Skip to content

Setup and Configuration

The metadata server binary (meta.flexfs) is installed to /sbin by the Enterprise and Community server installers. To install it on another host, or to upgrade it, use manage.flexfs (for example, sudo manage.flexfs install meta). See manage.flexfs.

The metadata server requires credentials to authenticate with the admin server and (optionally) access block storage. Initialize them as the user that runs the metadata server, before starting it:

Terminal window
meta.flexfs init creds \
--adminAddr admin.example.com:443 \
--token <meta-token> \
--blockUser <username> \
--blockPass <password>

If --token is omitted, the command prompts interactively. This writes a TOML credentials file to ~/.flexfs/meta/creds in that user’s home folder (/root/.flexfs/meta/creds for root):

adminAddr = "admin.example.com:443"
blockPass = "<password>"
blockUser = "<username>"
token = "<meta-token>"

To keep it elsewhere, pass the same --credsFile to both init creds and start.

See meta.flexfs init creds for the full list of flags and their defaults.

Run meta.flexfs start as any user. A non-root user needs a --bindAddr port above 1023, since the default is port 443:

Terminal window
meta.flexfs start --bindAddr 0.0.0.0:8443

To run the metadata server as a root service that starts at boot, create a systemd unit:

Terminal window
sudo meta.flexfs init systemd --now

This creates and enables a systemd unit at /etc/systemd/system/flexfs-meta.service and optionally starts it immediately. The service runs as root, so it reads /root/.flexfs/meta/creds unless --startFlags names another --credsFile; create the credentials with sudo meta.flexfs init creds. The metadata service unit includes a 1-second startup delay (ExecStartPre=/bin/sleep 1) to allow dependent services to initialize.

To pass additional flags:

Terminal window
sudo meta.flexfs init systemd --now \
--startFlags "--dbFolder /data/meta-db"

See meta.flexfs init systemd for the full list of flags and their defaults.

See meta.flexfs start for the full list of flags and their defaults.

See meta.flexfs subcommands for the internal migrate, missing-objects, and verify subcommands.

--accessFile names a TOML file of IP addresses and CIDR blocks allowed to reach each endpoint. It defaults to ~/.flexfs/meta/access. Nothing creates that file, and while it is absent every endpoint is unrestricted; the file is re-read every couple of seconds, so access can be tightened or widened without a restart.

~/.flexfs/meta/access
allow = ["10.0.0.0/8", "127.0.0.1", "::1"]
[endpoint."DELETE /locks"]
allow = ["10.1.2.3"]

The WebSocket root (/), which is how mount clients reach this server, is left alone by the global list — only a rule naming it explicitly gates it. Everything else is covered, /metrics included, so whitelist the host that scrapes it. See API Access Control.

By default, the metadata server auto-generates a self-signed TLS certificate if none exists at the configured paths. To use custom certificates:

Terminal window
meta.flexfs start \
--sslCert /etc/ssl/meta.crt \
--sslKey /etc/ssl/meta.key

After starting, the metadata server logs its configuration. This example is a server run as root with default flags and static credentials:

--------------------------------------------------------------------------------
meta.flexfs | v1.9.1 linux/amd64 (2026-09-01 12:00)
--------------------------------------------------------------------------------
accessFile | /root/.flexfs/meta/access
adminAddr | admin.example.com:443
bindAddr | 0.0.0.0:443
blockPass | <provided>
blockUser | <username>
credsFile | /root/.flexfs/meta/creds
dbFolder | /root/.flexfs/meta/data
dbMemCapacity | 50% (32.00 GiB)
minDiskAvail | 1G (1.00 GiB)
minRESTVersion | 2
requestRetention | 6h
sslCert | /root/.flexfs/ssl/cert
sslKey | /root/.flexfs/ssl/key
--------------------------------------------------------------------------------
No access file at "/root/.flexfs/meta/access" - all endpoints unrestricted
Binding to 0.0.0.0:443 (encrypted)