⟳: reloaded at runtime; no mark: taken at restart. See Hot reload.
See The SFTP door, Timeouts.
| Key | Type | Default | Effect |
sftp | table | absent: SFTP door off | the SFTP door (feature door-sftp) |
sftp.listen | address | (required) | listen address and port; CRAFT_FILE_GATE_LISTEN replaces it |
sftp.host_keys | list | (required) | the host keys, existing files: a path, or a { path, algorithms } table |
sftp.host_keys[].path | path | (required) | the private key file, table form |
sftp.host_keys[].algorithms | list | depends on the key | the signature algorithms advertised for this key, [sftp.algorithms] syntax |
sftp.generate_host_key | string | absent | "ed25519" or "ecdsa-p256": creates the key of a missing host_keys file; single instance only |
sftp.login_grace_secs | integer | 120 | seconds to authenticate, connection closed beyond that; 0 disables |
sftp.server_id | string | CraftFileGate_<version> | the SSH-2.0-<server_id> banner |
sftp.inactivity_timeout_secs | integer | 600 | a connection with no packet is closed after this timeout; 0 never; at most 86400 |
sftp.keepalive_interval_secs | integer | 0 | SSH keepalive after this client silence; 0 none; at most 86400 |
sftp.keepalive_max | integer | 3 | unanswered keepalives before closing; 1 to 100 |
| Key | Type | Default | Effect |
sftp.algorithms | table | - | the SSH algorithms: +name adds to the default, -name removes, a list without prefix replaces |
sftp.algorithms.kex | list | mlkem768x25519-sha256, curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group16-sha512, diffie-hellman-group14-sha256 | key exchange |
sftp.algorithms.ciphers | list | chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr | ciphers |
sftp.algorithms.macs | list | hmac-sha2-512-etm@openssh.com, hmac-sha2-256-etm@openssh.com, hmac-sha2-512, hmac-sha2-256 | MAC |
sftp.algorithms.host_key | list | ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, rsa-sha2-256 | host key signatures |
sftp.algorithms.user_key | list | ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, sk-ssh-ed25519@openssh.com, sk-ecdsa-sha2-nistp256@openssh.com, rsa-sha2-512, rsa-sha2-256 | signatures allowed for a user key; ssh-rsa (SHA-1) not in the default |
See Bans.
| Key | Type | Default | Effect |
sftp.ban | table | absent: no ban | ban of addresses after authentication failures on the SFTP door |
sftp.ban.max_failures | integer | 5 | failures in the window before the ban; at least 1 |
sftp.ban.ban_duration_secs | integer | 600 | duration of a ban in seconds, from the verdict |
sftp.ban.window_secs | integer | 300 | failure counting window in seconds, fixed, opened by the first failure of a series |
sftp.ban.whitelist_ips | list | [] | addresses and CIDR networks, IPv4 or IPv6, never banned by this instance |
sftp.ban.trusted_proxies | list | [] | no effect on SSH |
sftp.ban.persist_file | path | absent: in memory | file where bans are kept and shared between instances |
sftp.ban.backend | string | "file" | "file", or "configmap" to share bans between Kubernetes pods |
sftp.ban.ban_configmap_name | string | craft-file-gate-bans | the ConfigMap of bans, with backend = "configmap" |
sftp.ban.reread_interval_secs | integer | 5 | re-read of the shared persist_file in seconds, on top of file watching; 1 to 30 |
| Key | Type | Default | Effect |
sftp.rate_limit | table | absent: no limit | token bucket per address, when a connection is accepted |
sftp.rate_limit.connections_per_minute | integer | (required) | sustained connection rate per address; at least 1 |
sftp.rate_limit.burst | integer | connections_per_minute | connections accepted in a row; at least 1 |