Blixt Documentation v2.9
Protocol Default Edition
NFSv4 On All
SMB 3 On All
NFSv3 Off Enterprise, High Performance
SFTP Off Enterprise, High Performance
WebDAV Off Enterprise, High Performance

Licensed protocols switch on automatically when your license includes them. See Licensing.

NFS

BlixtFS’s NFS gateway is based on NFS-Ganesha. The export root is /, which shows one directory per cloud provider.

nfs:
  root_squash: false        # map remote root to nobody
  sec_type: sys             # AUTH_SYS
  threads: 512
  attributes_expiration_seconds: 0
Setting Flag Meaning
nfs.root_squash --nfs_root_squash Map the client’s root user to an unprivileged user.
nfs.manage_gids --nfs_manage_gids Resolve group membership on the server instead of trusting the client’s list.
nfs.threads --nfs_threads Worker threads in the NFS server.
nfs.attributes_expiration_seconds --nfs_attributes_expiration_seconds How long the NFS server caches file attributes.
--nfs4=false Turn NFSv4 off.

NFSv3 uses port 2050 (mountd), 4045 (lock manager), as well as other ports. It therefore requires host networking in Docker.

SMB

BlixtFS’s SMB gateway is Samba with a BlixtFS module. It serves one share, bfs, and speaks SMB 3.1 with UNIX permission. Active Directory integration is in development. Please contact us if you need it.

Users

SMB clients sign in with a user name and password stored on the server. The simplest setup is a single shared account, created each time the server starts:

smb:
  default_user: alice

Pass the password in the environment or on the command line, not in the file:

docker run ... blixtfs/standard:latest --config /data/config.yaml \
  --smb_default_password "$SMB_PASSWORD"

Changing the password and restarting replaces the old one.

To turn SMB off, pass --smb=false, or set smb.enabled: false.

SFTP

With a license that includes SFTP, the gateway listens on port 2222 for the user bfs, with public-key authentication only.

Add authorised keys to /home/bfs/.ssh/authorized_keys inside the container. The easiest way is to mount a file:

docker run ... \
  -p 2222:2222 \
  -v /srv/blixt/authorized_keys:/home/bfs/.ssh/authorized_keys:ro \
  blixtfs/enterprise:2.9.0 --config /data/config.yaml
Setting Default
sftp.port 2222
sftp.user bfs
sftp.authorized_keys /home/bfs/.ssh/authorized_keys
sftp.host_key_path /etc/ssh/ssh_host_ed25519_key

Mount a persistent host key if clients shouldn’t see a new host key each time the container is recreated.

WebDAV

With a license that includes WebDAV, the gateway listens on port 8080. Change the port with --webdav_port.

Ownership of files

Files that were written by other tools, and so have no owner recorded, belong to the default user and group:

filesystem:
  default_uid: 1000
  default_gid: 1000

The defaults are the user and group BlixtFS runs as.