates it |
cluster.listen | address | - | the channel’s own port, in mutual TLS 1.3; CRAFT_FILE_GATE_CLUSTER_LISTEN replaces it |
cluster.peers | string or list | - | dns:<name>:<port>: each address of the name, re-resolved every 5 s (a headless Service yields each ready pod, Docker Compose each replica of the service); or <host>:<port> entries. Each one is called every second; the one that answers the instance’s own identifier (<pod_name>/<boot_id>) is itself; CRAFT_FILE_GATE_CLUSTER_PEERS replaces it |
cluster.cert_file | path | - | the shared certificate; when it and key_file are missing, generated (ECDSA P-256, 10 years) by the first instance, read by the others on a shared volume |
cluster.key_file | path | - | its key, created with 0600 |
cluster.secret_name | string | - | or the shared Kubernetes Secret, entries tls.crt and tls.key (feature k8s); CRAFT_FILE_GATE_CLUSTER_SECRET_NAME replaces it |
cluster.peer_timeout_ms | integer | 2000 | timeout of a call to a peer, from 100 to 10000 |
cluster.min_peers | integer | 1 | below this number of reachable peers for isolated_after_secs, the instance is isolated; 0: never; from 0 to 1000; CRAFT_FILE_GATE_CLUSTER_MIN_PEERS replaces it |
cluster.unready_when | list | []: alert only | the detectors that withdraw the instance from service (/readyz not ready), ORed: storage_alone, isolated, isolated_and_storage_down; CRAFT_FILE_GATE_CLUSTER_UNREADY_WHEN (comma-separated) replaces it |
cluster.isolated_after_secs | integer | 30 | time below min_peers before being isolated; immediate return; from 5 to 3600 |
cluster.unready_after_secs | integer | 60 | duration of a chosen detector before withdrawal, from 10 to 3600, at least 2 × server.backend_probe.interval_secs |
cluster.ready_after_secs | integer | 30 | duration without a chosen detector before returning, from 5 to 3600, at least server.backend_probe.interval_secs |