Housekeeping
Bifröst periodically removes expired sessions and resources that are no longer needed. Cleanup remains conservative when persisted state cannot be restored safely.
Cleanup guarantees
Session storage is deleted only after the session, environment, and authorization were disposed successfully. Transient or unknown errors retain the session for a later retry. Permanently unusable local authorization tokens can be removed during an audited disposal.
For an OIDC flow, lost access can dispose a session before its retention period ends. Disposal removes the locally stored token after successful cleanup; Bifröst does not need to revalidate that token with the provider before deletion. A temporary provider outage cannot indefinitely retain an otherwise expired session. A session with a known ValidUntil remains stored until that time plus keepExpiredFor, even if already disposed. Storage failures still prevent deletion. Audit failures prevent it under failurePolicy: strict; bestEffort may instead disable the audit log and continue. OIDC disposal does not revoke tokens at the provider.
Sealed session Recordings become eligible only after their retention period and every selected target's durable acknowledgement and success-audit marker. Housekeeping verifies and marks the signed receipt before deleting the artifact, then removes the receipt state. An interruption resumes this order without recreating deleted content. See Recording remote delivery and retention and the housekeeping.recording.delete.* events.
Removed flows
Sessions whose flow no longer exists are preserved because Bifröst can no longer interpret their environment and authorization tokens safely. Their resources are excluded from automatic orphan cleanup, and the skip is logged as housekeeping.orphaned-session.cleanup.skipped.
If a flow keeps its name but changes environment type, sessions with an old or unrecognized environment token are also left untouched. Bifröst logs a warning with the flow and session ID instead of disposing the session or letting the new environment discard a token that may still require account, process, or profile cleanup. Restore the original environment configuration to finish its cleanup, or inspect the session and its resources before removing anything manually. Such sessions remain stored until an operator resolves the mismatch, even after the retention period. Older sessions without an environment token have no persisted type information; Bifröst cannot detect a type change for them.
Corrupt sessions
Without automatic repair, corrupt entries are preserved and reported individually. Automatic repair is limited to configured flows; one corrupt entry does not block other sessions or environment cleanup. Even with automatic repair enabled, a corrupt session with a nonempty environment token is preserved for operator inspection rather than discarded with the token.
Properties
every
Duration = "10m"
How often the housekeeping should run.
initialDelay
Duration = 0
How long should be waited upon start of the application before the first run. If 0 it is also blocking, even before the first connection will be accepted.
autoRepair
bool = true
If true the service will try to repair potentially corrupt or broken states by itself, as long as this is safely possible.
keepExpiredFor
Duration = "336h"
For how long a disposed session will be kept. The session will no longer be usable, but it might be helpful for audit reasons.
Note
336h = 14 days