Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Reference: environment variables

The CRAFT_FILE_GATE_* variables replace a key from the file, after the file is read. They are mostly useful in containers.

Variables that replace a key

VariableKey replacedValue
CRAFT_FILE_GATE_LISTENsftp.listenip:port; with [sftp]
CRAFT_FILE_GATE_PROBES_LISTENserver.probes_listenip:port
CRAFT_FILE_GATE_ADMIN_LISTENadmin.listenip:port
CRAFT_FILE_GATE_ADMIN_CONTROL_LISTENadmin.control_listenip:port
CRAFT_FILE_GATE_ADMIN_HEADER_READ_TIMEOUT_SECSadmin.header_read_timeout_secsinteger, 1 to 300
CRAFT_FILE_GATE_ADMIN_BEARER_TOKENadmin.bearer_tokenthe token
CRAFT_FILE_GATE_ADMIN_BEARER_TOKEN_FILEadmin.bearer_tokena file that holds the token
CRAFT_FILE_GATE_ADMIN_TLS_CERTadmin.tls.cert_filepath; creates [admin.tls] if missing
CRAFT_FILE_GATE_ADMIN_TLS_KEYadmin.tls.key_filepath; creates [admin.tls] if missing
CRAFT_FILE_GATE_ADMIN_SESSION_SECRET_NAMEadmin.session.secret_namethe Secret name; the chart sets it
CRAFT_FILE_GATE_ADMIN_SESSION_BACKENDadmin.session.backendfile or configmap; the chart sets it next to the shared Secret
CRAFT_FILE_GATE_ADMIN_SESSION_REVOCATION_CONFIGMAP_NAMEadmin.session.revocation_configmap_namethe name of the revocations ConfigMap; the chart sets it
CRAFT_FILE_GATE_ADMIN_GRANTS_BACKENDadmin.grants.backendfile or configmap; the chart sets it
CRAFT_FILE_GATE_ADMIN_GRANTS_GRANT_CONFIGMAP_NAMEadmin.grants.grant_configmap_namethe name of the temporary access ConfigMap; the chart sets it
CRAFT_FILE_GATE_SFTP_BAN_CONFIGMAP_NAMEsftp.ban.ban_configmap_namethe name of the bans ConfigMap; the chart sets it
CRAFT_FILE_GATE_API_BAN_CONFIGMAP_NAMEapi.ban.ban_configmap_namelikewise
CRAFT_FILE_GATE_ADMIN_BAN_CONFIGMAP_NAMEadmin.ban.ban_configmap_namelikewise
CRAFT_FILE_GATE_CLUSTER_LISTENcluster.listenip:port; creates [cluster] if missing; the chart sets it
CRAFT_FILE_GATE_CLUSTER_PEERScluster.peersdns:<name>:<port>, or comma-separated <host>:<port> entries; the chart sets it
CRAFT_FILE_GATE_CLUSTER_SECRET_NAMEcluster.secret_namethe Secret name; the chart sets it
CRAFT_FILE_GATE_CLUSTER_MIN_PEERScluster.min_peersinteger; the chart sets it (cluster.minPeers)
CRAFT_FILE_GATE_CLUSTER_UNREADY_WHENcluster.unready_whencomma-separated detectors; the chart sets it with cluster.unreadyWhen
CRAFT_FILE_GATE_JWT_SECRETauth.jwt.secretthe HMAC secret
CRAFT_FILE_GATE_JWT_SECRET_FILEauth.jwt.secreta file that holds the secret
CRAFT_FILE_GATE_HASH_WORKERSauth.hash_workersinteger, 1 to 1024
CRAFT_FILE_GATE_HASH_QUEUEauth.hash_queueinteger, 1 to 65536
CRAFT_FILE_GATE_LOG_LEVELlog.leveltrace … off
CRAFT_FILE_GATE_LOG_DIRlog.dirpath
CRAFT_FILE_GATE_UPLOAD_IDLE_TIMEOUT_SECSuploads.idle_timeout_secsinteger, 1 to 86400

A variable applies to the key it replaces, where that key has an effect (CRAFT_FILE_GATE_ADMIN_* with [admin], CRAFT_FILE_GATE_JWT_SECRET with an HMAC algorithm). Once CRAFT_FILE_GATE_LOG_LEVEL is set, the file no longer sets the level. The startup line config override from env names each variable applied, never showing a secret.

Secrets: the _FILE form

CRAFT_FILE_GATE_ADMIN_BEARER_TOKEN_FILE and CRAFT_FILE_GATE_JWT_SECRET_FILE name a file read once, at startup. Prefer them: a variable stays readable in /proc/<pid>/environ.

RuleEffect
the filea trust file, in UTF-8, not empty; only one of the two forms X and X_FILE
a trailing newlineremoved
file modifiedtaken at the next restart

A Kubernetes Secret mounted read-only works as is: see Kubernetes secrets.

Other variables read

VariableEffect
RUST_LOGreplaces the log filter; keep audit=info in it, otherwise the audit trail goes silent (WARN at startup)
OTEL_EXPORTER_OTLP_PROTOCOL, OTEL_EXPORTER_OTLP_TRACES_PROTOCOLread to report in a WARN that they contradict [telemetry] protocol; the file decides
SSL_CERT_FILE, SSL_CERT_DIRthe TLS roots, if the image carries none (:scratch)
TOKIO_WORKER_THREADSthreads of the main runtime; quoted on the startup line
HOSTNAMEthe pod_name of sessions in the admin API