Filesystem session
This variant of session is stored on the same local filesystem on which Bifröst is running.
Properties
type
Session Type = "fs"
Can be set to fs to enable the filesystem session. If absent, fs is always chosen by default.
idleTimeout
Duration = "30m"
For how long a session can be idle before it will forcibly be closed and disposed and can therefore not be used again. This can extend by actions of the client (regular interactions or keep alive) across all of client's connections.
maxTimeout
Duration = 0
The maximum duration of a session before it will forcibly be closed and disposed regardless whether there are actions or not.
maxConnections
uint16 = 0
The maximum amount of parallel connections of one session. Each new connecting connection will be instantly closed.
storage
File Path = "<os specific>"
Where the session information is stored locally.
Only one Bifröst process can open a filesystem session repository at a time. A non-blocking operating-system lock is held for the repository lifetime; startup fails if another process already owns the same storage or if the lock state cannot be determined safely. Session state updates use atomic file replacement so a process interruption cannot expose a partially written token.
The storage must not overlap an enabled audit log's journal, signing identity, encryption public-key file, or local SFTP target known_hosts and identity files. Bifröst resolves existing parents and symbolic links before checking these paths and rejects unsafe configurations during startup.
The default value is different, depending on the platform Bifröst runs on:
- Linux:
/var/lib/engity/bifroest/sessions - macOS:
/Library/Application Support/Engity/Bifroest/sessions - Windows:
C:\ProgramData\Engity\Bifroest\sessions
fileMode
File Mode = "0600"
All files/directories inside the session storage will be stored with this mode. Directories will always get the executable bit.
Compatibility
linux |
darwin |
windows |
|---|---|---|
| / | / | / |