Files
nfs/docs/CONFIGURATION.md
T
petrbalvin a9b8039ef7
Test / test (push) Successful in 2m4s
Release / gates (push) Successful in 2m5s
Release / build (amd64, freebsd) (push) Successful in 1m27s
Release / build (amd64, linux) (push) Successful in 1m22s
Release / build (amd64, netbsd) (push) Successful in 1m19s
Release / build (amd64, openbsd) (push) Successful in 1m20s
Release / build (arm64, darwin) (push) Successful in 1m21s
Release / build (arm64, freebsd) (push) Successful in 1m26s
Release / build (arm64, linux) (push) Successful in 1m25s
Release / build (arm64, netbsd) (push) Successful in 1m31s
Release / build (arm64, openbsd) (push) Successful in 1m27s
Release / build (loong64, linux) (push) Successful in 1m37s
Release / build (riscv64, linux) (push) Successful in 1m21s
Release / release (push) Successful in 40s
feat: full NFSv4.2 server and client in pure Go
Assisted-by: GLM 5.3 Flash
2026-09-21 18:51:17 +02:00

2.4 KiB

Configuration

nfsd reads its configuration from the file the -config flag names, in TOML. Without -config no file is read and every setting comes from the flags and the built-in defaults; the file is never looked for in a default location.

File

A complete example with every key present:

listen = ":2049"
log-ops = false
state-dir = ""
max-connections = 0

[tls]
cert = ""
key = ""

[[export]]
path = "/srv/demo"
read-only = false
root-squash = false

Keys

Key Type Default Effect
listen string ":2049" the TCP address to listen on, the -addr flag
log-ops boolean false log every operation to stderr, the -log-ops flag
state-dir string "" the directory for persisted handles and opens, the -state-dir flag; empty means nothing persists
max-connections integer 0 the cap on live connections, the -max-connections flag; 0 means no cap
tls.cert string "" the certificate chain in PEM for RPC-with-TLS (RFC 9289), the -tls-cert flag
tls.key string "" the private key in PEM for RPC-with-TLS, the -tls-key flag
export.path string the directory to serve; required, the -export flag
export.read-only boolean false serve the export read only, the -ro flag
export.root-squash boolean false map a client claiming uid 0 onto nobody (65534), the -root-squash flag; the default keeps the trust AUTH_SYS gives to the claim, and operators serving untrusted clients are advised to turn it on

The [[export]] array carries exactly one table: this server serves one export. A future release that serves several exports lifts the count without changing the schema.

Precedence

The command line flags win, then the file, then the built-in defaults. A flag present on the command line overrides the file even when it carries the default value, so -ro=false keeps a read-only = true from the file at false. A key the file leaves out yields to the flag default.

Validation

A file that fails is a failed start up. A syntax error is reported with the file and the line: nfsd: /etc/nfsd/nfsd.toml:2: expected '=' after key. A key the schema does not carry is rejected, so a typo never slips through as an ignored setting. A file without exactly one [[export]], or one without path, ends the start up with a message naming the file and the count.