Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Reference: [sftp] and the SSH door

⟳: reloaded at runtime; no mark: taken at restart. See Hot reload.

[sftp]

See The SFTP door, Timeouts.

KeyTypeDefaultEffect
sftptableabsent: SFTP door offthe SFTP door (feature door-sftp)
sftp.listenaddress(required)listen address and port; CRAFT_FILE_GATE_LISTEN replaces it
sftp.host_keyslist(required)the host keys, existing files: a path, or a { path, algorithms } table
sftp.host_keys[].pathpath(required)the private key file, table form
sftp.host_keys[].algorithmslistdepends on the keythe signature algorithms advertised for this key, [sftp.algorithms] syntax
sftp.generate_host_keystringabsent"ed25519" or "ecdsa-p256": creates the key of a missing host_keys file; single instance only
sftp.login_grace_secsinteger120seconds to authenticate, connection closed beyond that; 0 disables
sftp.server_idstringCraftFileGate_<version>the SSH-2.0-<server_id> banner
sftp.inactivity_timeout_secsinteger600a connection with no packet is closed after this timeout; 0 never; at most 86400
sftp.keepalive_interval_secsinteger0SSH keepalive after this client silence; 0 none; at most 86400
sftp.keepalive_maxinteger3unanswered keepalives before closing; 1 to 100

[sftp.algorithms]

KeyTypeDefaultEffect
sftp.algorithmstable-the SSH algorithms: +name adds to the default, -name removes, a list without prefix replaces
sftp.algorithms.kexlistmlkem768x25519-sha256, curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group16-sha512, diffie-hellman-group14-sha256key exchange
sftp.algorithms.cipherslistchacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctrciphers
sftp.algorithms.macslisthmac-sha2-512-etm@openssh.com, hmac-sha2-256-etm@openssh.com, hmac-sha2-512, hmac-sha2-256MAC
sftp.algorithms.host_keylistssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, rsa-sha2-256host key signatures
sftp.algorithms.user_keylistssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, sk-ssh-ed25519@openssh.com, sk-ecdsa-sha2-nistp256@openssh.com, rsa-sha2-512, rsa-sha2-256signatures allowed for a user key; ssh-rsa (SHA-1) not in the default

[sftp.ban]

See Bans.

KeyTypeDefaultEffect
sftp.bantableabsent: no banban of addresses after authentication failures on the SFTP door
sftp.ban.max_failuresinteger5failures in the window before the ban; at least 1
sftp.ban.ban_duration_secsinteger600duration of a ban in seconds, from the verdict
sftp.ban.window_secsinteger300failure counting window in seconds, fixed, opened by the first failure of a series
sftp.ban.whitelist_ipslist[]addresses and CIDR networks, IPv4 or IPv6, never banned by this instance
sftp.ban.trusted_proxieslist[]no effect on SSH
sftp.ban.persist_filepathabsent: in memoryfile where bans are kept and shared between instances
sftp.ban.backendstring"file""file", or "configmap" to share bans between Kubernetes pods
sftp.ban.ban_configmap_namestringcraft-file-gate-bansthe ConfigMap of bans, with backend = "configmap"
sftp.ban.reread_interval_secsinteger5re-read of the shared persist_file in seconds, on top of file watching; 1 to 30

[sftp.rate_limit]

KeyTypeDefaultEffect
sftp.rate_limittableabsent: no limittoken bucket per address, when a connection is accepted
sftp.rate_limit.connections_per_minuteinteger(required)sustained connection rate per address; at least 1
sftp.rate_limit.burstintegerconnections_per_minuteconnections accepted in a row; at least 1