Configuration
Explains how probod loads its JSON/YAML configuration file at boot, the probod-bootstrap role, and what secrets should remain persistent during restart.
probod loads a JSON or YAML configuration file past with -cfg-file. The configuration is read at boot and is not re-loaded. After changing the file, restart each instance of the application for the new settings to come into effect.
Configuration sources
Section entitled “Configuration sources”For container-based implementations, the official image can instead use probod-bootstrap to generate a YAML file from the environment variables PROBOD_* before starting probod.
flowchart LR
managed["JSON or YAML configuration"] --> probod["probod<br/>-cfg-file config"]
environment["PROBOD_* environment variables"] --> bootstrap["probod-bootstrap"]
bootstrap --> generated["Generated YAML configuration"]
generated --> probod
probod-bootstrap is a one-time configuration generator. It stops after writing the file; does not run next to probod, monitors the environment or recharges the configuration.
Set persistent secrets before first boot
“Set persistent secrets before first boot”Some configuration keys protect persistent data or authentication status. generate them before the first production starts, use the same values on each application instance and keep recoverable backups of them.
| Setting | Purpose | The effect of its replacement or loss |
|---|---|---|
| Encryption key | Encrypts sensitive application data | Existing encrypted data becomes unreadable |
| Session cookie secret | Signs authentication cookies | Existing user sessions become invalid |
| Password pepper | Protects stored password hashes | Existing passwords can no longer be verified |
| OAuth 2.0 server signing key | Token signals issued by the platform | Previously issued tokens can no longer be verified |