jump to content

Configuration

Explains how probod loads its JSON/YAML configuration file at boot, the probod-bootstrap role, and what secrets should remain persistent during restart.

Show as Markdown

probod loads a JSON or YAML configuration file past with -cfg-file. The configuration is read at boot and is not re-loaded. After changing the file, restart each instance of the application for the new settings to come into effect.

For container-based implementations, the official image can instead use probod-bootstrap to generate a YAML file from the environment variables PROBOD_* before starting probod.

flowchart LR
    managed["JSON or YAML configuration"] --> probod["probod<br/>-cfg-file config"]
    environment["PROBOD_* environment variables"] --> bootstrap["probod-bootstrap"]
    bootstrap --> generated["Generated YAML configuration"]
    generated --> probod

probod-bootstrap is a one-time configuration generator. It stops after writing the file; does not run next to probod, monitors the environment or recharges the configuration.

Set persistent secrets before first boot

“Set persistent secrets before first boot”

Some configuration keys protect persistent data or authentication status. generate them before the first production starts, use the same values on each application instance and keep recoverable backups of them.

Setting Purpose The effect of its replacement or loss
Encryption key Encrypts sensitive application data Existing encrypted data becomes unreadable
Session cookie secret Signs authentication cookies Existing user sessions become invalid
Password pepper Protects stored password hashes Existing passwords can no longer be verified
OAuth 2.0 server signing key Token signals issued by the platform Previously issued tokens can no longer be verified

Ultima actualizare: