jump to content

JSON and YAML Configuration

Configure probod binary directly with a JSON or YAML file transmitted through the -cfg file, coverage structure, secrecy protection, and troubleshooting.

Show as Markdown

The probod binary reads the full runtime configuration from a JSON or YAML file.

Terminal window
probod -cfg-file /etc/probod/config.yml

probod does not search for a default file when the binary is executed directly.

The root object contains two sections:

  • unit Configures process-level metrics and OpenTelemetry exports.
  • probod configures the application, database, authentication, storage, notifications, integrations and workers.

The following YAML shows the shape of a typical production configuration. It is an example rather than a complete scheme; available fields can vary between versions.

unit:
metrics:
addr: "0.0.0.0:8081"
tracing:
addr: "otel-collector:4318"
max-batch-size: 512
batch-timeout: 5
export-timeout: 30
max-queue-size: 2048
probod:
base-url: "https://probo.example.com"
encryption-key: "<base64-encoded 32-byte key>"
chrome-dp-addr: "chrome:9222"
api:
addr: "0.0.0.0:8080"
cors:
allowed-origins:
- "https://probo.example.com"
pg:
addr: "postgres.example.com:5432"
username: "probod"
password: "<database password>"
database: "probod"
pool-size: 100
min-pool-size: 10
auth:
disable-signup: false
cookie:
domain: "probo.example.com"
secret: "<base64-encoded 32-byte key>"
duration: 24
secure: true
same-site: "lax"
password:
pepper: "<base64-encoded 32-byte key>"
iterations: 1000000
oauth2-server:
signing-keys:
- private-key: |
<PEM private key content goes here>
kid: "default"
active: true
aws:
region: "eu-west-1"
bucket: "probo-production"
notifications:
mailer:
sender-name: "Probo"
sender-email: "no-reply@example.com"
smtp:
addr: "smtp.example.com:587"
tls-required: true

Omit tracking when you don’t run an OpenTelemetry collector. For S3 onAWSsubmit static access keys when the workload has an IAM role. For another S3 compatible service, set endpoint and, if necessary, use-path-style: true.

JSON uses the same hierarchy and field names as YAML.

Keep it out of source control, restrict reading access to the account running probod and protect stored copies with the same controls as other production credentials.

Terminal window
chmod 600 /etc/probod/config.yml

Secret references, such as awssm://secret-id and awsps:///parameter-name are interpreted only by probod-bootstrap; probod does not resolve them.

The encryption key, session cookie secret, password pepper and token signature key must remain available for the lifetime of the implementation. Set persistent secrets before first boot before creating a production file.

The configuration is loaded once during the boot process. To apply an update:

  1. Prepare and protect the replacement file.
  2. Reopen each instance probod with the same configuration.
  3. Confirms that each instance successfully starts before the previous file is deleted.

The faulty or incomplete replacement prevents the start of ___ZBT_I18N_RUNTIME_BLOCK_186__.

Troubleshoot startup

Title: Troubleshoot Startup

When probod stops during boot:

  1. Read the first log error; subsequent failures can be consequences of it.
  2. Confirms that -cfg-file indicates a readable file.
  3. Check the JSON or YAML syntax, indentation and scaling types.
  4. Check that the required values are present and the multiline PEM keys or certificates are complete.
  5. If parsing succeeds, check the connectivity to the configured database, object storage, SMTP server, Chrome endpoint, and telemetry collector.

The configuration scheme evolves with the platform. Review configuration changes before upgrading and use the scheme from the same version as the running binary version. pkg/probodconfig types.

Ultima actualizare: