| Shawn O. Pearce | e31d02c | 2009-12-08 12:21:37 -0800 | [diff] [blame] | 1 | Gerrit Code Review - Configuration |
| 2 | ================================== |
| Shawn O. Pearce | d2b73db | 2009-01-09 11:55:47 -0800 | [diff] [blame] | 3 | |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 4 | File `etc/gerrit.config` |
| 5 | ------------------------ |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 6 | |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 7 | The optional file `'$site_path'/etc/gerrit.config` is a Git-style |
| 8 | config file that controls many host specific settings for Gerrit. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 9 | |
| 10 | [NOTE] |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 11 | The contents of the `etc/gerrit.config` file are cached at startup |
| Brandon Casey | 4a21add | 2011-07-05 13:14:18 -0500 | [diff] [blame] | 12 | by Gerrit. If you modify any properties in this file, Gerrit needs |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 13 | to be restarted before it will use the new values. |
| 14 | |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 15 | Sample `etc/gerrit.config`: |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 16 | ---- |
| 17 | [core] |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 18 | packedGitLimit = 200 m |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 19 | |
| 20 | [cache] |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 21 | directory = /var/cache/gerrit2 |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 22 | ---- |
| 23 | |
| Dave Borowitz | 45baa89 | 2012-02-23 16:43:05 -0800 | [diff] [blame] | 24 | [[accounts]]Section accounts |
| 25 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 26 | |
| Matthias Sohn | f336066 | 2012-04-05 15:42:52 +0200 | [diff] [blame] | 27 | [[accounts.visibility]]accounts.visibility:: |
| Dave Borowitz | 45baa89 | 2012-02-23 16:43:05 -0800 | [diff] [blame] | 28 | + |
| 29 | Controls visibility of other users' dashboard pages and |
| 30 | completion suggestions to web users. |
| 31 | + |
| 32 | If `ALL`, all users are visible to all other users, even |
| 33 | anonymous users. |
| 34 | + |
| 35 | If `SAME_GROUP`, only users who are also members of a group the |
| 36 | current user is a member of are visible. |
| 37 | + |
| 38 | If `VISIBLE_GROUP`, only users who are members of at least one group |
| 39 | that is visible to the current user are visible. |
| 40 | + |
| 41 | If `NONE`, no users other than the current user are visible. |
| 42 | + |
| 43 | Default is `ALL`. |
| 44 | |
| Edwin Kempin | 49cb3e1 | 2011-06-29 14:35:14 +0200 | [diff] [blame] | 45 | [[addreviewer]]Section addreviewer |
| 46 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 47 | |
| 48 | [[addreviewer.maxWithoutConfirmation]]addreviewer.maxWithoutConfirmation:: |
| 49 | + |
| 50 | The maximum number of reviewers a user can add at once by adding a |
| 51 | group as reviewer without being asked to confirm the operation. |
| 52 | + |
| 53 | If set to 0, the user will never be asked to confirm adding a group |
| 54 | as reviewer. |
| 55 | + |
| 56 | Default is 10. |
| Edwin Kempin | 5e65d9b | 2011-07-08 07:35:48 +0200 | [diff] [blame] | 57 | + |
| 58 | This setting only applies for adding reviewers in the Gerrit WebUI, |
| 59 | but is ignored when adding reviewers with the |
| Edwin Kempin | 33e92d0 | 2011-07-11 22:00:57 +0200 | [diff] [blame] | 60 | link:cmd-set-reviewers.html[set-reviewers] command. |
| Edwin Kempin | 49cb3e1 | 2011-06-29 14:35:14 +0200 | [diff] [blame] | 61 | |
| 62 | [[addreviewer.maxAllowed]]addreviewer.maxAllowed:: |
| 63 | + |
| 64 | The maximum number of reviewers a user can add at once by adding a |
| 65 | group as reviewer. |
| 66 | + |
| 67 | If set to 0, there is no limit for the number of reviewers that can |
| 68 | be added at once by adding a group as reviewer. |
| 69 | + |
| 70 | Default is 20. |
| 71 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 72 | [[auth]]Section auth |
| 73 | ~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 74 | |
| 75 | See also link:config-sso.html[SSO configuration]. |
| 76 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 77 | [[auth.type]]auth.type:: |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 78 | + |
| Shawn O. Pearce | 2920ef3 | 2009-08-03 08:03:34 -0700 | [diff] [blame] | 79 | Type of user authentication employed by Gerrit. The supported |
| 80 | values are: |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 81 | + |
| 82 | * `OpenID` |
| 83 | + |
| 84 | The default setting. Gerrit uses any valid OpenID |
| 85 | provider chosen by the end-user. For more information see |
| Shawn O. Pearce | 2920ef3 | 2009-08-03 08:03:34 -0700 | [diff] [blame] | 86 | http://openid.net/[openid.net]. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 87 | + |
| James E. Blair | ca8bc3b | 2011-12-21 18:12:26 +0000 | [diff] [blame] | 88 | * `OpenID_SSO` |
| 89 | + |
| 90 | Supports OpenID from a single provider. There is no registration |
| 91 | link, and the "Sign In" link sends the user directly to the provider's |
| 92 | SSO entry point. |
| 93 | + |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 94 | * `HTTP` |
| 95 | + |
| Shawn O. Pearce | 2920ef3 | 2009-08-03 08:03:34 -0700 | [diff] [blame] | 96 | Gerrit relies upon data presented in the HTTP request. This includes |
| Edwin Kempin | f1acbb8 | 2011-09-15 12:49:42 +0200 | [diff] [blame] | 97 | HTTP basic authentication, or some types of commercial single-sign-on |
| Shawn O. Pearce | 2920ef3 | 2009-08-03 08:03:34 -0700 | [diff] [blame] | 98 | solutions. With this setting enabled the authentication must |
| 99 | take place in the web server or servlet container, and not from |
| 100 | within Gerrit. |
| 101 | + |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 102 | * `HTTP_LDAP` |
| 103 | + |
| 104 | Exactly like `HTTP` (above), but additionally Gerrit pre-populates |
| 105 | a user's full name and email address based on information obtained |
| 106 | from the user's account object in LDAP. The user's group membership |
| 107 | is also pulled from LDAP, making any LDAP groups that a user is a |
| 108 | member of available as groups in Gerrit. |
| 109 | + |
| Sasa Zivkov | eabc897 | 2010-10-04 15:47:08 +0200 | [diff] [blame] | 110 | * `CLIENT_SSL_CERT_LDAP` |
| 111 | + |
| 112 | This authentication type is actually kind of SSO. Gerrit will configure |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 113 | Jetty's SSL channel to request the client's SSL certificate. For this |
| Sasa Zivkov | eabc897 | 2010-10-04 15:47:08 +0200 | [diff] [blame] | 114 | authentication to work a Gerrit administrator has to import the root |
| 115 | certificate of the trust chain used to issue the client's certificate |
| 116 | into the <review-site>/etc/keystore. |
| 117 | After the authentication is done Gerrit will obtain basic user |
| 118 | registration (name and email) from LDAP, and some group memberships. |
| 119 | Therefore, the "_LDAP" suffix in the name of this authentication type. |
| 120 | This authentication type can only be used under hosted daemon mode, and |
| 121 | the httpd.listenUrl must use https:// as the protocol. |
| 122 | + |
| Shawn O. Pearce | f7e065e | 2009-09-26 20:01:10 -0700 | [diff] [blame] | 123 | * `LDAP` |
| 124 | + |
| 125 | Gerrit prompts the user to enter a username and a password, which |
| 126 | it then verifies by performing a simple bind against the configured |
| 127 | <<ldap.server,ldap.server>>. In this configuration the web server |
| 128 | is not involved in the user authentication process. |
| 129 | + |
| Shawn O. Pearce | c892d34 | 2010-02-17 17:00:50 -0800 | [diff] [blame] | 130 | The actual username used in the LDAP simple bind request is the |
| 131 | account's full DN, which is discovered by first querying the |
| 132 | directory using either an anonymous request, or the configured |
| Robin Rosenberg | a3baed0 | 2012-10-14 14:09:32 +0200 | [diff] [blame] | 133 | <<ldap.username,ldap.username>> identity. Gerrit can also use kerberos if |
| 134 | <<ldap.authentication,ldap.authentication>> is set to `GSSAPI`. |
| Shawn O. Pearce | c892d34 | 2010-02-17 17:00:50 -0800 | [diff] [blame] | 135 | |
| 136 | * `LDAP_BIND` |
| 137 | + |
| 138 | Gerrit prompts the user to enter a username and a password, which |
| 139 | it then verifies by performing a simple bind against the configured |
| 140 | <<ldap.server,ldap.server>>. In this configuration the web server |
| 141 | is not involved in the user authentication process. |
| 142 | + |
| 143 | Unlike LDAP above, the username used to perform the LDAP simple bind |
| 144 | request is the exact string supplied by in the dialog by the user. |
| Robin Rosenberg | 524a303 | 2012-10-14 14:24:36 +0200 | [diff] [blame] | 145 | The configured <<ldap.username,ldap.username>> identity is not used to obtain |
| Shawn O. Pearce | c892d34 | 2010-02-17 17:00:50 -0800 | [diff] [blame] | 146 | account information. |
| 147 | + |
| Shawn O. Pearce | 2920ef3 | 2009-08-03 08:03:34 -0700 | [diff] [blame] | 148 | * `DEVELOPMENT_BECOME_ANY_ACCOUNT` |
| 149 | + |
| 150 | *DO NOT USE*. Only for use in a development environment. |
| 151 | + |
| 152 | When this is the configured authentication method a hyperlink titled |
| 153 | `Become` appears in the top right corner of the page, taking the |
| 154 | user to a form where they can enter the username of any existing |
| 155 | user account, and immediately login as that account, without any |
| 156 | authentication taking place. This form of authentication is only |
| 157 | useful for the GWT hosted mode shell, where OpenID authentication |
| 158 | redirects might be risky to the developer's host computer, and HTTP |
| 159 | authentication is not possible. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 160 | |
| 161 | + |
| 162 | By default, OpenID. |
| 163 | |
| Shawn O. Pearce | 533cafc | 2010-05-11 16:05:27 -0700 | [diff] [blame] | 164 | [[auth.allowedOpenID]]auth.allowedOpenID:: |
| 165 | + |
| 166 | List of permitted OpenID providers. A user may only authenticate |
| 167 | with an OpenID that matches this list. Only used if `auth.type` |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 168 | is set to OpenID (the default). |
| Shawn O. Pearce | 533cafc | 2010-05-11 16:05:27 -0700 | [diff] [blame] | 169 | + |
| Magnus Bäck | e561183 | 2011-02-02 08:57:15 +0100 | [diff] [blame] | 170 | Patterns may be either a |
| 171 | link:http://download.oracle.com/javase/6/docs/api/java/util/regex/Pattern.html[standard |
| 172 | Java regular expression (java.util.regex)] (start with `^` and |
| Shawn O. Pearce | 533cafc | 2010-05-11 16:05:27 -0700 | [diff] [blame] | 173 | end with `$`) or be a simple prefix (any other string). |
| 174 | + |
| 175 | By default, the list contains two values, `http://` and `https://`, |
| 176 | allowing users to authenticate with any OpenID provider. |
| 177 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 178 | [[auth.trustedOpenID]]auth.trustedOpenID:: |
| Shawn O. Pearce | d7c026d | 2009-08-05 20:11:22 -0700 | [diff] [blame] | 179 | + |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 180 | List of trusted OpenID providers. Only used if `auth.type` is |
| Shawn O. Pearce | d7c026d | 2009-08-05 20:11:22 -0700 | [diff] [blame] | 181 | set to OpenID (the default). |
| 182 | + |
| 183 | In order for a user to take advantage of permissions beyond those |
| 184 | granted to the `Anonymous Users` and `Registered Users` groups, |
| 185 | the user account must only have OpenIDs which match at least one |
| 186 | pattern from this list. |
| 187 | + |
| Magnus Bäck | e561183 | 2011-02-02 08:57:15 +0100 | [diff] [blame] | 188 | Patterns may be either a |
| 189 | link:http://download.oracle.com/javase/6/docs/api/java/util/regex/Pattern.html[standard |
| 190 | Java regular expression (java.util.regex)] (start with `^` and |
| Shawn O. Pearce | d7c026d | 2009-08-05 20:11:22 -0700 | [diff] [blame] | 191 | end with `$`) or be a simple prefix (any other string). |
| 192 | + |
| 193 | By default, the list contains two values, `http://` and `https://`, |
| 194 | allowing Gerrit to trust any OpenID it receives. |
| 195 | |
| Mike Gouline | d2ab0cd | 2012-12-18 11:20:53 +1100 | [diff] [blame] | 196 | [[auth.openIdDomain]]auth.openIdDomain:: |
| 197 | + |
| 198 | List of allowed OpenID email address domains. Only used if |
| 199 | `auth.type` is set to "OPENID" or "OPENID_SSO". |
| 200 | + |
| 201 | Domain is case insensitive and must be in the same form as it |
| 202 | appears in the email address, for example, "example.com". |
| 203 | + |
| 204 | By default, any domain is accepted. |
| 205 | |
| Shawn O. Pearce | 89030bc | 2010-04-24 17:25:29 -0700 | [diff] [blame] | 206 | [[auth.maxOpenIdSessionAge]]auth.maxOpenIdSessionAge:: |
| 207 | + |
| 208 | Time in seconds before an OpenID provider must force the user |
| 209 | to authenticate themselves again before authentication to this |
| 210 | Gerrit server. Currently this is only a polite request, and users |
| 211 | coming from providers that don't support the PAPE extension will |
| 212 | be accepted anyway. In the future it may be enforced, rejecting |
| 213 | users coming from providers that don't honor the max session age. |
| 214 | + |
| 215 | If set to 0, the provider will always force the user to authenticate |
| 216 | (e.g. supply their password). Values should use common unit suffixes |
| 217 | to express their setting: |
| 218 | + |
| 219 | * s, sec, second, seconds |
| 220 | * m, min, minute, minutes |
| 221 | * h, hr, hour, hours |
| 222 | * d, day, days |
| 223 | * w, week, weeks (`1 week` is treated as `7 days`) |
| 224 | * mon, month, months (`1 month` is treated as `30 days`) |
| 225 | * y, year, years (`1 year` is treated as `365 days`) |
| 226 | |
| 227 | + |
| 228 | Default is -1, permitting infinite time between authentications. |
| 229 | |
| Shawn O. Pearce | 34f38cf | 2011-06-16 19:18:54 -0700 | [diff] [blame] | 230 | [[auth.maxRegisterEmailTokenAge]]auth.maxRegisterEmailTokenAge:: |
| 231 | + |
| 232 | Time in seconds before an email verification token sent to a user in |
| 233 | order to validate their email address expires. |
| 234 | + |
| 235 | * s, sec, second, seconds |
| 236 | * m, min, minute, minutes |
| 237 | * h, hr, hour, hours |
| 238 | * d, day, days |
| 239 | * w, week, weeks (`1 week` is treated as `7 days`) |
| 240 | * mon, month, months (`1 month` is treated as `30 days`) |
| 241 | * y, year, years (`1 year` is treated as `365 days`) |
| 242 | |
| 243 | + |
| Shawn O. Pearce | d6bd00b | 2012-01-20 12:40:51 -0800 | [diff] [blame] | 244 | Default is 12 hours. |
| Shawn O. Pearce | 34f38cf | 2011-06-16 19:18:54 -0700 | [diff] [blame] | 245 | |
| James E. Blair | ca8bc3b | 2011-12-21 18:12:26 +0000 | [diff] [blame] | 246 | [[auth.openIdSsoUrl]]auth.openIdSsoUrl:: |
| 247 | + |
| 248 | The SSO entry point URL. Only used if `auth.type` was set to |
| 249 | OpenID_SSO. |
| 250 | + |
| 251 | The "Sign In" link will send users directly to this URL. |
| 252 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 253 | [[auth.httpHeader]]auth.httpHeader:: |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 254 | + |
| 255 | HTTP header to trust the username from, or unset to select HTTP basic |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 256 | or digest authentication. Only used if `auth.type` is set to HTTP. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 257 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 258 | [[auth.logoutUrl]]auth.logoutUrl:: |
| Shawn O. Pearce | 12b5d84 | 2009-08-15 15:11:10 -0700 | [diff] [blame] | 259 | + |
| 260 | URL to redirect a browser to after the end-user has clicked on the |
| 261 | "Sign Out" link in the upper right corner. Organizations using an |
| 262 | enterprise single-sign-on solution may want to redirect the browser |
| 263 | to the SSO product's sign-out page. |
| 264 | + |
| 265 | If not set, the redirect returns to the list of all open changes. |
| 266 | |
| Shawn O. Pearce | c9d26b5 | 2009-12-16 08:05:27 -0800 | [diff] [blame] | 267 | [[auth.registerUrl]]auth.registerUrl:: |
| 268 | + |
| 269 | Target for the "Register" link in the upper right corner. Used only |
| 270 | when auth.type is `LDAP`. |
| 271 | + |
| 272 | If not set, no "Register" link is displayed. |
| 273 | |
| Chad Horohoe | 6589708 | 2012-11-10 10:26:25 -0800 | [diff] [blame] | 274 | [[auth.registerText]]auth.registerText:: |
| 275 | + |
| 276 | Text for the "Register" link in the upper right corner. Used only |
| 277 | when auth.type is `LDAP`. |
| 278 | + |
| 279 | If not set, defaults to "Register". |
| 280 | |
| David Pursehouse | 3d60449 | 2013-01-25 17:41:53 +0900 | [diff] [blame] | 281 | [[auth.editFullNameUrl]]auth.editFullNameUrl:: |
| 282 | + |
| 283 | Target for the "Edit" button when the user is allowed to edit their |
| 284 | full name. |
| 285 | |
| 286 | [[auth.httpPasswordUrl]]auth.httpPasswordUrl:: |
| 287 | + |
| 288 | Target for the "Obtain Password" link. Used only when auth.type is |
| 289 | `LDAP`, `LDAP_BIND` or `CUSTOM_EXTENSION`. |
| 290 | + |
| 291 | |
| Piotr Sikora | 7cec2f8 | 2011-02-26 12:57:30 +0000 | [diff] [blame] | 292 | [[auth.cookiePath]]auth.cookiePath:: |
| 293 | + |
| 294 | Sets "path" attribute of the authentication cookie. |
| 295 | + |
| 296 | If not set, HTTP request's path is used. |
| 297 | |
| 298 | [[auth.cookieSecure]]auth.cookieSecure:: |
| 299 | + |
| 300 | Sets "secure" flag of the authentication cookie. If true, cookies |
| 301 | will be transmitted only over HTTPS protocol. |
| 302 | + |
| 303 | By default, false. |
| 304 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 305 | [[auth.emailFormat]]auth.emailFormat:: |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 306 | + |
| 307 | Optional format string to construct user email addresses out of |
| Shawn O. Pearce | f7e065e | 2009-09-26 20:01:10 -0700 | [diff] [blame] | 308 | user login names. Only used if auth.type is `HTTP`, `HTTP_LDAP` |
| 309 | or `LDAP`. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 310 | + |
| Shawn O. Pearce | 44221bf | 2011-06-27 10:37:30 -0700 | [diff] [blame] | 311 | This value can be set to a format string, where `{0}` is replaced |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 312 | with the login name. E.g. "\{0\}+gerrit@example.com" with a user |
| 313 | login name of "foo" will produce "foo+gerrit@example.com" during |
| 314 | the first time user "foo" registers. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 315 | + |
| Shawn O. Pearce | f7e065e | 2009-09-26 20:01:10 -0700 | [diff] [blame] | 316 | If the site is using `HTTP_LDAP` or `LDAP`, using this option is |
| 317 | discouraged. Setting `ldap.accountEmailAddress` and importing the |
| 318 | email address from the LDAP directory is generally preferred. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 319 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 320 | [[auth.contributorAgreements]]auth.contributorAgreements:: |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 321 | + |
| 322 | Controls whether or not the contributor agreement features are |
| 323 | enabled for the Gerrit site. If enabled a user must complete a |
| 324 | contributor agreement before they can upload changes. |
| 325 | + |
| Marc Petit-Huguenin | bbb8549 | 2012-12-03 11:11:00 -0800 | [diff] [blame] | 326 | If enabled, the admin must also add one or more |
| 327 | link:config-cla.html[contributor-agreement sections] |
| 328 | in project.config and create agreement files under |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 329 | `'$site_path'/static`, so users can actually complete one or |
| Grzegorz Kossakowski | 28e4e1b | 2009-09-23 11:33:34 -0700 | [diff] [blame] | 330 | more agreements. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 331 | + |
| 332 | By default this is false (no agreements are used). |
| 333 | |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 334 | auth.allowGoogleAccountUpgrade:: |
| 335 | + |
| Shawn O. Pearce | 48eea07 | 2009-08-31 10:53:12 -0700 | [diff] [blame] | 336 | Allows Google Account users to automatically update their Gerrit |
| 337 | account when/if their Google Account OpenID identity token changes. |
| 338 | Identity tokens can change if the server changes hostnames, or |
| 339 | for other reasons known only to Google. The upgrade path works |
| 340 | by matching users by email address if the identity is not present, |
| 341 | and then changing the identity. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 342 | + |
| Shawn O. Pearce | 48eea07 | 2009-08-31 10:53:12 -0700 | [diff] [blame] | 343 | This setting also permits old Gerrit 1.x users to seamlessly upgrade |
| 344 | from Google Accounts on Google App Engine to OpenID authentication. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 345 | + |
| Shawn O. Pearce | 48eea07 | 2009-08-31 10:53:12 -0700 | [diff] [blame] | 346 | Having this enabled incurs an extra database query when Google |
| Shawn O. Pearce | e31d02c | 2009-12-08 12:21:37 -0800 | [diff] [blame] | 347 | Account users register with the Gerrit server. |
| Shawn O. Pearce | 0d3ecff | 2009-06-01 08:34:17 -0700 | [diff] [blame] | 348 | + |
| 349 | By default, unset/false. |
| 350 | |
| Christian Halstrick | a3d88a5 | 2011-08-31 09:21:41 +0200 | [diff] [blame] | 351 | [[auth.trustContainerAuth]]auth.trustContainerAuth:: |
| 352 | + |
| 353 | If true then it is the responsibility of the container hosting |
| 354 | Gerrit to authenticate users. In this case Gerrit will blindly trust |
| 355 | the container. |
| 356 | + |
| 357 | This parameter only affects git over http traffic. If set to false |
| 358 | then Gerrit will do the authentication (using DIGEST authentication). |
| 359 | + |
| 360 | By default this is set to false. |
| 361 | |
| Luca Milanesio | 4205884 | 2012-01-05 21:25:38 +0000 | [diff] [blame] | 362 | [[auth.gitBasicAuth]]auth.gitBasicAuth:: |
| 363 | + |
| 364 | If true then Git over HTTP and HTTP/S traffic is authenticated using |
| 365 | standard BasicAuth and credentials validated using the same auth |
| 366 | method configured for Gerrit Web UI. |
| 367 | + |
| 368 | This parameter only affects git over http traffic. If set to false |
| 369 | then Gerrit will authenticate through DIGEST authentication and |
| 370 | the randomly generated HTTP password in Gerrit DB. |
| 371 | + |
| 372 | By default this is set to false. |
| 373 | |
| Edwin Kempin | 4b9e5e7 | 2011-09-22 15:06:14 +0200 | [diff] [blame] | 374 | [[auth.userNameToLowerCase]]auth.userNameToLowerCase:: |
| 375 | + |
| 376 | If set the username that is received to authenticate a git operation |
| 377 | is converted to lower case for looking up the user account in Gerrit. |
| 378 | + |
| 379 | By setting this parameter a case insensitive authentication for the |
| 380 | git operations can be achieved, if it is ensured that the usernames in |
| 381 | Gerrit (scheme `username`) are stored in lower case (e.g. if the |
| 382 | parameter link:#ldap.accountSshUserName[ldap.accountSshUserName] is |
| 383 | set to `${sAMAccountName.toLowerCase}`). It is important that for all |
| 384 | existing accounts this username is already in lower case. It is not |
| 385 | possible to convert the usernames of the existing accounts to lower |
| 386 | case because this would break the access to existing per-user |
| 387 | branches. |
| 388 | + |
| 389 | This parameter only affects git over http and git over SSH traffic. |
| 390 | + |
| 391 | By default this is set to false. |
| 392 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 393 | [[cache]]Section cache |
| 394 | ~~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 395 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 396 | [[cache.directory]]cache.directory:: |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 397 | + |
| 398 | Path to a local directory where Gerrit can write cached entities for |
| Shawn O. Pearce | 4b21228 | 2009-08-05 19:45:56 -0700 | [diff] [blame] | 399 | future lookup. This local disk cache is used to retain potentially |
| 400 | expensive to compute information across restarts. If the location |
| 401 | does not exist, Gerrit will try to create it. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 402 | + |
| Shawn O. Pearce | 4b21228 | 2009-08-05 19:45:56 -0700 | [diff] [blame] | 403 | If not absolute, the path is resolved relative to `$site_path`. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 404 | + |
| Shawn O. Pearce | 4b21228 | 2009-08-05 19:45:56 -0700 | [diff] [blame] | 405 | Default is unset, no disk cache. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 406 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 407 | [[cache.name.maxAge]]cache.<name>.maxAge:: |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 408 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 409 | Maximum age to keep an entry in the cache. Entries are removed from |
| 410 | the cache and refreshed from source data every maxAge interval. |
| Shawn O. Pearce | d9c403e | 2009-08-19 08:35:41 -0700 | [diff] [blame] | 411 | Values should use common unit suffixes to express their setting: |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 412 | + |
| Shawn O. Pearce | d9c403e | 2009-08-19 08:35:41 -0700 | [diff] [blame] | 413 | * s, sec, second, seconds |
| 414 | * m, min, minute, minutes |
| 415 | * h, hr, hour, hours |
| 416 | * d, day, days |
| 417 | * w, week, weeks (`1 week` is treated as `7 days`) |
| 418 | * mon, month, months (`1 month` is treated as `30 days`) |
| 419 | * y, year, years (`1 year` is treated as `365 days`) |
| 420 | |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 421 | + |
| Edwin Kempin | abcd504 | 2013-03-12 16:04:37 +0100 | [diff] [blame] | 422 | If a unit suffix is not specified, `seconds` is assumed. If 0 is |
| Shawn O. Pearce | 3fdbf39 | 2009-09-04 18:08:26 -0700 | [diff] [blame] | 423 | supplied, the maximum age is infinite and items are never purged |
| 424 | except when the cache is full. |
| Shawn O. Pearce | d9c403e | 2009-08-19 08:35:41 -0700 | [diff] [blame] | 425 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 426 | Default is `0`, meaning store forever with no expire, except: |
| Shawn O. Pearce | d9c403e | 2009-08-19 08:35:41 -0700 | [diff] [blame] | 427 | + |
| Shawn O. Pearce | 05687e9 | 2011-04-04 17:29:03 -0400 | [diff] [blame] | 428 | * `"adv_bases"`: default is `10 minutes` |
| Shawn O. Pearce | d9c403e | 2009-08-19 08:35:41 -0700 | [diff] [blame] | 429 | * `"ldap_groups"`: default is `1 hour` |
| Shawn O. Pearce | d9c403e | 2009-08-19 08:35:41 -0700 | [diff] [blame] | 430 | * `"web_sessions"`: default is `12 hours` |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 431 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 432 | [[cache.name.memoryLimit]]cache.<name>.memoryLimit:: |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 433 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 434 | The total cost of entries to retain in memory. The cost computation |
| 435 | varies by the cache. For most caches where the in-memory size of each |
| 436 | entry is relatively the same, memoryLimit is currently defined to be |
| 437 | the number of entries held by the cache (each entry costs 1). |
| 438 | + |
| 439 | For caches where the size of an entry can vary significantly between |
| 440 | individual entries (notably `"diff"`, `"diff_intraline"`), memoryLimit |
| 441 | is an approximation of the total number of bytes stored by the cache. |
| 442 | Larger entries that represent bigger patch sets or longer source files |
| 443 | will consume a bigger portion of the memoryLimit. For these caches the |
| 444 | memoryLimit should be set to roughly the amount of RAM (in bytes) the |
| 445 | administrator can dedicate to the cache. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 446 | + |
| Shawn O. Pearce | efaf979 | 2009-09-02 18:12:52 -0700 | [diff] [blame] | 447 | Default is 1024 for most caches, except: |
| 448 | + |
| Shawn O. Pearce | 05687e9 | 2011-04-04 17:29:03 -0400 | [diff] [blame] | 449 | * `"adv_bases"`: default is `4096` |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 450 | * `"diff"`: default is `10m` (10 MiB of memory) |
| 451 | * `"diff_intraline"`: default is `10m` (10 MiB of memory) |
| 452 | * `"plugin_resources"`: default is 2m (2 MiB of memory) |
| 453 | |
| 454 | + |
| 455 | If set to 0 the cache is disabled. Entries are removed immediately |
| 456 | after being stored by the cache. This is primarily useful for testing. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 457 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 458 | [[cache.name.diskLimit]]cache.<name>.diskLimit:: |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 459 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 460 | Total size in bytes of the keys and values stored on disk. Caches that |
| 461 | have grown bigger than this size are scanned daily at 1 AM local |
| 462 | server time to trim the cache. Entries are removed in least recently |
| 463 | accessed order until the cache fits within this limit. Caches may |
| 464 | grow larger than this during the day, as the size check is only |
| 465 | performed once every 24 hours. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 466 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 467 | Default is 128 MiB per cache. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 468 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 469 | If 0, disk storage for the cache is disabled. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 470 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 471 | [[cache_names]]Standard Caches |
| Shawn O. Pearce | 4016a93 | 2009-05-28 15:12:40 -0700 | [diff] [blame] | 472 | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 473 | |
| Shawn O. Pearce | 4a45271 | 2009-05-28 20:12:33 -0700 | [diff] [blame] | 474 | cache `"accounts"`:: |
| 475 | + |
| Shawn O. Pearce | 4dba988 | 2009-08-05 19:55:15 -0700 | [diff] [blame] | 476 | Cache entries contain important details of an active user, including |
| 477 | their display name, preferences, known email addresses, and group |
| 478 | memberships. Entry information is obtained from the following |
| 479 | database tables: |
| 480 | + |
| 481 | * `accounts` |
| 482 | + |
| 483 | * `account_group_members` |
| 484 | + |
| 485 | * `account_external_ids` |
| 486 | |
| 487 | + |
| 488 | If direct updates are made to any of these database tables, this |
| 489 | cache should be flushed. |
| 490 | |
| 491 | cache `"accounts_byemail"`:: |
| 492 | + |
| 493 | Caches account identities keyed by email address, which is scanned |
| 494 | from the `account_external_ids` database table. If updates are |
| 495 | made to this table, this cache should be flushed. |
| Shawn O. Pearce | 4a45271 | 2009-05-28 20:12:33 -0700 | [diff] [blame] | 496 | |
| Shawn O. Pearce | 05687e9 | 2011-04-04 17:29:03 -0400 | [diff] [blame] | 497 | cache `"adv_bases"`:: |
| 498 | + |
| 499 | Used only for push over smart HTTP when branch level access controls |
| 500 | are enabled. The cache entry contains all commits that are avaliable |
| 501 | for the client to use as potential delta bases. Push over smart HTTP |
| 502 | requires two HTTP requests, and this cache tries to carry state from |
| 503 | the first request into the second to ensure it can complete. |
| 504 | |
| Gustaf Lundh | 47ce4e3 | 2012-05-21 11:18:42 +0200 | [diff] [blame] | 505 | cache `"changes"`:: |
| 506 | + |
| Gustaf Lundh | 5349377 | 2012-11-18 18:41:15 -0800 | [diff] [blame] | 507 | The size determines the number of projects that will have all its changes |
| 508 | cached. If the cache is set to 1024, this means all changes for up to |
| 509 | 1024 projects can be held in the cache. |
| 510 | + |
| 511 | Default size is 0 (disabled). It is disabled by default due to the fact |
| 512 | that change updates are not communicated between Gerrit servers. |
| 513 | Hence this cache should be disabled in an multi-master/multi-slave setup. |
| 514 | + |
| 515 | The cache should be flushed whenever the database changes table is modified |
| Gustaf Lundh | 47ce4e3 | 2012-05-21 11:18:42 +0200 | [diff] [blame] | 516 | outside of gerrit. |
| 517 | |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 518 | cache `"diff"`:: |
| 519 | + |
| Shawn O. Pearce | efaf979 | 2009-09-02 18:12:52 -0700 | [diff] [blame] | 520 | Each item caches the differences between two commits, at both the |
| 521 | directory and file levels. Gerrit uses this cache to accelerate |
| 522 | the display of affected file names, as well as file contents. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 523 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 524 | Entries in this cache are relatively large, so memoryLimit is an |
| 525 | estimate in bytes of memory used. Administrators should try to target |
| 526 | cache.diff.memoryLimit to fit all changes users will view in a 1 or 2 |
| 527 | day span. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 528 | |
| Shawn O. Pearce | f0cfe53 | 2011-04-11 23:40:06 -0400 | [diff] [blame] | 529 | cache `"diff_intraline"`:: |
| 530 | + |
| 531 | Each item caches the intraline difference of one file, when compared |
| 532 | between two commits. Gerrit uses this cache to accelerate display of |
| 533 | intraline differences when viewing a file. |
| 534 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 535 | Entries in this cache are relatively large, so memoryLimit is an |
| 536 | estimate in bytes of memory used. Administrators should try to target |
| 537 | cache.diff.memoryLimit to fit all files users will view in a 1 or 2 |
| 538 | day span. |
| Shawn O. Pearce | f0cfe53 | 2011-04-11 23:40:06 -0400 | [diff] [blame] | 539 | |
| Shawn O. Pearce | 2d65d29 | 2011-06-24 08:12:02 -0700 | [diff] [blame] | 540 | cache `"git_tags"`:: |
| 541 | + |
| 542 | If branch or reference level READ access controls are used, this |
| 543 | cache tracks which tags are reachable from the branch tips of a |
| 544 | repository. Gerrit uses this information to determine the set |
| 545 | of tags that a client may access, derived from which tags are |
| 546 | part of the history of a visible branch. |
| 547 | + |
| 548 | The cache is persisted to disk across server restarts as it can |
| 549 | be expensive to compute (60 or more seconds for a large history |
| 550 | like the Linux kernel repository). |
| 551 | |
| Shawn O. Pearce | 4a45271 | 2009-05-28 20:12:33 -0700 | [diff] [blame] | 552 | cache `"groups"`:: |
| 553 | + |
| Shawn O. Pearce | 4dba988 | 2009-08-05 19:55:15 -0700 | [diff] [blame] | 554 | Caches the basic group information from the `account_groups` table, |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 555 | including the group owner, name, and description. |
| 556 | + |
| 557 | Gerrit group membership obtained from the `account_group_members` |
| 558 | table is cached under the `"accounts"` cache, above. External group |
| 559 | membership obtained from LDAP is cached under `"ldap_groups"`. |
| 560 | |
| Matt Fischer | 620255a | 2011-03-22 14:28:23 -0500 | [diff] [blame] | 561 | cache `"groups_byinclude"`:: |
| 562 | + |
| 563 | Caches group inclusions in other groups. If direct updates are made |
| 564 | to the `account_group_includes` table, this cache should be flushed. |
| 565 | |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 566 | cache `"ldap_groups"`:: |
| 567 | + |
| 568 | Caches the LDAP groups that a user belongs to, if LDAP has been |
| 569 | configured on this server. This cache should be configured with a |
| 570 | low maxAge setting, to ensure LDAP modifications are picked up in |
| 571 | a timely fashion. |
| Shawn O. Pearce | 4a45271 | 2009-05-28 20:12:33 -0700 | [diff] [blame] | 572 | |
| Gustaf Lundh | 0919a49 | 2012-10-19 15:29:23 +0200 | [diff] [blame] | 573 | cache `"ldap_groups_byinclude"`:: |
| 574 | + |
| 575 | Caches the hierarchical structure of LDAP groups. |
| 576 | |
| Shawn O. Pearce | 6d26f4a | 2009-08-24 15:43:52 -0700 | [diff] [blame] | 577 | cache `"ldap_usernames"`:: |
| 578 | + |
| 579 | Caches a mapping of LDAP username to Gerrit account identity. The |
| 580 | cache automatically updates when a user first creates their account |
| 581 | within Gerrit, so the cache expire time is largely irrelevant. |
| 582 | |
| Shawn O. Pearce | 0c1abdb | 2011-06-24 11:01:25 -0700 | [diff] [blame] | 583 | cache `"permission_sort"`:: |
| 584 | + |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 585 | Caches the order in which access control sections must be applied to a |
| Shawn O. Pearce | 0c1abdb | 2011-06-24 11:01:25 -0700 | [diff] [blame] | 586 | reference. Sorting the sections can be expensive when regular |
| 587 | expressions are used, so this cache remembers the ordering for |
| 588 | each branch. |
| 589 | |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 590 | cache `"plugin_resources"`:: |
| 591 | + |
| 592 | Caches formatted plugin resources, such as plugin documentation that |
| 593 | has been converted from Markdown to HTML. The memoryLimit refers to |
| 594 | the bytes of memory dedicated to storing the documentation. |
| 595 | |
| Shawn O. Pearce | 4a45271 | 2009-05-28 20:12:33 -0700 | [diff] [blame] | 596 | cache `"projects"`:: |
| 597 | + |
| 598 | Caches the project description records, from the `projects` table |
| 599 | in the database. If a project record is updated or deleted, this |
| 600 | cache should be flushed. Newly inserted projects do not require |
| 601 | a cache flush, as they will be read upon first reference. |
| 602 | |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 603 | cache `"sshkeys"`:: |
| 604 | + |
| 605 | Caches unpacked versions of user SSH keys, so the internal SSH daemon |
| 606 | can match against them during authentication. The unit of storage |
| 607 | is per-user, so 1024 items translates to 1024 unique user accounts. |
| 608 | As each individual user account may configure multiple SSH keys, |
| 609 | the total number of keys may be larger than the item count. |
| Shawn O. Pearce | 4a45271 | 2009-05-28 20:12:33 -0700 | [diff] [blame] | 610 | + |
| 611 | This cache is based off the `account_ssh_keys` table and the |
| 612 | `accounts.ssh_user_name` column in the database. If either is |
| 613 | modified directly, this cache should be flushed. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 614 | |
| Shawn O. Pearce | b09322b | 2009-08-15 17:49:00 -0700 | [diff] [blame] | 615 | cache `"web_sessions"`:: |
| 616 | + |
| 617 | Tracks the live user sessions coming in over HTTP. Flushing this |
| 618 | cache would cause all users to be signed out immediately, forcing |
| Shawn O. Pearce | 727d80f | 2009-08-17 07:57:54 -0700 | [diff] [blame] | 619 | them to sign-in again. To avoid breaking active users, this cache |
| 620 | is not flushed automatically by `gerrit flush-caches --all`, but |
| 621 | instead must be explicitly requested. |
| 622 | + |
| 623 | If no disk cache is configured (or `cache.web_sessions.diskLimit` |
| 624 | is set to 0) a server restart will force all users to sign-out, |
| 625 | and need to sign-in again after the restart, as the cache was |
| 626 | unable to persist the session information. Enabling a disk cache |
| 627 | is strongly recommended. |
| 628 | + |
| Shawn O. Pearce | 2e1cb2b | 2012-05-24 14:28:40 -0700 | [diff] [blame] | 629 | Session storage is relatively inexpensive. The average entry in |
| 630 | this cache is approximately 346 bytes. |
| Shawn O. Pearce | b09322b | 2009-08-15 17:49:00 -0700 | [diff] [blame] | 631 | |
| Shawn O. Pearce | 4016a93 | 2009-05-28 15:12:40 -0700 | [diff] [blame] | 632 | See also link:cmd-flush-caches.html[gerrit flush-caches]. |
| 633 | |
| Shawn O. Pearce | 29de436 | 2010-03-03 17:51:26 -0800 | [diff] [blame] | 634 | [[cache_options]]Cache Options |
| 635 | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ |
| 636 | |
| Shawn O. Pearce | 617aa39 | 2010-11-15 14:03:28 -0800 | [diff] [blame] | 637 | cache.diff_intraline.maxIdleWorkers:: |
| 638 | + |
| 639 | Number of idle worker threads to maintain for the intraline difference |
| 640 | computations. There is no upper bound on how many concurrent requests |
| 641 | can occur at once, if additional threads are started to handle a peak |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 642 | load, only this many will remain idle afterwards. |
| Shawn O. Pearce | 617aa39 | 2010-11-15 14:03:28 -0800 | [diff] [blame] | 643 | + |
| 644 | Default is 1.5x number of available CPUs. |
| 645 | |
| 646 | cache.diff_intraline.timeout:: |
| 647 | + |
| 648 | Maximum number of milliseconds to wait for intraline difference data |
| 649 | before giving up and disabling it for a particular file pair. This is |
| 650 | a work around for an infinite loop bug in the intraline difference |
| 651 | implementation. If computation takes longer than the timeout the |
| 652 | worker thread is terminated and no intraline difference is displayed. |
| 653 | + |
| 654 | Values should use common unit suffixes to express their setting: |
| 655 | + |
| 656 | * ms, milliseconds |
| 657 | * s, sec, second, seconds |
| 658 | * m, min, minute, minutes |
| 659 | * h, hr, hour, hours |
| 660 | |
| 661 | + |
| 662 | If a unit suffix is not specified, `milliseconds` is assumed. |
| 663 | + |
| 664 | Default is 5 seconds. |
| 665 | |
| Shawn O. Pearce | 307dd4e | 2010-11-15 12:12:20 -0800 | [diff] [blame] | 666 | cache.diff_intraline.enabled:: |
| Shawn O. Pearce | 29de436 | 2010-03-03 17:51:26 -0800 | [diff] [blame] | 667 | + |
| 668 | Boolean to enable or disable the computation of intraline differences |
| Shawn O. Pearce | 307dd4e | 2010-11-15 12:12:20 -0800 | [diff] [blame] | 669 | when populating a diff cache entry. This flag is provided primarily |
| 670 | as a backdoor to disable the intraline difference feature if |
| 671 | necessary. To maintain backwards compatability with prior versions, |
| 672 | this setting will fallback to `cache.diff.intraline` if not set in the |
| 673 | configuration. |
| Shawn O. Pearce | 29de436 | 2010-03-03 17:51:26 -0800 | [diff] [blame] | 674 | + |
| 675 | Default is true, enabled. |
| 676 | |
| Shawn O. Pearce | b8e4e35 | 2011-05-19 18:09:01 -0700 | [diff] [blame] | 677 | cache.projects.checkFrequency:: |
| 678 | + |
| 679 | How often project configuration should be checked for update from Git. |
| 680 | Gerrit Code Review caches project access rules and configuration in |
| 681 | memory, checking the refs/meta/config branch every checkFrequency |
| 682 | minutes to see if a new revision should be loaded and used for future |
| 683 | access. Values can be specified using standard time unit abbreviations |
| 684 | ('ms', 'sec', 'min', etc.). |
| 685 | + |
| 686 | If set to 0, checks occur every time, which may slow down operations. |
| Shawn Pearce | c825ef1 | 2013-02-20 11:29:46 -0800 | [diff] [blame] | 687 | If set to 'disabled' or 'off', no check will ever be done. |
| Shawn O. Pearce | b8e4e35 | 2011-05-19 18:09:01 -0700 | [diff] [blame] | 688 | Administrators may force the cache to flush with |
| 689 | link:cmd-flush-caches.html[gerrit flush-caches]. |
| 690 | + |
| 691 | Default is 5 minutes. |
| 692 | |
| carloseduardo.baldacin | 14246de | 2011-07-14 17:52:22 -0300 | [diff] [blame] | 693 | [[changeMerge]]Section changeMerge |
| Remy Bohmer | 203eea3 | 2012-02-19 21:21:36 +0100 | [diff] [blame] | 694 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| carloseduardo.baldacin | 14246de | 2011-07-14 17:52:22 -0300 | [diff] [blame] | 695 | |
| Dave Borowitz | 204669c2 | 2012-10-11 11:06:08 -0700 | [diff] [blame] | 696 | changeMerge.checkFrequency:: |
| 697 | + |
| 698 | How often the database should be rescanned for changes that have been |
| 699 | submitted but not merged due to transient errors. Values can be |
| 700 | specified using standard time unit abbreviations ('ms', 'sec', 'min', |
| 701 | etc.). Set to 0 to disable periodic rescanning, only scanning once on |
| 702 | master node startup. |
| 703 | + |
| 704 | Default is 300 seconds (5 minutes). |
| 705 | |
| 706 | changeMerge.test:: |
| 707 | + |
| carloseduardo.baldacin | 14246de | 2011-07-14 17:52:22 -0300 | [diff] [blame] | 708 | Controls whether or not the mergeability test of changes is |
| 709 | enabled. If enabled, when the change page is loaded, the test is |
| 710 | triggered. The submit button will be enabled or disabled according to |
| 711 | the result. |
| Dave Borowitz | 204669c2 | 2012-10-11 11:06:08 -0700 | [diff] [blame] | 712 | + |
| carloseduardo.baldacin | 14246de | 2011-07-14 17:52:22 -0300 | [diff] [blame] | 713 | By default this is false (test is not enabled). |
| 714 | |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 715 | [[commentlink]]Section commentlink |
| Remy Bohmer | 203eea3 | 2012-02-19 21:21:36 +0100 | [diff] [blame] | 716 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 717 | Comment links are find/replace strings applied to change descriptions, |
| Chris Harris | 63c7cdd | 2012-11-23 12:17:36 -0500 | [diff] [blame] | 718 | patch comments, in-line code comments and approval category value descriptions |
| 719 | to turn set strings into hyperlinks. One common use is for linking to |
| 720 | bug-tracking systems. |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 721 | |
| 722 | In the following example configuration the 'changeid' comment link |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 723 | will match typical Gerrit Change-Id values and create a hyperlink |
| 724 | to changes which reference it. The second configuration 'bugzilla' |
| 725 | will hyperlink terms such as 'bug 42' to an external bug tracker, |
| 726 | supplying the argument record number '42' for display. The third |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 727 | configuration 'tracker' uses raw HTML to more precisely control |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 728 | how the replacement is displayed to the user. |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 729 | |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 730 | ---- |
| 731 | [commentlink "changeid"] |
| 732 | match = (I[0-9a-f]{8,40}) |
| 733 | link = "#q,$1,n,z" |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 734 | |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 735 | [commentlink "bugzilla"] |
| Shawn O. Pearce | c99630a | 2010-02-21 19:11:56 -0800 | [diff] [blame] | 736 | match = "(bug\\s+#?)(\\d+)" |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 737 | link = http://bugs.example.com/show_bug.cgi?id=$2 |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 738 | |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 739 | [commentlink "tracker"] |
| 740 | match = ([Bb]ug:\\s+)(\\d+) |
| 741 | html = $1<a href=\"http://trak.example.com/$2\">$2</a> |
| 742 | ---- |
| 743 | |
| Dave Borowitz | 13b3800 | 2013-04-08 12:03:29 -0700 | [diff] [blame^] | 744 | Comment links can also be specified in `project.config` and sections in |
| 745 | children override those in parents. The only restriction is that to |
| 746 | avoid injecting arbitrary user-supplied HTML in the page, comment links |
| 747 | defined in `project.config` may only supply `link`, not `html`. |
| 748 | |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 749 | [[commentlink.name.match]]commentlink.<name>.match:: |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 750 | + |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 751 | A JavaScript regular expression to match positions to be replaced |
| 752 | with a hyperlink. Subexpressions of the matched string can be |
| 753 | stored using groups and accessed with `$'n'` syntax, where 'n' |
| 754 | is the group number, starting from 1. |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 755 | + |
| Shawn O. Pearce | c99630a | 2010-02-21 19:11:56 -0800 | [diff] [blame] | 756 | The configuration file parser eats one level of backslashes, so the |
| 757 | character class `\s` requires `\\s` in the configuration file. The |
| 758 | parser also terminates the line at the first `#`, so a match |
| 759 | expression containing # must be wrapped in double quotes. |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 760 | + |
| Shawn O. Pearce | 665beaa | 2010-02-21 22:41:03 -0800 | [diff] [blame] | 761 | To match case insensitive strings, a character class with both the |
| 762 | upper and lower case character for each position must be used. For |
| 763 | example, to match the string `bug` in a case insensitive way the match |
| 764 | pattern `[bB][uU][gG]` needs to be used. |
| 765 | + |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 766 | A common pattern to match is `bug\\s+(\\d+)`. |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 767 | |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 768 | [[commentlink.name.link]]commentlink.<name>.link:: |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 769 | + |
| Shawn O. Pearce | da866ae | 2009-12-16 15:46:03 -0800 | [diff] [blame] | 770 | The URL to direct the user to whenever the regular expression is |
| 771 | matched. Groups in the match expression may be accessed as `$'n'`. |
| 772 | + |
| 773 | The link property is used only when the html property is not present. |
| 774 | |
| 775 | [[commentlink.name.html]]commentlink.<name>.html:: |
| 776 | + |
| 777 | HTML to replace the entire matched string with. If present, |
| 778 | this property overrides the link property above. Groups in the |
| 779 | match expression may be accessed as `$'n'`. |
| 780 | + |
| 781 | The configuration file eats double quotes, so escaping them as |
| 782 | `\"` is necessary to protect them from the parser. |
| Brad Larson | 991a31b | 2009-11-03 14:30:26 -0600 | [diff] [blame] | 783 | |
| 784 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 785 | [[contactstore]]Section contactstore |
| 786 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 787 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 788 | [[contactstore.url]]contactstore.url:: |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 789 | + |
| 790 | URL of the web based contact store Gerrit will send any offline |
| 791 | contact information to when it collects the data from users as part |
| 792 | of a contributor agreement. |
| 793 | + |
| 794 | See link:config-contact.html[Contact Information]. |
| 795 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 796 | [[contactstore.appsec]]contactstore.appsec:: |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 797 | + |
| 798 | Shared secret of the web based contact store. |
| 799 | |
| Shawn O. Pearce | e24c71fb | 2009-12-07 20:32:40 -0800 | [diff] [blame] | 800 | |
| 801 | [[container]]Section container |
| 802 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 803 | |
| 804 | These settings are applied only if Gerrit is started as the container |
| 805 | process through Gerrit's 'gerrit.sh' rc.d compatible wrapper script. |
| 806 | |
| 807 | [[container.heapLimit]]container.heapLimit:: |
| 808 | + |
| 809 | Maximum heap size of the Java process running Gerrit, in bytes. |
| 810 | This property is translated into the '-Xmx' flag for the JVM. |
| 811 | + |
| 812 | Default is platform and JVM specific. |
| 813 | + |
| 814 | Common unit suffixes of 'k', 'm', or 'g' are supported. |
| 815 | |
| 816 | [[container.javaHome]]container.javaHome:: |
| 817 | + |
| 818 | Path of the JRE/JDK installation to run Gerrit with. If not set, the |
| 819 | Gerrit startup script will attempt to search your system and guess |
| 820 | a suitable JRE. Overrides the environment variable 'JAVA_HOME'. |
| 821 | |
| 822 | [[container.javaOptions]]container.javaOptions:: |
| 823 | + |
| 824 | Additional options to pass along to the Java runtime. If multiple |
| 825 | values are configured, they are passed in order on the command line, |
| 826 | separated by spaces. These options are appended onto 'JAVA_OPTIONS'. |
| 827 | |
| Fredrik Luthander | b8f7d6d | 2010-05-18 21:11:22 +0200 | [diff] [blame] | 828 | [[container.slave]]container.slave:: |
| 829 | + |
| 830 | Used on Gerrit slave installations. If set to true the Gerrit JVM is |
| 831 | called with the '--slave' switch, enabling slave mode. If no value is |
| 832 | set (or any other value), gerrit defaults to master mode. |
| 833 | |
| Shawn O. Pearce | e24c71fb | 2009-12-07 20:32:40 -0800 | [diff] [blame] | 834 | [[container.user]]container.user:: |
| 835 | + |
| 836 | Login name (or UID) of the operating system user the Gerrit JVM |
| 837 | will execute as. If not set, defaults to the user who launched |
| 838 | the 'gerrit.sh' wrapper script. |
| 839 | |
| 840 | [[container.war]]container.war:: |
| 841 | + |
| 842 | Path of the JAR file to start daemon execution with. This should |
| 843 | be the path of the local 'gerrit.war' archive. Overrides the |
| 844 | environment variable 'GERRIT_WAR'. |
| 845 | + |
| 846 | If not set, defaults to '$site_path/bin/gerrit.war', or to |
| 847 | '$HOME/gerrit.war'. |
| 848 | |
| 849 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 850 | [[core]]Section core |
| 851 | ~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 852 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 853 | [[core.packedGitWindowSize]]core.packedGitWindowSize:: |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 854 | + |
| 855 | Number of bytes of a pack file to load into memory in a single |
| 856 | read operation. This is the "page size" of the JGit buffer cache, |
| 857 | used for all pack access operations. All disk IO occurs as single |
| 858 | window reads. Setting this too large may cause the process to load |
| 859 | more data than is required; setting this too small may increase |
| 860 | the frequency of `read()` system calls. |
| 861 | + |
| 862 | Default on JGit is 8 KiB on all platforms. |
| 863 | + |
| 864 | Common unit suffixes of 'k', 'm', or 'g' are supported. |
| 865 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 866 | [[core.packedGitLimit]]core.packedGitLimit:: |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 867 | + |
| 868 | Maximum number of bytes to load and cache in memory from pack files. |
| 869 | If JGit needs to access more than this many bytes it will unload less |
| 870 | frequently used windows to reclaim memory space within the process. |
| 871 | As this buffer must be shared with the rest of the JVM heap, it |
| 872 | should be a fraction of the total memory available. |
| 873 | + |
| 874 | Default on JGit is 10 MiB on all platforms. |
| 875 | + |
| 876 | Common unit suffixes of 'k', 'm', or 'g' are supported. |
| 877 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 878 | [[core.deltaBaseCaseLimit]]core.deltaBaseCacheLimit:: |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 879 | + |
| 880 | Maximum number of bytes to reserve for caching base objects |
| 881 | that multiple deltafied objects reference. By storing the entire |
| 882 | decompressed base object in a cache Git is able to avoid unpacking |
| 883 | and decompressing frequently used base objects multiple times. |
| 884 | + |
| 885 | Default on JGit is 10 MiB on all platforms. You probably do not |
| 886 | need to adjust this value. |
| 887 | + |
| 888 | Common unit suffixes of 'k', 'm', or 'g' are supported. |
| 889 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 890 | [[core.packedGitOpenFiles]]core.packedGitOpenFiles:: |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 891 | + |
| 892 | Maximum number of pack files to have open at once. A pack file |
| 893 | must be opened in order for any of its data to be available in |
| 894 | a cached window. |
| 895 | + |
| 896 | If you increase this to a larger setting you may need to also adjust |
| 897 | the ulimit on file descriptors for the host JVM, as Gerrit needs |
| 898 | additional file descriptors available for network sockets and other |
| 899 | repository data manipulation. |
| 900 | + |
| 901 | Default on JGit is 128 file descriptors on all platforms. |
| 902 | |
| Shawn O. Pearce | 329fe79 | 2010-09-03 15:44:23 -0700 | [diff] [blame] | 903 | [[core.streamFileThreshold]]core.streamFileThreshold:: |
| 904 | + |
| 905 | Largest object size, in bytes, that JGit will allocate as a |
| 906 | contiguous byte array. Any file revision larger than this threshold |
| 907 | will have to be streamed, typically requiring the use of temporary |
| 908 | files under '$GIT_DIR/objects' to implement psuedo-random access |
| 909 | during delta decompression. |
| 910 | + |
| 911 | Servers with very high traffic should set this to be larger than |
| 912 | the size of their common big files. For example a server managing |
| 913 | the Android platform typically has to deal with ~10-12 MiB XML |
| 914 | files, so `15 m` would be a reasonable setting in that environment. |
| 915 | Setting this too high may cause the JVM to run out of heap space |
| 916 | when handling very big binary files, such as device firmware or |
| 917 | CD-ROM ISO images. |
| 918 | + |
| Shawn O. Pearce | e3febd9 | 2010-10-13 21:17:53 -0700 | [diff] [blame] | 919 | Default is 50 MiB on all platforms. Prior to Gerrit 2.1.6, |
| Shawn O. Pearce | 329fe79 | 2010-09-03 15:44:23 -0700 | [diff] [blame] | 920 | this value was effectively 2047 MiB. |
| 921 | + |
| 922 | Common unit suffixes of 'k', 'm', or 'g' are supported. |
| 923 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 924 | [[core.packedGitMmap]]core.packedGitMmap:: |
| Shawn O. Pearce | 6854bdc | 2009-06-01 08:14:15 -0700 | [diff] [blame] | 925 | + |
| 926 | When true, JGit will use `mmap()` rather than `malloc()+read()` |
| 927 | to load data from pack files. The use of mmap can be problematic |
| 928 | on some JVMs as the garbage collector must deduce that a memory |
| 929 | mapped segment is no longer in use before a call to `munmap()` |
| 930 | can be made by the JVM native code. |
| 931 | + |
| 932 | In server applications (such as Gerrit) that need to access many |
| 933 | pack files, setting this to true risks artifically running out |
| 934 | of virtual address space, as the garbage collector cannot reclaim |
| 935 | unused mapped spaces fast enough. |
| 936 | + |
| 937 | Default on JGit is false. Although potentially slower, it yields |
| 938 | much more predictable behavior. |
| 939 | |
| Sasa Zivkov | f69aeb1 | 2012-06-11 14:05:14 +0200 | [diff] [blame] | 940 | [[core.asyncLoggingBufferSize]]core.asyncLoggingBufferSize:: |
| 941 | + |
| 942 | Size of the buffer to store logging events for asynchronous logging. |
| 943 | Putting a larger value can protect threads from stalling when the |
| 944 | AsyncAppender threads are not fast enough to consume the logging events |
| 945 | from the buffer. It also protects from loosing log entries in this case. |
| 946 | + |
| 947 | Default is 64 entries. |
| 948 | |
| Dave Borowitz | 1bec65a | 2013-03-13 10:59:01 -0700 | [diff] [blame] | 949 | [[core.useRecursiveMerge]]core.useRecursiveMerge:: |
| 950 | + |
| 951 | Use JGit's new, experimental recursive merger for three-way merges. |
| 952 | This only affects projects configured to automatically resolve |
| 953 | conflicts. |
| 954 | + |
| 955 | Default is false, but in a future release may default to true. |
| 956 | |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 957 | [[database]]Section database |
| 958 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 959 | |
| 960 | The database section configures where Gerrit stores its metadata |
| 961 | records about user accounts and change reviews. |
| 962 | |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 963 | ---- |
| 964 | [database] |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 965 | type = POSTGRESQL |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 966 | hostname = localhost |
| 967 | database = reviewdb |
| 968 | username = gerrit2 |
| 969 | password = s3kr3t |
| 970 | ---- |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 971 | |
| 972 | [[database.type]]database.type:: |
| 973 | + |
| 974 | Type of database server to connect to. If set this value will be |
| 975 | used to automatically create correct database.driver and database.url |
| 976 | values to open the connection. |
| 977 | + |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 978 | * `POSTGRESQL` |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 979 | + |
| 980 | Connect to a PostgreSQL database server. |
| 981 | + |
| 982 | * `H2` |
| 983 | + |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 984 | Connect to a local embedded H2 database. |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 985 | + |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 986 | * `MYSQL` |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 987 | + |
| 988 | Connect to a MySQL database server. |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 989 | + |
| 990 | * `JDBC` |
| 991 | + |
| 992 | Connect using a JDBC driver class name and URL. |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 993 | |
| 994 | + |
| 995 | If not specified, database.driver and database.url are used as-is, |
| 996 | and if they are also not specified, defaults to H2. |
| 997 | |
| 998 | [[database.hostname]]database.hostname:: |
| 999 | + |
| 1000 | Hostname of the database server. Defaults to 'localhost'. |
| 1001 | |
| 1002 | [[database.port]]database.port:: |
| 1003 | + |
| 1004 | Port number of the database server. Defaults to the default port |
| 1005 | of the server named by database.type. |
| 1006 | |
| 1007 | [[database.database]]database.database:: |
| 1008 | + |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 1009 | For POSTGRESQL or MYSQL, the name of the database on the server. |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 1010 | + |
| 1011 | For H2, this is the path to the database, and if not absolute is |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 1012 | relative to `'$site_path'`. |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 1013 | |
| 1014 | [[database.username]]database.username:: |
| 1015 | + |
| 1016 | Username to connect to the database server as. |
| 1017 | |
| 1018 | [[database.password]]database.password:: |
| 1019 | + |
| 1020 | Password to authenticate to the database server with. |
| 1021 | |
| 1022 | [[database.driver]]database.driver:: |
| 1023 | + |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 1024 | Name of the JDBC driver class to connect to the database with. |
| 1025 | Setting this usually isn't necessary as it can be derived from |
| 1026 | database.type or database.url for any supported database. |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 1027 | |
| 1028 | [[database.url]]database.url:: |
| 1029 | + |
| Shawn O. Pearce | 1be3906 | 2009-12-19 14:11:52 -0800 | [diff] [blame] | 1030 | 'jdbc:' URL for the database. Setting this variable usually |
| 1031 | isn't necessary as it can be constructed from the all of the |
| 1032 | above properties. |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 1033 | |
| Shawn O. Pearce | 07f35177d | 2010-02-23 09:47:10 -0800 | [diff] [blame] | 1034 | [[database.poolLimit]]database.poolLimit:: |
| 1035 | + |
| 1036 | Maximum number of open database connections. If the server needs |
| 1037 | more than this number, request processing threads will wait up |
| 1038 | to <<database.poolMaxWait, poolMaxWait>> seconds for a |
| 1039 | connection to be released before they abort with an exception. |
| 1040 | This limit must be several units higher than the total number of |
| 1041 | httpd and sshd threads as some request processing code paths may |
| 1042 | need multiple connections. |
| 1043 | + |
| 1044 | Default is 8. |
| 1045 | |
| Shawn O. Pearce | f458bf6 | 2010-02-25 09:03:03 -0800 | [diff] [blame] | 1046 | [[database.poolMinIdle]]database.poolMinIdle:: |
| Shawn O. Pearce | 07f35177d | 2010-02-23 09:47:10 -0800 | [diff] [blame] | 1047 | + |
| 1048 | Minimum number of connections to keep idle in the pool. |
| 1049 | Default is 4. |
| 1050 | |
| Shawn O. Pearce | f458bf6 | 2010-02-25 09:03:03 -0800 | [diff] [blame] | 1051 | [[database.poolMaxIdle]]database.poolMaxIdle:: |
| Shawn O. Pearce | 07f35177d | 2010-02-23 09:47:10 -0800 | [diff] [blame] | 1052 | + |
| 1053 | Maximum number of connections to keep idle in the pool. If there |
| 1054 | are more idle connections, connections will be closed instead of |
| 1055 | being returned back to the pool. |
| 1056 | Default is 4. |
| 1057 | |
| 1058 | [[database.poolMaxWait]]database.poolMaxWait:: |
| 1059 | + |
| 1060 | Maximum amount of time a request processing thread will wait to |
| 1061 | acquire a database connection from the pool. If no connection is |
| 1062 | released within this time period, the processing thread will abort |
| 1063 | its current operations and return an error to the client. |
| 1064 | Values should use common unit suffixes to express their setting: |
| 1065 | + |
| 1066 | * ms, milliseconds |
| 1067 | * s, sec, second, seconds |
| 1068 | * m, min, minute, minutes |
| 1069 | * h, hr, hour, hours |
| 1070 | |
| 1071 | + |
| 1072 | If a unit suffix is not specified, `milliseconds` is assumed. |
| 1073 | + |
| 1074 | Default is `30 seconds`. |
| 1075 | |
| monica.dionisio | 3f63044 | 2010-06-29 15:42:57 -0300 | [diff] [blame] | 1076 | [[download]]Section download |
| Nasser Grainawi | b9a5037 | 2010-08-10 07:57:47 -0600 | [diff] [blame] | 1077 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| monica.dionisio | 3f63044 | 2010-06-29 15:42:57 -0300 | [diff] [blame] | 1078 | |
| 1079 | ---- |
| 1080 | [download] |
| Edwin Kempin | 08b03a2 | 2012-09-14 16:32:57 +0200 | [diff] [blame] | 1081 | command = checkout |
| 1082 | command = cherry_pick |
| 1083 | command = pull |
| 1084 | command = format_patch |
| monica.dionisio | 3f63044 | 2010-06-29 15:42:57 -0300 | [diff] [blame] | 1085 | scheme = ssh |
| 1086 | scheme = http |
| 1087 | scheme = anon_http |
| 1088 | scheme = anon_git |
| 1089 | scheme = repo_download |
| 1090 | ---- |
| 1091 | |
| 1092 | The download section configures the allowed download methods. |
| 1093 | |
| Edwin Kempin | 08b03a2 | 2012-09-14 16:32:57 +0200 | [diff] [blame] | 1094 | [[download.command]]download.command:: |
| 1095 | + |
| 1096 | Commands that should be offered to download changes. |
| 1097 | + |
| 1098 | Multiple commands are supported: |
| 1099 | + |
| 1100 | * `checkout` |
| 1101 | + |
| 1102 | Command to fetch and checkout the patch set. |
| 1103 | + |
| 1104 | * `cherry_pick` |
| 1105 | + |
| 1106 | Command to fetch the patch set and to cherry-pick it onto the current |
| 1107 | commit. |
| 1108 | + |
| 1109 | * `pull` |
| 1110 | + |
| 1111 | Command to pull the patch set. |
| 1112 | + |
| 1113 | * `format_patch` |
| 1114 | + |
| 1115 | Command to fetch the patch set and to feed it into the `format-patch` |
| 1116 | command. |
| 1117 | |
| 1118 | + |
| 1119 | If `download.command` is not specified, all download commands are |
| 1120 | offered. |
| 1121 | |
| monica.dionisio | 3f63044 | 2010-06-29 15:42:57 -0300 | [diff] [blame] | 1122 | [[download.scheme]]download.scheme:: |
| 1123 | + |
| 1124 | Schemes that should be used to download changes. |
| 1125 | + |
| 1126 | Multiple schemes are supported: |
| 1127 | + |
| 1128 | * `http` |
| 1129 | + |
| Shawn O. Pearce | 5c46a07 | 2010-08-23 08:33:32 -0700 | [diff] [blame] | 1130 | Authenticated HTTP download is allowed. |
| monica.dionisio | 3f63044 | 2010-06-29 15:42:57 -0300 | [diff] [blame] | 1131 | + |
| 1132 | * `ssh` |
| 1133 | + |
| Shawn O. Pearce | 5c46a07 | 2010-08-23 08:33:32 -0700 | [diff] [blame] | 1134 | Authenticated SSH download is allowed. |
| monica.dionisio | 3f63044 | 2010-06-29 15:42:57 -0300 | [diff] [blame] | 1135 | + |
| 1136 | * `anon_http` |
| 1137 | + |
| 1138 | Anonymous HTTP download is allowed. |
| 1139 | + |
| 1140 | * `anon_git` |
| 1141 | + |
| Shawn O. Pearce | 5c46a07 | 2010-08-23 08:33:32 -0700 | [diff] [blame] | 1142 | Anonymous Git download is allowed. This is not default, it is also |
| 1143 | necessary to set <<gerrit.canonicalGitUrl,gerrit.canonicalGitUrl>> |
| 1144 | variable. |
| monica.dionisio | 3f63044 | 2010-06-29 15:42:57 -0300 | [diff] [blame] | 1145 | + |
| 1146 | * `repo_download` |
| 1147 | + |
| Shawn O. Pearce | 5c46a07 | 2010-08-23 08:33:32 -0700 | [diff] [blame] | 1148 | Gerrit advertises patch set downloads with the `repo download` |
| 1149 | command, assuming that all projects managed by this instance are |
| 1150 | generally worked on with the repo multi-repository tool. This is |
| 1151 | not default, as not all instances will deploy repo. |
| monica.dionisio | 3f63044 | 2010-06-29 15:42:57 -0300 | [diff] [blame] | 1152 | |
| 1153 | + |
| Edwin Kempin | 08b03a2 | 2012-09-14 16:32:57 +0200 | [diff] [blame] | 1154 | If `download.scheme` is not specified, SSH, HTTP and Anonymous HTTP |
| Shawn O. Pearce | 5c46a07 | 2010-08-23 08:33:32 -0700 | [diff] [blame] | 1155 | downloads are allowed. |
| Shawn O. Pearce | fb5548e | 2009-11-11 07:39:21 -0800 | [diff] [blame] | 1156 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 1157 | [[gerrit]]Section gerrit |
| 1158 | ~~~~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | eb7f8ce | 2009-06-01 09:57:15 -0700 | [diff] [blame] | 1159 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1160 | [[gerrit.basePath]]gerrit.basePath:: |
| Shawn O. Pearce | 9743d0b | 2009-06-01 10:10:06 -0700 | [diff] [blame] | 1161 | + |
| 1162 | Local filesystem directory holding all Git repositories that |
| 1163 | Gerrit knows about and can process changes for. A project |
| 1164 | entity in Gerrit maps to a local Git repository by creating |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1165 | the path string `"${basePath}/${project_name}.git"`. |
| Shawn O. Pearce | 9743d0b | 2009-06-01 10:10:06 -0700 | [diff] [blame] | 1166 | + |
| 1167 | If relative, the path is resolved relative to `'$site_path'`. |
| 1168 | |
| Shawn O. Pearce | 897d921 | 2011-06-16 16:59:59 -0700 | [diff] [blame] | 1169 | [[gerrit.allProjects]]gerrit.allProjects:: |
| 1170 | + |
| 1171 | Name of the permissions-only project defining global server |
| 1172 | access controls and settings. These are inherited into every |
| 1173 | other project managed by the running server. The name is |
| 1174 | relative to `gerrit.basePath`. |
| 1175 | + |
| 1176 | Defaults to `All-Projects` if not set. |
| 1177 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1178 | [[gerrit.canonicalWebUrl]]gerrit.canonicalWebUrl:: |
| Shawn O. Pearce | eb7f8ce | 2009-06-01 09:57:15 -0700 | [diff] [blame] | 1179 | + |
| 1180 | The default URL for Gerrit to be accessed through. |
| 1181 | + |
| 1182 | Typically this would be set to "http://review.example.com/" or |
| 1183 | "http://example.com/gerrit/" so Gerrit can output links that point |
| 1184 | back to itself. |
| 1185 | + |
| 1186 | Setting this is highly recommended, as its necessary for the upload |
| 1187 | code invoked by "git push" or "repo upload" to output hyperlinks |
| 1188 | to the newly uploaded changes. |
| 1189 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1190 | [[gerrit.canonicalGitUrl]]gerrit.canonicalGitUrl:: |
| Shawn O. Pearce | eb7f8ce | 2009-06-01 09:57:15 -0700 | [diff] [blame] | 1191 | + |
| 1192 | Optional base URL for repositories available over the anonymous git |
| 1193 | protocol. For example, set this to `git://mirror.example.com/base/` |
| 1194 | to have Gerrit display patch set download URLs in the UI. Gerrit |
| 1195 | automatically appends the project name onto the end of the URL. |
| 1196 | + |
| 1197 | By default unset, as the git daemon must be configured externally |
| 1198 | by the system administrator, and might not even be running on the |
| 1199 | same host as Gerrit. |
| 1200 | |
| Shawn O. Pearce | 5d6de52 | 2011-10-07 18:00:16 -0700 | [diff] [blame] | 1201 | [[gerrit.gitHttpUrl]]gerrit.gitHttpUrl:: |
| 1202 | + |
| 1203 | Optional base URL for repositories available over the HTTP |
| 1204 | protocol. For example, set this to `http://mirror.example.com/base/` |
| 1205 | to have Gerrit display URLs from this server, rather than itself. |
| 1206 | + |
| 1207 | By default unset, as the HTTP daemon must be configured externally |
| 1208 | by the system administrator, and might not even be running on the |
| 1209 | same host as Gerrit. |
| 1210 | |
| Shawn O. Pearce | b8bea1b | 2012-08-16 17:18:58 -0700 | [diff] [blame] | 1211 | [[gerrit.reportBugUrl]]gerrit.reportBugUrl:: |
| 1212 | + |
| 1213 | URL to direct users to when they need to report a bug about the |
| 1214 | Gerrit service. By default this links to the upstream Gerrit |
| 1215 | Code Review's own bug tracker but could be directed to the system |
| 1216 | administrator's ticket queue. |
| 1217 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 1218 | [[gitweb]]Section gitweb |
| 1219 | ~~~~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | d7ba11f | 2009-06-01 09:35:41 -0700 | [diff] [blame] | 1220 | |
| Shawn O. Pearce | 618dae2 | 2010-03-12 19:07:43 -0800 | [diff] [blame] | 1221 | Gerrit can forward requests to either an internally managed gitweb |
| 1222 | (which allows Gerrit to enforce some access controls), or to an |
| 1223 | externally managed gitweb (where the web server manages access). |
| Shawn O. Pearce | d7ba11f | 2009-06-01 09:35:41 -0700 | [diff] [blame] | 1224 | See also link:config-gitweb.html[Gitweb Integration]. |
| 1225 | |
| Shawn O. Pearce | 618dae2 | 2010-03-12 19:07:43 -0800 | [diff] [blame] | 1226 | [[gitweb.cgi]]gitweb.cgi:: |
| 1227 | + |
| 1228 | Path to the locally installed `gitweb.cgi` executable. This CGI will |
| 1229 | be called by Gerrit Code Review when the URL `/gitweb` is accessed. |
| 1230 | Project level access controls are enforced prior to calling the CGI. |
| 1231 | + |
| 1232 | Defaults to `/usr/lib/cgi-bin/gitweb.cgi` if gitweb.url is not set. |
| 1233 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1234 | [[gitweb.url]]gitweb.url:: |
| Shawn O. Pearce | d7ba11f | 2009-06-01 09:35:41 -0700 | [diff] [blame] | 1235 | + |
| 1236 | Optional URL of an affiliated gitweb service. Defines the |
| 1237 | web location where a `gitweb.cgi` is installed to browse |
| Shawn O. Pearce | 9743d0b | 2009-06-01 10:10:06 -0700 | [diff] [blame] | 1238 | gerrit.basePath and the repositories it contains. |
| Shawn O. Pearce | d7ba11f | 2009-06-01 09:35:41 -0700 | [diff] [blame] | 1239 | + |
| 1240 | Gerrit appends any necessary query arguments onto the end of this URL. |
| 1241 | For example, "?p=$project.git;h=$commit". |
| 1242 | |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1243 | [[gitweb.type]]gitweb.type:: |
| 1244 | + |
| 1245 | Optional type of affiliated gitweb service. This allows using |
| Shawn O. Pearce | 2b11da0 | 2011-09-06 16:18:12 -0700 | [diff] [blame] | 1246 | alternatives to gitweb, such as cgit. If set to disabled there |
| 1247 | is no gitweb hyperlinking support. |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1248 | + |
| Shawn O. Pearce | 2b11da0 | 2011-09-06 16:18:12 -0700 | [diff] [blame] | 1249 | Valid values are `gitweb`, `cgit`, `disabled` or `custom`. |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1250 | |
| Edwin Kempin | d86909c | 2012-03-26 10:36:29 +0200 | [diff] [blame] | 1251 | [[gitweb.revision]]gitweb.revision:: |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1252 | + |
| 1253 | Optional pattern to use for constructing the gitweb URL when pointing |
| 1254 | at a specific commit when `custom` is used above. |
| 1255 | + |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1256 | Valid replacements are `${project}` for the project name in Gerrit |
| 1257 | and `${commit}` for the SHA1 hash for the commit. |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1258 | |
| Edwin Kempin | d86909c | 2012-03-26 10:36:29 +0200 | [diff] [blame] | 1259 | [[gitweb.project]]gitweb.project:: |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1260 | + |
| 1261 | Optional pattern to use for constructing the gitweb URL when pointing |
| 1262 | at a specific project when `custom` is used above. |
| 1263 | + |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1264 | Valid replacements are `${project}` for the project name in Gerrit. |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1265 | |
| Edwin Kempin | d86909c | 2012-03-26 10:36:29 +0200 | [diff] [blame] | 1266 | [[gitweb.branch]]gitweb.branch:: |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1267 | + |
| 1268 | Optional pattern to use for constructing the gitweb URL when pointing |
| 1269 | at a specific branch when `custom` is used above. |
| 1270 | + |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1271 | Valid replacements are `${project}` for the project name in Gerrit |
| 1272 | and `${branch}` for the name of the branch. |
| Shane Mc Cormack | 27868a4 | 2009-12-28 04:49:39 +0000 | [diff] [blame] | 1273 | |
| Edwin Kempin | 6401156 | 2012-03-26 10:50:12 +0200 | [diff] [blame] | 1274 | [[gitweb.filehistory]]gitweb.filehistory:: |
| 1275 | + |
| 1276 | Optional pattern to use for constructing the gitweb URL when pointing |
| 1277 | at the history of a file in a specific branch when `custom` is used |
| 1278 | above. |
| 1279 | + |
| 1280 | Valid replacements are `${project}` for the project name in Gerrit, |
| 1281 | `${file}` for the file name and `${branch}` for the name of the |
| 1282 | branch. |
| 1283 | |
| Gustaf Lundh | a07d2e7 | 2011-10-27 15:26:35 -0700 | [diff] [blame] | 1284 | [[gitweb.linkname]]gitweb.linkname:: |
| 1285 | + |
| 1286 | Optional setting for modifying the link name presented to the user |
| 1287 | in the Gerrit web-UI. |
| 1288 | + |
| 1289 | Default linkname for custom type is "gitweb". |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1290 | |
| Adrian Goerler | f200707 | 2011-11-10 08:39:55 +0100 | [diff] [blame] | 1291 | [[gitweb.pathSeparator]]gitweb.pathSeparator:: |
| 1292 | + |
| 1293 | Optional character to substitute the standard path separator (slash) in |
| 1294 | project names and branch names. |
| 1295 | + |
| 1296 | By default, Gerrit will use hexadecimal encoding for slashes in project and |
| 1297 | branch names. Some web servers, such as Tomcat, reject this hexadecimal |
| 1298 | encoding in the URL. |
| 1299 | + |
| 1300 | Some alternative gitweb services, such as link:http://gitblit.com[Gitblit], |
| 1301 | allow using an alternative path separator character. In Gitblit, this can be |
| 1302 | configured through the property link:http://gitblit.com/properties.html[web.forwardSlashCharacter]. |
| 1303 | In Gerrit, the alternative path separator can be configured correspondingly |
| 1304 | using the property 'gitweb.pathSeparator'. |
| 1305 | + |
| 1306 | Valid values are the characters '*', '(' and ')'. |
| 1307 | |
| Edwin Kempin | 4bbff70 | 2013-01-11 09:59:53 +0100 | [diff] [blame] | 1308 | [[groups]]Section groups |
| 1309 | ~~~~~~~~~~~~~~~~~~~~~~~~ |
| 1310 | |
| 1311 | [[groups.newGroupsVisibleToAll]]groups.newGroupsVisibleToAll:: |
| 1312 | + |
| 1313 | Controls whether newly created groups should be by default visible to |
| 1314 | all registered users. |
| 1315 | + |
| 1316 | By default, false. |
| 1317 | |
| Shane Mc Cormack | 6c2b677 | 2010-01-12 21:56:44 +0000 | [diff] [blame] | 1318 | [[hooks]]Section hooks |
| Remy Bohmer | 203eea3 | 2012-02-19 21:21:36 +0100 | [diff] [blame] | 1319 | ~~~~~~~~~~~~~~~~~~~~~~ |
| Shane Mc Cormack | 6c2b677 | 2010-01-12 21:56:44 +0000 | [diff] [blame] | 1320 | |
| 1321 | See also link:config-hooks.html[Hooks]. |
| 1322 | |
| 1323 | [[hooks.path]]hooks.path:: |
| 1324 | + |
| 1325 | Optional path to hooks, if not specified then `'$site_path'/hooks` will be used. |
| 1326 | |
| 1327 | [[hooks.patchsetCreatedHook]]hooks.patchsetCreatedHook:: |
| 1328 | + |
| 1329 | Optional filename for the patchset created hook, if not specified then |
| 1330 | `patchset-created` will be used. |
| 1331 | |
| David Pursehouse | d556c19 | 2012-06-12 18:34:37 +0900 | [diff] [blame] | 1332 | [[hooks.draftPublishedHook]]hooks.draftPublishedHook:: |
| 1333 | + |
| 1334 | Optional filename for the draft published hook, if not specified then |
| 1335 | `draft-published` will be used. |
| 1336 | |
| Shane Mc Cormack | 6c2b677 | 2010-01-12 21:56:44 +0000 | [diff] [blame] | 1337 | [[hooks.commentAddedHook]]hooks.commentAddedHook:: |
| 1338 | + |
| 1339 | Optional filename for the comment added hook, if not specified then |
| 1340 | `comment-added` will be used. |
| 1341 | |
| 1342 | [[hooks.changeMergedHook]]hooks.changeMergedHook:: |
| 1343 | + |
| 1344 | Optional filename for the change merged hook, if not specified then |
| 1345 | `change-merged` will be used. |
| 1346 | |
| David Pursehouse | f9f3b27 | 2012-09-28 19:58:59 +0900 | [diff] [blame] | 1347 | [[hooks.mergeFailedHook]]hooks.mergeFailedHook:: |
| 1348 | + |
| 1349 | Optional filename for the merge failed hook, if not specified then |
| 1350 | `merge-failed` will be used. |
| 1351 | |
| Shane Mc Cormack | 6c2b677 | 2010-01-12 21:56:44 +0000 | [diff] [blame] | 1352 | [[hooks.changeAbandonedHook]]hooks.changeAbandonedHook:: |
| 1353 | + |
| 1354 | Optional filename for the change abandoned hook, if not specified then |
| 1355 | `change-abandoned` will be used. |
| 1356 | |
| David Pursehouse | a93c930 | 2012-06-15 16:29:26 +0900 | [diff] [blame] | 1357 | [[hooks.changeRestoredHook]]hooks.changeRestoredHook:: |
| 1358 | + |
| 1359 | Optional filename for the change restored hook, if not specified then |
| 1360 | `change-restored` will be used. |
| 1361 | |
| 1362 | [[hooks.refUpdatedHook]]hooks.refUpdatedHook:: |
| 1363 | + |
| 1364 | Optional filename for the ref updated hook, if not specified then |
| 1365 | `ref-updated` will be used. |
| 1366 | |
| David Pursehouse | 2336bd8 | 2012-09-21 12:50:19 +0900 | [diff] [blame] | 1367 | [[hooks.reviewerAddedHook]]hooks.reviewerAddedHook:: |
| 1368 | + |
| 1369 | Optional filename for the reviewer added hook, if not specified then |
| 1370 | `reviewer-added` will be used. |
| 1371 | |
| David Pursehouse | a93c930 | 2012-06-15 16:29:26 +0900 | [diff] [blame] | 1372 | [[hooks.claSignedHook]]hooks.claSignedHook:: |
| 1373 | + |
| 1374 | Optional filename for the CLA signed hook, if not specified then |
| 1375 | `cla-signed` will be used. |
| 1376 | |
| Chris Harris | f736d6c | 2012-11-21 09:35:56 -0500 | [diff] [blame] | 1377 | [[hooks.refUpdateHook]]hooks.refUpdateHook:: |
| 1378 | + |
| 1379 | Optional filename for the ref update hook, if not specified then |
| 1380 | `ref-update` will be used. |
| 1381 | |
| 1382 | [[hooks.syncHookTimeout]]hooks.syncHookTimeout:: |
| David Pursehouse | 6fdc8d9 | 2012-11-28 12:34:18 +0900 | [diff] [blame] | 1383 | + |
| 1384 | Optional timeout value in seconds for synchronous hooks, if not specified |
| Chris Harris | f736d6c | 2012-11-21 09:35:56 -0500 | [diff] [blame] | 1385 | then 30 seconds will be used. |
| 1386 | |
| Shawn O. Pearce | 309d8d3 | 2009-11-17 16:03:16 -0800 | [diff] [blame] | 1387 | [[http]]Section http |
| 1388 | ~~~~~~~~~~~~~~~~~~~~ |
| 1389 | |
| 1390 | [[http.proxy]]http.proxy:: |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 1391 | + |
| 1392 | URL of the proxy server when making outgoing HTTP |
| 1393 | connections for OpenID login transactions. Syntax |
| 1394 | should be `http://`'hostname'`:`'port'. |
| Shawn O. Pearce | 309d8d3 | 2009-11-17 16:03:16 -0800 | [diff] [blame] | 1395 | |
| 1396 | [[http.proxyUsername]]http.proxyUsername:: |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 1397 | + |
| 1398 | Optional username to authenticate to the HTTP proxy with. |
| Robin Rosenberg | 524a303 | 2012-10-14 14:24:36 +0200 | [diff] [blame] | 1399 | This property is honored only if the username does not |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 1400 | appear in the http.proxy property above. |
| Shawn O. Pearce | 309d8d3 | 2009-11-17 16:03:16 -0800 | [diff] [blame] | 1401 | |
| 1402 | [[http.proxyPassword]]http.proxyPassword:: |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 1403 | + |
| 1404 | Optional password to authenticate to the HTTP proxy with. |
| Robin Rosenberg | 524a303 | 2012-10-14 14:24:36 +0200 | [diff] [blame] | 1405 | This property is honored only if the password does not |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 1406 | appear in the http.proxy property above. |
| Shawn O. Pearce | 309d8d3 | 2009-11-17 16:03:16 -0800 | [diff] [blame] | 1407 | |
| 1408 | |
| 1409 | [[httpd]]Section httpd |
| 1410 | ~~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | fa2486a | 2009-11-11 14:51:30 -0800 | [diff] [blame] | 1411 | |
| 1412 | The httpd section configures the embedded servlet container. |
| 1413 | |
| 1414 | [[httpd.listenUrl]]httpd.listenUrl:: |
| 1415 | + |
| 1416 | Specifies the URLs the internal HTTP daemon should listen for |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1417 | connections on. The special hostname '*' may be used to listen |
| Shawn O. Pearce | fa2486a | 2009-11-11 14:51:30 -0800 | [diff] [blame] | 1418 | on all local addresses. A context path may optionally be included, |
| 1419 | placing Gerrit Code Review's web address within a subdirectory of |
| 1420 | the server. |
| 1421 | + |
| 1422 | Multiple protocol schemes are supported: |
| 1423 | + |
| 1424 | * `http://`'hostname'`:`'port' |
| 1425 | + |
| 1426 | Plain-text HTTP protocol. If port is not supplied, defaults to 80, |
| 1427 | the standard HTTP port. |
| 1428 | + |
| 1429 | * `https://`'hostname'`:`'port' |
| 1430 | + |
| 1431 | SSL encrypted HTTP protocol. If port is not supplied, defaults to |
| 1432 | 443, the standard HTTPS port. |
| 1433 | + |
| 1434 | Externally facing production sites are encouraged to use a reverse |
| 1435 | proxy configuration and `proxy-https://` (below), rather than using |
| 1436 | the embedded servlet container to implement the SSL processing. |
| 1437 | The proxy server with SSL support is probably easier to configure, |
| 1438 | provides more configuration options to control cipher usage, and |
| 1439 | is likely using natively compiled encryption algorithms, resulting |
| 1440 | in higher throughput. |
| 1441 | + |
| 1442 | * `proxy-http://`'hostname'`:`'port' |
| 1443 | + |
| 1444 | Plain-text HTTP relayed from a reverse proxy. If port is not |
| 1445 | supplied, defaults to 8080. |
| 1446 | + |
| 1447 | Like http, but additional header parsing features are |
| 1448 | enabled to honor X-Forwarded-For, X-Forwarded-Host and |
| 1449 | X-Forwarded-Server. These headers are typically set by Apache's |
| 1450 | link:http://httpd.apache.org/docs/2.2/mod/mod_proxy.html#x-headers[mod_proxy]. |
| 1451 | + |
| 1452 | * `proxy-https://`'hostname'`:`'port' |
| 1453 | + |
| 1454 | Plain text HTTP relayed from a reverse proxy that has already |
| 1455 | handled the SSL encryption/decryption. If port is not supplied, |
| 1456 | defaults to 8080. |
| 1457 | + |
| 1458 | Behaves exactly like proxy-http, but also sets the scheme to assume |
| 1459 | 'https://' is the proper URL back to the server. |
| 1460 | |
| 1461 | + |
| 1462 | If multiple values are supplied, the daemon will listen on all |
| 1463 | of them. |
| 1464 | + |
| 1465 | By default, http://*:8080. |
| 1466 | |
| 1467 | [[httpd.reuseAddress]]httpd.reuseAddress:: |
| 1468 | + |
| 1469 | If true, permits the daemon to bind to the port even if the port |
| 1470 | is already in use. If false, the daemon ensures the port is not |
| 1471 | in use before starting. Busy sites may need to set this to true |
| 1472 | to permit fast restarts. |
| 1473 | + |
| 1474 | By default, true. |
| 1475 | |
| 1476 | [[httpd.requestHeaderSize]]httpd.requestHeaderSize:: |
| 1477 | + |
| 1478 | Size, in bytes, of the buffer used to parse the HTTP headers of an |
| 1479 | incoming HTTP request. The entire request headers, including any |
| 1480 | cookies sent by the browser, must fit within this buffer, otherwise |
| 1481 | the server aborts with the response '413 Request Entity Too Large'. |
| 1482 | + |
| 1483 | One buffer of this size is allocated per active connection. |
| 1484 | Allocating a buffer that is too large wastes memory that cannot be |
| 1485 | reclaimed, allocating a buffer that is too small may cause unexpected |
| 1486 | errors caused by very long Referer URLs or large cookie values. |
| 1487 | + |
| 1488 | By default, 16384 (16 K), which is sufficient for most OpenID and |
| 1489 | other web-based single-sign-on integrations. |
| 1490 | |
| 1491 | [[httpd.sslKeyStore]]httpd.sslKeyStore:: |
| 1492 | + |
| 1493 | Path of the Java keystore containing the server's SSL certificate |
| 1494 | and private key. This keystore is required for `https://` in URL. |
| 1495 | + |
| 1496 | To create a self-signed certificate for simple internal usage: |
| 1497 | + |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 1498 | ---- |
| 1499 | keytool -keystore keystore -alias jetty -genkey -keyalg RSA |
| 1500 | chmod 600 keystore |
| 1501 | ---- |
| Shawn O. Pearce | fa2486a | 2009-11-11 14:51:30 -0800 | [diff] [blame] | 1502 | + |
| 1503 | If not absolute, the path is resolved relative to `$site_path`. |
| 1504 | + |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 1505 | By default, `$site_path/etc/keystore`. |
| Shawn O. Pearce | fa2486a | 2009-11-11 14:51:30 -0800 | [diff] [blame] | 1506 | |
| 1507 | [[httpd.sslKeyPassword]]httpd.sslKeyPassword:: |
| 1508 | + |
| 1509 | Password used to decrypt the private portion of the sslKeyStore. |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1510 | Java keystores require a password, even if the administrator |
| Shawn O. Pearce | fa2486a | 2009-11-11 14:51:30 -0800 | [diff] [blame] | 1511 | doesn't want to enable one. |
| 1512 | + |
| 1513 | If set to the empty string the embedded server will prompt for the |
| 1514 | password during startup. |
| 1515 | + |
| 1516 | By default, `gerrit`. |
| 1517 | |
| Shawn O. Pearce | 1766f50 | 2010-01-15 10:49:46 -0800 | [diff] [blame] | 1518 | [[httpd.requestLog]]httpd.requestLog:: |
| 1519 | + |
| 1520 | Enable (or disable) the `'$site_path'/logs/httpd_log` request log. |
| 1521 | If enabled, an NCSA combined log format request log file is written |
| 1522 | out by the internal HTTP daemon. |
| 1523 | + |
| 1524 | By default, true if httpd.listenUrl uses http:// or https://, |
| 1525 | and false if httpd.listenUrl uses proxy-http:// or proxy-https://. |
| 1526 | |
| Shawn O. Pearce | fa2486a | 2009-11-11 14:51:30 -0800 | [diff] [blame] | 1527 | [[httpd.acceptorThreads]]httpd.acceptorThreads:: |
| 1528 | + |
| 1529 | Number of worker threads dedicated to accepting new incoming TCP |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1530 | connections and allocating them connection-specific resources. |
| Shawn O. Pearce | fa2486a | 2009-11-11 14:51:30 -0800 | [diff] [blame] | 1531 | + |
| 1532 | By default, 2, which should be suitable for most high-traffic sites. |
| 1533 | |
| 1534 | [[httpd.minThreads]]httpd.minThreads:: |
| 1535 | + |
| 1536 | Minimum number of spare threads to keep in the worker thread pool. |
| 1537 | This number must be at least 1 larger than httpd.acceptorThreads |
| 1538 | multipled by the number of httpd.listenUrls configured. |
| 1539 | + |
| 1540 | By default, 5, suitable for most lower-volume traffic sites. |
| 1541 | |
| 1542 | [[httpd.maxThreads]]httpd.maxThreads:: |
| 1543 | + |
| 1544 | Maximum number of threads to permit in the worker thread pool. |
| 1545 | + |
| 1546 | By default 25, suitable for most lower-volume traffic sites. |
| 1547 | |
| 1548 | [[httpd.maxQueued]]httpd.maxQueued:: |
| 1549 | + |
| 1550 | Maximum number of client connections which can enter the worker |
| 1551 | thread pool waiting for a worker thread to become available. |
| 1552 | 0 disables the queue and permits infinite number of connections. |
| 1553 | + |
| 1554 | By default 50. |
| 1555 | |
| Shawn O. Pearce | e5452b7 | 2010-01-15 14:32:50 -0800 | [diff] [blame] | 1556 | [[httpd.maxWait]]httpd.maxWait:: |
| 1557 | + |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1558 | Maximum amount of time a client will wait for an available |
| Shawn O. Pearce | e5452b7 | 2010-01-15 14:32:50 -0800 | [diff] [blame] | 1559 | thread to handle a project clone, fetch or push request over the |
| 1560 | smart HTTP transport. |
| 1561 | + |
| 1562 | Values should use common unit suffixes to express their setting: |
| 1563 | + |
| 1564 | * s, sec, second, seconds |
| 1565 | * m, min, minute, minutes |
| 1566 | * h, hr, hour, hours |
| 1567 | * d, day, days |
| 1568 | * w, week, weeks (`1 week` is treated as `7 days`) |
| 1569 | * mon, month, months (`1 month` is treated as `30 days`) |
| 1570 | * y, year, years (`1 year` is treated as `365 days`) |
| 1571 | |
| 1572 | + |
| 1573 | If a unit suffix is not specified, `minutes` is assumed. If 0 |
| 1574 | is supplied, the maximum age is infinite and connections will not |
| 1575 | abort until the client disconnects. |
| 1576 | + |
| 1577 | By default, 5 minutes. |
| 1578 | |
| Shawn O. Pearce | fa2486a | 2009-11-11 14:51:30 -0800 | [diff] [blame] | 1579 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 1580 | [[ldap]]Section ldap |
| 1581 | ~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1582 | |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1583 | LDAP integration is only enabled if `auth.type` is set to |
| Sasa Zivkov | eabc897 | 2010-10-04 15:47:08 +0200 | [diff] [blame] | 1584 | `HTTP_LDAP`, `LDAP` or `CLIENT_SSL_CERT_LDAP`. See above for a |
| 1585 | detailed description of the auth.type settings and their |
| 1586 | implications. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1587 | |
| Shawn O. Pearce | 02c2e80 | 2009-10-29 14:46:03 -0700 | [diff] [blame] | 1588 | An example LDAP configuration follows, and then discussion of |
| 1589 | the parameters introduced here. Suitable defaults for most |
| 1590 | parameters are automatically guessed based on the type of server |
| 1591 | detected during startup. The guessed defaults support both |
| 1592 | link:http://www.ietf.org/rfc/rfc2307.txt[RFC 2307] and Active |
| 1593 | Directory. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1594 | |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 1595 | ---- |
| 1596 | [ldap] |
| 1597 | server = ldap://ldap.example.com |
| 1598 | |
| 1599 | accountBase = ou=people,dc=example,dc=com |
| 1600 | accountPattern = (&(objectClass=person)(uid=${username})) |
| 1601 | accountFullName = displayName |
| 1602 | accountEmailAddress = mail |
| 1603 | |
| 1604 | groupBase = ou=groups,dc=example,dc=com |
| 1605 | groupMemberPattern = (&(objectClass=group)(member=${dn})) |
| 1606 | ---- |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1607 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1608 | [[ldap.server]]ldap.server:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1609 | + |
| 1610 | URL of the organization's LDAP server to query for user information |
| 1611 | and group membership from. Must be of the form `ldap://host` or |
| 1612 | `ldaps://host` to bind with either a plaintext or SSL connection. |
| Shawn O. Pearce | f7e065e | 2009-09-26 20:01:10 -0700 | [diff] [blame] | 1613 | + |
| 1614 | If auth.type is `LDAP` this setting should use `ldaps://` to |
| 1615 | ensure the end user's plaintext password is transmitted only over |
| 1616 | an encrypted connection. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1617 | |
| Shawn O. Pearce | 02c2e80 | 2009-10-29 14:46:03 -0700 | [diff] [blame] | 1618 | [[ldap.sslVerify]]ldap.sslVerify:: |
| 1619 | + |
| 1620 | If false and ldap.server is an `ldaps://` style URL, Gerrit |
| 1621 | will not verify the server certificate when it connects to |
| 1622 | perform a query. |
| 1623 | + |
| 1624 | By default, true, requiring the certificate to be verified. |
| 1625 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1626 | [[ldap.username]]ldap.username:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1627 | + |
| 1628 | _(Optional)_ Username to bind to the LDAP server with. If not set, |
| 1629 | an anonymous connection to the LDAP server is attempted. |
| 1630 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1631 | [[ldap.password]]ldap.password:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1632 | + |
| 1633 | _(Optional)_ Password for the user identified by `ldap.username`. |
| 1634 | If not set, an anonymous (or passwordless) connection to the LDAP |
| 1635 | server is attempted. |
| 1636 | |
| Ben Wu | 0410a15 | 2010-06-04 16:17:24 +0800 | [diff] [blame] | 1637 | [[ldap.referral]]ldap.referral:: |
| 1638 | + |
| 1639 | _(Optional)_ How an LDAP referral should be handled if it is |
| 1640 | encountered during directory traversal. Set to `follow` to |
| James Y Knight | 1244ed0 | 2011-01-04 02:40:32 -0500 | [diff] [blame] | 1641 | automatically follow any referrals, or `ignore` to ignore the |
| 1642 | referrals. |
| Ben Wu | 0410a15 | 2010-06-04 16:17:24 +0800 | [diff] [blame] | 1643 | + |
| 1644 | By default, `ignore`. |
| 1645 | |
| Sasa Zivkov | 100bd4b | 2011-11-07 14:58:46 +0100 | [diff] [blame] | 1646 | [[ldap.readTimeout]]ldap.readTimeout:: |
| 1647 | + |
| 1648 | _(Optional)_ The read timeout for an LDAP operation. The value is |
| 1649 | in the usual time-unit format like "1 s", "100 ms", etc... |
| 1650 | A timeout can be used to avoid blocking all of the SSH command start |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1651 | threads in case the LDAP server becomes slow. |
| Sasa Zivkov | 100bd4b | 2011-11-07 14:58:46 +0100 | [diff] [blame] | 1652 | + |
| 1653 | By default there is no timeout and Gerrit will wait for the LDAP |
| 1654 | server to respond until the TCP connection times out. |
| 1655 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1656 | [[ldap.accountBase]]ldap.accountBase:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1657 | + |
| 1658 | Root of the tree containing all user accounts. This is typically |
| 1659 | of the form `ou=people,dc=example,dc=com`. |
| 1660 | |
| Shawn O. Pearce | 304ccdb | 2009-08-25 12:25:27 -0700 | [diff] [blame] | 1661 | [[ldap.accountScope]]ldap.accountScope:: |
| 1662 | + |
| 1663 | Scope of the search performed for accounts. Must be one of: |
| 1664 | + |
| 1665 | * `one`: Search only one level below accountBase, but not recursive |
| 1666 | * `sub` or `subtree`: Search recursively below accountBase |
| 1667 | * `base` or `object`: Search exactly accountBase; probably not desired |
| 1668 | |
| 1669 | + |
| 1670 | Default is `subtree` as many directories have several levels. |
| 1671 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1672 | [[ldap.accountPattern]]ldap.accountPattern:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1673 | + |
| 1674 | Query pattern to use when searching for a user account. This may be |
| 1675 | any valid LDAP query expression, including the standard `(&...)` and |
| 1676 | `(|...)` operators. If auth.type is `HTTP_LDAP` then the variable |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1677 | `${username}` is replaced with a parameter set to the username |
| Shawn O. Pearce | f7e065e | 2009-09-26 20:01:10 -0700 | [diff] [blame] | 1678 | that was supplied by the HTTP server. If auth.type is `LDAP` then |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1679 | the variable `${username}` is replaced by the string entered by |
| Shawn O. Pearce | f7e065e | 2009-09-26 20:01:10 -0700 | [diff] [blame] | 1680 | the end user. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1681 | + |
| 1682 | This pattern is used to search the objects contained directly under |
| 1683 | the `ldap.accountBase` tree. A typical setting for this parameter |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1684 | is `(uid=${username})` or `(cn=${username})`, but the proper |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1685 | setting depends on the LDAP schema used by the directory server. |
| 1686 | + |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1687 | Default is `(uid=${username})` for RFC 2307 servers, |
| Shawn O. Pearce | 02c2e80 | 2009-10-29 14:46:03 -0700 | [diff] [blame] | 1688 | and `(&(objectClass=user)(sAMAccountName=${username}))` |
| 1689 | for Active Directory. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1690 | |
| Shawn O. Pearce | 37dc1f8 | 2009-08-19 09:49:07 -0700 | [diff] [blame] | 1691 | [[ldap.accountFullName]]ldap.accountFullName:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1692 | + |
| 1693 | _(Optional)_ Name of an attribute on the user account object which |
| 1694 | contains the initial value for the user's full name field in Gerrit. |
| 1695 | Typically this is the `displayName` property in LDAP, but could |
| 1696 | also be `legalName` or `cn`. |
| 1697 | + |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1698 | Attribute values may be concatenated with literal strings. For |
| 1699 | example to join given name and surname together, use the pattern |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1700 | `${givenName} ${SN}`. |
| Shawn O. Pearce | b86ae00 | 2009-09-26 16:54:05 -0700 | [diff] [blame] | 1701 | + |
| Shawn O. Pearce | 3ca1dcf | 2009-08-20 08:56:23 -0700 | [diff] [blame] | 1702 | If set, users will be unable to modify their full name field, as |
| 1703 | Gerrit will populate it only from the LDAP data. |
| 1704 | + |
| Shawn O. Pearce | 02c2e80 | 2009-10-29 14:46:03 -0700 | [diff] [blame] | 1705 | Default is `displayName` for RFC 2307 servers, |
| 1706 | and `${givenName} ${sn}` for Active Directory. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1707 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1708 | [[ldap.accountEmailAddress]]ldap.accountEmailAddress:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1709 | + |
| 1710 | _(Optional)_ Name of an attribute on the user account object which |
| 1711 | contains the user's Internet email address, as defined by this |
| 1712 | LDAP server. |
| 1713 | + |
| Shawn O. Pearce | b86ae00 | 2009-09-26 16:54:05 -0700 | [diff] [blame] | 1714 | Attribute values may be concatenated with literal strings, |
| 1715 | for example to set the email address to the lowercase form |
| 1716 | of sAMAccountName followed by a constant domain name, use |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1717 | `${sAMAccountName.toLowerCase}@example.com`. |
| Shawn O. Pearce | b86ae00 | 2009-09-26 16:54:05 -0700 | [diff] [blame] | 1718 | + |
| Shawn O. Pearce | 3ca1dcf | 2009-08-20 08:56:23 -0700 | [diff] [blame] | 1719 | If set, the preferred email address will be prefilled from LDAP, |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1720 | but users may still be able to register additional email addresses, |
| Shawn O. Pearce | 3ca1dcf | 2009-08-20 08:56:23 -0700 | [diff] [blame] | 1721 | and select a different preferred email address. |
| 1722 | + |
| Shawn O. Pearce | 02c2e80 | 2009-10-29 14:46:03 -0700 | [diff] [blame] | 1723 | Default is `mail`. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1724 | |
| Shawn O. Pearce | 59e0922 | 2009-08-19 09:04:49 -0700 | [diff] [blame] | 1725 | [[ldap.accountSshUserName]]ldap.accountSshUserName:: |
| 1726 | + |
| 1727 | _(Optional)_ Name of an attribute on the user account object which |
| 1728 | contains the initial value for the user's SSH username field in |
| 1729 | Gerrit. Typically this is the `uid` property in LDAP, but could |
| 1730 | also be `cn`. Administrators should prefer to match the attribute |
| 1731 | corresponding to the user's workstation username, as this is what |
| 1732 | SSH clients will default to. |
| 1733 | + |
| Shawn O. Pearce | b86ae00 | 2009-09-26 16:54:05 -0700 | [diff] [blame] | 1734 | Attribute values may also be forced to lowercase, or to uppercase in |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1735 | an expression. For example, `${sAMAccountName.toLowerCase}` will |
| Shawn O. Pearce | b86ae00 | 2009-09-26 16:54:05 -0700 | [diff] [blame] | 1736 | force the value of sAMAccountName, if defined, to be all lowercase. |
| 1737 | The suffix `.toUpperCase` can be used for the other direction. |
| 1738 | The suffix `.localPart` can be used to split attribute values of |
| 1739 | the form 'user@example.com' and return only the left hand side, for |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1740 | example `${userPrincipalName.localPart}` would provide only 'user'. |
| Shawn O. Pearce | b86ae00 | 2009-09-26 16:54:05 -0700 | [diff] [blame] | 1741 | + |
| Shawn O. Pearce | 3ca1dcf | 2009-08-20 08:56:23 -0700 | [diff] [blame] | 1742 | If set, users will be unable to modify their SSH username field, as |
| 1743 | Gerrit will populate it only from the LDAP data. |
| 1744 | + |
| Shawn O. Pearce | 02c2e80 | 2009-10-29 14:46:03 -0700 | [diff] [blame] | 1745 | Default is `uid` for RFC 2307 servers, |
| 1746 | and `${sAMAccountName.toLowerCase}` for Active Directory. |
| Shawn O. Pearce | 59e0922 | 2009-08-19 09:04:49 -0700 | [diff] [blame] | 1747 | |
| Shawn O. Pearce | 7d25f78 | 2009-10-30 08:01:03 -0700 | [diff] [blame] | 1748 | [[ldap.accountMemberField]]ldap.accountMemberField:: |
| Anthony | 93de7db | 2009-10-03 10:01:50 -0400 | [diff] [blame] | 1749 | + |
| 1750 | _(Optional)_ Name of an attribute on the user account object which |
| Shawn O. Pearce | 7d25f78 | 2009-10-30 08:01:03 -0700 | [diff] [blame] | 1751 | contains the groups the user is part of. Typically used for Active |
| 1752 | Directory servers. |
| Anthony | 93de7db | 2009-10-03 10:01:50 -0400 | [diff] [blame] | 1753 | + |
| Shawn O. Pearce | 02c2e80 | 2009-10-29 14:46:03 -0700 | [diff] [blame] | 1754 | Default is unset for RFC 2307 servers (disabled) |
| 1755 | and `memberOf` for Active Directory. |
| Anthony | 93de7db | 2009-10-03 10:01:50 -0400 | [diff] [blame] | 1756 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1757 | [[ldap.groupBase]]ldap.groupBase:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1758 | + |
| 1759 | Root of the tree containing all group objects. This is typically |
| 1760 | of the form `ou=groups,dc=example,dc=com`. |
| 1761 | |
| Shawn O. Pearce | 304ccdb | 2009-08-25 12:25:27 -0700 | [diff] [blame] | 1762 | [[ldap.groupScope]]ldap.groupScope:: |
| 1763 | + |
| 1764 | Scope of the search performed for group objects. Must be one of: |
| 1765 | + |
| 1766 | * `one`: Search only one level below groupBase, but not recursive |
| 1767 | * `sub` or `subtree`: Search recursively below groupBase |
| 1768 | * `base` or `object`: Search exactly groupBase; probably not desired |
| 1769 | |
| 1770 | + |
| 1771 | Default is `subtree` as many directories have several levels. |
| 1772 | |
| Shawn O. Pearce | 7d25f78 | 2009-10-30 08:01:03 -0700 | [diff] [blame] | 1773 | [[ldap.groupPattern]]ldap.groupPattern:: |
| 1774 | + |
| 1775 | Query pattern used when searching for an LDAP group to connect |
| 1776 | to a Gerrit group. This may be any valid LDAP query expression, |
| 1777 | including the standard `(&...)` and `(|...)` operators. The variable |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1778 | `${groupname}` is replaced with the search term supplied by the |
| Shawn O. Pearce | 7d25f78 | 2009-10-30 08:01:03 -0700 | [diff] [blame] | 1779 | group owner. |
| 1780 | + |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1781 | Default is `(cn=${groupname})` for RFC 2307, |
| 1782 | and `(&(objectClass=group)(cn=${groupname}))` for Active Directory. |
| Shawn O. Pearce | 7d25f78 | 2009-10-30 08:01:03 -0700 | [diff] [blame] | 1783 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1784 | [[ldap.groupMemberPattern]]ldap.groupMemberPattern:: |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1785 | + |
| 1786 | Query pattern to use when searching for the groups that a user |
| 1787 | account is currently a member of. This may be any valid LDAP query |
| 1788 | expression, including the standard `(&...)` and `(|...)` operators. |
| 1789 | + |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1790 | If auth.type is `HTTP_LDAP` then the variable `${username}` is |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1791 | replaced with a parameter set to the username that was supplied |
| 1792 | by the HTTP server. Other variables appearing in the pattern, |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1793 | such as `${fooBarAttribute}`, are replaced with the value of the |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1794 | corresponding attribute (in this case, `fooBarAttribute`) as read |
| 1795 | from the user's account object matched under `ldap.accountBase`. |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1796 | Attributes such as `${dn}` or `${uidNumber}` may be useful. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1797 | + |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1798 | Default is `(memberUid=${username})` for RFC 2307, |
| Shawn O. Pearce | 02c2e80 | 2009-10-29 14:46:03 -0700 | [diff] [blame] | 1799 | and unset (disabled) for Active Directory. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1800 | |
| Auke Schrijnen | 5780913 | 2012-09-26 21:05:39 +0200 | [diff] [blame] | 1801 | [[ldap.groupName]]ldap.groupName:: |
| 1802 | + |
| David Pursehouse | 39489ae | 2012-10-12 13:50:04 +0900 | [diff] [blame] | 1803 | _(Optional)_ Name of the attribute on the group object which contains |
| 1804 | the value to use as the group name in Gerrit. |
| Auke Schrijnen | 5780913 | 2012-09-26 21:05:39 +0200 | [diff] [blame] | 1805 | + |
| David Pursehouse | 39489ae | 2012-10-12 13:50:04 +0900 | [diff] [blame] | 1806 | Typically the attribute name is `cn` for RFC 2307 and Active Directory |
| 1807 | servers. For other servers the attribute name may differ, for example |
| 1808 | `apple-group-realname` on Apple MacOS X Server. |
| Auke Schrijnen | 5780913 | 2012-09-26 21:05:39 +0200 | [diff] [blame] | 1809 | + |
| David Pursehouse | 39489ae | 2012-10-12 13:50:04 +0900 | [diff] [blame] | 1810 | It is also possible to specify a literal string containing a pattern of |
| 1811 | attribute values. For example to create a Gerrit group name consisting of |
| 1812 | LDAP group name and group ID, use the pattern `${cn} (${gidNumber})`. |
| 1813 | + |
| 1814 | Default is `cn`. |
| Auke Schrijnen | 5780913 | 2012-09-26 21:05:39 +0200 | [diff] [blame] | 1815 | |
| Edwin Kempin | b3b0d29 | 2011-09-14 14:17:34 +0200 | [diff] [blame] | 1816 | [[ldap.localUsernameToLowerCase]]ldap.localUsernameToLowerCase:: |
| 1817 | + |
| 1818 | Converts the local username, that is used to login into the Gerrit |
| 1819 | WebUI, to lower case before doing the LDAP authentication. By setting |
| 1820 | this parameter to true, a case insensitive login to the Gerrit WebUI |
| 1821 | can be achieved. |
| 1822 | + |
| 1823 | If set, it must be ensured that the local usernames for all existing |
| 1824 | accounts are converted to lower case, otherwise a user that has a |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1825 | local username that contains upper case characters will not be able to login |
| Edwin Kempin | b3b0d29 | 2011-09-14 14:17:34 +0200 | [diff] [blame] | 1826 | anymore. The local usernames for the existing accounts can be |
| 1827 | converted to lower case by running the server program |
| 1828 | link:pgm-LocalUsernamesToLowerCase.html[LocalUsernamesToLowerCase]. |
| 1829 | Please be aware that the conversion of the local usernames to lower |
| 1830 | case can't be undone. For newly created accounts the local username |
| 1831 | will be directly stored in lower case. |
| 1832 | + |
| 1833 | By default, unset/false. |
| Shawn O. Pearce | 302a7dd | 2009-08-18 19:33:15 -0700 | [diff] [blame] | 1834 | |
| Robin Rosenberg | a3baed0 | 2012-10-14 14:09:32 +0200 | [diff] [blame] | 1835 | [[ldap.authentication]]ldap.authentication:: |
| 1836 | + |
| 1837 | Defines how Gerrit authenticates with the server. When set to `GSSAPI` |
| 1838 | Gerrit will use Kerberos. To use kerberos the |
| 1839 | `java.security.auth.login.config` system property must point to a |
| 1840 | login to a JAAS configuration file and, if Java 6 is used, the system |
| 1841 | property `java.security.krb5.conf` must point to the appropriate |
| 1842 | krb5.ini file with references to the KDC. |
| 1843 | |
| 1844 | Typical jaas.conf. |
| 1845 | |
| 1846 | ---- |
| 1847 | KerberosLogin { |
| 1848 | com.sun.security.auth.module.Krb5LoginModule |
| 1849 | required |
| 1850 | useTicketCache=true |
| 1851 | doNotPrompt=true |
| 1852 | renewTGT=true; |
| 1853 | }; |
| 1854 | ---- |
| 1855 | |
| 1856 | See Java documentation on how to create the krb5.ini file. |
| 1857 | |
| 1858 | Note the `renewTGT` property to make sure the TGT does not expire, |
| 1859 | and `useTicketCache` to use the TGT supplied by the operating system. As |
| 1860 | the whole point of using GSSAPI is to have passwordless authentication |
| 1861 | to the LDAP service, this option does not aquire a new TGT on its own. |
| 1862 | |
| 1863 | On Windows servers the registry key `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\Kerberos\Parameters` |
| 1864 | must have the DWORD value `allowtgtsessionkey` set to 1 and the account must not |
| 1865 | have local administrator privileges. |
| 1866 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 1867 | [[mimetype]]Section mimetype |
| 1868 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | 01cb1190 | 2009-07-15 08:19:01 -0700 | [diff] [blame] | 1869 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 1870 | [[mimetype.name.safe]]mimetype.<name>.safe:: |
| Shawn O. Pearce | 01cb1190 | 2009-07-15 08:19:01 -0700 | [diff] [blame] | 1871 | + |
| 1872 | If set to true, files with the MIME type `<name>` will be sent as |
| 1873 | direct downloads to the user's browser, rather than being wrapped up |
| 1874 | inside of zipped archives. The type name may be a complete type |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 1875 | name, e.g. `image/gif`, a generic media type, e.g. `image/*`, |
| 1876 | or the wildcard `*/*` to match all types. |
| Shawn O. Pearce | 01cb1190 | 2009-07-15 08:19:01 -0700 | [diff] [blame] | 1877 | + |
| 1878 | By default, false for all MIME types. |
| 1879 | |
| 1880 | Common examples: |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 1881 | ---- |
| 1882 | [mimetype "image/*"] |
| 1883 | safe = true |
| 1884 | |
| 1885 | [mimetype "application/pdf"] |
| 1886 | safe = true |
| 1887 | |
| 1888 | [mimetype "application/msword"] |
| 1889 | safe = true |
| 1890 | |
| 1891 | [mimetype "application/vnd.ms-excel"] |
| 1892 | safe = true |
| 1893 | ---- |
| Shawn O. Pearce | 01cb1190 | 2009-07-15 08:19:01 -0700 | [diff] [blame] | 1894 | |
| Shawn O. Pearce | 5f11b29 | 2010-08-05 17:57:35 -0700 | [diff] [blame] | 1895 | |
| 1896 | [[pack]]Section pack |
| 1897 | ~~~~~~~~~~~~~~~~~~~~ |
| 1898 | Global settings controlling how Gerrit Code Review creates pack |
| 1899 | streams for Git clients running clone, fetch, or pull. Most of these |
| 1900 | variables are per-client request, and thus should be carefully set |
| 1901 | given the expected concurrent request load and available CPU and |
| 1902 | memory resources. |
| 1903 | |
| 1904 | [[pack.deltacompression]]pack.deltacompression:: |
| 1905 | + |
| 1906 | If true, delta compression between objects is enabled. This may |
| 1907 | result in a smaller overall transfer for the client, but requires |
| 1908 | more server memory and CPU time. |
| 1909 | + |
| 1910 | False (off) by default, matching Gerrit Code Review 2.1.4. |
| 1911 | |
| 1912 | [[pack.threads]]pack.threads:: |
| 1913 | + |
| 1914 | Maximum number of threads to use for delta compression (if enabled). |
| 1915 | This is per-client request. If set to 0 then the number of CPUs is |
| 1916 | auto-detected and one thread per CPU is used, per client request. |
| 1917 | + |
| 1918 | By default, 1. |
| 1919 | |
| 1920 | |
| Shawn O. Pearce | 5ad16ea | 2012-05-09 14:24:25 -0700 | [diff] [blame] | 1921 | [[plugins]]Section plugins |
| 1922 | ~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 1923 | |
| 1924 | [[plugins.checkFrequency]]plugins.checkFrequency:: |
| 1925 | + |
| 1926 | How often plugins should be examined for new plugins to load, removed |
| 1927 | plugins to be unloaded, or updated plugins to be reloaded. Values can |
| 1928 | be specified using standard time unit abbreviations ('ms', 'sec', |
| 1929 | 'min', etc.). |
| 1930 | + |
| 1931 | If set to 0, automatic plugin reloading is disabled. Administrators |
| 1932 | may force reloading with link:cmd-plugin.html[gerrit plugin reload]. |
| 1933 | + |
| 1934 | Default is 1 minute. |
| 1935 | |
| 1936 | |
| lincoln | 2be1160 | 2010-07-05 10:53:25 -0300 | [diff] [blame] | 1937 | [[receive]]Section receive |
| 1938 | ~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| Sasa Zivkov | 59d89c3 | 2011-11-18 15:32:35 +0100 | [diff] [blame] | 1939 | This section is used to set who can execute the 'receive-pack' and |
| 1940 | to limit the maximum Git object size that 'receive-pack' will accept. |
| 1941 | 'receive-pack' is what runs on the server during a user's push or |
| Dave Borowitz | 234734a | 2012-03-01 14:22:29 -0800 | [diff] [blame] | 1942 | repo upload command. It also contains some advanced options for tuning the |
| 1943 | behavior of Gerrit's 'receive-pack' mechanism. |
| lincoln | 2be1160 | 2010-07-05 10:53:25 -0300 | [diff] [blame] | 1944 | |
| 1945 | ---- |
| 1946 | [receive] |
| 1947 | allowGroup = GROUP_ALLOWED_TO_EXECUTE |
| 1948 | allowGroup = YET_ANOTHER_GROUP_ALLOWED_TO_EXECUTE |
| Sasa Zivkov | 59d89c3 | 2011-11-18 15:32:35 +0100 | [diff] [blame] | 1949 | maxObjectSizeLimit = 40 m |
| lincoln | 2be1160 | 2010-07-05 10:53:25 -0300 | [diff] [blame] | 1950 | ---- |
| 1951 | |
| Shawn Pearce | 5cb31bf | 2013-02-27 16:20:26 -0800 | [diff] [blame] | 1952 | [[receive.checkMagicRefs]]receive.checkMagicRefs:: |
| 1953 | + |
| 1954 | If true, Gerrit will verify the destination repository has |
| 1955 | no references under the magic 'refs/drafts', 'refs/for', or |
| 1956 | 'refs/publish' branch namespaces. Names under these locations |
| 1957 | confuse clients when trying to upload code reviews so Gerrit |
| 1958 | requires them to be empty. |
| 1959 | + |
| 1960 | If false Gerrit skips the sanity check and assumes administrators |
| 1961 | have ensured the repository does not contain any magic references. |
| 1962 | Setting to false to skip the check can decrease latency during push. |
| 1963 | + |
| 1964 | Default is true. |
| 1965 | |
| Gustaf Lundh | 9062fd6 | 2013-02-14 17:23:11 +0100 | [diff] [blame] | 1966 | [[receive.checkReferencedObjectsAreReachable]]receive.checkReferencedObjectsAreReachable:: |
| 1967 | + |
| 1968 | If set to true, Gerrit will validate that all referenced objects that |
| 1969 | are not included in the received pack are reachable by the user. |
| 1970 | + |
| 1971 | Carrying out this check on gits with many refs and commits can be a |
| 1972 | very CPU-heavy operation. For non public Gerrit-servers this check may |
| 1973 | be overkill. |
| 1974 | + |
| 1975 | Only disable this check if you trust the clients not to forge SHA1 |
| 1976 | references to access commits intended to be hidden from the user. |
| 1977 | + |
| 1978 | Default is true. |
| 1979 | |
| lincoln | 2be1160 | 2010-07-05 10:53:25 -0300 | [diff] [blame] | 1980 | [[receive.allowGroup]]receive.allowGroup:: |
| 1981 | + |
| 1982 | Name of the groups of users that are allowed to execute |
| 1983 | 'receive-pack' on the server. One or more groups can be set. |
| 1984 | + |
| 1985 | If no groups are added, any user will be allowed to execute |
| 1986 | 'receive-pack' on the server. |
| 1987 | |
| Sasa Zivkov | 59d89c3 | 2011-11-18 15:32:35 +0100 | [diff] [blame] | 1988 | [[receive.maxObjectSizeLimit]]receive.maxObjectSizeLimit:: |
| 1989 | + |
| 1990 | Maximum allowed Git object size that 'receive-pack' will accept. |
| 1991 | If an object is larger than the given size the pack-parsing will abort |
| 1992 | and the push operation will fail. If set to zero then there is no |
| 1993 | limit. |
| 1994 | + |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 1995 | Gerrit administrators can use this setting to prevent developers |
| Sasa Zivkov | 59d89c3 | 2011-11-18 15:32:35 +0100 | [diff] [blame] | 1996 | from pushing objects which are too large to Gerrit. |
| 1997 | + |
| 1998 | Default is zero. |
| 1999 | + |
| 2000 | Common unit suffixes of 'k', 'm', or 'g' are supported. |
| 2001 | |
| Dave Borowitz | 234734a | 2012-03-01 14:22:29 -0800 | [diff] [blame] | 2002 | [[receive.threadPoolSize]]receive.threadPoolSize:: |
| 2003 | + |
| 2004 | Maximum size of the thread pool in which the change data in received packs is |
| 2005 | processed. |
| 2006 | + |
| 2007 | Defaults to the number of available CPUs according to the Java runtime. |
| 2008 | |
| Shawn O. Pearce | c545c09 | 2012-07-27 16:38:55 -0700 | [diff] [blame] | 2009 | [[receive.changeUpdateThreads]]receive.changeUpdateThreads:: |
| 2010 | + |
| 2011 | Number of threads to perform change creation or patch set updates |
| 2012 | concurrently. Each thread uses its own database connection from |
| 2013 | the database connection pool, and if all threads are busy then |
| 2014 | main receive thread will also perform a change creation or patch |
| 2015 | set update. |
| 2016 | + |
| 2017 | Defaults to 1, using only the main receive thread. This feature is for |
| 2018 | databases with very high latency that can benfit from concurrent |
| 2019 | operations when multiple changes are impacted at once. |
| 2020 | |
| Dave Borowitz | 1c40136 | 2012-03-02 17:39:17 -0800 | [diff] [blame] | 2021 | [[receive.timeout]]receive.timeout:: |
| 2022 | + |
| Shawn O. Pearce | 00dd12d | 2012-03-12 15:52:11 -0700 | [diff] [blame] | 2023 | Overall timeout on the time taken to process the change data in |
| 2024 | received packs. Only includes the time processing Gerrit changes |
| 2025 | and updating references, not the time to index the pack. Values can |
| 2026 | be specified using standard time unit abbreviations ('ms', 'sec', |
| 2027 | 'min', etc.). |
| Dave Borowitz | 1c40136 | 2012-03-02 17:39:17 -0800 | [diff] [blame] | 2028 | + |
| Shawn O. Pearce | 00dd12d | 2012-03-12 15:52:11 -0700 | [diff] [blame] | 2029 | Default is 2 minutes. If no unit is specified, millisconds |
| 2030 | is assumed. |
| Dave Borowitz | 1c40136 | 2012-03-02 17:39:17 -0800 | [diff] [blame] | 2031 | |
| lincoln | 2be1160 | 2010-07-05 10:53:25 -0300 | [diff] [blame] | 2032 | |
| Hugo Josefson | 072b470 | 2010-04-21 19:27:11 +0200 | [diff] [blame] | 2033 | [[repository]]Section repository |
| 2034 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 2035 | Repositories in this sense are the same as projects. |
| 2036 | |
| Shawn O. Pearce | 897d921 | 2011-06-16 16:59:59 -0700 | [diff] [blame] | 2037 | In the following example configuration `Registered Users` is set |
| 2038 | to be the default owner of new projects. |
| Hugo Josefson | 072b470 | 2010-04-21 19:27:11 +0200 | [diff] [blame] | 2039 | |
| 2040 | ---- |
| 2041 | [repository "*"] |
| Hugo Josefson | 072b470 | 2010-04-21 19:27:11 +0200 | [diff] [blame] | 2042 | ownerGroup = Registered Users |
| 2043 | ---- |
| 2044 | |
| 2045 | [NOTE] |
| 2046 | Currently only the repository name `*` is supported. |
| 2047 | This is a wildcard designating all repositories. |
| 2048 | |
| Hugo Josefson | 072b470 | 2010-04-21 19:27:11 +0200 | [diff] [blame] | 2049 | [[repository.name.ownerGroup]]repository.<name>.ownerGroup:: |
| 2050 | + |
| 2051 | A name of a group which exists in the database. Zero, one or many |
| 2052 | groups are allowed. Each on its own line. Groups which don't exist |
| 2053 | in the database are ignored. |
| Hugo Josefson | 072b470 | 2010-04-21 19:27:11 +0200 | [diff] [blame] | 2054 | |
| Shawn O. Pearce | 94860ee | 2011-09-29 13:11:08 -0700 | [diff] [blame] | 2055 | [[rules]]Section rules |
| 2056 | ~~~~~~~~~~~~~~~~~~~~~~ |
| 2057 | |
| 2058 | [[rules.enable]]rules.enable:: |
| 2059 | + |
| 2060 | If true, Gerrit will load and excute 'rules.pl' files in each |
| 2061 | project's refs/meta/config branch, if present. When set to false, |
| 2062 | only the default internal rules will be used. |
| 2063 | + |
| 2064 | Default is true, to execute project specific rules. |
| 2065 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 2066 | [[sendemail]]Section sendemail |
| 2067 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | b0572c6 | 2009-06-01 14:18:22 -0700 | [diff] [blame] | 2068 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2069 | [[sendemail.enable]]sendemail.enable:: |
| Shawn O. Pearce | 2e4573b | 2009-06-02 09:09:50 -0700 | [diff] [blame] | 2070 | + |
| 2071 | If false Gerrit will not send email messages, for any reason, |
| 2072 | and all other properties of section sendemail are ignored. |
| 2073 | + |
| 2074 | By default, true, allowing notifications to be sent. |
| 2075 | |
| Shawn O. Pearce | 5c31bd7 | 2009-09-10 18:13:33 -0700 | [diff] [blame] | 2076 | [[sendemail.from]]sendemail.from:: |
| 2077 | + |
| 2078 | Designates what name and address Gerrit will place in the From |
| 2079 | field of any generated email messages. The supported values are: |
| 2080 | + |
| 2081 | * `USER` |
| 2082 | + |
| 2083 | Gerrit will set the From header to use the current user's |
| 2084 | Full Name and Preferred Email. This may cause messsages to be |
| 2085 | classified as spam if the user's domain has SPF or DKIM enabled |
| 2086 | and <<sendemail.smtpServer,sendemail.smtpServer>> is not a trusted |
| 2087 | relay for that domain. |
| 2088 | + |
| 2089 | * `MIXED` |
| 2090 | + |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 2091 | Shorthand for `${user} (Code Review) <review@example.com>` where |
| Shawn O. Pearce | 5c31bd7 | 2009-09-10 18:13:33 -0700 | [diff] [blame] | 2092 | `review@example.com` is the same as <<user.email,user.email>>. |
| 2093 | See below for a description of how the replacement is handled. |
| 2094 | + |
| 2095 | * `SERVER` |
| 2096 | + |
| 2097 | Gerrit will set the From header to the same name and address |
| 2098 | it records in any commits Gerrit creates. This is set by |
| 2099 | <<user.name,user.name>> and <<user.email,user.email>>, or guessed |
| 2100 | from the local operating system. |
| 2101 | + |
| 2102 | * 'Code Review' `<`'review'`@`'example.com'`>` |
| 2103 | + |
| 2104 | If set to a name and email address in brackets, Gerrit will use |
| 2105 | this name and email address for any messages, overriding the name |
| 2106 | that may have been selected for commits by user.name and user.email. |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 2107 | Optionally, the name portion may contain the placeholder `${user}`, |
| Shawn O. Pearce | 5c31bd7 | 2009-09-10 18:13:33 -0700 | [diff] [blame] | 2108 | which is replaced by the Full Name of the current user. |
| 2109 | |
| 2110 | + |
| 2111 | By default, MIXED. |
| 2112 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2113 | [[sendemail.smtpServer]]sendemail.smtpServer:: |
| Shawn O. Pearce | b0572c6 | 2009-06-01 14:18:22 -0700 | [diff] [blame] | 2114 | + |
| 2115 | Hostname (or IP address) of a SMTP server that will relay |
| 2116 | messages generated by Gerrit to end users. |
| 2117 | + |
| 2118 | By default, 127.0.0.1 (aka localhost). |
| 2119 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2120 | [[sendemail.smtpServerPort]]sendemail.smtpServerPort:: |
| Shawn O. Pearce | b0572c6 | 2009-06-01 14:18:22 -0700 | [diff] [blame] | 2121 | + |
| 2122 | Port number of the SMTP server in sendemail.smtpserver. |
| 2123 | + |
| Shawn O. Pearce | 6e9a83f | 2009-11-02 10:30:48 -0800 | [diff] [blame] | 2124 | By default, 25, or 465 if smtpEncryption is 'ssl'. |
| 2125 | |
| 2126 | [[sendemail.smtpEncryption]]sendemail.smtpEncryption:: |
| 2127 | + |
| 2128 | Specify the encryption to use, either 'ssl' or 'tls'. |
| 2129 | + |
| 2130 | By default, 'none', indicating no encryption is used. |
| 2131 | |
| 2132 | [[sendemail.sslVerify]]sendemail.sslVerify:: |
| 2133 | + |
| 2134 | If false and sendemail.smtpEncryption is 'ssl' or 'tls', Gerrit |
| 2135 | will not verify the server certificate when it connects to send |
| 2136 | an email message. |
| 2137 | + |
| 2138 | By default, true, requiring the certificate to be verified. |
| Shawn O. Pearce | b0572c6 | 2009-06-01 14:18:22 -0700 | [diff] [blame] | 2139 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2140 | [[sendemail.smtpUser]]sendemail.smtpUser:: |
| Shawn O. Pearce | b0572c6 | 2009-06-01 14:18:22 -0700 | [diff] [blame] | 2141 | + |
| 2142 | User name to authenticate with, if required for relay. |
| 2143 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2144 | [[sendemail.smtpPass]]sendemail.smtpPass:: |
| Shawn O. Pearce | b0572c6 | 2009-06-01 14:18:22 -0700 | [diff] [blame] | 2145 | + |
| 2146 | Password for the account named by sendemail.smtpUser. |
| 2147 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2148 | [[sendemail.allowrcpt]]sendemail.allowrcpt:: |
| Shawn O. Pearce | 219a8ee | 2009-06-01 18:13:57 -0700 | [diff] [blame] | 2149 | + |
| 2150 | If present, each value adds one entry to the whitelist of email |
| 2151 | addresses that Gerrit can send email to. If set to a complete |
| 2152 | email address, that one address is added to the white list. |
| 2153 | If set to a domain name, any address at that domain can receive |
| 2154 | email from Gerrit. |
| 2155 | + |
| 2156 | By default, unset, permitting delivery to any email address. |
| 2157 | |
| Shawn O. Pearce | 02aacbc | 2012-06-12 13:44:22 -0700 | [diff] [blame] | 2158 | [[sendemail.includeDiff]]sendemail.includeDiff:: |
| 2159 | + |
| Bruce Zu | eb00ff3 | 2012-11-27 17:38:10 +0800 | [diff] [blame] | 2160 | If true, new change emails and merged change emails from Gerrit |
| 2161 | will include the complete unified diff of the change. |
| 2162 | Variable maxmimumDiffSize places an upper limit on how large the |
| 2163 | email can get when this option is enabled. |
| Shawn O. Pearce | 02aacbc | 2012-06-12 13:44:22 -0700 | [diff] [blame] | 2164 | + |
| 2165 | By default, false. |
| 2166 | |
| Shawn O. Pearce | 28a950b | 2012-06-12 14:36:34 -0700 | [diff] [blame] | 2167 | [[sendemail.maximumDiffSize]]sendemail.maximumDiffSize:: |
| 2168 | + |
| 2169 | Largest size of unified diff output to include in an email. When |
| 2170 | the diff exceeds this size the file paths will be listed instead. |
| 2171 | Standard byte unit suffixes are supported. |
| 2172 | + |
| 2173 | By default, 256 KiB. |
| 2174 | |
| Alex Blewitt | 9cca740 | 2011-02-11 01:39:30 +0000 | [diff] [blame] | 2175 | [[sendemail.importance]]sendemail.importance:: |
| 2176 | + |
| 2177 | If present, emails sent from Gerrit will have the given level |
| 2178 | of importance. Valid values include 'high' and 'low', which |
| 2179 | email clients will render in different ways. |
| 2180 | + |
| 2181 | By default, unset, so no Importance header is generated. |
| 2182 | |
| 2183 | [[sendemail.expiryDays]]sendemail.expiryDays:: |
| 2184 | + |
| 2185 | If present, emails sent from Gerrit will expire after the given |
| 2186 | number of days. This will add the Expiry-Date header and |
| 2187 | email clients may expire or expunge mails whose Expiry-Date |
| 2188 | header is in the past. This should be a positive non-zero |
| 2189 | number indicating how many days in the future the mails |
| 2190 | should expire. |
| 2191 | + |
| 2192 | By default, unset, so no Expiry-Date header is generated. |
| 2193 | |
| Shawn O. Pearce | dba9764 | 2011-09-07 20:12:31 -0700 | [diff] [blame] | 2194 | |
| 2195 | [[site]]Section site |
| 2196 | ~~~~~~~~~~~~~~~~~~~~ |
| 2197 | |
| 2198 | [[site.checkUserAgent]]site.checkUserAgent:: |
| 2199 | + |
| 2200 | If true the server checks the User-Agent HTTP header and sends the |
| 2201 | correct JavaScript to the client as part of the initial page load. |
| 2202 | This usually reduces a round-trip for the client, allowing the UI to |
| 2203 | start more quickly. If false, a tiny JavaScript loader is sent to the |
| 2204 | client instead to determine the correct code to use. Default is true. |
| 2205 | |
| 2206 | [[site.refreshHeaderFooter]]site.refreshHeaderFooter:: |
| 2207 | + |
| 2208 | If true the server checks the site header, footer and CSS files for |
| 2209 | updated versions. If false, a server restart is required to change |
| 2210 | any of these resources. Default is true, allowing automatic reloads. |
| 2211 | |
| Shawn O. Pearce | 6bd04fd | 2012-04-05 14:39:22 -0700 | [diff] [blame] | 2212 | [[site.enableDeprecatedQuery]]site.enableDeprecatedQuery:: |
| 2213 | + |
| 2214 | If true the deprecated `/query` URL is available to return JSON |
| 2215 | and text results for changes. If false, the URL is disabled and |
| 2216 | returns 404 to clients. Default is true, enabling `/query`. |
| 2217 | |
| Sasa Zivkov | de980a4 | 2012-06-14 14:57:53 +0200 | [diff] [blame] | 2218 | [[site.upgradeSchemaOnStartup]]site.upgradeSchemaOnStartup:: |
| 2219 | + |
| 2220 | Control whether schema upgrade should be done on Gerrit startup. The following |
| 2221 | values are supported: |
| 2222 | + |
| 2223 | * `OFF` |
| 2224 | + |
| 2225 | No automatic schema upgrade on startup. |
| 2226 | + |
| 2227 | * `AUTO` |
| 2228 | + |
| 2229 | Perform schema migration on startup, if necessary. If, as a result of |
| 2230 | schema migration, there would be any unused database objects they will |
| 2231 | be dropped automatically. |
| 2232 | + |
| 2233 | * `AUTO_NO_PRUNE` |
| 2234 | + |
| 2235 | Like `AUTO` but unused database objects will not be pruned. |
| 2236 | |
| 2237 | + |
| 2238 | The default is `OFF`. |
| 2239 | |
| Shawn O. Pearce | 521380a | 2012-05-11 14:57:56 -0700 | [diff] [blame] | 2240 | [[ssh-alias]] Section ssh-alias |
| 2241 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 2242 | |
| 2243 | Variables in section ssh-alias permit the site administrator to alias |
| 2244 | another command from Gerrit or a plugin into the `gerrit` command |
| 2245 | namespace. To alias `replication start` to `gerrit replicate`: |
| 2246 | |
| 2247 | ---- |
| 2248 | [ssh-alias] |
| 2249 | replicate = replication start |
| 2250 | ---- |
| Shawn O. Pearce | dba9764 | 2011-09-07 20:12:31 -0700 | [diff] [blame] | 2251 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 2252 | [[sshd]] Section sshd |
| Shawn O. Pearce | a758fef | 2009-08-19 08:29:32 -0700 | [diff] [blame] | 2253 | ~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | 9410f2c | 2009-05-14 10:26:47 -0700 | [diff] [blame] | 2254 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2255 | [[sshd.listenAddress]]sshd.listenAddress:: |
| Shawn O. Pearce | 1d3cb444 | 2009-05-30 14:03:31 -0700 | [diff] [blame] | 2256 | + |
| 2257 | Specifies the local addresses the internal SSHD should listen |
| 2258 | for connections on. The following forms may be used to specify |
| 2259 | an address. In any form, `:'port'` may be omitted to use the |
| 2260 | default of 29418. |
| 2261 | + |
| 2262 | * 'hostname':'port' (for example `review.example.com:29418`) |
| 2263 | * 'IPv4':'port' (for example `10.0.0.1:29418`) |
| 2264 | * ['IPv6']:'port' (for example `[ff02::1]:29418`) |
| Edwin Kempin | cdb0e00 | 2011-09-08 14:23:30 +0200 | [diff] [blame] | 2265 | * *:'port' (for example `*:29418`) |
| Shawn O. Pearce | 1d3cb444 | 2009-05-30 14:03:31 -0700 | [diff] [blame] | 2266 | |
| 2267 | + |
| 2268 | If multiple values are supplied, the daemon will listen on all |
| 2269 | of them. |
| 2270 | + |
| Shawn O. Pearce | 6af6f5f | 2010-06-08 17:38:43 -0700 | [diff] [blame] | 2271 | To disable the internal SSHD, set listenAddress to `off`. |
| 2272 | + |
| Shawn O. Pearce | 1d3cb444 | 2009-05-30 14:03:31 -0700 | [diff] [blame] | 2273 | By default, *:29418. |
| 2274 | |
| James Y Knight | 910bd86 | 2011-01-11 20:05:56 -0500 | [diff] [blame] | 2275 | [[sshd.advertisedAddress]]sshd.advertisedAddress:: |
| 2276 | + |
| 2277 | Specifies the addresses clients should be told to connect to. |
| 2278 | This may differ from sshd.listenAddress if a firewall based port |
| 2279 | redirector is being used, making Gerrit appear to answer on port |
| 2280 | 22. The following forms may be used to specify an address. In any |
| 2281 | form, `:'port'` may be omitted to use the default SSH port of 22. |
| 2282 | + |
| 2283 | * 'hostname':'port' (for example `review.example.com:22`) |
| 2284 | * 'IPv4':'port' (for example `10.0.0.1:29418`) |
| 2285 | * ['IPv6']:'port' (for example `[ff02::1]:29418`) |
| 2286 | |
| 2287 | + |
| 2288 | If multiple values are supplied, the daemon will advertise all |
| 2289 | of them. |
| 2290 | + |
| 2291 | By default, sshd.listenAddress. |
| 2292 | |
| Shawn O. Pearce | 149238a | 2009-09-10 12:25:20 -0700 | [diff] [blame] | 2293 | [[sshd.reuseAddress]]sshd.reuseAddress:: |
| Shawn O. Pearce | 9410f2c | 2009-05-14 10:26:47 -0700 | [diff] [blame] | 2294 | + |
| 2295 | If true, permits the daemon to bind to the port even if the port |
| 2296 | is already in use. If false, the daemon ensures the port is not |
| 2297 | in use before starting. Busy sites may need to set this to true |
| 2298 | to permit fast restarts. |
| 2299 | + |
| 2300 | By default, true. |
| Shawn O. Pearce | 51967cd | 2009-05-08 19:46:57 -0700 | [diff] [blame] | 2301 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2302 | [[sshd.tcpKeepAlive]]sshd.tcpKeepAlive:: |
| Shawn O. Pearce | fc9081f | 2009-05-14 10:26:59 -0700 | [diff] [blame] | 2303 | + |
| 2304 | If true, enables TCP keepalive messages to the other side, so |
| 2305 | the daemon can terminate connections if the peer disappears. |
| 2306 | + |
| 2307 | By default, true. |
| 2308 | |
| Shawn O. Pearce | 1a4580b | 2009-11-19 17:37:10 -0800 | [diff] [blame] | 2309 | [[sshd.threads]]sshd.threads:: |
| 2310 | + |
| 2311 | Number of threads to use when executing SSH command requests. |
| 2312 | If additional requests are received while all threads are busy they |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 2313 | are queued and serviced in a first-come-first-served order. |
| Shawn O. Pearce | 1a4580b | 2009-11-19 17:37:10 -0800 | [diff] [blame] | 2314 | + |
| 2315 | By default, 1.5x the number of CPUs available to the JVM. |
| 2316 | |
| Nico Sallembien | fc53f7f | 2010-05-18 16:40:10 -0700 | [diff] [blame] | 2317 | [[sshd.batchThreads]]sshd.batchThreads:: |
| 2318 | + |
| 2319 | Number of threads to allocate for SSH command requests from |
| Fredrik Luthander | 4684302 | 2012-03-13 16:11:02 +0100 | [diff] [blame] | 2320 | link:access-control.html#non-interactive_users[non-interactive users]. |
| 2321 | If equals to 0, then all non-interactive requests are executed in the same |
| 2322 | queue as interactive requests. |
| Nico Sallembien | fc53f7f | 2010-05-18 16:40:10 -0700 | [diff] [blame] | 2323 | + |
| 2324 | Any other value will remove the number of threads from the queue |
| 2325 | allocated to interactive users, and create a separate thread pool |
| 2326 | of the requested size, which will be used to run commands from |
| 2327 | non-interactive users. |
| 2328 | + |
| 2329 | If the number of threads requested for non-interactive users is larger |
| 2330 | than the total number of threads allocated in sshd.threads, then the |
| 2331 | value of sshd.threads is increased to accomodate the requested value. |
| 2332 | + |
| 2333 | By default, 0. |
| 2334 | |
| Kenny Root | 15ac1b8 | 2010-02-24 00:29:20 -0800 | [diff] [blame] | 2335 | [[sshd.streamThreads]]sshd.streamThreads:: |
| 2336 | + |
| 2337 | Number of threads to use when formatting events to asynchronous |
| 2338 | streaming clients. Event formatting is multiplexed onto this thread |
| 2339 | pool by a simple FIFO scheduling system. |
| 2340 | + |
| 2341 | By default, 1 plus the number of CPUs available to the JVM. |
| 2342 | |
| Edwin Kempin | b5df3b8 | 2011-10-10 11:31:14 +0200 | [diff] [blame] | 2343 | [[sshd.commandStartThreads]]sshd.commandStartThreads:: |
| Shawn O. Pearce | d629655 | 2011-05-15 13:56:30 -0700 | [diff] [blame] | 2344 | + |
| 2345 | Number of threads used to parse a command line submitted by a client |
| 2346 | over SSH for execution, create the internal data structures used by |
| 2347 | that command, and schedule it for execution on another thread. |
| 2348 | + |
| 2349 | By default, 2. |
| 2350 | |
| Shawn O. Pearce | 8a0bf36 | 2010-11-05 17:49:41 -0700 | [diff] [blame] | 2351 | [[sshd.maxAuthTries]]sshd.maxAuthTries:: |
| 2352 | + |
| 2353 | Maximum number of authentication attempts before the server |
| 2354 | disconnects the client. Each public key that a client has loaded |
| 2355 | into its local agent counts as one auth request. Users can work |
| 2356 | around the server's limit by loading less keys into their agent, |
| 2357 | or selecting a specific key in their `~/.ssh/config` file with |
| 2358 | the `IdentityFile` option. |
| 2359 | + |
| 2360 | By default, 6. |
| 2361 | |
| 2362 | [[sshd.loginGraceTime]]sshd.loginGraceTime:: |
| 2363 | + |
| 2364 | Time in seconds that a client has to authenticate before the server |
| 2365 | automatically terminates their connection. Values should use common |
| 2366 | unit suffixes to express their setting: |
| 2367 | + |
| 2368 | * s, sec, second, seconds |
| 2369 | * m, min, minute, minutes |
| 2370 | * h, hr, hour, hours |
| 2371 | * d, day, days |
| 2372 | |
| 2373 | + |
| 2374 | By default, 2 minutes. |
| 2375 | |
| Christian Aistleitner | 3d79459 | 2013-04-08 00:19:40 +0200 | [diff] [blame] | 2376 | [[sshd.idleTimeout]]sshd.idleTimeout:: |
| 2377 | + |
| 2378 | Time in seconds after which the server automatically terminates idle |
| 2379 | connections (or 0 to disable closing of idle connections). Values |
| 2380 | should use common unit suffixes to express their setting: |
| 2381 | + |
| 2382 | * s, sec, second, seconds |
| 2383 | * m, min, minute, minutes |
| 2384 | * h, hr, hour, hours |
| 2385 | * d, day, days |
| 2386 | |
| 2387 | + |
| 2388 | By default, 0. |
| 2389 | |
| Shawn O. Pearce | 8a0bf36 | 2010-11-05 17:49:41 -0700 | [diff] [blame] | 2390 | [[sshd.maxConnectionsPerUser]]sshd.maxConnectionsPerUser:: |
| 2391 | + |
| 2392 | Maximum number of concurrent SSH sessions that a user account |
| 2393 | may open at one time. This is the number of distinct SSH logins |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 2394 | that each user may have active at one time, and is not related to |
| Shawn O. Pearce | 8a0bf36 | 2010-11-05 17:49:41 -0700 | [diff] [blame] | 2395 | the number of commands a user may issue over a single connection. |
| 2396 | If set to 0, there is no limit. |
| 2397 | + |
| 2398 | By default, 64. |
| 2399 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2400 | [[sshd.cipher]]sshd.cipher:: |
| Shawn O. Pearce | 0bf2f52 | 2009-05-14 11:02:03 -0700 | [diff] [blame] | 2401 | + |
| 2402 | Available ciphers. To permit multiple ciphers, specify multiple |
| 2403 | `sshd.cipher` keys in the configuration file, one cipher name |
| 2404 | per key. Cipher names starting with `+` are enabled in addition |
| 2405 | to the default ciphers, cipher names starting with `-` are removed |
| 2406 | from the default cipher set. |
| 2407 | + |
| 2408 | Supported ciphers: aes128-cbc, aes128-cbc, aes256-cbc, blowfish-cbc, |
| 2409 | 3des-cbc, none. |
| 2410 | + |
| 2411 | By default, all supported ciphers except `none` are available. |
| 2412 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2413 | [[sshd.mac]]sshd.mac:: |
| Shawn O. Pearce | 0bf2f52 | 2009-05-14 11:02:03 -0700 | [diff] [blame] | 2414 | + |
| 2415 | Available MAC (message authentication code) algorithms. To permit |
| 2416 | multiple algorithms, specify multiple `sshd.mac` keys in the |
| 2417 | configuration file, one MAC per key. MAC names starting with `+` |
| 2418 | are enabled in addition to the default MACs, MAC names starting with |
| 2419 | `-` are removed from the default MACs. |
| 2420 | + |
| 2421 | Supported MACs: hmac-md5, hmac-md5-96, hmac-sha1, hmac-sha1-96. |
| 2422 | + |
| 2423 | By default, all supported MACs are available. |
| 2424 | |
| Alex Blewitt | 7efb06f | 2013-04-01 12:46:48 -0400 | [diff] [blame] | 2425 | [[sshd.kerberosKeytab]]sshd.kerberosKeytab:: |
| 2426 | + |
| 2427 | Enable kerberos authentication for SSH connections. To permit |
| 2428 | kerberos authentication, the server must have a host principal |
| 2429 | (see `sshd.kerberosPrincipal`) which is acquired from a keytab. |
| 2430 | This must be provisioned by the kerberos administrators, and is |
| 2431 | typically installed into `/etc/krb5.keytab` on host machines. |
| 2432 | + |
| 2433 | The keytab must contain at least one `host/` principal, typically |
| 2434 | using the host's canonical name. If it does not use the |
| 2435 | canonical name, the `sshd.kerberosPrincipal` should be configured |
| 2436 | with the correct name. |
| 2437 | + |
| 2438 | By default, not set and so kerberos authentication is not enabled. |
| 2439 | |
| 2440 | [[sshd.kerberosPrincipal]]sshd.kerberosPrincipal:: |
| 2441 | + |
| 2442 | If kerberos authentication is enabled with `sshd.kerberosKeytab`, |
| 2443 | instead use the given principal name instead of the default. |
| 2444 | If the principal does not begin with `host/` a warning message is |
| 2445 | printed and may prevent successful authentication. |
| 2446 | + |
| 2447 | This may be useful if the host is behind an IP load balancer or |
| 2448 | other SSH forwarding systems, since the principal name is constructed |
| 2449 | by the client and must match for kerberos authentication to work. |
| 2450 | + |
| 2451 | By default, `host/canonical.host.name` |
| 2452 | |
| Shawn O. Pearce | 07bd6fb | 2011-04-29 19:15:47 -0700 | [diff] [blame] | 2453 | [[suggest]] Section suggest |
| 2454 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 2455 | |
| Dave Borowitz | 1ae8c53 | 2012-03-09 18:39:40 -0800 | [diff] [blame] | 2456 | [[suggest.accounts]]suggest.accounts:: |
| Shawn O. Pearce | 07bd6fb | 2011-04-29 19:15:47 -0700 | [diff] [blame] | 2457 | + |
| Dave Borowitz | 45baa89 | 2012-02-23 16:43:05 -0800 | [diff] [blame] | 2458 | If `true`, visible user accounts (according to the value of |
| 2459 | `accounts.visibility`) will be offered as completion suggestions |
| 2460 | when adding a reviewer to a change, or a user to a group. |
| Shawn O. Pearce | 07bd6fb | 2011-04-29 19:15:47 -0700 | [diff] [blame] | 2461 | + |
| Dave Borowitz | 45baa89 | 2012-02-23 16:43:05 -0800 | [diff] [blame] | 2462 | If `false`, account suggestion is disabled. |
| Shawn O. Pearce | 07bd6fb | 2011-04-29 19:15:47 -0700 | [diff] [blame] | 2463 | + |
| Dave Borowitz | 45baa89 | 2012-02-23 16:43:05 -0800 | [diff] [blame] | 2464 | Older configurations may also have one of the `accounts.visibility` |
| 2465 | values for this field, including `OFF` as a synonym for `NONE`. If |
| 2466 | `accounts.visibility` is also set, that value overrides this one; |
| 2467 | otherwise, this value applies to both `suggest.accounts` and |
| 2468 | `accounts.visibility`. |
| Edwin Kempin | 4248881 | 2011-05-20 03:11:43 +0200 | [diff] [blame] | 2469 | + |
| Dave Borowitz | 45baa89 | 2012-02-23 16:43:05 -0800 | [diff] [blame] | 2470 | New configurations should prefer the boolean value for this field |
| 2471 | and an enum value for `accounts.visibility`. |
| Shawn O. Pearce | 07bd6fb | 2011-04-29 19:15:47 -0700 | [diff] [blame] | 2472 | |
| Edwin Kempin | f957dc2 | 2012-10-19 20:41:18 +0200 | [diff] [blame] | 2473 | [[suggest.from]]suggest.from:: |
| 2474 | + |
| 2475 | The number of characters that a user must have typed before suggestions |
| 2476 | are provided. If set to 0, suggestions are always provided. |
| 2477 | + |
| 2478 | By default 0. |
| 2479 | |
| Shawn O. Pearce | 2ba3ab4 | 2010-02-25 12:10:10 -0800 | [diff] [blame] | 2480 | [[theme]] Section theme |
| 2481 | ~~~~~~~~~~~~~~~~~~~~~~~ |
| 2482 | |
| 2483 | [[theme.backgroundColor]]theme.backgroundColor:: |
| 2484 | + |
| 2485 | Background color for the page, and major data tables like the all |
| 2486 | open changes table or the account dashboard. The value must be a |
| 2487 | valid HTML hex color code, or standard color name. |
| 2488 | + |
| Chad Horohoe | bbdf748 | 2012-11-13 18:23:15 -0800 | [diff] [blame] | 2489 | By default white, `FFFFFF`. |
| Shawn O. Pearce | 2ba3ab4 | 2010-02-25 12:10:10 -0800 | [diff] [blame] | 2490 | |
| 2491 | [[theme.topMenuColor]]theme.topMenuColor:: |
| 2492 | + |
| 2493 | This is the color of the main menu bar at the top of the page. |
| 2494 | The value must be a valid HTML hex color code, or standard color |
| Chad Horohoe | bbdf748 | 2012-11-13 18:23:15 -0800 | [diff] [blame] | 2495 | name. |
| 2496 | + |
| 2497 | By default white, `FFFFFF`. |
| Shawn O. Pearce | 2ba3ab4 | 2010-02-25 12:10:10 -0800 | [diff] [blame] | 2498 | |
| 2499 | [[theme.textColor]]theme.textColor:: |
| 2500 | + |
| 2501 | Text color for the page, and major data tables like the all |
| 2502 | open changes table or the account dashboard. The value must be a |
| 2503 | valid HTML hex color code, or standard color name. |
| 2504 | + |
| Chad Horohoe | bbdf748 | 2012-11-13 18:23:15 -0800 | [diff] [blame] | 2505 | By default dark grey, `353535`. |
| Shawn O. Pearce | 2ba3ab4 | 2010-02-25 12:10:10 -0800 | [diff] [blame] | 2506 | |
| 2507 | [[theme.trimColor]]theme.trimColor:: |
| 2508 | + |
| 2509 | Primary color used as a background color behind text. This is |
| 2510 | the color of the main menu bar at the top, of table headers, |
| 2511 | and of major UI areas that we want to offset from other portions |
| 2512 | of the page. The value must be a valid HTML hex color code, or |
| 2513 | standard color name. |
| 2514 | + |
| Chad Horohoe | bbdf748 | 2012-11-13 18:23:15 -0800 | [diff] [blame] | 2515 | By default a light grey, `EEEEEE`. |
| Shawn O. Pearce | 2ba3ab4 | 2010-02-25 12:10:10 -0800 | [diff] [blame] | 2516 | |
| 2517 | [[theme.selectionColor]]theme.selectionColor:: |
| 2518 | + |
| 2519 | Background color used within a trimColor area to denote the currently |
| 2520 | selected tab, or the background color used in a table to denote the |
| 2521 | currently selected row. The value must be a valid HTML hex color |
| 2522 | code, or standard color name. |
| 2523 | + |
| Chad Horohoe | bbdf748 | 2012-11-13 18:23:15 -0800 | [diff] [blame] | 2524 | By default a pale blue, `D8EDF9`. |
| Shawn O. Pearce | 2ba3ab4 | 2010-02-25 12:10:10 -0800 | [diff] [blame] | 2525 | |
| Andrew Hutchings | cfd7abb | 2012-06-29 10:57:05 +0100 | [diff] [blame] | 2526 | [[theme.changeTableOutdatedColor]]theme.changeTableOutdatedColor:: |
| 2527 | + |
| 2528 | Background color used for patch outdated messages. The value must be |
| 2529 | a valid HTML hex color code, or standard color name. |
| 2530 | + |
| Edwin Kempin | b034733 | 2012-07-17 10:14:32 +0200 | [diff] [blame] | 2531 | By default a shade of red, `F08080`. |
| Andrew Hutchings | cfd7abb | 2012-06-29 10:57:05 +0100 | [diff] [blame] | 2532 | |
| 2533 | [[theme.tableOddRowColor]]theme.tableOddRowColor:: |
| 2534 | + |
| 2535 | Background color for tables such as lists of open reviews for odd |
| 2536 | rows. This is so you can have a different color for odd and even |
| 2537 | rows of the table. The value must be a valid HTML hex color code, |
| 2538 | or standard color name. |
| 2539 | + |
| 2540 | By default transparent. |
| 2541 | |
| 2542 | [[theme.tableEvenRowColor]]theme.tableEvenRowColor:: |
| 2543 | + |
| 2544 | Background color for tables such as lists of open reviews for even |
| 2545 | rows. This is so you can have a different color for odd and even |
| 2546 | rows of the table. The value must be a valid HTML hex color code, |
| 2547 | or standard color name. |
| 2548 | + |
| 2549 | By default transparent. |
| 2550 | |
| Shawn O. Pearce | a83bb1c | 2011-05-20 08:46:48 -0700 | [diff] [blame] | 2551 | A different theme may be used for signed-in vs. signed-out user status |
| 2552 | by using the "signed-in" and "signed-out" theme sections. Variables |
| 2553 | not specified in a section are inherited from the default theme. |
| 2554 | |
| 2555 | ---- |
| 2556 | [theme] |
| 2557 | backgroundColor = FFFFFF |
| 2558 | [theme "signed-in"] |
| 2559 | backgroundColor = C0C0C0 |
| 2560 | [theme "signed-out"] |
| 2561 | backgroundColor = 00FFFF |
| 2562 | ---- |
| 2563 | |
| Goran Lungberg | 04132a1 | 2010-06-15 17:20:37 -0700 | [diff] [blame] | 2564 | [[trackingid]] Section trackingid |
| Shawn O. Pearce | 91763a0 | 2010-06-16 15:39:33 -0700 | [diff] [blame] | 2565 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| Goran Lungberg | 04132a1 | 2010-06-15 17:20:37 -0700 | [diff] [blame] | 2566 | |
| Shawn O. Pearce | e800b1e | 2010-06-16 17:33:43 -0700 | [diff] [blame] | 2567 | Tagged footer lines containing references to external |
| 2568 | tracking systems, parsed out of the commit message and |
| 2569 | saved in Gerrit's database. After making changes to |
| 2570 | this section, existing changes must be reindexed with the |
| 2571 | link:pgm-ScanTrackingIds.html[ScanTrackingIds] program. |
| Goran Lungberg | 04132a1 | 2010-06-15 17:20:37 -0700 | [diff] [blame] | 2572 | |
| Edwin Kempin | bb421f1 | 2011-08-25 11:19:00 +0200 | [diff] [blame] | 2573 | The tracking ids are searchable using tr:<tracking id> or |
| Shawn O. Pearce | 91763a0 | 2010-06-16 15:39:33 -0700 | [diff] [blame] | 2574 | bug:<tracking id>. |
| Goran Lungberg | 04132a1 | 2010-06-15 17:20:37 -0700 | [diff] [blame] | 2575 | |
| 2576 | ---- |
| 2577 | [trackingid "jira-bug"] |
| 2578 | footer = Bugfix: |
| 2579 | match = JRA\\d{2,8} |
| 2580 | system = JIRA |
| 2581 | |
| 2582 | [trackingid "jira-feature"] |
| 2583 | footer = Feature |
| 2584 | match = JRA(\\d{2,8}) |
| 2585 | system = JIRA |
| 2586 | ---- |
| 2587 | |
| 2588 | [[trackingid.name.footer]]trackingid.<name>.footer:: |
| 2589 | + |
| 2590 | A prefix tag that identify the footer line to parse for tracking ids. |
| Kevin Degi | 9af42ea | 2011-08-01 15:54:42 -0600 | [diff] [blame] | 2591 | Several trackingid entries can have the same footer tag. A single |
| 2592 | trackingid entry can have multiple footer tags. If multiple footer |
| 2593 | tags are specified, each tag will be parsed separately. |
| Goran Lungberg | 04132a1 | 2010-06-15 17:20:37 -0700 | [diff] [blame] | 2594 | (the trailing ":" is optional) |
| 2595 | |
| 2596 | [[trackingid.name.match]]trackingid.<name>.match:: |
| 2597 | + |
| Magnus Bäck | e561183 | 2011-02-02 08:57:15 +0100 | [diff] [blame] | 2598 | A link:http://download.oracle.com/javase/6/docs/api/java/util/regex/Pattern.html[standard |
| 2599 | Java regular expression (java.util.regex)] used to match the |
| 2600 | external tracking id part of the footer line. The match can |
| 2601 | result in several entries in the DB. If grouping is used in the |
| 2602 | regex the first group will be interpreted as the tracking id. |
| Christian Aistleitner | 5cec368 | 2013-03-16 23:02:37 +0100 | [diff] [blame] | 2603 | Tracking ids longer than 32 characters will be ignored. |
| Goran Lungberg | 04132a1 | 2010-06-15 17:20:37 -0700 | [diff] [blame] | 2604 | + |
| 2605 | The configuration file parser eats one level of backslashes, so the |
| 2606 | character class `\s` requires `\\s` in the configuration file. The |
| 2607 | parser also terminates the line at the first `#`, so a match |
| 2608 | expression containing # must be wrapped in double quotes. |
| 2609 | |
| 2610 | [[trackingid.name.system]]trackingid.<name>.system:: |
| 2611 | + |
| David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 2612 | The name of the external tracking system (maximum 10 characters). |
| Goran Lungberg | 04132a1 | 2010-06-15 17:20:37 -0700 | [diff] [blame] | 2613 | It is possible to have several trackingid entries for the same |
| 2614 | tracking system. |
| 2615 | |
| Shawn O. Pearce | 6e4dfdd | 2010-05-12 17:26:08 -0700 | [diff] [blame] | 2616 | [[transfer]] Section transfer |
| 2617 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 2618 | |
| 2619 | [[transfer.timeout]]transfer.timeout:: |
| 2620 | + |
| 2621 | Number of seconds to wait for a single network read or write |
| 2622 | to complete before giving up and declaring the remote side is |
| 2623 | not responding. If 0, there is no timeout, and this server will |
| 2624 | wait indefinitely for a transfer to finish. |
| 2625 | + |
| 2626 | A timeout should be large enough to mostly transfer the objects to |
| 2627 | the other side. 1 second may be too small for larger projects, |
| 2628 | especially over a WAN link, while 10-30 seconds is a much more |
| 2629 | reasonable timeout value. |
| 2630 | + |
| 2631 | Defaults to 0 seconds, wait indefinitely. |
| 2632 | |
| lincoln | 2be1160 | 2010-07-05 10:53:25 -0300 | [diff] [blame] | 2633 | |
| 2634 | [[upload]]Section upload |
| Remy Bohmer | 203eea3 | 2012-02-19 21:21:36 +0100 | [diff] [blame] | 2635 | ~~~~~~~~~~~~~~~~~~~~~~~~ |
| lincoln | 2be1160 | 2010-07-05 10:53:25 -0300 | [diff] [blame] | 2636 | Sets the group of users allowed to execute 'upload-pack' on the |
| 2637 | server, 'upload-pack' is what runs on the server during a user's |
| 2638 | fetch, clone or repo sync command. |
| 2639 | |
| 2640 | ---- |
| 2641 | [upload] |
| 2642 | allowGroup = GROUP_ALLOWED_TO_EXECUTE |
| 2643 | allowGroup = YET_ANOTHER_GROUP_ALLOWED_TO_EXECUTE |
| 2644 | ---- |
| 2645 | |
| 2646 | [[upload.allowGroup]]upload.allowGroup:: |
| 2647 | + |
| 2648 | Name of the groups of users that are allowed to execute 'upload-pack' |
| 2649 | on the server. One or more groups can be set. |
| 2650 | + |
| 2651 | If no groups are added, any user will be allowed to execute |
| 2652 | 'upload-pack' on the server. |
| 2653 | |
| 2654 | |
| Shawn O. Pearce | 8efb2a7 | 2009-08-18 19:45:33 -0700 | [diff] [blame] | 2655 | [[user]] Section user |
| Shawn O. Pearce | a758fef | 2009-08-19 08:29:32 -0700 | [diff] [blame] | 2656 | ~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | 0a35191 | 2009-06-01 08:14:46 -0700 | [diff] [blame] | 2657 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2658 | [[user.name]]user.name:: |
| Shawn O. Pearce | 0a35191 | 2009-06-01 08:14:46 -0700 | [diff] [blame] | 2659 | + |
| 2660 | Name that Gerrit calls itself in Git when it creates a new Git |
| 2661 | commit, such as a merge during change submission. |
| 2662 | + |
| 2663 | By default this is "Gerrit Code Review". |
| 2664 | |
| Shawn O. Pearce | 92a7fd1 | 2009-08-18 19:52:48 -0700 | [diff] [blame] | 2665 | [[user.email]]user.email:: |
| Shawn O. Pearce | 0a35191 | 2009-06-01 08:14:46 -0700 | [diff] [blame] | 2666 | + |
| 2667 | Email address that Gerrit refers to itself as when it creates a |
| 2668 | new Git commit, such as a merge commit during change submission. |
| 2669 | + |
| 2670 | If not set, Gerrit generates this as "gerrit@`hostname`", where |
| 2671 | `hostname` is the hostname of the system Gerrit is running on. |
| 2672 | + |
| 2673 | By default, not set, generating the value at startup. |
| 2674 | |
| Edwin Kempin | 0e02ded | 2011-09-16 15:10:14 +0200 | [diff] [blame] | 2675 | [[user.anonymousCoward]]user.anonymousCoward:: |
| 2676 | + |
| 2677 | Username that this displayed in the Gerrit WebUI and in e-mail |
| 2678 | notifications if the full name of the user is not set. |
| 2679 | + |
| 2680 | By default "Anonymous Coward" is used. |
| 2681 | |
| Shawn O. Pearce | 0bf2f52 | 2009-05-14 11:02:03 -0700 | [diff] [blame] | 2682 | |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 2683 | File `etc/secure.config` |
| Remy Bohmer | 203eea3 | 2012-02-19 21:21:36 +0100 | [diff] [blame] | 2684 | ------------------------ |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 2685 | The optional file `'$site_path'/etc/secure.config` overrides (or |
| 2686 | supplements) the settings supplied by `'$site_path'/etc/gerrit.config`. |
| Shawn O. Pearce | 0d4037a | 2009-11-12 18:33:46 -0800 | [diff] [blame] | 2687 | The file should be readable only by the daemon process and can be |
| 2688 | used to contain private configuration entries that wouldn't normally |
| 2689 | be exposed to everyone. |
| 2690 | |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 2691 | Sample `etc/secure.config`: |
| Shawn O. Pearce | 0d4037a | 2009-11-12 18:33:46 -0800 | [diff] [blame] | 2692 | ---- |
| Shawn O. Pearce | 34f38cf | 2011-06-16 19:18:54 -0700 | [diff] [blame] | 2693 | [auth] |
| 2694 | registerEmailPrivateKey = 2zHNrXE2bsoylzUqDxZp0H1cqUmjgWb6 |
| Brad Larson | 3a6f077 | 2012-07-25 11:41:22 -0500 | [diff] [blame] | 2695 | restTokenPrivateKey = 7e40PzCjlUKOnXATvcBNXH6oyiu+r0dFk2c= |
| Shawn O. Pearce | 34f38cf | 2011-06-16 19:18:54 -0700 | [diff] [blame] | 2696 | |
| Shawn O. Pearce | 0d4037a | 2009-11-12 18:33:46 -0800 | [diff] [blame] | 2697 | [database] |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 2698 | username = webuser |
| 2699 | password = s3kr3t |
| Shawn O. Pearce | 0d4037a | 2009-11-12 18:33:46 -0800 | [diff] [blame] | 2700 | |
| 2701 | [ldap] |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 2702 | password = l3tm3srch |
| Shawn O. Pearce | 0d4037a | 2009-11-12 18:33:46 -0800 | [diff] [blame] | 2703 | |
| 2704 | [httpd] |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 2705 | sslKeyPassword = g3rr1t |
| Shawn O. Pearce | 0d4037a | 2009-11-12 18:33:46 -0800 | [diff] [blame] | 2706 | |
| 2707 | [sendemail] |
| Shawn O. Pearce | 9d342a4 | 2009-12-16 15:49:05 -0800 | [diff] [blame] | 2708 | smtpPass = sp@m |
| Shawn O. Pearce | 7929d87 | 2011-05-15 13:33:15 -0700 | [diff] [blame] | 2709 | |
| 2710 | [remote "bar"] |
| 2711 | password = s3kr3t |
| Shawn O. Pearce | 0d4037a | 2009-11-12 18:33:46 -0800 | [diff] [blame] | 2712 | ---- |
| 2713 | |
| Johan Bjork | 3e5ee30 | 2012-01-27 17:59:54 +0100 | [diff] [blame] | 2714 | File `etc/peer_keys` |
| 2715 | -------------------- |
| 2716 | |
| 2717 | The optional file `'$site_path'/etc/peer_keys` controls who can |
| 2718 | login as the 'Gerrit Code Review' user, required for the link:cmd-suexec.html[suexec] |
| 2719 | command. |
| 2720 | |
| 2721 | The format is one Base-64 encoded public key per line. |
| 2722 | |
| 2723 | |
| Shawn O. Pearce | 7b40571 | 2009-05-08 18:27:53 -0700 | [diff] [blame] | 2724 | Database system_config |
| 2725 | ---------------------- |
| 2726 | |
| 2727 | Several columns in the `system_config` table within the metadata |
| 2728 | database may be set to control how Gerrit behaves. |
| Shawn O. Pearce | d2b73db | 2009-01-09 11:55:47 -0800 | [diff] [blame] | 2729 | |
| 2730 | [NOTE] |
| 2731 | The contents of the `system_config` table are cached at startup |
| 2732 | by Gerrit. If you modify any columns in this table, Gerrit needs |
| 2733 | to be restarted before it will use the new values. |
| 2734 | |
| Shawn O. Pearce | 7b40571 | 2009-05-08 18:27:53 -0700 | [diff] [blame] | 2735 | Configurable Parameters |
| 2736 | ~~~~~~~~~~~~~~~~~~~~~~~ |
| Shawn O. Pearce | d2b73db | 2009-01-09 11:55:47 -0800 | [diff] [blame] | 2737 | |
| Shawn O. Pearce | 8e9c73b | 2009-05-08 17:38:25 -0700 | [diff] [blame] | 2738 | site_path:: |
| 2739 | + |
| Shawn O. Pearce | d2b73db | 2009-01-09 11:55:47 -0800 | [diff] [blame] | 2740 | Local filesystem directory holding the site customization assets. |
| 2741 | Placing this directory under version control and/or backup is a |
| 2742 | good idea. |
| Shawn O. Pearce | 8e9c73b | 2009-05-08 17:38:25 -0700 | [diff] [blame] | 2743 | + |
| Shawn O. Pearce | c5fed82 | 2009-11-17 16:10:10 -0800 | [diff] [blame] | 2744 | Files in this directory provide additional configuration. |
| Shawn O. Pearce | 8e9c73b | 2009-05-08 17:38:25 -0700 | [diff] [blame] | 2745 | + |
| Shawn O. Pearce | d2b73db | 2009-01-09 11:55:47 -0800 | [diff] [blame] | 2746 | Other files support site customization. |
| Shawn O. Pearce | 8e9c73b | 2009-05-08 17:38:25 -0700 | [diff] [blame] | 2747 | + |
| Shawn O. Pearce | d2b73db | 2009-01-09 11:55:47 -0800 | [diff] [blame] | 2748 | * link:config-headerfooter.html[Site Header/Footer] |
| 2749 | |
| Shawn O. Pearce | 5500e69 | 2009-05-28 15:55:01 -0700 | [diff] [blame] | 2750 | GERRIT |
| 2751 | ------ |
| 2752 | Part of link:index.html[Gerrit Code Review] |