Reference: configuration
The whole configuration fits in one TOML file, passed with
craft-file-gate --config <file>. Users, roles and backends can also live
in users_file and roles_file, next to it.
| Page | Sections |
|---|---|
[server], [cluster] | [server], [server.hidden_stores], [cluster] |
[sftp] and the SSH door | [sftp], [sftp.algorithms], [sftp.ban], [sftp.rate_limit] |
[auth], users and roles | [auth], [auth.methods], [auth.jwt], [[users]], [[roles]], [[roles.mounts]], [[roles.mounts.acl]] |
[[backends]] | common keys, then local, sftp, s3, webhdfs |
[admin] and [api] | [admin], [[admin.roles]], [admin.tls], [admin.ban], [admin.metrics_thresholds], [api], [api.ban], [api.rate_limit], [api.ui] |
[log], [telemetry] and the rest | [log], [telemetry], [uploads], [uploads.stale_partials], [tcp_keepalive], [reload], [security] |
Only [auth] is required, with at least one role, plus at least one door:
[sftp], or [api] with [admin]. With no door configured, the server
refuses to start.
craft-file-gate config explain <key> gives each key its type, its default and
its bounds (Checking a configuration).
Reading these tables
| Column | Meaning |
|---|---|
| Key | the full path; [] marks an entry of an array of tables: roles[].mounts[].home_dir is the home_dir key of a [[roles.mounts]]; ⟳: reloaded at runtime |
| Type | string, integer, boolean, list, table, array of tables, path, address (ip:port), URL |
| Default | the value when the key is absent; (required): its absence refuses startup; -: no value of its own |
| Effect | what the key sets, and its bounds |
A key without a mark waits for a restart. An open session keeps its roles and its mounts until it ends. See Hot reload.
Common rules
| Rule | Effect |
|---|---|
| relative path | relative to the directory of the configuration file, not to the current directory |
roles.toml, users.toml next to the configuration | used if not declared; the startup log says which |
| environment variable | replaces the value from the file: see Environment variables |
| unknown key, out-of-bounds value, key with no effect | Troubleshooting |