# Configuration nfsd reads its configuration from the file the `-config` flag names, in TOML. Without `-config` no file is read and every setting comes from the flags and the built-in defaults; the file is never looked for in a default location. ## File A complete example with every key present: ```toml listen = ":2049" log-ops = false state-dir = "" max-connections = 0 [tls] cert = "" key = "" [[export]] path = "/srv/demo" read-only = false root-squash = false ``` ## Keys | Key | Type | Default | Effect | |---|---|---|---| | `listen` | string | `":2049"` | the TCP address to listen on, the `-addr` flag | | `log-ops` | boolean | `false` | log every operation to stderr, the `-log-ops` flag | | `state-dir` | string | `""` | the directory for persisted handles and opens, the `-state-dir` flag; empty means nothing persists | | `max-connections` | integer | `0` | the cap on live connections, the `-max-connections` flag; `0` means no cap | | `tls.cert` | string | `""` | the certificate chain in PEM for RPC-with-TLS (RFC 9289), the `-tls-cert` flag | | `tls.key` | string | `""` | the private key in PEM for RPC-with-TLS, the `-tls-key` flag | | `export.path` | string | | the directory to serve; required, the `-export` flag | | `export.read-only` | boolean | `false` | serve the export read only, the `-ro` flag | | `export.root-squash` | boolean | `false` | map a client claiming uid 0 onto nobody (65534), the `-root-squash` flag; the default keeps the trust AUTH_SYS gives to the claim, and operators serving untrusted clients are advised to turn it on | The `[[export]]` array carries exactly one table: this server serves one export. A future release that serves several exports lifts the count without changing the schema. ## Precedence The command line flags win, then the file, then the built-in defaults. A flag present on the command line overrides the file even when it carries the default value, so `-ro=false` keeps a `read-only = true` from the file at `false`. A key the file leaves out yields to the flag default. ## Validation A file that fails is a failed start up. A syntax error is reported with the file and the line: `nfsd: /etc/nfsd/nfsd.toml:2: expected '=' after key`. A key the schema does not carry is rejected, so a typo never slips through as an ignored setting. A file without exactly one `[[export]]`, or one without `path`, ends the start up with a message naming the file and the count.