Reference: environment variables
The CRAFT_FILE_GATE_* variables replace a key from the file, after the file
is read. They are mostly useful in containers.
Variables that replace a key
| Variable | Key replaced | Value |
|---|---|---|
CRAFT_FILE_GATE_LISTEN | sftp.listen | ip:port; with [sftp] |
CRAFT_FILE_GATE_PROBES_LISTEN | server.probes_listen | ip:port |
CRAFT_FILE_GATE_ADMIN_LISTEN | admin.listen | ip:port |
CRAFT_FILE_GATE_ADMIN_CONTROL_LISTEN | admin.control_listen | ip:port |
CRAFT_FILE_GATE_ADMIN_HEADER_READ_TIMEOUT_SECS | admin.header_read_timeout_secs | integer, 1 to 300 |
CRAFT_FILE_GATE_ADMIN_BEARER_TOKEN | admin.bearer_token | the token |
CRAFT_FILE_GATE_ADMIN_BEARER_TOKEN_FILE | admin.bearer_token | a file that holds the token |
CRAFT_FILE_GATE_ADMIN_TLS_CERT | admin.tls.cert_file | path; creates [admin.tls] if missing |
CRAFT_FILE_GATE_ADMIN_TLS_KEY | admin.tls.key_file | path; creates [admin.tls] if missing |
CRAFT_FILE_GATE_ADMIN_SESSION_SECRET_NAME | admin.session.secret_name | the Secret name; the chart sets it |
CRAFT_FILE_GATE_ADMIN_SESSION_BACKEND | admin.session.backend | file or configmap; the chart sets it next to the shared Secret |
CRAFT_FILE_GATE_ADMIN_SESSION_REVOCATION_CONFIGMAP_NAME | admin.session.revocation_configmap_name | the name of the revocations ConfigMap; the chart sets it |
CRAFT_FILE_GATE_ADMIN_GRANTS_BACKEND | admin.grants.backend | file or configmap; the chart sets it |
CRAFT_FILE_GATE_ADMIN_GRANTS_GRANT_CONFIGMAP_NAME | admin.grants.grant_configmap_name | the name of the temporary access ConfigMap; the chart sets it |
CRAFT_FILE_GATE_SFTP_BAN_CONFIGMAP_NAME | sftp.ban.ban_configmap_name | the name of the bans ConfigMap; the chart sets it |
CRAFT_FILE_GATE_API_BAN_CONFIGMAP_NAME | api.ban.ban_configmap_name | likewise |
CRAFT_FILE_GATE_ADMIN_BAN_CONFIGMAP_NAME | admin.ban.ban_configmap_name | likewise |
CRAFT_FILE_GATE_CLUSTER_LISTEN | cluster.listen | ip:port; creates [cluster] if missing; the chart sets it |
CRAFT_FILE_GATE_CLUSTER_PEERS | cluster.peers | dns:<name>:<port>, or comma-separated <host>:<port> entries; the chart sets it |
CRAFT_FILE_GATE_CLUSTER_SECRET_NAME | cluster.secret_name | the Secret name; the chart sets it |
CRAFT_FILE_GATE_CLUSTER_MIN_PEERS | cluster.min_peers | integer; the chart sets it (cluster.minPeers) |
CRAFT_FILE_GATE_CLUSTER_UNREADY_WHEN | cluster.unready_when | comma-separated detectors; the chart sets it with cluster.unreadyWhen |
CRAFT_FILE_GATE_JWT_SECRET | auth.jwt.secret | the HMAC secret |
CRAFT_FILE_GATE_JWT_SECRET_FILE | auth.jwt.secret | a file that holds the secret |
CRAFT_FILE_GATE_HASH_WORKERS | auth.hash_workers | integer, 1 to 1024 |
CRAFT_FILE_GATE_HASH_QUEUE | auth.hash_queue | integer, 1 to 65536 |
CRAFT_FILE_GATE_LOG_LEVEL | log.level | trace … off |
CRAFT_FILE_GATE_LOG_DIR | log.dir | path |
CRAFT_FILE_GATE_UPLOAD_IDLE_TIMEOUT_SECS | uploads.idle_timeout_secs | integer, 1 to 86400 |
A variable applies to the key it replaces, where that key has an effect
(CRAFT_FILE_GATE_ADMIN_* with [admin], CRAFT_FILE_GATE_JWT_SECRET with
an HMAC algorithm). Once CRAFT_FILE_GATE_LOG_LEVEL is set, the file no
longer sets the level. The startup line config override from env names each
variable applied, never showing a secret.
Secrets: the _FILE form
CRAFT_FILE_GATE_ADMIN_BEARER_TOKEN_FILE and CRAFT_FILE_GATE_JWT_SECRET_FILE
name a file read once, at startup. Prefer them: a variable
stays readable in /proc/<pid>/environ.
| Rule | Effect |
|---|---|
| the file | a trust file, in UTF-8, not empty; only one of the two forms X and X_FILE |
| a trailing newline | removed |
| file modified | taken at the next restart |
A Kubernetes Secret mounted read-only works as is: see Kubernetes secrets.
Other variables read
| Variable | Effect |
|---|---|
RUST_LOG | replaces the log filter; keep audit=info in it, otherwise the audit trail goes silent (WARN at startup) |
OTEL_EXPORTER_OTLP_PROTOCOL, OTEL_EXPORTER_OTLP_TRACES_PROTOCOL | read to report in a WARN that they contradict [telemetry] protocol; the file decides |
SSL_CERT_FILE, SSL_CERT_DIR | the TLS roots, if the image carries none (:scratch) |
TOKIO_WORKER_THREADS | threads of the main runtime; quoted on the startup line |
HOSTNAME | the pod_name of sessions in the admin API |