Gateway Service Configuration

Introduction

The Infinite Scale Gateway service is responsible for passing requests to the storage providers. Other services never talk to the storage providers directly but will always send their requests via the `gateway` service.

Default Values

  • Gateway listens on port 9142 by default.

Caching

The gateway service can use a configured store via GATEWAY_STAT_CACHE_STORE. Possible stores are:

Store Type Description

memory

Basic in-memory store and the default.

ocmem

Advanced in-memory store allowing max size.

redis

Stores data in a configured Redis cluster.

redis-sentinel

Stores data in a configured Redis Sentinel cluster.

etcd

Stores data in a configured etcd cluster.

nats-js

Stores data using the key-value-store feature of NATS JetStream.

noop

Stores nothing. Useful for testing. Not recommended in production environments.

  1. Note that in-memory stores are by nature not reboot-persistent.

  2. Though usually not necessary, a database name and a database table can be configured for event stores if the event store supports this. Generally not applicable for stores of type in-memory. These settings are blank by default which means that the standard settings of the configured store apply.

  3. The gateway service can be scaled if not using in-memory stores and the stores are configured identically over all instances.

  4. When using redis-sentinel, the Redis master to use is configured via GATEWAY_STAT_CACHE_STORE_NODES in the form of <sentinel-host>:<sentinel-port>/<redis-master> like 10.10.0.200:26379/mymaster.

Configuration

Environment Variables

The gateway service is configured via the following environment variables. Read the Environment Variable Types documentation for important details.

  • 4.0.5

Environment variables for the gateway service
Name Type Default Value Description

OCIS_TRACING_ENABLED
GATEWAY_TRACING_ENABLED

bool

false

Activates tracing.

OCIS_TRACING_TYPE
GATEWAY_TRACING_TYPE

string

The type of tracing. Defaults to '', which is the same as 'jaeger'. Allowed tracing types are 'jaeger' and '' as of now.

OCIS_TRACING_ENDPOINT
GATEWAY_TRACING_ENDPOINT

string

The endpoint of the tracing agent.

OCIS_TRACING_COLLECTOR
GATEWAY_TRACING_COLLECTOR

string

The HTTP endpoint for sending spans directly to a collector, i.e. http://jaeger-collector:14268/api/traces. Only used if the tracing endpoint is unset.

OCIS_LOG_LEVEL
GATEWAY_LOG_LEVEL

string

The log level. Valid values are: 'panic', 'fatal', 'error', 'warn', 'info', 'debug', 'trace'.

OCIS_LOG_PRETTY
GATEWAY_LOG_PRETTY

bool

false

Activates pretty log output.

OCIS_LOG_COLOR
GATEWAY_LOG_COLOR

bool

false

Activates colorized log output.

OCIS_LOG_FILE
GATEWAY_LOG_FILE

string

The path to the log file. Activates logging to this file if set.

GATEWAY_DEBUG_ADDR

string

127.0.0.1:9143

Bind address of the debug server, where metrics, health, config and debug endpoints will be exposed.

GATEWAY_DEBUG_TOKEN

string

Token to secure the metrics endpoint.

GATEWAY_DEBUG_PPROF

bool

false

Enables pprof, which can be used for profiling.

GATEWAY_DEBUG_ZPAGES

bool

false

Enables zpages, which can be used for collecting and viewing in-memory traces.

OCIS_GATEWAY_GRPC_ADDR
GATEWAY_GRPC_ADDR

string

127.0.0.1:9142

The bind address of the GRPC service.

GATEWAY_GRPC_PROTOCOL

string

tcp

The transport protocol of the GRPC service.

OCIS_JWT_SECRET
GATEWAY_JWT_SECRET

string

The secret to mint and validate jwt tokens.

OCIS_REVA_GATEWAY

string

com.owncloud.api.gateway

The CS3 gateway endpoint.

OCIS_GRPC_CLIENT_TLS_MODE

string

TLS mode for grpc connection to the go-micro based grpc services. Possible values are 'off', 'insecure' and 'on'. 'off': disables transport security for the clients. 'insecure' allows using transport security, but disables certificate verification (to be used with the autogenerated self-signed certificates). 'on' enables transport security, including server certificate verification.

OCIS_GRPC_CLIENT_TLS_CACERT

string

Path/File name for the root CA certificate (in PEM format) used to validate TLS server certificates of the go-micro based grpc services.

GATEWAY_SKIP_USER_GROUPS_IN_TOKEN

bool

false

Disables the loading of user’s group memberships from the reva access token.

GATEWAY_COMMIT_SHARE_TO_STORAGE_GRANT

bool

true

Commit shares to storage grants. This grants access to shared resources for the share receiver directly on the storage.

GATEWAY_SHARE_FOLDER_NAME

string

Shares

Name of the share folder in users' home space.

GATEWAY_DISABLE_HOME_CREATION_ON_LOGIN

bool

true

Disable creation of the home space on login.

OCIS_TRANSFER_SECRET

string

The storage transfer secret.

GATEWAY_TRANSFER_EXPIRES

int

86400

Expiry for the gateway tokens.

OCIS_CACHE_STORE
GATEWAY_STAT_CACHE_STORE

string

noop

The type of the cache store. Supported values are: 'memory', 'ocmem', 'etcd', 'redis', 'redis-sentinel', 'nats-js', 'noop'. See the text description for details.

OCIS_CACHE_STORE_NODES
GATEWAY_STAT_CACHE_STORE_NODES

[]string

[]

A comma separated list of nodes to access the configured store. This has no effect when 'memory' or 'ocmem' stores are configured. Note that the behaviour how nodes are used is dependent on the library of the configured store.

OCIS_CACHE_DATABASE

string

ocis

The database name the configured store should use.

OCIS_CACHE_TTL
GATEWAY_STAT_CACHE_TTL

Duration

5m0s

Default time to live for user info in the cache. Only applied when access tokens has no expiration. The duration can be set as number followed by a unit identifier like s, m or h. Defaults to '300s' (300 seconds).

OCIS_CACHE_SIZE
GATEWAY_STAT_CACHE_SIZE

int

0

The maximum quantity of items in the cache. Only applies when store type 'ocmem' is configured. Defaults to 512.

OCIS_CACHE_STORE
GATEWAY_PROVIDER_CACHE_STORE

string

noop

The type of the cache store. Supported values are: 'memory', 'ocmem', 'etcd', 'redis', 'redis-sentinel', 'nats-js', 'noop'. See the text description for details.

OCIS_CACHE_STORE_NODES
GATEWAY_PROVIDER_CACHE_STORE_NODES

[]string

[]

A comma separated list of nodes to access the configured store. This has no effect when 'memory' or 'ocmem' stores are configured. Note that the behaviour how nodes are used is dependent on the library of the configured store.

OCIS_CACHE_DATABASE

string

ocis

The database name the configured store should use.

OCIS_CACHE_TTL
GATEWAY_PROVIDER_CACHE_TTL

Duration

5m0s

Default time to live for user info in the cache. Only applied when access tokens has no expiration. The duration can be set as number followed by a unit identifier like s, m or h. Defaults to '300s' (300 seconds).

OCIS_CACHE_SIZE
GATEWAY_PROVIDER_CACHE_SIZE

int

0

The maximum quantity of items in the cache. Only applies when store type 'ocmem' is configured. Defaults to 512.

OCIS_CACHE_STORE
GATEWAY_CREATE_HOME_CACHE_STORE

string

noop

The type of the cache store. Supported values are: 'memory', 'ocmem', 'etcd', 'redis', 'redis-sentinel', 'nats-js', 'noop'. See the text description for details.

OCIS_CACHE_STORE_NODES
GATEWAY_CREATE_HOME_CACHE_STORE_NODES

[]string

[]

A comma separated list of nodes to access the configured store. This has no effect when 'memory' or 'ocmem' stores are configured. Note that the behaviour how nodes are used is dependent on the library of the configured store.

OCIS_CACHE_DATABASE

string

ocis

The database name the configured store should use.

OCIS_CACHE_TTL
GATEWAY_CREATE_HOME_CACHE_TTL

Duration

5m0s

Default time to live for user info in the cache. Only applied when access tokens has no expiration. The duration can be set as number followed by a unit identifier like s, m or h. Defaults to '300s' (300 seconds).

OCIS_CACHE_SIZE
GATEWAY_CREATE_HOME_CACHE_SIZE

int

0

The maximum quantity of items in the cache. Only applies when store type 'ocmem' is configured. Defaults to 512.

OCIS_URL
GATEWAY_FRONTEND_PUBLIC_URL

string

https://localhost:9200

The public facing URL of the oCIS frontend.

GATEWAY_STORAGE_USERS_MOUNT_ID

string

Mount ID of this storage. Admins can set the ID for the storage in this config option manually which is then used to reference the storage. Any reasonable long string is possible, preferably this would be an UUIDv4 format.

YAML Example

Note that the filename shown below has been chosen on purpose.
See the Configuration File Naming for details when setting up your own configuration.

  • 4.0.5

# Autogenerated
# Filename: gateway-config-example.yaml

tracing:
  enabled: false
  type: ""
  endpoint: ""
  collector: ""
log:
  level: ""
  pretty: false
  color: false
  file: ""
debug:
  addr: 127.0.0.1:9143
  token: ""
  pprof: false
  zpages: false
grpc:
  addr: 127.0.0.1:9142
  tls: null
  protocol: tcp
token_manager:
  jwt_secret: ""
reva:
  address: com.owncloud.api.gateway
  tls:
    mode: ""
    cacert: ""
skip_user_groups_in_token: false
commit_share_to_storage_grant: true
share_folder_name: Shares
disable_home_creation_on_login: true
transfer_secret: ""
transfer_expires: 86400
cache:
  stat_cache_store: noop
  stat_cache_nodes: []
  stat_cache_database: ocis
  stat_cache_ttl: 5m0s
  stat_cache_size: 0
  provider_cache_store: noop
  provider_cache_nodes: []
  provider_cache_database: ocis
  provider_cache_ttl: 5m0s
  provider_cache_size: 0
  create_home_cache_store: noop
  create_home_cache_nodes: []
  create_home_cache_database: ocis
  create_home_cache_ttl: 5m0s
  create_home_cache_size: 0
frontend_public_url: https://localhost:9200
storage_registry:
  driver: spaces
  rules: []
  json: ""
  storage_users_mount_id: ""