Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Depannage

Un index des erreurs : le mot exact que vous voyez (message au demarrage, reason d’une ligne d’audit, statut SFTP, code REST) mene a la page du guide qui definit l’option en cause, puis, entre parentheses, a sa table dans la reference, et a l’identifiant de la regle de comportement, a citer au support. <...> marque une partie variable. Le vocabulaire complet des lignes d’audit est dans la reference.

Demarrage et configuration

Un reglage casse refuse le demarrage ; un reglage sans effet demarre avec un WARN qui nomme la cle.

MessageOu c’est regleRegle
--config is required when not using a subcommand, Configuration error: failed to read config file: <cause>Le fichier de configurationR-CONFIG-001
Configuration error: failed to parse config TOML: unknown field <cle>, expected one of ... (at line <l>, column <c>)la page du guide de la section nommee (reference) : la cle mal orthographieeR-CONFIG-005
... `sftp.<cle>` is now `server.<cle>`: move it to the [server] table : shutdown_grace_period_secs, max_sessions_per_user ou hidden_stores ecrite sous [sftp]Les cles de [sftp] ([server])R-CONFIG-015
[sftp]: this binary is built without the SFTP door (Cargo feature door-sftp) (ou [api], REST, door-rest), no door is configured, nothing would be served: ..., this binary is built without any door ...reference : [sftp], ou [api] avec [admin] ; Les features du binaire : un binaire construit sans cette porteR-CONFIG-016
server.probes_listen = <adresse> is also <cle> — the probes need a port of their ownUne porte ou deux ([server])R-ADMIN-020
server.backend_probe.<cle> = <n> is out of bounds: between <min> and <max>, server.backend_probe.timeout_secs = <n> is not below interval_secs = <m>: ...Disponibilite ([server.backend_probe])R-AVAIL-001
Configuration error: <section>: <cause>, <cle> = <n> is out of range: accepted values are <min> to <max>la page du guide de la section ou de la cle nommee (reference)R-CONFIG-010
Configuration error: failed to load local users: <cause>Les comptes locaux ([[users]])R-AUTH-004
duplicate username: <nom> — each [[users]] entry needs its own usernameLes comptes locaux ([[users]])R-CONFIG-011
user <nom> has a sha512-crypt password hash, which is not accepted — set [auth.methods] local.allow_sha512_crypt = true ... (ou bcrypt) ; WARN local user's password_hash is the example published in the README or the example files ..., local user's argon2 hash asks for more memory per verification than auth.methods.local.max_argon2_memory_kib allows: ..., local users whose password hash has another format or other parameters than most of the users file: ..., local users whose password hash cannot be verified (...): ..., accounts still depend on a legacy password hash flag: ..., legacy password hash flag enabled but no account uses this format ..., password hash is not argon2id — ...Les hashes ([auth.methods])R-AUTH-004, R-AUTH-005, R-AUTH-007, R-AUTH-008, R-AUTH-010, R-CONFIG-012
Configuration error: failed to load roles/backends: <cause> ; nom de role en double, role sans [[roles.mounts]], montage vers un backend inconnuLes cles d’un role et d’un montage, Les cles de tout backend ([[roles]], [[roles.mounts]], [[backends]])R-AUTH-028
unknown field backend (ou home_dir, acl) sous [[roles]] : une cle de montage ecrite au niveau du roleLes cles d’un role et d’un montage ([[roles.mounts]])R-CONFIG-005
role has no ACL entry: access is deny-by-default, ... (WARN)Ecrire une ACL ([[roles.mounts.acl]])R-ACL-003
role "<nom>" holds ACL paths that name one path on this backend, whose ACL compares paths folded (case and Unicode normalization), with different rights: [...]Casse des noms, Casse des chemins de l’ACL ([[roles.mounts.acl]], [[backends]])R-ACL-006
role missing required fields: role '<nom>': mount '<p>': home_dir = "<h>" climbs out of the backend's rootOu vont les fichiers ([[roles.mounts]])R-AUTH-032
user '<nom>': roles '<a>' and '<b>' both claim '<mount_path>' ... (au demarrage, ou failed to reload roles file) : montages en conflit d’un utilisateur localCumuler des roles, Recettes ([[roles.mounts]])R-AUTH-030
role '<nom>': user_key_algorithms: "<algorithme>" is not an algorithm this server supports; ...Les algorithmes de signature d’une cle ([[roles]])R-AUTH-019
no authentication methods enabledChoisir les methodes ([auth.methods])R-AUTH-001
aucune source de cle JWT, jwks_url avec une autre source, algorithm inconnu ; premier chargement JWKS en echec, the first fetch from auth.jwt.jwks_url failed, ... ; WARN auth.jwt.public_key_file is never read: ..., every JWT will be refused: auth.jwt.secret and auth.jwt.public_key_file are both set ..., [auth.jwt] is configured but auth.methods.jwt.enabled is false: ...JWT, Brancher un fournisseur d’identite ([auth.jwt])R-AUTH-020, R-AUTH-026, R-AUTH-025
auth: auth.hash_workers = 0 is refused: it must be between 1 and 1024 ...Verification des mots de passe ([auth])R-AUTH-014
unknown backend type "<type>": this binary knows <types>Les types, Les features du binaire ([[backends]])R-CONFIG-013
sftp.host_keys: <chemin> does not exist. Create it (ssh-keygen ...) or set sftp.generate_host_key ..., sftp.host_keys: cannot read <chemin>: <erreur> (la cle doit etre lisible par l’utilisateur de l’image)Cles d’hote, Docker, Secrets ([sftp])R-SFTP-003
une liste d’algorithmes refusee (nom inconnu, formes melangees, liste vide)Algorithmes ([sftp.algorithms])R-SFTP-006
[cluster] has no listen ..., ... has no peers ..., ... has no certificate source ..., ... sets both cert_file/key_file and secret_name ..., cluster.peers entry "<entree>" cannot be read: ..., cluster.secret_name is empty: ..., cluster.secret_name is set, but this binary was built without the k8s feature: ..., cannot listen on cluster.listen = <adresse>: <cause>, the cluster channel cannot start, refusing to boot: ..., cluster.<cle> is set without cluster.<autre> ..., cluster.peer_timeout_ms = <n> is out of bounds ..., cluster.listen = <adresse> is also <cle> ..., cluster certificate (cert_file=<c>, key_file=<k>): <raison> ; WARN [cluster] has nothing to add across instances: ...Plusieurs instances ([cluster])R-CLUSTER-001, R-CLUSTER-002
cluster.<cle> = <n> is out of bounds ..., cluster.unready_when names <detecteur>, but cluster.min_peers = 0 turns isolation off ..., ... but server.backend_probe.enabled = false ..., cluster.<cle> = <n> is under <min> s (...): one storage verdict could withdraw or restore the instance, CRAFT_FILE_GATE_CLUSTER_MIN_PEERS = ... cannot be read ..., CRAFT_FILE_GATE_CLUSTER_UNREADY_WHEN = "..." cannot be read: ... ; WARN a [cluster] detector key is set where it has no effectDetecteurs et retrait du service ([cluster])R-CLUSTER-016
WARN cluster detector active (detector, reason), cluster detector inactive ; withdrawn from service: ..., back in service: ... ; /readyz 503 withdrawn_by ; storage_alone actif sans retraitDetecteurs et retrait du service : storage_alone, le stockage de ce pod seul (montage, reseau du noeud) ; actif sans retrait : aucun pod en service et sain (sans backend en panne) ne voit tous ses backends en panne disponibles, ou un pod de plus petit identifiant passe d’abord ; isolated, le reseau entre pods ; isolated_and_storage_down, isole et chaque backend non local en panne : le reseau du noeud ; la raison est dans /admin/health (checks.cluster)R-CLUSTER-015, R-CLUSTER-016
<ancre>: [the directory ]<chemin> is <raison>: whoever can write there decides who gets in. ... ; a file this server trusts can be rewritten: ... (WARN)Les fichiers de confiance : chmod go-w, ou monter en lecture seuleR-TRUST-008
<ancre>: <chemin> is writable by the server's own group (<gid>): ...[security] ([security])R-TRUST-004
<ancre>: <chemin> cannot be resolved: <erreur>Les poserR-TRUST-007
cle privee lisible par les autres (WARN)Les fichiers de confianceR-TRUST-011
<X> and <X>_FILE are both set: one secret, two sources..., <X>_FILE is set but empty, ... is empty: an empty secret is no secret, ... is not UTF-8 textUn fichier plutot qu’une variable (Variables d’environnement)R-CONFIG-009
<VARIABLE>="<valeur>" is refused: it must be a whole number... ; env override ignored, the configured value stands, env override is empty (WARN)L’environnement (Variables d’environnement)R-CONFIG-008
server.shutdown_grace_period_secs must be > 0Arret ([server])R-SHUTDOWN-004
admin requires a bearer_token or at least one role under [[admin.roles]]S’authentifier ([admin], [[admin.roles]])R-ADMIN-001
admin.listen and sftp.listen are the same address — they cannot share a port, admin.control_listen = <adresse> is also admin.listen — the control door needs a port of its own, the admin door cannot start, refusing to boot: ... cannot listen on <adresse> (port deja pris)Une porte ou deux ([admin])R-ADMIN-001, R-ADMIN-002
tls: cert_file and key_file must both be set, tls: enabled but no cert source ..., tls: cert_file and auto_generate are mutually exclusive ; paire refusee au demarrage : <cause> (cert_file=<chemin>, key_file=<chemin>)Recommandations de deploiement ([admin.tls])R-ADMIN-001, R-ADMIN-003
[[admin.roles]] has an entry with a blank name, [[admin.roles]] names the role <nom> twice, [[admin.roles]] <nom> grants no permission: ..., unknown variant <permission> ; [[admin.roles]] is set but no credential can open the admin door: ...S’authentifier ([[admin.roles]], [auth.methods], [auth.jwt])R-ADMIN-006
role <nom> is also the name of an [[admin.roles]] entry: admin roles and file roles need different names (au demarrage, ou failed to reload roles file, keeping old config) ; an admin role and a file role have names that differ only by case or spaces: ... (WARN)S’authentifier ([[admin.roles]], [[roles]]) : renommer l’un des deuxR-ADMIN-006
this user's keys open no door: its authorities name no role with mounts, only admin roles, ... (WARN)S’authentifier ([[admin.roles]]) : retirer authorized_keys, ou donner un role de fichiersR-ADMIN-006
the admin door signs local accounts in with their passwords ... and has no [admin.ban]: ...Session de console ([admin.ban])R-ADMIN-022
admin.session.key_file <chemin> holds <n> bytes: a session key needs 32 at least ..., admin.session.key_file: ... writable by ..., admin.session.key_file <chemin>: <cause> ; admin.session.ttl_secs = <n> is out of range ..., admin.session.max_age_secs = <n> is under admin.session.ttl_secs ..., admin.session.key_file and admin.session.secret_name are both set ..., admin.session.secret_name is empty ..., admin.session.secret_name is set, but this binary was built without the k8s feature ...La cle de session ([admin.session]) : head -c 32 /dev/urandom, chmod 400 ; Les features du binaireR-ADMIN-022
auth.jwt.issuer = "craft-file-gate" is the issuer of the console's own session tokens ...[auth.jwt] : un autre issuerR-ADMIN-005
admin session key generated for this process: ... (WARN), jetons refuses par un autre pod ou apres un redemarrageLa cle de session ([admin.session]) : key_file ou secret_nameR-ADMIN-022
admin.allow_static_token = false, and a static admin token is set by <source>: ... ; the static admin token is enabled beside admin roles: ..., static admin token used: it is meant for break-glass only (WARN)S’authentifier ([admin]) : retirer le jeton de <source>, ou allow_static_token = falseR-ADMIN-024
api.enabled requires [admin] section to be configuredAPI REST de fichiers ([api], [admin])R-REST-001
[api.ui] enabled = true requires [api] enabled = true: ..., [api.ui] path "<path>" is not usable, ... collides with ...Explorateur ([api.ui], [api])R-EXPLORER-001, R-EXPLORER-002
[api] openapi = true requires [api] enabled = true: ...API REST de fichiers ([api])R-REST-012
admin.metrics_thresholds.jwks_age_secs = <age> is not above auth.jwt.jwks_refresh_interval_secs ... ; WARN a metrics threshold is set where it has no effect: ...Seuils de la console ([admin.metrics_thresholds], [auth.jwt])R-METRICS-017
invalid telemetry otlp_endpoint, invalid telemetry protocol, invalid telemetry metrics_interval_secs ; cannot build the OTLP <signal> exporter: ...; refusing to startLe point d’acces, [telemetry] ([telemetry]) : on_exporter_errorR-TELEMETRY-001, R-TELEMETRY-003
unknown ban backend ...: expected "file" or "configmap", sftp.ban: ..., api.ban: ..., admin.ban: ... ; the file API has no ban list: set [api.ban], ..., the admin routes have no ban list: set [admin.ban], ..., [api.ban] is set where it has no effect: ... (WARN)Les cles d’un ban, Une liste par porte ([sftp.ban], [api.ban], [admin.ban])R-BAN-018
[api.ban] trusted_proxies [...] and [admin.ban] trusted_proxies [...] differ, while the file API and the admin routes share [admin] listen: ..., [admin.ban] trusted_proxies [...] is set and the file API has no [api.ban]: ..., [api.ban] trusted_proxies [...] is set and there is no [admin.ban], while ... share [admin] listen: ...L’adresse d’un client HTTP ([api.ban], [admin.ban]) : les deux listes avec les memes trusted_proxies, ou [admin] control_listenR-BAN-021
hidden_stores : prefixe en forme de verrou, aucun affixe, grace_secs hors bornes (... is too short: ...)Ecritures atomiques ([server.hidden_stores], [[backends]], [[roles.mounts]])R-HIDDEN-004, R-HIDDEN-005, R-HIDDEN-014
uploads.takeover_idle_secs is not below uploads.idle_timeout_secs: ...Deux uploads vers la meme destination ([uploads])R-RESERVE-017, R-CONFIG-010
WARN create_home is set on a mount whose backend is not local: ..., home_dir holds a marker that is not {username}: ..., follow_symlinks = true on this local backend: ...Les cles communes sur un backend local, La racine et les liens symboliques, {username}R-LOCAL-002, R-LOCAL-005, R-AUTH-032
lock_prefix invalide ; cross_instance_reservation = true is not supported on a local backend on WindowsReservation entre instances ([[backends]])R-RESERVE-013, R-RESERVE-016
reload.poll_interval_secs = <n> is out of range: accepted values are 1 to 60 ; refusing to start avec reload.watch = "inotify" and the inotify instance cannot be created (ou a directory cannot be watched)Rechargement ([reload]) : watch = "auto" ou "poll"R-RELOAD-010
a [telemetry] metrics key is set where it has no effect, ... is set where it has no effect (WARN)la page du guide de la cle nommee (reference) : la retirerR-CONFIG-010
this secret is the example published in the README or the example files (WARN)Secrets : changer le secretR-CONFIG-012
outbound TLS is configured but there are no CA certificates to verify it with, ... (WARN), cause : SSL_CERT_FILE points at <chemin>, which does not exist, so it is ignoredRacines de confiance TLS (Variables d’environnement)R-TRUST-014

Rechargement

Un fichier refuse au rechargement garde ce qui est en vigueur. Voir Rechargement.

MessageOu c’est regleRegle
configuration edited but not applied until restart (keys=...)Ce qu’un rechargement applique, cle par cle (reference) : redemarrerR-RELOAD-003
failed to reload users file, keeping old config, failed to reload roles file, keeping old config, failed to build backends registry from reloaded roles, keeping old config, failed to re-read the config for its log level, keeping the current one, [log] level is not a log level (accepted values: ...); keeping the log filter currently in forceLes comptes locaux, Les cles d’un role et d’un montage, Les cles de tout backend, [log] ([[users]], [[roles]], [[backends]], [log]) : le champ e dit la causeR-RELOAD-005
password hashing pool size edit not applied: the pool is sized once, at startupVerification des mots de passe ([auth])R-AUTH-014
[log] format edit ignored: ...[log] ([log]) : redemarrerR-AUDIT-029
[log] level edit ignored: <variable> is in force ...Qui decide du niveau ([log], Variables d’environnement) : la variable l’emporteR-CONFIG-007
admin TLS certificate reload failed, still serving the previous certificate ; admin TLS certificate reload refused, still serving the previous certificate (ERROR)Ce qu’un rechargement applique, cle par cle, Les fichiers de confiance ([admin.tls]) : paire illisible, desaccordee ou refuseeR-RELOAD-008, R-TRUST-010
file hot reload cannot use inotify, falling back to re-reading the files every <n> s ; the file watcher lost events: its event queue overflowed, ..., the file watcher failed and may have lost events ...Rechargement ([reload])R-RELOAD-010, R-RELOAD-012
reload panicked, previous configuration kept; hot reload still armed (ERROR)a signalerR-RELOAD-013

Connexion et authentification

reason des lignes connection_rejected, et ce que voit le client. Les portes HTTP repondent une erreur en application/problem+json, champ detail.

reason, code ou detailOu c’est regleRegle
absent, 401 invalid credentials (l’explorateur : Invalid credentials ; 429 : Too many attempts) ; en DEBUG, local password authentication rejected (ou public key), reason no such user in the users file, password does not match the stored hash, the stored hash could not be parsed, no local user store configured, user has no authoritiesLes comptes locaux ([[users]]) : mot de passe faux ou nom inconnuR-AUDIT-022, R-AUTH-006, R-EXPLORER-006
no authorized key offeredLa cle publique ([[users]]) : authorized_keysR-AUTH-016
signature algorithm not allowedLes algorithmes de signature d’une cle ([[roles]], [sftp.algorithms])R-AUTH-018
missing credential, empty credential, malformed credential ; 401 missing or invalid authorization header, invalid Basic auth, JWT not configured, local auth not configuredAPI REST de fichiers, Choisir les methodes ([auth.methods]) : envoyer Basic ou BearerR-REST-003
invalid token, expired token, wrong issuer, wrong audience, 401 invalid JWTJWT ([auth.jwt]) : issuer, audience, cleR-AUTH-022
verifier unavailable ; ERROR JWKS background refresh failed ... (le cache garde ses cles)JWT, Brancher un fournisseur d’identite ([auth.jwt])R-AUTH-026, R-AUTH-027
no username claim, 401 token carries no username claimJWT ([auth.jwt]) : username_pathR-AUTH-024
method disabled, 401 authentication method disabledChoisir les methodes ([auth.methods])R-AUTH-003
no matching roles, 403 no roles resolved ; role resolution, 503 roles could not be resolved, retry later ; WARN authz service returned non-200, authz service call failedD’ou viennent les roles, Le contrat du service d’autorisation ([[users]], [auth.jwt], [auth]) : authorities, authorities_path, authz_base_urlR-AUTH-029
mount conflict, 503 ; backend initialization failed, 500 ; deconnexion SFTP server configuration error: <cause>; see the server logCumuler des roles, Les types ([[roles.mounts]], [[backends]]) : le journal applicatif dit la causeR-AUTH-030, R-AUTH-031
username not usable as home directory{username} ([[roles.mounts]])R-AUTH-032
session limit, session rejected: session limit exceeded for user <nom>Les cles de [sftp] ([server]) : max_sessions_per_userR-SFTP-011
banned, 403 IP temporarily banned ; SFTP : deconnexion address banned, WARN address banned while this login was in flight — ...La vie d’un ban, Lever un ban ([sftp.ban], [api.ban], [admin.ban])R-BAN-008, R-BAN-008
rate limit, 429 rate limit exceededLimites de debit ([sftp.rate_limit], [api.rate_limit])R-BAN-022
password checks saturated, 503 password checks saturated, retry laterVerification des mots de passe ([auth])R-AUTH-011
password checks saturated for addressVerification des mots de passe ([auth], [api.ban]) : NAT, trusted_proxiesR-AUTH-012
shutting downArretR-AUTH-015
invalid ticket, expired ticket, revoked ticket, 403 invalid download ticket, download ticket expired, download ticket revoked ; 400 a download ticket is only redeemed by GET, ... is asked for with POST ?ticket, ... and an Authorization header are exclusive, ... only downloads a file, ?ticket and ?rename are exclusiveTelecharger : le ticket, API REST de fichiers : redemander un ticketR-REST-009, R-REST-010
429 too many live download ticketsAPI REST de fichiers : 32 tickets vivants par utilisateur, attendre l’expiration du plus ancienR-REST-009
range not satisfiable, 416API REST de fichiers : le Range commence apres la fin du fichier, le client l’a deja entierR-REST-006
login grace time exceededSSH : [sftp] ([sftp]) : login_grace_secsR-TIMEOUT-001
WARN failed to accept SFTP connections; retrying with backoff (descripteurs epuises, ulimit -n)Porte SFTPR-SFTP-002
SSH session ended: the peer offered no algorithm in commonUn vieux client ([sftp.algorithms])R-SFTP-010
SSH request refused: ... (shell, exec, renvoi de port) ; SSH_MSG_CHANNEL_FAILURE sur un second sous-systeme sftpseul le sous-systeme sftp est servi, une fois par connexion : PortesR-SFTP-012, R-SFTP-013
SSH_FX_FAILURE internal server error: this SFTP session is closed ; ERROR a thread panicked: a defect in the server, ... (panic_payload, location, thread, backtrace avec RUST_BACKTRACE=1)un verbe a panique ; session_end reason=internal_error : a signalerR-SFTP-019

Operations sur fichiers

reason des lignes d’operation, statut SFTP et code REST.

reasonSFTPRESTOu c’est regleRegle
aclSSH_FX_PERMISSION_DENIED403Quelle entree decide ([[roles.mounts.acl]])R-ACL-003
acl subtreeSSH_FX_PERMISSION_DENIED403Les droits ([[roles.mounts.acl]]) : delete sur tout l’arbreR-DELETE-005
synthetic pathSSH_FX_PERMISSION_DENIED403Repertoires synthetiquesR-ACL-005
rename across mountsSSH_FX_OP_UNSUPPORTED422Un montage ou plusieursR-RENAME-010
invalid pathSSH_FX_PERMISSION_DENIED400caractere de controle, \, :, point final, nom court 8.3 : Les chemins des clientsR-UPLOAD-001
reserved nameSSH_FX_PERMISSION_DENIED403Deux uploads vers la meme destinationR-RESERVE-010
rename into restrictedSSH_FX_PERMISSION_DENIED403Les droits ([[roles.mounts.acl]]) : write a la destinationR-RENAME-008
existsSSH_FX_FAILURE409, 412destination existanteR-RENAME-002
is a directory, not a directorySSH_FX_FAILURE409rm d’un repertoire, rmdir d’un fichierR-DELETE-002
upload in progress ; recursive delete refused: an upload is in progress beneath (WARN)SSH_FX_PERMISSION_DENIED (curl : Permission denied (3))409Deux uploads vers la meme destinationR-RESERVE-001, R-RESERVE-012
quota exceededSSH_FX_FAILURE507Plafonner la taille d’un fichier ([[roles.mounts]]) : max_file_mbR-UPLOAD-007
session killedSSH_FX_CONNECTION_LOST-session coupee : SessionsR-SFTP-020
unsupportedSSH_FX_OP_UNSUPPORTED501Ecritures atomiques, Fichiers et repertoires sur S3 ([server.hidden_stores]) : reprise ou ajout, renvoyer le fichier entierR-UPLOAD-009
upload in progress au CLOSE, client : upload not published: another upload took this file: <chemin>SSH_FX_PERMISSION_DENIED409le verrou de cet upload a ete repris par une autre instance avant la publication (rafraichissement bloque) : rien n’est publie, renvoyer le fichier ; Reservation entre instancesR-RESERVE-008
taken overSSH_FX_FAILURE sur l’ancien handle409 a l’ancien uploadun upload bloque (client suspendu) repris par une relance du meme compte : Deux uploads vers la meme destination ([uploads]) : takeover_idle_secsR-RESERVE-017
upload idle timeout, upload below minimum rateSSH_FX_FAILURE408Uploads : [uploads] ([uploads])R-UPLOAD-013
session ended: admin_kick-503 the upload was cut by an administrator: nothing was writtenun transfert REST coupe depuis la console : SessionsR-REST-013
session ended: <cause>, session ended--le client est parti ; <cause> est le reason du session_endR-AUDIT-018
commit interrupted (result=unknown)--client parti pendant la publication : verifier le fichierR-AUDIT-017
no roles-403voir no matching roles plus hautR-AUDIT-020
-SSH_FX_OP_UNSUPPORTED-READLINK, SYMLINK, posix-rename@openssh.com : non servisR-LIST-012
--400 missing ?rename= query param ; 405 (verbe non servi)API REST de fichiersR-REST-002
-SSH_FX_FAILURE-handle inconnu ou d’un autre genre : bug du clientR-SFTP-017

Stockage

Une erreur du stockage porte son genre dans reason (result=error) ; son texte est dans le journal applicatif, a la meme heure.

reason, messageSFTPRESTOu c’est regleRegle
not foundSSH_FX_NO_SUCH_FILE404Les cles communes sur un backend local ([[roles.mounts]]) : chemin absent ; home_dir absent sans create_home ; sur S3, un repertoire ne se renomme pasR-UPLOAD-015, R-S3-004
permission deniedSSH_FX_PERMISSION_DENIED403droits du stockage ; S3 sans s3:ListBucket : Les droits du bucket ; WebHDFS (AuthorizationException, doAs non autorise) : PrerequisR-UPLOAD-015, R-WEBHDFS-005
symlink escapeSSH_FX_PERMISSION_DENIED403La racine et les liens symboliques ([[backends]] local) : metrique craftfilegate_local_symlink_refusals_totalR-LOCAL-004
already exists, directory not emptySSH_FX_FAILURE409etat du stockageR-UPLOAD-015
storage errorSSH_FX_FAILURE backend error500le journal applicatif dit la causeR-UPLOAD-015
not implementedSSH_FX_OP_UNSUPPORTED501operation que ce backend n’a pas : Les typesR-UPLOAD-015
root <chemin> cannot be canonicalized and opened as a directory: <erreur>--La racine et les liens symboliques ([[backends]] local)R-LOCAL-003
no host_key_fingerprint: the upstream's host key would not be checked, ... ; SFTP proxy: the upstream's host key does not match host_key_fingerprint (ERROR)--La cle d’hote de l’amont ([[backends]] sftp) : ssh-keyscan -p <port> <hote> | ssh-keygen -lf -R-PROXY-002, R-PROXY-004
SFTP proxy: authentication failed: the upstream accepts only ssh-rsa (SHA-1) ...--Les cles ([[backends]] sftp) : cle ed25519 ou ECDSAR-PROXY-005
WARN this store refused the conditional CopyObject with a 400 this code does not treat as "precondition not implemented": ... (chaque renommage echoue) ; could not list the multipart uploads under this backend's prefix, ..., listing the parts of a multipart upload was refused, ..., could not read the S3 service's clock (no usable Date header on its response) and ..., this S3 backend has no prefix, so its abandoned multipart uploads are never swept: ...--Les droits du bucket, Les uploads multipart, Les ecritures conditionnellesR-S3-010, R-S3-013
SFTP proxy connect: ... ; WARN accept_any_host_key = true on this SFTP proxy backend: ..., sftp proxy: the upstream cannot replace a file atomically (posix-rename@openssh.com), ..., sftp proxy: the second SFTP channel used for posix-rename@openssh.com could not be opened (...), ...--La cle d’hote de l’amont, Les envoisR-PROXY-001, R-PROXY-003, R-PROXY-007
ERROR sftp proxy: the destination was removed to publish an upload and the rename ... which is kept, sftp proxy: an upload was interrupted after the removal of its destination ... which is kept (champs temp, destination)--Les envois : le fichier en cours est la seule copie, le renommer a la mainR-PROXY-008
the conditional writes are not proven on this S3 store: <pourquoi> (WARN), refus avec cross_instance_reservation ; INFO S3 upload precondition self-test verdict = ignored, not implemented, if-match ignored, delete refused, inconclusive--Les ecritures conditionnelles ([[backends]]) : cross_instance_reservationR-S3-007, R-RESERVE-015
the SFTP upstream refuses the name of the upload lock files, ..., could not refresh the lock file of an upload in progress: ..., this upload's lock was taken over by another instance: it is not published (WARN)--Reservation entre instances ([[backends]]) : lock_prefixR-RESERVE-005, R-RESERVE-007, R-RESERVE-008
backend "<nom>" (webhdfs): Knox refused the service account on GETFILESTATUS of the root ... ; session refusee : nom d’utilisateur qui ne peut pas etre un doAs ; WARN this WebHDFS backend's url is plain http ..., this WebHDFS backend's gateway could not be checked at startup ..., this WebHDFS answers no LISTSTATUS_BATCH ...--Prerequis, Le montage sur WebHDFS ([[backends]] webhdfs) : auth, url, ca_bundleR-WEBHDFS-004, R-WEBHDFS-005, R-WEBHDFS-001, R-WEBHDFS-010
case_insensitive = true on a WebHDFS backend: ...--Le montage sur WebHDFS ([[backends]])R-WEBHDFS-014
the storage's clock differs from this server's by more than 30 s (WARN) ; stale in-flight files on this SFTP upstream are never collected (age_check = false): ..., stale in-flight files of this backend are aged on this server's clock (age_check = false): ..., abandoned multipart uploads of this S3 backend are aged on this server's clock (age_check = false): ..., could not read the storage's clock with a probe file in this directory (age_check is on), ..., this storage offers no lock to tell an in-flight upload from the leftovers of one killed with the server ...--Restes d’un transfert interrompu ([uploads.stale_partials]) : NTP du stockageR-HIDDEN-016, R-HIDDEN-011, R-HIDDEN-013
this filesystem does not support RENAME_NOREPLACE ... (WARN)--Performances et limites : NFS, FUSER-LOCAL-011
backend unavailable: its storage did not answer the availability probe (WARN, backend, backend_type, failures, reason) ; backend available again: ... (WARN, down_secs)--Disponibilite ([server.backend_probe]) : reason dit ce que la visite a trouve (racine absente, bucket refuse, amont injoignable, cle d’hote differente, delai)R-AVAIL-002
reason SFTP proxy: authentication failed — probe paused until reload--Proxy SFTP : le compte de service ou son mot de passe ; la sonde ne se reconnecte qu’au prochain rechargement des roles, pour ne pas faire bannir la passerelle par l’amontR-AVAIL-001

Console et API

Code et detailOu c’est regleRegle
401 missing or invalid authorization header, invalid tokenS’authentifier ([admin], [auth.jwt])R-ADMIN-005
401 invalid credentials sur POST /admin/login (compte pour [admin.ban] ; un compte sans role admin : admin sign-in refused: the password is right, ... en WARN), 503 password checks saturated, retry later, 400 expected a JSON body {"username": ..., "password": ...}, 415 expected Content-Type: application/json (un client qui n’envoie pas Content-Type: application/json), 403 sign-in from another site refused (Sec-Fetch-Site autre que same-origin ou none : une page d’un autre site ; ni l’un ni l’autre ne compte pour le ban), 400 username longer than 256 bytes ; 401 revoked token (compte retire, mot de passe change ; ou revoque, voir plus bas), 401 session too old: sign in again, 400 only a session token is renewed: ...Se connecter ([admin.session], users_file) : se reconnecterR-ADMIN-022
404 password sign-in is not available on this door sur POST /admin/login ; [admin.session] sets a session key or a revocation store, but no account signs in to the console: ... (WARN) ; console : seul le champ du jeton, pas de formulaire de mot de passe (GET /admin/login dit {"password": false})Session de console ([auth.methods], [[admin.roles]]) : mots de passe locaux et roles adminR-ADMIN-022, R-ADMIN-018
401 revoked token apres POST /admin/revocations ou POST /admin/logout : se reconnecter ; lift local_only et WARN the session tokens were revoked on this instance only: ... ; admin session revocations are kept in memory beside a shared session key: ..., [admin.session] sets revocation keys this store does not read, shared admin session revocation records refused ..., ... ahead of this clock ... (WARN) ; ERROR the shared admin session revocations cannot be read: ... ; refus de demarrer ... the revocations cannot be read ..., admin.session.backend = ..., admin.session.reread_interval_secs must be between 1 and 30 ..., admin.session.revocation_configmap_name is empty ..., admin.session.persist_file <chemin> is also the persist_file of a ban list ... ; 400 expected a JSON body {"username": ...}, username blank or longer than 256 bytes, 404 this door issues no session token: there is nothing to revokeRevoquer, se deconnecter, Partager les revocations ([admin.session]) : persist_file ou backend, NTPR-ADMIN-023
POST /admin/grants : 400 unknown role, until in the past, invalid period, duration over max ; 403 role not grantable ; 409 role already held, mount conflict, already granted, too many grants ; 403 the grant permission is required ; 404 this door grants no temporary access (ecouteur sans [admin]) ; DELETE : 404 grant not found, 409 grant ended, grant ended: it is already <etat> ; lift local_only ; refus de demarrer admin.grants.* ..., [cluster] is set and the temporary access grants are kept in memory: ..., ... the grants cannot be read ... ; WARN [admin.grants] is set, but no credential holds the grant permission: ... ; session SFTP coupee temporary access expired / temporary access revoked, upload REST 503 the upload was cut: the temporary access it used ended; nothing was written ; WARN a temporary access grant names a role this server does not define: ignored, ... names an admin role: ignored ; ERROR the shared temporary access grants cannot be read: ...Reference [admin.grants] : max_duration_secs, persist_file, backendR-GRANT-002, R-GRANT-006, R-GRANT-003, R-GRANT-005, R-GRANT-009, R-GRANT-010
console : Wrong username or password. (un mot de passe faux, un nom inconnu ou un compte sans role admin : un seul message) ; Your session was revoked: sign in again., Your session expired: sign in again., Your session reached its maximum duration: sign in again., Token rejected: sign in again. ; la page redemande la connexion apres un rechargement ou dans un nouvel ongletDans la console ([admin.session]) : se reconnecter ; le jeton ne vit que dans la pageR-ADMIN-018
console blanche ou sans style derriere un reverse proxy, Refused to ... / violates the following Content Security Policy directive dans la console du navigateurLa console : la CSP du proxy permet au moins celle de la pageR-ADMIN-018
403 no matching admin roles ; 403 the <permission> permission is requiredS’authentifier ([[admin.roles]])R-ADMIN-006, R-ADMIN-007
404 session not found: <id>, 400 invalid session ID formatSessionsR-ADMIN-010
404 no log files: [log] dir is not set, 404 unknown log source: expected app or audit, 500 the log file could not be read, 403 the log file is a symbolic link, which the log viewer does not follow ; 400 lines: not a number, level: unknown level, q: longer than 256 bytes, field: ... ; 429 too many log reads at once: retry in a momentFichiers de log, Journaux et flux ([log])R-ADMIN-013
429 too many admin streams open: close one or retry laterJournaux et fluxR-ADMIN-014
unban 409 lift=overruled (un ban posterieur a la demande s’applique), 200 lift=local_only (etat partage non ecrit), 404 not banned, no ban manager, 400 unknown protocol (sftp, api ou admin)Lever un ban, Partager les bans entre instances ([sftp.ban], [api.ban], [admin.ban])R-BAN-011
401 (404 avec l’explorateur, [api.ui]) sur /metrics, /admin, /health, /livez ou /readyz appeles sur admin.listen ; 404 sur <prefix> : [api] enabled absent, ou requete sur control_listenUne porte ou deux ([admin], [api]) : avec control_listen ou probes_listen, chaque route a son portR-METRICS-001, R-REST-001
404 ou 401 sur /api/docs, /api/openapi.jsonAPI REST de fichiers ([api]) : openapi = trueR-REST-012
port injoignable de l’exterieur d’un conteneur, connection refused ; conteneur unhealthy (craft-file-gate healthcheck en echec)Docker, Les outils du binaire ([admin]) : listen = "0.0.0.0:...", pas 127.0.0.1 ; l’adresse que healthcheck interrogeR-ADMIN-001, R-ADMIN-015
the admin door shares its listener with the file API ... (WARN)Une porte ou deux ([admin]) : poser control_listenR-ADMIN-002
admin TLS certificate expires soon, has expired, admin TLS certificate expiry could not be readCe que vous verrez ([admin.tls]) : renouveler ; un certificat expire est servi quand memeR-ADMIN-004

Kubernetes

Symptome ou messageOu c’est regleRegle
sondes en echec, connection refusedKubernetes ([sftp], [admin]) : listen = "0.0.0.0:..." ; sondes bloquees par la NetworkPolicy selon le CNI : le CIDR des noeuds dans networkPolicy.controlFromR-ADMIN-001
/readyz 503, data_runtime=unresponsive (runtime sature) ou sftp=not_accepting (port SFTP ferme, arret en cours)Les sondesR-K8S-002
rendu du chart en echec : networkPolicy.controlFrom is empty ..., config.existingConfigMap and config.inline are both set, no configuration: ..., adminRevocations.backend = ...: expected memory, file, configmap or empty, replicaCount > 1 with clusterSecret.enabled = false ..., replicaCount > 1 with a shared console session key and adminRevocations kept in memory ..., cluster is on (replicaCount > 1, or cluster.enabled) and clusterSecret.enabled is false ..., cluster.unreadyWhen names <valeur>: ...Le chart, Le Secret partage des podsR-K8S-005
backend = "configmap" refuse : ConfigMap illisible pendant 30 s (message nommant <namespace>/<nom> et le Role) ; WARN a chaque relecture des bans, propagation en 30 s (droit watch manquant)Le partage par ConfigMap ([sftp.ban], [api.ban], [admin.ban]) : Role et RoleBindingR-BAN-017
cannot read or fill the entry admin-session.key of Secret <ns>/<nom> ..., shared Secret not readable or writable yet; ... (WARN)Le Secret partage des pods ([admin.session]) : le Secret cree par le chart, le Role (get, update sur ce nom)R-ADMIN-022
cannot read the admin session revocations in ConfigMap <ns>/<nom> ..., admin session revocations not readable yet; ... (WARN)Partager les revocations : la ConfigMap et le Role du chart (adminRevocations.backend: configmap, get, update, patch sur ce nom)R-ADMIN-023
cannot read or fill the entry tls.key of Secret <ns>/<nom> ..., the entries tls.crt and tls.key of Secret <nom> do not go together ..., ... the key does not belong to the certificate ; WARN cluster peers name does not resolve: its last addresses are kept ; WARN cluster peer unreachable (seulement d’un pair qui a deja repondu ; avant, en DEBUG), cluster peer presents another certificate than this instance ..., cluster state cut to fit: ..., cluster peer state holds absurd records ..., cluster peer's failure series are all past their window ... (horloges a synchroniser, NTP)Le certificat partage : le Secret et le Role du chart, une rotation en cours ; le port cluster dans la NetworkPolicyR-CLUSTER-002, R-CLUSTER-006, R-CLUSTER-005, R-CLUSTER-003
onglet Instances, peers d’une liste scope=cluster, kick ou levee relayes : unauthorized on <instance>, forbidden on <instance> ; WARN audit: relayed credential refused ... sur le pair ; 400 unknown scope: ... (scope autre que local ou cluster)Plusieurs instances : le meme jeton statique, la meme cle de session, le meme [auth.jwt] et les memes [[admin.roles]] partoutR-CLUSTER-009, R-CLUSTER-010, R-CLUSTER-008
backend = "configmap" refuse par un binaire sans la feature k8sLes features du binaireR-BAN-018
failed to create the file watcher, falling back to re-reading ...inotify sur un noeud partage ([reload])R-RELOAD-010
pod OOMKilled pendant une rafale de connexionsMemoire, Verification des mots de passe ([auth])R-AUTH-014
« host key changed » d’un pod a l’autre ; WARN host key not found, generated a new one (sftp.generate_host_key)Cle d’hote SSH ([sftp])R-SFTP-004

Journaux, metriques et telemetrie

MessageOu c’est regleRegle
craft-file-gate: <n> log line(s) could not be written ... (stderr)Une piste incompleteR-AUDIT-031
audit target disabled by RUST_LOG, audit successes disabled by RUST_LOGRUST_LOG (Variables d’environnement) : RUST_LOG=warn,audit=infoR-AUDIT-002
process resource sampling failed; the process_* series are absent from /metricsMetriquesR-METRICS-010
OTLP collector unreachable — telemetry spans will be dropped until recoveryEnvois, relances et arret ([telemetry])R-TELEMETRY-010
failed to create the OTLP <signal> exporter, ... ([telemetry] on_exporter_error = "warn") (ERROR)[telemetry] ([telemetry])R-TELEMETRY-003
sessions were still ending when the grace period ran out: ...Regler l’orchestrateur ([server]) : shutdown_grace_period_secsR-SHUTDOWN-007
ban file was still being written when the shutdown stopped waiting ; the shutdown stopped waiting for the removal of upload lock files; ...ArretR-BAN-019, R-SHUTDOWN-008