X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/b12f667daa270a4e3c656d16f30620ca763f9578..1f760632ae0fbb9f11af5cfb831b7c3ed49a7009:/services/api/config/application.yml.example diff --git a/services/api/config/application.yml.example b/services/api/config/application.yml.example index 89662f551f..d6db3a4f8b 100644 --- a/services/api/config/application.yml.example +++ b/services/api/config/application.yml.example @@ -11,19 +11,22 @@ # 5. Section in application.default.yml called "common" development: - # The permission_key needs to be identical to the - # permission key given to Keep. If you run both - # apiserver and Keep in development, change this to - # a hardcoded string and make sure both systems use - # the same value. - permission_key: <%= rand(2**512).to_s(36) %> + # The blob_signing_key is a string of alphanumeric characters used + # to sign permission hints for Keep locators. It must be identical + # to the permission key given to Keep. If you run both apiserver + # and Keep in development, change this to a hardcoded string and + # make sure both systems use the same value. + blob_signing_key: ~ production: # At minimum, you need a nice long randomly generated secret_token here. + # Use a long string of alphanumeric characters (at least 36). secret_token: ~ - # The permission key must be identical to the key provisioned to Keep. - permission_key: ~ + # blob_signing_key is required and must be identical to the + # permission secret provisioned to Keep. + # Use a long string of alphanumeric characters (at least 36). + blob_signing_key: ~ uuid_prefix: bogus @@ -35,17 +38,17 @@ production: # The version below is suitable for AWS. # Uncomment and change <%# to <%= to use it. # compute_node_nameservers: <%# - require 'net/http' - ['local', 'public'].collect do |iface| - Net::HTTP.get(URI("http://169.254.169.254/latest/meta-data/#{iface}-ipv4")).match(/^[\d\.]+$/)[0] - end << '172.16.0.23' - %> + # require 'net/http' + # ['local', 'public'].collect do |iface| + # Net::HTTP.get(URI("http://169.254.169.254/latest/meta-data/#{iface}-ipv4")).match(/^[\d\.]+$/)[0] + # end << '172.16.0.23' + # %> test: uuid_prefix: zzzzz secret_token: <%= rand(2**512).to_s(36) %> - permission_key: <%= rand(2**512).to_s(36) %> common: #git_repositories_dir: /var/cache/git #git_internal_dir: /var/cache/arvados/internal.git +