Depannage
Un index des erreurs : le mot exact que vous voyez (message au demarrage,
reason d’une ligne d’audit, statut SFTP, code REST) mene a la page du guide
qui definit l’option en cause, puis, entre parentheses, a sa table dans la
reference, et a l’identifiant de la regle de comportement, a citer au support.
<...> marque une partie variable. Le vocabulaire complet des lignes d’audit
est dans la reference.
Demarrage et configuration
Un reglage casse refuse le demarrage ; un reglage sans effet demarre avec un
WARN qui nomme la cle.
| Message | Ou c’est regle | Regle |
|---|---|---|
--config is required when not using a subcommand, Configuration error: failed to read config file: <cause> | Le fichier de configuration | R-CONFIG-001 |
Configuration error: failed to parse config TOML: unknown field <cle>, expected one of ... (at line <l>, column <c>) | la page du guide de la section nommee (reference) : la cle mal orthographiee | R-CONFIG-005 |
... `sftp.<cle>` is now `server.<cle>`: move it to the [server] table : shutdown_grace_period_secs, max_sessions_per_user ou hidden_stores ecrite sous [sftp] | Les cles de [sftp] ([server]) | R-CONFIG-015 |
[sftp]: this binary is built without the SFTP door (Cargo feature door-sftp) (ou [api], REST, door-rest), no door is configured, nothing would be served: ..., this binary is built without any door ... | reference : [sftp], ou [api] avec [admin] ; Les features du binaire : un binaire construit sans cette porte | R-CONFIG-016 |
server.probes_listen = <adresse> is also <cle> — the probes need a port of their own | Une porte ou deux ([server]) | R-ADMIN-020 |
server.backend_probe.<cle> = <n> is out of bounds: between <min> and <max>, server.backend_probe.timeout_secs = <n> is not below interval_secs = <m>: ... | Disponibilite ([server.backend_probe]) | R-AVAIL-001 |
Configuration error: <section>: <cause>, <cle> = <n> is out of range: accepted values are <min> to <max> | la page du guide de la section ou de la cle nommee (reference) | R-CONFIG-010 |
Configuration error: failed to load local users: <cause> | Les comptes locaux ([[users]]) | R-AUTH-004 |
duplicate username: <nom> — each [[users]] entry needs its own username | Les comptes locaux ([[users]]) | R-CONFIG-011 |
user <nom> has a sha512-crypt password hash, which is not accepted — set [auth.methods] local.allow_sha512_crypt = true ... (ou bcrypt) ; WARN local user's password_hash is the example published in the README or the example files ..., local user's argon2 hash asks for more memory per verification than auth.methods.local.max_argon2_memory_kib allows: ..., local users whose password hash has another format or other parameters than most of the users file: ..., local users whose password hash cannot be verified (...): ..., accounts still depend on a legacy password hash flag: ..., legacy password hash flag enabled but no account uses this format ..., password hash is not argon2id — ... | Les hashes ([auth.methods]) | R-AUTH-004, R-AUTH-005, R-AUTH-007, R-AUTH-008, R-AUTH-010, R-CONFIG-012 |
Configuration error: failed to load roles/backends: <cause> ; nom de role en double, role sans [[roles.mounts]], montage vers un backend inconnu | Les cles d’un role et d’un montage, Les cles de tout backend ([[roles]], [[roles.mounts]], [[backends]]) | R-AUTH-028 |
unknown field backend (ou home_dir, acl) sous [[roles]] : une cle de montage ecrite au niveau du role | Les cles d’un role et d’un montage ([[roles.mounts]]) | R-CONFIG-005 |
role has no ACL entry: access is deny-by-default, ... (WARN) | Ecrire une ACL ([[roles.mounts.acl]]) | R-ACL-003 |
role "<nom>" holds ACL paths that name one path on this backend, whose ACL compares paths folded (case and Unicode normalization), with different rights: [...] | Casse des noms, Casse des chemins de l’ACL ([[roles.mounts.acl]], [[backends]]) | R-ACL-006 |
role missing required fields: role '<nom>': mount '<p>': home_dir = "<h>" climbs out of the backend's root | Ou vont les fichiers ([[roles.mounts]]) | R-AUTH-032 |
user '<nom>': roles '<a>' and '<b>' both claim '<mount_path>' ... (au demarrage, ou failed to reload roles file) : montages en conflit d’un utilisateur local | Cumuler des roles, Recettes ([[roles.mounts]]) | R-AUTH-030 |
role '<nom>': user_key_algorithms: "<algorithme>" is not an algorithm this server supports; ... | Les algorithmes de signature d’une cle ([[roles]]) | R-AUTH-019 |
no authentication methods enabled | Choisir les methodes ([auth.methods]) | R-AUTH-001 |
aucune source de cle JWT, jwks_url avec une autre source, algorithm inconnu ; premier chargement JWKS en echec, the first fetch from auth.jwt.jwks_url failed, ... ; WARN auth.jwt.public_key_file is never read: ..., every JWT will be refused: auth.jwt.secret and auth.jwt.public_key_file are both set ..., [auth.jwt] is configured but auth.methods.jwt.enabled is false: ... | JWT, Brancher un fournisseur d’identite ([auth.jwt]) | R-AUTH-020, R-AUTH-026, R-AUTH-025 |
auth: auth.hash_workers = 0 is refused: it must be between 1 and 1024 ... | Verification des mots de passe ([auth]) | R-AUTH-014 |
unknown backend type "<type>": this binary knows <types> | Les types, Les features du binaire ([[backends]]) | R-CONFIG-013 |
sftp.host_keys: <chemin> does not exist. Create it (ssh-keygen ...) or set sftp.generate_host_key ..., sftp.host_keys: cannot read <chemin>: <erreur> (la cle doit etre lisible par l’utilisateur de l’image) | Cles d’hote, Docker, Secrets ([sftp]) | R-SFTP-003 |
| une liste d’algorithmes refusee (nom inconnu, formes melangees, liste vide) | Algorithmes ([sftp.algorithms]) | R-SFTP-006 |
[cluster] has no listen ..., ... has no peers ..., ... has no certificate source ..., ... sets both cert_file/key_file and secret_name ..., cluster.peers entry "<entree>" cannot be read: ..., cluster.secret_name is empty: ..., cluster.secret_name is set, but this binary was built without the k8s feature: ..., cannot listen on cluster.listen = <adresse>: <cause>, the cluster channel cannot start, refusing to boot: ..., cluster.<cle> is set without cluster.<autre> ..., cluster.peer_timeout_ms = <n> is out of bounds ..., cluster.listen = <adresse> is also <cle> ..., cluster certificate (cert_file=<c>, key_file=<k>): <raison> ; WARN [cluster] has nothing to add across instances: ... | Plusieurs instances ([cluster]) | R-CLUSTER-001, R-CLUSTER-002 |
cluster.<cle> = <n> is out of bounds ..., cluster.unready_when names <detecteur>, but cluster.min_peers = 0 turns isolation off ..., ... but server.backend_probe.enabled = false ..., cluster.<cle> = <n> is under <min> s (...): one storage verdict could withdraw or restore the instance, CRAFT_FILE_GATE_CLUSTER_MIN_PEERS = ... cannot be read ..., CRAFT_FILE_GATE_CLUSTER_UNREADY_WHEN = "..." cannot be read: ... ; WARN a [cluster] detector key is set where it has no effect | Detecteurs et retrait du service ([cluster]) | R-CLUSTER-016 |
WARN cluster detector active (detector, reason), cluster detector inactive ; withdrawn from service: ..., back in service: ... ; /readyz 503 withdrawn_by ; storage_alone actif sans retrait | Detecteurs et retrait du service : storage_alone, le stockage de ce pod seul (montage, reseau du noeud) ; actif sans retrait : aucun pod en service et sain (sans backend en panne) ne voit tous ses backends en panne disponibles, ou un pod de plus petit identifiant passe d’abord ; isolated, le reseau entre pods ; isolated_and_storage_down, isole et chaque backend non local en panne : le reseau du noeud ; la raison est dans /admin/health (checks.cluster) | R-CLUSTER-015, R-CLUSTER-016 |
<ancre>: [the directory ]<chemin> is <raison>: whoever can write there decides who gets in. ... ; a file this server trusts can be rewritten: ... (WARN) | Les fichiers de confiance : chmod go-w, ou monter en lecture seule | R-TRUST-008 |
<ancre>: <chemin> is writable by the server's own group (<gid>): ... | [security] ([security]) | R-TRUST-004 |
<ancre>: <chemin> cannot be resolved: <erreur> | Les poser | R-TRUST-007 |
cle privee lisible par les autres (WARN) | Les fichiers de confiance | R-TRUST-011 |
<X> and <X>_FILE are both set: one secret, two sources..., <X>_FILE is set but empty, ... is empty: an empty secret is no secret, ... is not UTF-8 text | Un fichier plutot qu’une variable (Variables d’environnement) | R-CONFIG-009 |
<VARIABLE>="<valeur>" is refused: it must be a whole number... ; env override ignored, the configured value stands, env override is empty (WARN) | L’environnement (Variables d’environnement) | R-CONFIG-008 |
server.shutdown_grace_period_secs must be > 0 | Arret ([server]) | R-SHUTDOWN-004 |
admin requires a bearer_token or at least one role under [[admin.roles]] | S’authentifier ([admin], [[admin.roles]]) | R-ADMIN-001 |
admin.listen and sftp.listen are the same address — they cannot share a port, admin.control_listen = <adresse> is also admin.listen — the control door needs a port of its own, the admin door cannot start, refusing to boot: ... cannot listen on <adresse> (port deja pris) | Une porte ou deux ([admin]) | R-ADMIN-001, R-ADMIN-002 |
tls: cert_file and key_file must both be set, tls: enabled but no cert source ..., tls: cert_file and auto_generate are mutually exclusive ; paire refusee au demarrage : <cause> (cert_file=<chemin>, key_file=<chemin>) | Recommandations de deploiement ([admin.tls]) | R-ADMIN-001, R-ADMIN-003 |
[[admin.roles]] has an entry with a blank name, [[admin.roles]] names the role <nom> twice, [[admin.roles]] <nom> grants no permission: ..., unknown variant <permission> ; [[admin.roles]] is set but no credential can open the admin door: ... | S’authentifier ([[admin.roles]], [auth.methods], [auth.jwt]) | R-ADMIN-006 |
role <nom> is also the name of an [[admin.roles]] entry: admin roles and file roles need different names (au demarrage, ou failed to reload roles file, keeping old config) ; an admin role and a file role have names that differ only by case or spaces: ... (WARN) | S’authentifier ([[admin.roles]], [[roles]]) : renommer l’un des deux | R-ADMIN-006 |
this user's keys open no door: its authorities name no role with mounts, only admin roles, ... (WARN) | S’authentifier ([[admin.roles]]) : retirer authorized_keys, ou donner un role de fichiers | R-ADMIN-006 |
the admin door signs local accounts in with their passwords ... and has no [admin.ban]: ... | Session de console ([admin.ban]) | R-ADMIN-022 |
admin.session.key_file <chemin> holds <n> bytes: a session key needs 32 at least ..., admin.session.key_file: ... writable by ..., admin.session.key_file <chemin>: <cause> ; admin.session.ttl_secs = <n> is out of range ..., admin.session.max_age_secs = <n> is under admin.session.ttl_secs ..., admin.session.key_file and admin.session.secret_name are both set ..., admin.session.secret_name is empty ..., admin.session.secret_name is set, but this binary was built without the k8s feature ... | La cle de session ([admin.session]) : head -c 32 /dev/urandom, chmod 400 ; Les features du binaire | R-ADMIN-022 |
auth.jwt.issuer = "craft-file-gate" is the issuer of the console's own session tokens ... | [auth.jwt] : un autre issuer | R-ADMIN-005 |
admin session key generated for this process: ... (WARN), jetons refuses par un autre pod ou apres un redemarrage | La cle de session ([admin.session]) : key_file ou secret_name | R-ADMIN-022 |
admin.allow_static_token = false, and a static admin token is set by <source>: ... ; the static admin token is enabled beside admin roles: ..., static admin token used: it is meant for break-glass only (WARN) | S’authentifier ([admin]) : retirer le jeton de <source>, ou allow_static_token = false | R-ADMIN-024 |
api.enabled requires [admin] section to be configured | API REST de fichiers ([api], [admin]) | R-REST-001 |
[api.ui] enabled = true requires [api] enabled = true: ..., [api.ui] path "<path>" is not usable, ... collides with ... | Explorateur ([api.ui], [api]) | R-EXPLORER-001, R-EXPLORER-002 |
[api] openapi = true requires [api] enabled = true: ... | API REST de fichiers ([api]) | R-REST-012 |
admin.metrics_thresholds.jwks_age_secs = <age> is not above auth.jwt.jwks_refresh_interval_secs ... ; WARN a metrics threshold is set where it has no effect: ... | Seuils de la console ([admin.metrics_thresholds], [auth.jwt]) | R-METRICS-017 |
invalid telemetry otlp_endpoint, invalid telemetry protocol, invalid telemetry metrics_interval_secs ; cannot build the OTLP <signal> exporter: ...; refusing to start | Le point d’acces, [telemetry] ([telemetry]) : on_exporter_error | R-TELEMETRY-001, R-TELEMETRY-003 |
unknown ban backend ...: expected "file" or "configmap", sftp.ban: ..., api.ban: ..., admin.ban: ... ; the file API has no ban list: set [api.ban], ..., the admin routes have no ban list: set [admin.ban], ..., [api.ban] is set where it has no effect: ... (WARN) | Les cles d’un ban, Une liste par porte ([sftp.ban], [api.ban], [admin.ban]) | R-BAN-018 |
[api.ban] trusted_proxies [...] and [admin.ban] trusted_proxies [...] differ, while the file API and the admin routes share [admin] listen: ..., [admin.ban] trusted_proxies [...] is set and the file API has no [api.ban]: ..., [api.ban] trusted_proxies [...] is set and there is no [admin.ban], while ... share [admin] listen: ... | L’adresse d’un client HTTP ([api.ban], [admin.ban]) : les deux listes avec les memes trusted_proxies, ou [admin] control_listen | R-BAN-021 |
hidden_stores : prefixe en forme de verrou, aucun affixe, grace_secs hors bornes (... is too short: ...) | Ecritures atomiques ([server.hidden_stores], [[backends]], [[roles.mounts]]) | R-HIDDEN-004, R-HIDDEN-005, R-HIDDEN-014 |
uploads.takeover_idle_secs is not below uploads.idle_timeout_secs: ... | Deux uploads vers la meme destination ([uploads]) | R-RESERVE-017, R-CONFIG-010 |
WARN create_home is set on a mount whose backend is not local: ..., home_dir holds a marker that is not {username}: ..., follow_symlinks = true on this local backend: ... | Les cles communes sur un backend local, La racine et les liens symboliques, {username} | R-LOCAL-002, R-LOCAL-005, R-AUTH-032 |
lock_prefix invalide ; cross_instance_reservation = true is not supported on a local backend on Windows | Reservation entre instances ([[backends]]) | R-RESERVE-013, R-RESERVE-016 |
reload.poll_interval_secs = <n> is out of range: accepted values are 1 to 60 ; refusing to start avec reload.watch = "inotify" and the inotify instance cannot be created (ou a directory cannot be watched) | Rechargement ([reload]) : watch = "auto" ou "poll" | R-RELOAD-010 |
a [telemetry] metrics key is set where it has no effect, ... is set where it has no effect (WARN) | la page du guide de la cle nommee (reference) : la retirer | R-CONFIG-010 |
this secret is the example published in the README or the example files (WARN) | Secrets : changer le secret | R-CONFIG-012 |
outbound TLS is configured but there are no CA certificates to verify it with, ... (WARN), cause : SSL_CERT_FILE points at <chemin>, which does not exist, so it is ignored | Racines de confiance TLS (Variables d’environnement) | R-TRUST-014 |
Rechargement
Un fichier refuse au rechargement garde ce qui est en vigueur. Voir Rechargement.
| Message | Ou c’est regle | Regle |
|---|---|---|
configuration edited but not applied until restart (keys=...) | Ce qu’un rechargement applique, cle par cle (reference) : redemarrer | R-RELOAD-003 |
failed to reload users file, keeping old config, failed to reload roles file, keeping old config, failed to build backends registry from reloaded roles, keeping old config, failed to re-read the config for its log level, keeping the current one, [log] level is not a log level (accepted values: ...); keeping the log filter currently in force | Les comptes locaux, Les cles d’un role et d’un montage, Les cles de tout backend, [log] ([[users]], [[roles]], [[backends]], [log]) : le champ e dit la cause | R-RELOAD-005 |
password hashing pool size edit not applied: the pool is sized once, at startup | Verification des mots de passe ([auth]) | R-AUTH-014 |
[log] format edit ignored: ... | [log] ([log]) : redemarrer | R-AUDIT-029 |
[log] level edit ignored: <variable> is in force ... | Qui decide du niveau ([log], Variables d’environnement) : la variable l’emporte | R-CONFIG-007 |
admin TLS certificate reload failed, still serving the previous certificate ; admin TLS certificate reload refused, still serving the previous certificate (ERROR) | Ce qu’un rechargement applique, cle par cle, Les fichiers de confiance ([admin.tls]) : paire illisible, desaccordee ou refusee | R-RELOAD-008, R-TRUST-010 |
file hot reload cannot use inotify, falling back to re-reading the files every <n> s ; the file watcher lost events: its event queue overflowed, ..., the file watcher failed and may have lost events ... | Rechargement ([reload]) | R-RELOAD-010, R-RELOAD-012 |
reload panicked, previous configuration kept; hot reload still armed (ERROR) | a signaler | R-RELOAD-013 |
Connexion et authentification
reason des lignes connection_rejected, et ce que voit le client. Les portes
HTTP repondent une erreur en application/problem+json, champ detail.
reason, code ou detail | Ou c’est regle | Regle |
|---|---|---|
absent, 401 invalid credentials (l’explorateur : Invalid credentials ; 429 : Too many attempts) ; en DEBUG, local password authentication rejected (ou public key), reason no such user in the users file, password does not match the stored hash, the stored hash could not be parsed, no local user store configured, user has no authorities | Les comptes locaux ([[users]]) : mot de passe faux ou nom inconnu | R-AUDIT-022, R-AUTH-006, R-EXPLORER-006 |
no authorized key offered | La cle publique ([[users]]) : authorized_keys | R-AUTH-016 |
signature algorithm not allowed | Les algorithmes de signature d’une cle ([[roles]], [sftp.algorithms]) | R-AUTH-018 |
missing credential, empty credential, malformed credential ; 401 missing or invalid authorization header, invalid Basic auth, JWT not configured, local auth not configured | API REST de fichiers, Choisir les methodes ([auth.methods]) : envoyer Basic ou Bearer | R-REST-003 |
invalid token, expired token, wrong issuer, wrong audience, 401 invalid JWT | JWT ([auth.jwt]) : issuer, audience, cle | R-AUTH-022 |
verifier unavailable ; ERROR JWKS background refresh failed ... (le cache garde ses cles) | JWT, Brancher un fournisseur d’identite ([auth.jwt]) | R-AUTH-026, R-AUTH-027 |
no username claim, 401 token carries no username claim | JWT ([auth.jwt]) : username_path | R-AUTH-024 |
method disabled, 401 authentication method disabled | Choisir les methodes ([auth.methods]) | R-AUTH-003 |
no matching roles, 403 no roles resolved ; role resolution, 503 roles could not be resolved, retry later ; WARN authz service returned non-200, authz service call failed | D’ou viennent les roles, Le contrat du service d’autorisation ([[users]], [auth.jwt], [auth]) : authorities, authorities_path, authz_base_url | R-AUTH-029 |
mount conflict, 503 ; backend initialization failed, 500 ; deconnexion SFTP server configuration error: <cause>; see the server log | Cumuler des roles, Les types ([[roles.mounts]], [[backends]]) : le journal applicatif dit la cause | R-AUTH-030, R-AUTH-031 |
username not usable as home directory | {username} ([[roles.mounts]]) | R-AUTH-032 |
session limit, session rejected: session limit exceeded for user <nom> | Les cles de [sftp] ([server]) : max_sessions_per_user | R-SFTP-011 |
banned, 403 IP temporarily banned ; SFTP : deconnexion address banned, WARN address banned while this login was in flight — ... | La vie d’un ban, Lever un ban ([sftp.ban], [api.ban], [admin.ban]) | R-BAN-008, R-BAN-008 |
rate limit, 429 rate limit exceeded | Limites de debit ([sftp.rate_limit], [api.rate_limit]) | R-BAN-022 |
password checks saturated, 503 password checks saturated, retry later | Verification des mots de passe ([auth]) | R-AUTH-011 |
password checks saturated for address | Verification des mots de passe ([auth], [api.ban]) : NAT, trusted_proxies | R-AUTH-012 |
shutting down | Arret | R-AUTH-015 |
invalid ticket, expired ticket, revoked ticket, 403 invalid download ticket, download ticket expired, download ticket revoked ; 400 a download ticket is only redeemed by GET, ... is asked for with POST ?ticket, ... and an Authorization header are exclusive, ... only downloads a file, ?ticket and ?rename are exclusive | Telecharger : le ticket, API REST de fichiers : redemander un ticket | R-REST-009, R-REST-010 |
429 too many live download tickets | API REST de fichiers : 32 tickets vivants par utilisateur, attendre l’expiration du plus ancien | R-REST-009 |
range not satisfiable, 416 | API REST de fichiers : le Range commence apres la fin du fichier, le client l’a deja entier | R-REST-006 |
login grace time exceeded | SSH : [sftp] ([sftp]) : login_grace_secs | R-TIMEOUT-001 |
WARN failed to accept SFTP connections; retrying with backoff (descripteurs epuises, ulimit -n) | Porte SFTP | R-SFTP-002 |
SSH session ended: the peer offered no algorithm in common | Un vieux client ([sftp.algorithms]) | R-SFTP-010 |
SSH request refused: ... (shell, exec, renvoi de port) ; SSH_MSG_CHANNEL_FAILURE sur un second sous-systeme sftp | seul le sous-systeme sftp est servi, une fois par connexion : Portes | R-SFTP-012, R-SFTP-013 |
SSH_FX_FAILURE internal server error: this SFTP session is closed ; ERROR a thread panicked: a defect in the server, ... (panic_payload, location, thread, backtrace avec RUST_BACKTRACE=1) | un verbe a panique ; session_end reason=internal_error : a signaler | R-SFTP-019 |
Operations sur fichiers
reason des lignes d’operation, statut SFTP et code REST.
reason | SFTP | REST | Ou c’est regle | Regle |
|---|---|---|---|---|
acl | SSH_FX_PERMISSION_DENIED | 403 | Quelle entree decide ([[roles.mounts.acl]]) | R-ACL-003 |
acl subtree | SSH_FX_PERMISSION_DENIED | 403 | Les droits ([[roles.mounts.acl]]) : delete sur tout l’arbre | R-DELETE-005 |
synthetic path | SSH_FX_PERMISSION_DENIED | 403 | Repertoires synthetiques | R-ACL-005 |
rename across mounts | SSH_FX_OP_UNSUPPORTED | 422 | Un montage ou plusieurs | R-RENAME-010 |
invalid path | SSH_FX_PERMISSION_DENIED | 400 | caractere de controle, \, :, point final, nom court 8.3 : Les chemins des clients | R-UPLOAD-001 |
reserved name | SSH_FX_PERMISSION_DENIED | 403 | Deux uploads vers la meme destination | R-RESERVE-010 |
rename into restricted | SSH_FX_PERMISSION_DENIED | 403 | Les droits ([[roles.mounts.acl]]) : write a la destination | R-RENAME-008 |
exists | SSH_FX_FAILURE | 409, 412 | destination existante | R-RENAME-002 |
is a directory, not a directory | SSH_FX_FAILURE | 409 | rm d’un repertoire, rmdir d’un fichier | R-DELETE-002 |
upload in progress ; recursive delete refused: an upload is in progress beneath (WARN) | SSH_FX_PERMISSION_DENIED (curl : Permission denied (3)) | 409 | Deux uploads vers la meme destination | R-RESERVE-001, R-RESERVE-012 |
quota exceeded | SSH_FX_FAILURE | 507 | Plafonner la taille d’un fichier ([[roles.mounts]]) : max_file_mb | R-UPLOAD-007 |
session killed | SSH_FX_CONNECTION_LOST | - | session coupee : Sessions | R-SFTP-020 |
unsupported | SSH_FX_OP_UNSUPPORTED | 501 | Ecritures atomiques, Fichiers et repertoires sur S3 ([server.hidden_stores]) : reprise ou ajout, renvoyer le fichier entier | R-UPLOAD-009 |
upload in progress au CLOSE, client : upload not published: another upload took this file: <chemin> | SSH_FX_PERMISSION_DENIED | 409 | le verrou de cet upload a ete repris par une autre instance avant la publication (rafraichissement bloque) : rien n’est publie, renvoyer le fichier ; Reservation entre instances | R-RESERVE-008 |
taken over | SSH_FX_FAILURE sur l’ancien handle | 409 a l’ancien upload | un upload bloque (client suspendu) repris par une relance du meme compte : Deux uploads vers la meme destination ([uploads]) : takeover_idle_secs | R-RESERVE-017 |
upload idle timeout, upload below minimum rate | SSH_FX_FAILURE | 408 | Uploads : [uploads] ([uploads]) | R-UPLOAD-013 |
session ended: admin_kick | - | 503 the upload was cut by an administrator: nothing was written | un transfert REST coupe depuis la console : Sessions | R-REST-013 |
session ended: <cause>, session ended | - | - | le client est parti ; <cause> est le reason du session_end | R-AUDIT-018 |
commit interrupted (result=unknown) | - | - | client parti pendant la publication : verifier le fichier | R-AUDIT-017 |
no roles | - | 403 | voir no matching roles plus haut | R-AUDIT-020 |
| - | SSH_FX_OP_UNSUPPORTED | - | READLINK, SYMLINK, posix-rename@openssh.com : non servis | R-LIST-012 |
| - | - | 400 missing ?rename= query param ; 405 (verbe non servi) | API REST de fichiers | R-REST-002 |
| - | SSH_FX_FAILURE | - | handle inconnu ou d’un autre genre : bug du client | R-SFTP-017 |
Stockage
Une erreur du stockage porte son genre dans reason (result=error) ; son
texte est dans le journal applicatif, a la meme heure.
reason, message | SFTP | REST | Ou c’est regle | Regle |
|---|---|---|---|---|
not found | SSH_FX_NO_SUCH_FILE | 404 | Les cles communes sur un backend local ([[roles.mounts]]) : chemin absent ; home_dir absent sans create_home ; sur S3, un repertoire ne se renomme pas | R-UPLOAD-015, R-S3-004 |
permission denied | SSH_FX_PERMISSION_DENIED | 403 | droits du stockage ; S3 sans s3:ListBucket : Les droits du bucket ; WebHDFS (AuthorizationException, doAs non autorise) : Prerequis | R-UPLOAD-015, R-WEBHDFS-005 |
symlink escape | SSH_FX_PERMISSION_DENIED | 403 | La racine et les liens symboliques ([[backends]] local) : metrique craftfilegate_local_symlink_refusals_total | R-LOCAL-004 |
already exists, directory not empty | SSH_FX_FAILURE | 409 | etat du stockage | R-UPLOAD-015 |
storage error | SSH_FX_FAILURE backend error | 500 | le journal applicatif dit la cause | R-UPLOAD-015 |
not implemented | SSH_FX_OP_UNSUPPORTED | 501 | operation que ce backend n’a pas : Les types | R-UPLOAD-015 |
root <chemin> cannot be canonicalized and opened as a directory: <erreur> | - | - | La racine et les liens symboliques ([[backends]] local) | R-LOCAL-003 |
no host_key_fingerprint: the upstream's host key would not be checked, ... ; SFTP proxy: the upstream's host key does not match host_key_fingerprint (ERROR) | - | - | La cle d’hote de l’amont ([[backends]] sftp) : ssh-keyscan -p <port> <hote> | ssh-keygen -lf - | R-PROXY-002, R-PROXY-004 |
SFTP proxy: authentication failed: the upstream accepts only ssh-rsa (SHA-1) ... | - | - | Les cles ([[backends]] sftp) : cle ed25519 ou ECDSA | R-PROXY-005 |
WARN this store refused the conditional CopyObject with a 400 this code does not treat as "precondition not implemented": ... (chaque renommage echoue) ; could not list the multipart uploads under this backend's prefix, ..., listing the parts of a multipart upload was refused, ..., could not read the S3 service's clock (no usable Date header on its response) and ..., this S3 backend has no prefix, so its abandoned multipart uploads are never swept: ... | - | - | Les droits du bucket, Les uploads multipart, Les ecritures conditionnelles | R-S3-010, R-S3-013 |
SFTP proxy connect: ... ; WARN accept_any_host_key = true on this SFTP proxy backend: ..., sftp proxy: the upstream cannot replace a file atomically (posix-rename@openssh.com), ..., sftp proxy: the second SFTP channel used for posix-rename@openssh.com could not be opened (...), ... | - | - | La cle d’hote de l’amont, Les envois | R-PROXY-001, R-PROXY-003, R-PROXY-007 |
ERROR sftp proxy: the destination was removed to publish an upload and the rename ... which is kept, sftp proxy: an upload was interrupted after the removal of its destination ... which is kept (champs temp, destination) | - | - | Les envois : le fichier en cours est la seule copie, le renommer a la main | R-PROXY-008 |
the conditional writes are not proven on this S3 store: <pourquoi> (WARN), refus avec cross_instance_reservation ; INFO S3 upload precondition self-test verdict = ignored, not implemented, if-match ignored, delete refused, inconclusive | - | - | Les ecritures conditionnelles ([[backends]]) : cross_instance_reservation | R-S3-007, R-RESERVE-015 |
the SFTP upstream refuses the name of the upload lock files, ..., could not refresh the lock file of an upload in progress: ..., this upload's lock was taken over by another instance: it is not published (WARN) | - | - | Reservation entre instances ([[backends]]) : lock_prefix | R-RESERVE-005, R-RESERVE-007, R-RESERVE-008 |
backend "<nom>" (webhdfs): Knox refused the service account on GETFILESTATUS of the root ... ; session refusee : nom d’utilisateur qui ne peut pas etre un doAs ; WARN this WebHDFS backend's url is plain http ..., this WebHDFS backend's gateway could not be checked at startup ..., this WebHDFS answers no LISTSTATUS_BATCH ... | - | - | Prerequis, Le montage sur WebHDFS ([[backends]] webhdfs) : auth, url, ca_bundle | R-WEBHDFS-004, R-WEBHDFS-005, R-WEBHDFS-001, R-WEBHDFS-010 |
case_insensitive = true on a WebHDFS backend: ... | - | - | Le montage sur WebHDFS ([[backends]]) | R-WEBHDFS-014 |
the storage's clock differs from this server's by more than 30 s (WARN) ; stale in-flight files on this SFTP upstream are never collected (age_check = false): ..., stale in-flight files of this backend are aged on this server's clock (age_check = false): ..., abandoned multipart uploads of this S3 backend are aged on this server's clock (age_check = false): ..., could not read the storage's clock with a probe file in this directory (age_check is on), ..., this storage offers no lock to tell an in-flight upload from the leftovers of one killed with the server ... | - | - | Restes d’un transfert interrompu ([uploads.stale_partials]) : NTP du stockage | R-HIDDEN-016, R-HIDDEN-011, R-HIDDEN-013 |
this filesystem does not support RENAME_NOREPLACE ... (WARN) | - | - | Performances et limites : NFS, FUSE | R-LOCAL-011 |
backend unavailable: its storage did not answer the availability probe (WARN, backend, backend_type, failures, reason) ; backend available again: ... (WARN, down_secs) | - | - | Disponibilite ([server.backend_probe]) : reason dit ce que la visite a trouve (racine absente, bucket refuse, amont injoignable, cle d’hote differente, delai) | R-AVAIL-002 |
reason SFTP proxy: authentication failed — probe paused until reload | - | - | Proxy SFTP : le compte de service ou son mot de passe ; la sonde ne se reconnecte qu’au prochain rechargement des roles, pour ne pas faire bannir la passerelle par l’amont | R-AVAIL-001 |
Console et API
Code et detail | Ou c’est regle | Regle |
|---|---|---|
401 missing or invalid authorization header, invalid token | S’authentifier ([admin], [auth.jwt]) | R-ADMIN-005 |
401 invalid credentials sur POST /admin/login (compte pour [admin.ban] ; un compte sans role admin : admin sign-in refused: the password is right, ... en WARN), 503 password checks saturated, retry later, 400 expected a JSON body {"username": ..., "password": ...}, 415 expected Content-Type: application/json (un client qui n’envoie pas Content-Type: application/json), 403 sign-in from another site refused (Sec-Fetch-Site autre que same-origin ou none : une page d’un autre site ; ni l’un ni l’autre ne compte pour le ban), 400 username longer than 256 bytes ; 401 revoked token (compte retire, mot de passe change ; ou revoque, voir plus bas), 401 session too old: sign in again, 400 only a session token is renewed: ... | Se connecter ([admin.session], users_file) : se reconnecter | R-ADMIN-022 |
404 password sign-in is not available on this door sur POST /admin/login ; [admin.session] sets a session key or a revocation store, but no account signs in to the console: ... (WARN) ; console : seul le champ du jeton, pas de formulaire de mot de passe (GET /admin/login dit {"password": false}) | Session de console ([auth.methods], [[admin.roles]]) : mots de passe locaux et roles admin | R-ADMIN-022, R-ADMIN-018 |
401 revoked token apres POST /admin/revocations ou POST /admin/logout : se reconnecter ; lift local_only et WARN the session tokens were revoked on this instance only: ... ; admin session revocations are kept in memory beside a shared session key: ..., [admin.session] sets revocation keys this store does not read, shared admin session revocation records refused ..., ... ahead of this clock ... (WARN) ; ERROR the shared admin session revocations cannot be read: ... ; refus de demarrer ... the revocations cannot be read ..., admin.session.backend = ..., admin.session.reread_interval_secs must be between 1 and 30 ..., admin.session.revocation_configmap_name is empty ..., admin.session.persist_file <chemin> is also the persist_file of a ban list ... ; 400 expected a JSON body {"username": ...}, username blank or longer than 256 bytes, 404 this door issues no session token: there is nothing to revoke | Revoquer, se deconnecter, Partager les revocations ([admin.session]) : persist_file ou backend, NTP | R-ADMIN-023 |
POST /admin/grants : 400 unknown role, until in the past, invalid period, duration over max ; 403 role not grantable ; 409 role already held, mount conflict, already granted, too many grants ; 403 the grant permission is required ; 404 this door grants no temporary access (ecouteur sans [admin]) ; DELETE : 404 grant not found, 409 grant ended, grant ended: it is already <etat> ; lift local_only ; refus de demarrer admin.grants.* ..., [cluster] is set and the temporary access grants are kept in memory: ..., ... the grants cannot be read ... ; WARN [admin.grants] is set, but no credential holds the grant permission: ... ; session SFTP coupee temporary access expired / temporary access revoked, upload REST 503 the upload was cut: the temporary access it used ended; nothing was written ; WARN a temporary access grant names a role this server does not define: ignored, ... names an admin role: ignored ; ERROR the shared temporary access grants cannot be read: ... | Reference [admin.grants] : max_duration_secs, persist_file, backend | R-GRANT-002, R-GRANT-006, R-GRANT-003, R-GRANT-005, R-GRANT-009, R-GRANT-010 |
console : Wrong username or password. (un mot de passe faux, un nom inconnu ou un compte sans role admin : un seul message) ; Your session was revoked: sign in again., Your session expired: sign in again., Your session reached its maximum duration: sign in again., Token rejected: sign in again. ; la page redemande la connexion apres un rechargement ou dans un nouvel onglet | Dans la console ([admin.session]) : se reconnecter ; le jeton ne vit que dans la page | R-ADMIN-018 |
console blanche ou sans style derriere un reverse proxy, Refused to ... / violates the following Content Security Policy directive dans la console du navigateur | La console : la CSP du proxy permet au moins celle de la page | R-ADMIN-018 |
403 no matching admin roles ; 403 the <permission> permission is required | S’authentifier ([[admin.roles]]) | R-ADMIN-006, R-ADMIN-007 |
404 session not found: <id>, 400 invalid session ID format | Sessions | R-ADMIN-010 |
404 no log files: [log] dir is not set, 404 unknown log source: expected app or audit, 500 the log file could not be read, 403 the log file is a symbolic link, which the log viewer does not follow ; 400 lines: not a number, level: unknown level, q: longer than 256 bytes, field: ... ; 429 too many log reads at once: retry in a moment | Fichiers de log, Journaux et flux ([log]) | R-ADMIN-013 |
429 too many admin streams open: close one or retry later | Journaux et flux | R-ADMIN-014 |
unban 409 lift=overruled (un ban posterieur a la demande s’applique), 200 lift=local_only (etat partage non ecrit), 404 not banned, no ban manager, 400 unknown protocol (sftp, api ou admin) | Lever un ban, Partager les bans entre instances ([sftp.ban], [api.ban], [admin.ban]) | R-BAN-011 |
401 (404 avec l’explorateur, [api.ui]) sur /metrics, /admin, /health, /livez ou /readyz appeles sur admin.listen ; 404 sur <prefix> : [api] enabled absent, ou requete sur control_listen | Une porte ou deux ([admin], [api]) : avec control_listen ou probes_listen, chaque route a son port | R-METRICS-001, R-REST-001 |
404 ou 401 sur /api/docs, /api/openapi.json | API REST de fichiers ([api]) : openapi = true | R-REST-012 |
port injoignable de l’exterieur d’un conteneur, connection refused ; conteneur unhealthy (craft-file-gate healthcheck en echec) | Docker, Les outils du binaire ([admin]) : listen = "0.0.0.0:...", pas 127.0.0.1 ; l’adresse que healthcheck interroge | R-ADMIN-001, R-ADMIN-015 |
the admin door shares its listener with the file API ... (WARN) | Une porte ou deux ([admin]) : poser control_listen | R-ADMIN-002 |
admin TLS certificate expires soon, has expired, admin TLS certificate expiry could not be read | Ce que vous verrez ([admin.tls]) : renouveler ; un certificat expire est servi quand meme | R-ADMIN-004 |
Kubernetes
| Symptome ou message | Ou c’est regle | Regle |
|---|---|---|
sondes en echec, connection refused | Kubernetes ([sftp], [admin]) : listen = "0.0.0.0:..." ; sondes bloquees par la NetworkPolicy selon le CNI : le CIDR des noeuds dans networkPolicy.controlFrom | R-ADMIN-001 |
/readyz 503, data_runtime=unresponsive (runtime sature) ou sftp=not_accepting (port SFTP ferme, arret en cours) | Les sondes | R-K8S-002 |
rendu du chart en echec : networkPolicy.controlFrom is empty ..., config.existingConfigMap and config.inline are both set, no configuration: ..., adminRevocations.backend = ...: expected memory, file, configmap or empty, replicaCount > 1 with clusterSecret.enabled = false ..., replicaCount > 1 with a shared console session key and adminRevocations kept in memory ..., cluster is on (replicaCount > 1, or cluster.enabled) and clusterSecret.enabled is false ..., cluster.unreadyWhen names <valeur>: ... | Le chart, Le Secret partage des pods | R-K8S-005 |
backend = "configmap" refuse : ConfigMap illisible pendant 30 s (message nommant <namespace>/<nom> et le Role) ; WARN a chaque relecture des bans, propagation en 30 s (droit watch manquant) | Le partage par ConfigMap ([sftp.ban], [api.ban], [admin.ban]) : Role et RoleBinding | R-BAN-017 |
cannot read or fill the entry admin-session.key of Secret <ns>/<nom> ..., shared Secret not readable or writable yet; ... (WARN) | Le Secret partage des pods ([admin.session]) : le Secret cree par le chart, le Role (get, update sur ce nom) | R-ADMIN-022 |
cannot read the admin session revocations in ConfigMap <ns>/<nom> ..., admin session revocations not readable yet; ... (WARN) | Partager les revocations : la ConfigMap et le Role du chart (adminRevocations.backend: configmap, get, update, patch sur ce nom) | R-ADMIN-023 |
cannot read or fill the entry tls.key of Secret <ns>/<nom> ..., the entries tls.crt and tls.key of Secret <nom> do not go together ..., ... the key does not belong to the certificate ; WARN cluster peers name does not resolve: its last addresses are kept ; WARN cluster peer unreachable (seulement d’un pair qui a deja repondu ; avant, en DEBUG), cluster peer presents another certificate than this instance ..., cluster state cut to fit: ..., cluster peer state holds absurd records ..., cluster peer's failure series are all past their window ... (horloges a synchroniser, NTP) | Le certificat partage : le Secret et le Role du chart, une rotation en cours ; le port cluster dans la NetworkPolicy | R-CLUSTER-002, R-CLUSTER-006, R-CLUSTER-005, R-CLUSTER-003 |
onglet Instances, peers d’une liste scope=cluster, kick ou levee relayes : unauthorized on <instance>, forbidden on <instance> ; WARN audit: relayed credential refused ... sur le pair ; 400 unknown scope: ... (scope autre que local ou cluster) | Plusieurs instances : le meme jeton statique, la meme cle de session, le meme [auth.jwt] et les memes [[admin.roles]] partout | R-CLUSTER-009, R-CLUSTER-010, R-CLUSTER-008 |
backend = "configmap" refuse par un binaire sans la feature k8s | Les features du binaire | R-BAN-018 |
failed to create the file watcher, falling back to re-reading ... | inotify sur un noeud partage ([reload]) | R-RELOAD-010 |
pod OOMKilled pendant une rafale de connexions | Memoire, Verification des mots de passe ([auth]) | R-AUTH-014 |
« host key changed » d’un pod a l’autre ; WARN host key not found, generated a new one (sftp.generate_host_key) | Cle d’hote SSH ([sftp]) | R-SFTP-004 |
Journaux, metriques et telemetrie
| Message | Ou c’est regle | Regle |
|---|---|---|
craft-file-gate: <n> log line(s) could not be written ... (stderr) | Une piste incomplete | R-AUDIT-031 |
audit target disabled by RUST_LOG, audit successes disabled by RUST_LOG | RUST_LOG (Variables d’environnement) : RUST_LOG=warn,audit=info | R-AUDIT-002 |
process resource sampling failed; the process_* series are absent from /metrics | Metriques | R-METRICS-010 |
OTLP collector unreachable — telemetry spans will be dropped until recovery | Envois, relances et arret ([telemetry]) | R-TELEMETRY-010 |
failed to create the OTLP <signal> exporter, ... ([telemetry] on_exporter_error = "warn") (ERROR) | [telemetry] ([telemetry]) | R-TELEMETRY-003 |
sessions were still ending when the grace period ran out: ... | Regler l’orchestrateur ([server]) : shutdown_grace_period_secs | R-SHUTDOWN-007 |
ban file was still being written when the shutdown stopped waiting ; the shutdown stopped waiting for the removal of upload lock files; ... | Arret | R-BAN-019, R-SHUTDOWN-008 |