Configuration reference
A deployment is configured in two ways, and this page lists both. Startup settings are given in the environment the server starts in and change with a restart. Runtime settings are changed in the console under Settings → Settings, where each shows whether it applies at once or on the next restart; they can be given in the environment too, which then pins them.
Every setting is a key under jenrepo., and its environment variable is the key upper-cased with dots and dashes
as underscores: filesystem. is JENREPO_. A format, feed or other module is switched off with
JENREPO_, as described in Settings.
Startup settings
Store
| Key | Default | Effect |
|---|---|---|
store |
filesystem |
The store backend: filesystem, s3, gcs or azure-blob. |
filesystem. |
(required) | The directory the filesystem store keeps everything in; the server refuses to start without it. |
filesystem. |
strict |
strict forces every write to the disk before it answers, so an acknowledged write survives a power loss; relaxed leaves the flush to the operating system, so a power loss can roll back the last few seconds of writes but never tear one. Relaxed is for a development machine, whose disk often takes ten milliseconds or more per flush. |
s3. |
(required for s3) | The bucket. |
s3. |
us-east-1 |
The signing region. |
s3. |
(AWS) | An S3-compatible endpoint, such as MinIO; must be https. |
s3. |
(the AWS credential chain) | Static keys; set both or neither. |
s3. |
(SSE-S3) | A KMS key for server-side encryption. |
gcs. |
(required for gcs) | The bucket. |
gcs. |
(Application Default Credentials) | A service-account key file. |
gcs. |
(empty) | The project to create the bucket in on first use; empty means the bucket must exist. |
gcs. |
(Google) | Another endpoint, such as an emulator; must be https. |
azure-blob. |
(required for azure-blob) | The storage account connection string. |
azure-blob. |
jenesis-repository |
The blob container. |
s3. |
false |
Permit a plain-HTTP endpoint - for an emulator, never a deployment. |
s3. |
true |
Check at startup that the store honours conditional writes, and refuse to start if it does not. |
quota |
(empty - no cap) | The most the deployment may store, such as 10G; a publish over it is refused. |
Access
See Access.
| Key | Default | Effect |
|---|---|---|
auth |
true |
Require a key on every request. false serves everyone, and is reported as a security advisory. |
anonymous-rights |
(empty) | Rights granted to a request without a key, such as repository:read. |
read-only |
false |
Refuse every write at the store. |
bootstrap-key |
(empty) | A key provisioned at startup with every right on its tenant, for automation that needs one before anyone signs in. |
credential-default-lifetime |
(90 days) | How long a key issued without an expiry lives, as an ISO-8601 duration. |
credential-max-lifetime |
(no cap) | The longest any key may live. |
operator-tenant |
(the default tenant) | The tenant whose keys may administer the whole deployment - its settings, upstreams, logs and tenants. |
ui. |
(empty) | The administrator key that key sign-in accepts. |
ui. |
(empty) | Provider-qualified identifiers seeded as the deployment's administrators on every start. |
ui. |
(empty - off) | The OpenID Connect issuer and client. |
ui. |
Single sign-on |
The label on the OpenID Connect sign-in button. |
ui. |
(empty - off) | A GitHub OAuth app. Also runtime settings, under Sign-in, so they can be saved from the console. |
secrets-key |
(empty) | The key settings holding a secret - such as a sign-in client secret - are stored encrypted with: <key-id>:<base64 of 32 bytes>, several separated by commas, the first encrypting and every one decrypting. Without it such a setting is refused rather than stored. |
ui. |
(empty - off) | The directory to sign people in against. |
ui. |
(empty) | The distinguished name to bind as, with {0} for the name typed. |
ui. |
(empty) / (uid= |
Where and how to search for a person instead. |
ui. |
(empty) | The account to search with. |
ui. |
(empty) / (member= |
Where and how to find a person's groups. |
ui. |
(empty) | The group whose members administer the deployment. |
ui. |
false |
Upgrade a plain ldap:/ connection with StartTLS, or accept it as private. |
Serving
See Repositories.
| Key | Default | Effect |
|---|---|---|
tenancy |
fixed |
How a request's tenant is decided, read once at startup. fixed serves the one tenant default-tenant names and answers 404 for a URL naming any other; a name no installed routing answers to refuses to start. |
repositories. |
(empty) | A repository definition, as on Settings → Upstreams → Repository routing. It routes a repository that exists; it does not create one. |
proxy. |
(empty) | The upstream a format fetches a miss from, as on Settings → Upstreams → Format upstreams. |
proxy-miss-ttl |
60s |
How long an upstream miss is remembered. |
Several servers
| Key | Default | Effect |
|---|---|---|
consistency. |
false |
Have every server record a fingerprint of what it has seen, so a server that falls behind or disagrees is reported. |
consistency. |
(the host name) | This server's stable name among its peers. |
Runtime settings
The settings catalogue, as Settings → Settings shows it, grouped the same way. Level is the narrowest level a value may be set at: the deployment's alone, or also a tenant's, one repository's or one build-cache project's, each wider level holding the default the narrower one inherits - own only marks a setting with no wider default. Tier says whether the wizard of that level asks it (essential), the settings pages show it (standard), or fold it away as tuning (advanced). Applies says whether a change takes effect at once or on the next restart.
Access
Explained in Access.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
access-denied-status |
not-found |
deployment | advanced | at once | What a request for a tenant, a repository or an artifact the caller may not reach is answered, on every surface - the repository and registry paths, the build cache, the API and the console. not-found answers 404, exactly as a name that does not exist, so nobody can learn which tenants, repositories or artifacts exist by probing names and reading the status. forbidden answers 403, which tells a caller that their credential does not reach the name rather than that nothing is there, whether or not the name exists. |
Build cache
Explained in The build cache.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
build-cache |
true |
deployment | standard | on restart | Whether this deployment serves the remote build cache. |
Build cache project
Explained in The build cache.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
project-lru |
true |
project | advanced | at once | Which entries a size-cap sweep evicts first: the least recently used (the default), or the most recently used when switched off. |
project-size |
0 |
project | essential | at once | How many bytes a project's entries may take together; past it the least recently used entries are evicted after a write, and by the reaper. 0 is no cap. |
project-ttl |
(empty) | project | essential | at once | How long an entry nobody has read or written is kept before the reaper removes it (P30D, 30d); unset inherits the tenant's or the deployment's, none keeps entries for ever. |
Caches
Explained in Operations.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
auth. |
PT15M |
deployment | advanced | on restart | How long a node serves a credential's documents before asking the store again. |
cache. |
PT30S |
deployment | advanced | on restart | How long a node serves a listing it has already read - a packument, a Simple page, a Packages file, a tag list - from memory, so a burst of builds costs the store one read per document rather than one per build. |
cache. |
PT10S |
deployment | advanced | on restart | How long a node remembers that a coordinate it looked for was not there, and answers the same probe from memory instead of reading the store again - a build tool asking for a version range, a missing snapshot or an optional classifier asks the same question of the same repositories many times in a row. |
cache. |
PT5M |
deployment | advanced | on restart | How long a node serves a credential, a settings document, a ceiling or a tenant list it has already read before asking the store again. |
cache. |
PT6H |
deployment | advanced | on restart | How long a node serves a document it relayed from an upstream - a proxied maven-metadata.xml, packument or index the repository holds none of - from memory before fetching it again, so a burst of builds costs the upstream one fetch; this is how long a release published upstream may take to be listed here. Only a document the upstream served is remembered, and the memory is bounded. Zero switches it off. |
Collection
Explained in Retention, pins and cleanup.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
collect |
true |
deployment | standard | at once | Run the collector at the end of a walk, so the storage of content no live pointer names any more is freed. |
gc |
mark-sweep |
deployment | advanced | on restart | The collector to use, by name. |
gc. |
PT2H |
deployment | advanced | at once | A wall-clock floor on the gap between condemning a blob and deleting it, on top of the two-pass rule, so an upload whose pieces are unreferenced for a while - a push's layers before its manifest - is not collected when collection runs often. |
gc. |
20000 |
deployment | advanced | at once | Items the collector handles between checkpoints: the reference batch it holds in memory, the re-work a crash costs, and how often it renews a segment claim. |
Compliance
Explained in Screening what comes in.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
allow-redeploy |
false |
tenant | standard | at once | Off by default: release-version immutability refuses re-pointing an already-published immutable release coordinate at different bytes (a 409), a supply-chain / dependency-confusion guard. |
deny-list |
(empty) | deployment | standard | at once | Comma-separated coordinates an operator forbids; always refused. |
deny-list-action |
REJECT |
deployment | standard | at once | Verdict for a coordinate the deny list names. |
github |
false |
deployment | essential | at once | Consult the GitHub Advisory Database. |
github-endpoint |
https:/ |
deployment | advanced | at once | The GitHub REST API base URL, for a self-hosted GitHub or a proxy. |
inspection. |
STREAM |
deployment | advanced | at once | What to do with an artifact larger than the inspection prefix - jenrepo.inspection.prefix-bytes, 32 MiB by default - which is the most of one artifact an inspector is ever handed in memory. |
kev-auto-hold |
true |
deployment | advanced | on restart | When a scheduled scan finds an already-published artifact whose CVE is on a known-exploited catalogue, quarantine it for review (the same hold the gate writes). |
kev-auto-release |
true |
deployment | advanced | on restart | When a scheduled scan finds a retroactively KEV-held artifact whose CVE is no longer on any known-exploited catalogue (delisted, or the advisory retracted), automatically release the hold - the self-healing counterpart to KEV auto-hold. |
license-definitions |
(empty) | deployment | advanced | at once | Licenses to identify beyond the built-in table of SPDX licenses, one per line or separated by ';', each '<identifier> | <category> | <name or URL> | ...' - e.g. 'Acme-Internal-1.0 | proprietary | Acme Internal License | https://acme.example/license'. |
malware-action |
REJECT |
deployment | essential | at once | Verdict for a package the feed marks malicious: ALLOW, QUARANTINE or REJECT, which the console names Allow, Hold for review and Reject. |
openssf |
false |
deployment | essential | at once | Consult the curated OpenSSF malicious-packages feed (MAL- records, served by OSV.dev). |
openssf-endpoint |
https:/ |
deployment | advanced | at once | The OSV API base URL serving the dataset, for a mirror or a proxy. |
osv |
false |
deployment | essential | at once | Consult the OSV (osv.dev) vulnerability feed. |
osv-endpoint |
https:/ |
deployment | advanced | at once | The OSV API base URL, for a mirror or a proxy. |
policy-rules |
(empty) | tenant | standard | at once | Expression-based gate rules, one per line (or separated by ';'), each '<verdict> <expression>' where verdict is allow, quarantine or reject - e.g. 'quarantine #ecosystem == "npm" and #advisoryCount > 0' or 'quarantine !#licenses.?[#this matches "(?i).agpl."].empty'. |
provenance-admission-action |
QUARANTINE |
tenant | standard | at once | Verdict for an artifact whose inbound attestation fails verification - unsigned by a trusted key, signed for a different artifact, or an unexpected builder or source. |
provenance-admission-builder |
(empty) | tenant | standard | at once | Comma-separated builder identities an inbound attestation must name, e.g. "https://github.com/acme/.github/workflows/release.yml@refs/tags/*". |
provenance-admission-key |
(empty) | tenant | standard | at once | PEM public key(s) an inbound attestation's DSSE signature must verify against - the builder keys the tenant trusts. |
provenance-admission-source |
(empty) | tenant | standard | at once | Comma-separated source repository URIs an inbound attestation's provenance must have built from, e.g. "git+https://github.com/acme/*". |
provenance-attestation-sweep |
false |
deployment | advanced | at once | Reclaim provenance attestations whose artifact is gone. |
provenance-attestation-sweep-interval |
P1D |
deployment | advanced | at once | How often the attestation sweep runs. |
scan-full-every |
24 |
deployment | advanced | at once | Every Nth scheduled pass of the advisory scan, and of every other pass that re-reads what the repository holds, re-reads every published version; the passes between read only the versions published since the last full pass, and a catalogue that changed asks for a full pass at once. |
scan-interval-millis |
3600000 |
deployment | advanced | at once | Milliseconds between scheduled scans; each pass hits the upstream feeds. |
scan-lookback |
PT1M |
deployment | advanced | at once | How far before the last full pass's stamp an incremental pass still looks. |
scheduled-scan |
true |
deployment | standard | at once | Re-scan every repository's inventory against the advisory feeds on a schedule. |
signal-refresh-interval-millis |
300000 |
deployment | advanced | at once | Milliseconds between passes that draw a mirroring security signal (the known-exploited catalogue) into its stored snapshot, so a gate decision renders that snapshot instead of fetching on the publish thread. |
signature-attestation-lookup |
(empty) | tenant | advanced | at once | The attestation stores asked, by the artifact's digest, for the bundles they hold for an artifact just published, one <ecosystem> = <url> per line; the answer is kept beside the artifact and read as its evidence. |
signature-invalid |
REJECT |
tenant | standard | at once | Verdict for an artifact whose signature does not match its bytes - the artifact was altered after signing, or the signature was made for different content. |
signature-key-discovery |
(empty) | tenant | standard | at once | Sources to fetch the signing keys this deployment does not hold from, comma-separated, asked in the order named; empty (the default) fetches nothing and the pass does not run, so an installation makes no outbound call until this names a source. |
signature-key-discovery-accept |
false |
tenant | advanced | at once | Trust the keys the discovery sources served: a key looked up by its own id as if the operator had pasted it into the trusted signing keys, a key found through a maintainer for the artifacts that name that maintainer. |
signature-key-discovery-interval |
PT1H |
deployment | advanced | at once | How often the key-discovery pass asks the named sources for the keys still wanted, as a duration; a key a source did not have is asked for again after a day. |
signature-key-discovery-ubuntu-url |
https:/ |
tenant | advanced | at once | Where keyserver.ubuntu.com is reached - the public instance by default, or any host speaking the HKP lookup (op=get&options=mr&search=0x<key id>), which every SKS-descended keyserver and most internal mirrors do. |
signature-key-discovery-url |
https:/ |
tenant | advanced | at once | Where keys.openpgp.org is reached - the public instance by default, or an internal mirror of it that speaks the same lookup by key id. |
signature-missing |
ALLOW |
tenant | standard | at once | Verdict for an artifact carrying no signature where its format expects one. |
signature-missing-proxy |
ALLOW |
tenant | advanced | at once | Verdict for a proxied artifact carrying no signature where its format expects one. |
signature-provenance-accept |
(empty) | tenant | standard | at once | The OIDC issuers whose keyless identities are trusted by provenance, comma- or newline-separated - GitHub Actions' https://token.actions.githubusercontent.com being the one to name first. |
signature-quality-action |
ALLOW |
tenant | advanced | at once | What a signature below the quality floor does. |
signature-quality-floor |
none |
tenant | advanced | at once | The grade below which a signature raises a finding - none (the default, quality is reported and never gated), unusable, weak, acceptable or strong. |
signature-signer-changed |
QUARANTINE |
tenant | standard | at once | Verdict for a coordinate signed by a different signer than its earlier versions carried. |
signature-sigstore-trusted-root |
(empty) | tenant | advanced | at once | The Sigstore trusted root this deployment verifies bundles against - the JSON a cosign trusted-root or the public-good TUF repository serves, naming the Fulcio certificate authorities and the Rekor transparency logs to believe. |
signature-sigstore-trusted-root-interval |
P1D |
deployment | advanced | at once | How often the trusted root is fetched again, as a duration. |
signature-sigstore-trusted-root-url |
(empty) | tenant | advanced | at once | Where the Sigstore trusted root is fetched from when none is pasted above. |
signature-sweep |
false |
tenant | advanced | at once | Apply the signature dials below to what is already published: the sweep re-judges the signature outcome and grade the gate recorded for each version under the current dials and holds a version they no longer admit, in the same review queue as a publish-time hold. |
signature-sweep-interval |
P1D |
deployment | advanced | at once | How often the signature sweep runs while switched on, as a duration; every version is judged on its first and every Nth pass, the versions published since between. |
signature-trusted-certificates |
(empty) | tenant | advanced | at once | The PEM certificates a PKCS#7 (CMS) publisher signature must chain to - one or more concatenated -----BEGIN CERTIFICATE----- blocks: a NuGet author or repository signing root, a Swift registry's. |
signature-trusted-keys |
(empty) | tenant | standard | at once | The armoured OpenPGP public keys this deployment verifies publisher signatures against - one or more concatenated -----BEGIN PGP PUBLIC KEY BLOCK----- sections. |
signature-trusted-public-keys |
(empty) | tenant | advanced | at once | The PEM public keys a bare RSA publisher signature is verified against - an Alpine package's signature member, whose key the client keeps in /etc/apk/keys/. |
signature-trusted-signers |
(empty) | tenant | standard | at once | Per-namespace pinned signers, e.g. "org.apache.* = openpgp:0x1234ABCD", comma- or newline-separated, a trailing * matching a whole namespace. |
signature-untrusted |
ALLOW |
tenant | standard | at once | Verdict for a well-formed signature by a signer this deployment has no reason to believe - no key for it, or a key not admitted for that namespace. It is what every signed artifact reads as until an operator admits a signer, so by default it is served and the outcome recorded on the version. |
strict-hold-mapping |
false |
deployment | advanced | at once | Off by default: after an accepted publish through a blobs-namespace format, the publish-time hold-mapping round-trip check verifies the format's blobKeys/servedPaths resolve the served path and content hash just laid out (so a hold placed after the publish could retract it). |
vulnerability-action |
QUARANTINE |
deployment | essential | at once | Verdict for an artifact whose advisories reach the threshold below: ALLOW, QUARANTINE or REJECT, which the console names Allow, Hold for review and Reject. Holding it for review stores the bytes and withholds them until a reviewer releases or discards them; refusing it stores nothing. |
vulnerability-risk-threshold |
LOW |
deployment | standard | at once | The CVSS band from which a version's findings mark it as a risk, on its package's list of versions and on its own page. A finding below it is still listed with the repository's vulnerabilities but marks nothing; what is held is the vulnerability threshold's to decide. |
vulnerability-threshold |
CRITICAL |
deployment | essential | at once | The CVSS band at or above which a vulnerability brings the vulnerability action to bear; NONE switches the check off. |
Consistency
Explained in Running in production.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
consistency. |
PT15M |
deployment | advanced | on restart | How long a node may publish nothing before the fleet reports it dead rather than stale. |
consistency. |
PT24H |
deployment | advanced | on restart | How long a dead node's fingerprint is kept before the sweep removes it, so a decommissioned node leaves the report rather than sitting in it for good. |
consistency. |
(empty) | deployment | advanced | on restart | How often this node publishes its own fingerprint for the fleet to compare. |
consistency. |
PT5M |
deployment | advanced | on restart | How recently a node must have published its fingerprint to be counted live. |
consistency. |
PT1M |
deployment | advanced | on restart | How often a node publishes its own fingerprint and compares the fleet's. |
consistency. |
3 |
deployment | advanced | on restart | How many sweep intervals a node may fail to advance its cursor before it is reported stuck rather than merely behind. |
Console
Explained in Access.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
console |
true |
deployment | standard | on restart | Whether this deployment serves the admin console. |
key-login |
true |
deployment | essential | on restart | Whether the console accepts a pasted login key as a sign-in method - the way into a deployment before single sign-on is set up, on by default. |
First run
Explained in Settings.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
setup-wizard |
true |
deployment | standard | at once | Send a super-admin who signs in with the starter key to the first-run setup screen, which walks the decisions a new deployment should make: the starter credentials, the compliance verdicts, the advisory feeds, retention. |
Formats
Explained in Proxying upstreams.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
terraform. |
(empty) | deployment | advanced | on restart | The git hosts a proxied Terraform module's git source may be fetched from, so the module downloads through this repository rather than being cloned by the client. |
terraform. |
false |
deployment | advanced | on restart | Whether a proxied Terraform module whose git source cannot be fetched through this repository - its host is not in the git hosts, or it names no single ref - is refused rather than handed to the client to clone. |
terraform. |
/ |
deployment | advanced | on restart | The path this deployment serves its Terraform registry under, as the discovery document at /.well-known/terraform.json reports it. |
Hardening proxy
Explained in Proxying upstreams.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
harden-rescreen |
false |
deployment | advanced | at once | Back-fill a repository switched to harden late: a Lease-guarded, idempotent background pass re-screens the artifacts cached before hardening was enabled from their local bytes, records the digest-pinned verdict, and evicts any that re-screen non-ALLOW so a subsequent request re-fetches through the hardened leg. |
harden-rescreen-interval |
P1D |
deployment | advanced | at once | How often the migration re-screen sweep runs, as an ISO-8601 duration. |
Index
Explained in Repositories.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
index |
false |
deployment | standard | on restart | Publish an incremental, resumable repository index (Zstandard seekable chunks + descriptor) on the background sweep. |
index-interval |
P1D |
deployment | advanced | on restart | How often an incremental index chunk is published. |
index-max-chunk |
8388608 |
deployment | advanced | on restart | Maximum compressed size in bytes of one published index chunk before it rotates. |
index-rebase |
true |
deployment | advanced | at once | Rebase the published index onto a fresh chunk chain from every served pointer at the end of a walk of the store that carries this consumer (jenrepo.walks). |
Limits
Explained in Repositories.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
rate-limit |
0 |
tenant | standard | at once | Requests a minute a tenant's credentials make together before further ones are answered 429; 0 sets no ceiling. |
rate-limit-account |
0 |
tenant | advanced | at once | Requests a minute one credential makes before further ones are answered 429; 0 sets no ceiling of its own. |
rate-limit-address |
60000 |
deployment | advanced | at once | Requests a minute one client address makes, keyed or not, before further ones are answered 429; 0 sets no ceiling. |
tenant-quota |
0 |
tenant | standard | at once | The storage quota: how many bytes of stored content a tenant's repositories may hold together; 0 is unlimited. |
Maintenance
Explained in Operations.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
counters. |
PT1M |
deployment | advanced | on restart | How long a node holds the quota and folder-size deltas its publishes produce before folding them into one compare-and-set per counter; the node itself counts them at once. 0 writes every delta as it happens, one compare-and-set per publish per counter. |
inventory-backfill |
true |
deployment | advanced | on restart | Let the shared rebuild pass restore the inventory row of a blobs-namespace version whose row is missing, reading the coordinate back out of its own stored pointer - as a cached copy where its origin shows it was fetched from an upstream, as a release otherwise. |
listing-rebuild |
true |
deployment | advanced | at once | Regenerate, at the end of a walk of the store, the stored listings - the packuments, Simple pages, Packages files, repodata, sparse-index files, tag lists and search documents a client fetches, each maintained incrementally by the write that changes it and materialised on first read - so any drift an interrupted write could have left is corrected by the walk (jenrepo.walks) and never by a read. |
rebuild |
true |
deployment | advanced | at once | Drive every discovered walk consumer (a derived-metadata rebuilder's back-fill, refresh and self-heal route) from one shared enumeration of the pointer roots. |
reconcile |
true |
deployment | advanced | at once | Rebuild the publish-time inventory facts from the live pointer tree, in both directions, whenever a walk of the store runs: a crash that skipped a sidecar write converges instead of leaving a served artifact invisible to retention and the search and license index, and a crashed eviction's orphan facts and derived rows go. |
torn-write |
true |
deployment | advanced | at once | Judge crash-torn intermediate states whenever a walk of the store runs - a pointer whose blob is missing (flagged loudly; impossible under the blob-before-pointer ordering, so a signal of corruption) and a blob no pointer references (an orphan, confirmed and left to garbage collection). |
torn-write-apply |
false |
deployment | advanced | at once | When the torn-write reconcile is on, actually remove the dangling pointers a walk finds (a pointer that serves nothing because its blob is gone) rather than only flagging and counting them. |
walks |
(see the setting) | deployment | advanced | at once | The walks of the store this deployment schedules, as a JSON array of entries - each a name, a cron expression (Spring's grammar with seconds, in UTC) and the consumers that ride it ("*" for every one installed), enabled unless said otherwise. The rebuild entry is the walk a request runs, and carries the consumers it names like any other; without one, a request carries every consumer. |
withheld-reconcile |
true |
deployment | advanced | at once | Lift, whenever a walk of the store runs, a content-addressed withheld/<hash> serving marker for which no live holder remains - a marker stranded by two byte-identical aliases releasing at once, by a crash in the enforce sweep's marker-before-pointer window, or a pre-existing orphan. |
Maven
Explained in Connecting your build tools.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
maven-metadata-compute |
false |
deployment | advanced | on restart | Compute the artifact-level maven-metadata.xml on read rather than serving the publisher's stored document verbatim: reconcile only its <versions> list against the stored version folders (every other field preserved), and derive a document for a coordinate no client ever uploaded one for (an imported or batch-ingested repository). In a repository that also proxies, the document lists the upstream's versions beside the ones published here. |
Network
Explained in Running in production.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
block-private-import-hosts |
true |
deployment | advanced | on restart | Reject a migration URL - an import's source or an export's target - that is plaintext http, or that resolves to a loopback, link-local or private address. |
public-url |
(empty) | deployment | standard | on restart | The address clients reach this deployment at (https://repo.example.com), for the absolute URLs generated indexes carry. |
trusted-proxies |
(empty) | deployment | standard | on restart | Comma-separated CIDRs of reverse proxies whose X-Forwarded-For, X-Forwarded-Proto and X-Forwarded-Host are believed. |
trusted-sites |
(empty) | deployment | advanced | at once | Origins a browser may send a write from although they are not this deployment's own - comma-separated, each as a browser sends it (https://console.example.com). |
Operations
Explained in Operations.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
cleanup-lease |
PT10M |
deployment | advanced | on restart | How long one node holds the background-maintenance lease; keep under the task intervals. |
download-flush-interval |
PT6H |
deployment | advanced | on restart | How long download hits are held in memory before one compare-and-set adds them to the version's document and refreshes its last-download instant - at most one write per coordinate version per interval, and a count that lags by at most that. 0 or off writes on every drain. |
logs-buffer |
1000 |
deployment | advanced | on restart | How many most-recent log entries the in-memory recent-logs ring retains (the ring behind GET /api/logs and the operator GET /api/admin/logs) before the oldest is evicted. |
store-families |
false |
deployment | advanced | on restart | Count every store operation by the key family it touched as well as by its name, reported as jenrepo.store.family.<operation>.<family> beside jenrepo.store.ops.<operation>. |
track-downloads |
true |
deployment | advanced | on restart | Run the download-tracking worker; needed for the not-downloaded-for criterion. |
track-key-usage |
true |
deployment | advanced | on restart | Stamp each credential's last use, at most once per day. |
Outboxes
Explained in Operations.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
outbox-parked-cap |
0 |
deployment | advanced | on restart | A hard ceiling on a parked backlog: everything beyond the newest N is reclaimed whatever its age. |
outbox-parked-retention |
P30D |
deployment | advanced | on restart | How long a terminally-failed (parked) forward or webhook delivery is kept before its drain reclaims it. |
Proxy
Explained in Proxying upstreams.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
immaturity-hold-days |
2 |
deployment | essential | at once | Quarantine proxied artifacts the upstream published within this many days; 0 disables. |
proxy-allow-internal |
false |
deployment | advanced | on restart | Permit proxy upstreams, and the download URLs an upstream document advertises, that are plain http or resolve to a loopback, private, link-local or cloud-metadata address. |
proxy-enabled |
true |
deployment | standard | at once | Proxy reads that miss locally from the upstreams, caching and bridging them. |
proxy-fetch-deadline |
PT0S |
deployment | advanced | at once | The longest one upstream fetch may take, from the request to the last byte, before it is abandoned. |
proxy-throughput-floor |
16384 |
deployment | advanced | at once | The least an upstream fetch must deliver over each minute spent waiting on it, in bytes, or it is abandoned as the idle timeout abandons one that goes silent. |
PyPI
Explained in Proxying upstreams.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
pypi-provenance-url |
(empty) | deployment | advanced | on restart | Where the provenance document (PEP 740) of a proxied distribution is fetched from, the base of an integrity API answering <base>/<project>/<version>/<file>/provenance. |
Record lifetimes
Explained in Retention, pins and cleanup.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
export-job-ttl |
P7D |
deployment | advanced | at once | How long a finished export job's status stays before the scheduled cleanup dismisses it. |
import-job-ttl |
P7D |
deployment | advanced | at once | Auto-dismiss completed or failed migration jobs (and their remembered sources) this ISO-8601 duration after the sweep first sees them finished; a running job is never touched. |
quarantine-log-cap |
0 |
deployment | advanced | at once | Keep at most this many newest gate-decision log rows; 0 disables the count cap. |
quarantine-log-retention |
P180D |
deployment | advanced | at once | Remove gate-decision log rows older than this ISO-8601 duration on the scheduled cleanup pass; a still-held path keeps its verdict whatever its age. |
staging-ttl |
P30D |
deployment | advanced | at once | On the scheduled cleanup pass, drop open staging repositories untouched for this ISO-8601 duration (their staged artifacts are unpublished and garbage-collected) and remove promoted/dropped staging markers of the same age. |
Retention
Explained in Retention, pins and cleanup.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
cleanup-interval |
PT1H |
deployment | advanced | at once | How often the scheduled reaps run. |
keep-last |
0 |
repository | essential | at once | Keep at most this many newest versions per coordinate; 0 disables the count cap. |
max-age |
(empty) | repository | essential | at once | Evict versions older than this duration (P30D, 30d); unset inherits the tenant's or the deployment's rule, none switches the rule off for this repository. |
not-downloaded-for |
(empty) | repository | essential | at once | Evict versions not downloaded within this duration - it needs download tracking; unset inherits the tenant's or the deployment's rule, none switches the rule off for this repository. |
prerelease-expiry |
(empty) | repository | essential | at once | Evict prereleases older than this duration; unset inherits the tenant's or the deployment's rule, none switches the rule off for this repository. |
retention |
(empty) | deployment | advanced | at once | Select the retention engine by name; empty resolves the single enabled engine, and more than one enabled engine needs this setting to disambiguate them. |
scheduled-cleanup |
true |
deployment | advanced | at once | Run the scheduled reaps: finished import jobs past their time-to-live and a quota'd tenant's usage recount. |
Routing
Explained in Proxying upstreams.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
routing |
(empty) | repository (own only) | essential | at once | Whether this repository accepts uploads and where it fetches what it lacks, as clauses: writable, fallback <url> [nocache] [harden] [unscreened], fallback <repository>. |
RubyGems
Explained in Proxying upstreams.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
rubygems-attestations-url |
(empty) | deployment | advanced | on restart | Where the Sigstore attestations of a proxied gem are fetched from, the base of an API answering <base>/<name>-<version>.json with an array of bundles. |
Search
Explained in Repositories.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
full-text-search |
false |
repository | essential | at once | Keep a full-text index of this repository - package names, descriptions, keywords and authors - and answer searches from it. |
search-incremental |
true |
deployment | advanced | on restart | Apply only what changed (from the dirty-index feed) each pass instead of a full rebuild - the O(delta) steady state. |
search-index-claim |
PT10M |
deployment | advanced | on restart | How long an unfinished rebuild's claim on an index generation is honoured before another node's rebuild takes it over as a dead rebuild's - the cost a crashed or stalled node's rebuild puts on the fleet. |
search-index-interval |
PT10M |
deployment | advanced | on restart | How often the search-index pass applies what was published or removed since it last ran, for each repository with full-text search on. |
search-rebuild |
true |
deployment | advanced | at once | Rebuild the search index of each repository with full-text search on from truth, and compact its change feed, at the end of a walk of the store that carries this consumer (jenrepo.walks): the reconcile that heals whatever the feed missed. |
search-reconcile-interval |
(empty) | deployment | advanced | on restart | How long after its last full reconcile the pass rebuilds a repository's index from truth by itself, healing whatever the change feed missed; unset, the default, leaves the reconcile to the walk: the search-rebuild consumer rebuilds from truth and compacts the feed when a walk carrying it runs (jenrepo.walks). |
Serving
Explained in Connecting your build tools.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
folder-listing |
false |
repository | advanced | at once | Answer a folder URL of a Maven repository - a path ending in / - with a page listing what it serves, a thousand names at a time, for the clients that list a folder where maven-metadata.xml is missing (Coursier, sbt) and for people browsing. |
Sign-in
Explained in Settings.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
ui. |
(empty) | deployment | standard | at once | The client id of the GitHub OAuth app people sign in to the console with; empty, the sign-in page offers no GitHub button. Applies to the next sign-in. |
ui. |
(empty) | deployment | standard | at once | The client secret of the same app, stored encrypted with secrets-key. Applies to the next sign-in. |
Tenancy
Explained in Settings.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
default-tenant |
releases |
deployment | standard | on restart | Tenant a request resolves to when its key carries none. |
Uploads
Explained in Operations.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
batch-upload |
false |
deployment | advanced | at once | Explode a single PUT carrying the Jenesis-Explode: zip header into one publish per archive entry, each screened by the compliance gate. |
batch-upload-max-bytes |
4294967296 |
deployment | advanced | at once | The most bytes one exploded archive's entries may inflate to in all. |
batch-upload-max-entries |
10000 |
deployment | advanced | at once | The most members one exploded archive may publish; the walk stops at this cap. |
batch-upload-max-ratio |
100 |
deployment | advanced | at once | How many times the compressed bytes read an exploded archive may inflate to, once past a mebibyte - a ratio no archive of artifacts reaches and a zip bomb starts from. |
upload-max-bytes |
10737418240 |
deployment | advanced | at once | The most one request may send, in bytes: a publish declaring a larger body is refused with 413 before any of it is read, and one streaming without a declared length is refused at the byte that crosses it, so nothing of it is kept. |
Webhooks
Explained in Operations.
| Key | Default | Level | Tier | Applies | Effect |
|---|---|---|---|---|---|
webhook |
false |
deployment | standard | on restart | Deliver per-tenant HTTP callbacks over the background drain when an artifact is published or unpublished, the gate quarantines one, a hold is released or discarded, a finding is recorded, or a staged set is promoted. |
webhook-allow-internal |
false |
deployment | advanced | on restart | Permit webhook endpoints that resolve to a loopback, private, link-local or cloud-metadata address, AND plaintext http:// endpoints. |
webhook-attempts |
5 |
deployment | advanced | on restart | How many times a failing delivery is retried (with exponential backoff) before it is parked. |
webhook-endpoints |
(empty) | tenant | standard | on restart | One endpoint per line or semicolon: '<https-url> [events]'. 'events' is a comma-list of 'publish,unpublish,quarantine,release,discard,finding,promotion' or '*' (all). |
webhook-interval |
PT1M |
deployment | advanced | on restart | How often the webhook outbox is drained. |
webhook-secrets |
(empty) | tenant | standard | on restart | Per-endpoint HMAC-SHA256 signing secrets, one '<https-url>=<secret>' per line, keyed by the endpoint URL as it appears in 'webhook-endpoints'. |