JSON and YAML Configuration
Configure probod binary directly with a JSON or YAML file transmitted through the -cfg file, coverage structure, secrecy protection, and troubleshooting.
The probod binary reads the full runtime configuration from a JSON or YAML file.
probod -cfg-file /etc/probod/config.ymlprobod does not search for a default file when the binary is executed directly.
Configuration structure
Section entitled “Configuration structure”The root object contains two sections:
unitConfigures process-level metrics and OpenTelemetry exports.probodconfigures the application, database, authentication, storage, notifications, integrations and workers.
The following YAML shows the shape of a typical production configuration. It is an example rather than a complete scheme; available fields can vary between versions.
unit: metrics: addr: "0.0.0.0:8081" tracing: addr: "otel-collector:4318" max-batch-size: 512 batch-timeout: 5 export-timeout: 30 max-queue-size: 2048
probod: base-url: "https://probo.example.com" encryption-key: "<base64-encoded 32-byte key>" chrome-dp-addr: "chrome:9222"
api: addr: "0.0.0.0:8080" cors: allowed-origins: - "https://probo.example.com"
pg: addr: "postgres.example.com:5432" username: "probod" password: "<database password>" database: "probod" pool-size: 100 min-pool-size: 10
auth: disable-signup: false cookie: domain: "probo.example.com" secret: "<base64-encoded 32-byte key>" duration: 24 secure: true same-site: "lax" password: pepper: "<base64-encoded 32-byte key>" iterations: 1000000 oauth2-server: signing-keys: - private-key: | <PEM private key content goes here> kid: "default" active: true
aws: region: "eu-west-1" bucket: "probo-production"
notifications: mailer: sender-name: "Probo" sender-email: "no-reply@example.com" smtp: addr: "smtp.example.com:587" tls-required: trueOmit tracking when you don’t run an OpenTelemetry collector. For S3 onAWSsubmit static access keys when the workload has an IAM role. For another S3 compatible service, set endpoint and, if necessary, use-path-style: true.
JSON uses the same hierarchy and field names as YAML.
Protect the file
Section entitled “Protect the file”Keep it out of source control, restrict reading access to the account running probod and protect stored copies with the same controls as other production credentials.
chmod 600 /etc/probod/config.ymlSecret references, such as awssm://secret-id and awsps:///parameter-name are interpreted only by probod-bootstrap; probod does not resolve them.
The encryption key, session cookie secret, password pepper and token signature key must remain available for the lifetime of the implementation. Set persistent secrets before first boot before creating a production file.
Apply changes
Section entitled “Apply changes”The configuration is loaded once during the boot process. To apply an update:
- Prepare and protect the replacement file.
- Reopen each instance
probodwith the same configuration. - Confirms that each instance successfully starts before the previous file is deleted.
The faulty or incomplete replacement prevents the start of ___ZBT_I18N_RUNTIME_BLOCK_186__.
Troubleshoot startup
Title: Troubleshoot StartupWhen probod stops during boot:
- Read the first log error; subsequent failures can be consequences of it.
- Confirms that
-cfg-fileindicates a readable file. - Check the JSON or YAML syntax, indentation and scaling types.
- Check that the required values are present and the multiline PEM keys or certificates are complete.
- If parsing succeeds, check the connectivity to the configured database, object storage, SMTP server, Chrome endpoint, and telemetry collector.
Release compatibility
Section entitled “Release compatibility”The configuration scheme evolves with the platform. Review configuration changes before upgrading and use the scheme from the same version as the running binary version.
pkg/probodconfig
types.