Skip to content

free.flexfs

free.flexfs is the server for flexFS Community edition. It manages a single volume and provides the same deploy endpoint as the Enterprise admin server for mount client installation and auto-updates. All flags are public.

The Community server differs from the Enterprise admin server in the following ways:

  • Manages a single volume (no multi-volume support), named free, with a fixed 2 MiB block size and lz4 compression
  • No configure.flexfs support
  • No proxy group management
  • No end-to-end encryption
  • No dynamic CSI provisioning
  • Fixed volume limits (5 TiB and 5 million files) instead of configurable quotas, and no volume tokens with mount-path scoping

All CLI utilities (analyze.flexfs, dedup.flexfs, find.flexfs, manage.flexfs) work with the Community edition, though the Community server sets no storage rates, so cost fields always report $0. Local on-disk writeback caching (--diskWriteback with --diskQuota) is available on the mount client to help mitigate object storage latency.

These flags apply to every subcommand.

FlagTypeDefaultDescriptionVisibility
--reportErrorsboolfalseReport errors and panics to Paradigm4. Governs what this server reports about itself only — to require reporting on mount clients, see --reportMountErrors belowPublic
SubcommandDescriptionVisibility
deinit credsRemove the credentials filePublic
deinit systemdRemove the systemd service unitPublic
init credsInitialize the credentials filePublic
init systemdCreate and enable a systemd service unitPublic
licensePrint license informationPublic
startStart the serverPublic
versionPrint the build versionPublic
Terminal window
free.flexfs deinit creds [flags]

Removes the credentials file for the server. If the credentials file is referenced by a systemd unit, the command refuses unless --force is passed, in which case it removes the references too.

FlagTypeDefaultDescriptionVisibility
--credsFilestring~/.flexfs/free/credsCredentials file pathPublic
--forceboolfalseRemove creds even if referenced by systemd (removes references too)Public
Terminal window
sudo free.flexfs deinit systemd

Removes the systemd service unit (flexfs-free.service) for the server. Requires root.

Terminal window
free.flexfs init creds [flags]

Initializes a credentials file for the server with block storage and metadata configuration. init on its own does the same thing as init creds. The bucket name, prefix, --blockAddr endpoint ([scheme://]host[:port], with a path allowed only for the azure API) and OCI namespace are checked; an invalid value is refused and no file is written.

FlagTypeDefaultDescriptionVisibility
--apistring""Block storage API (s3, gcs, azure, oci; required)Public
--blockAddrstring""Custom block storage endpointPublic
--blockPassstring""Block storage passwordPublic
--blockUserstring""Block storage usernamePublic
--bucketstring""Block storage bucket (required)Public
--credsFilestring~/.flexfs/free/credsCredentials file pathPublic
--forceboolfalseOverwrite existing credentials filePublic
--metaAddrstring""Metadata server address (host:port) (required)Public
--namespacestring""Object storage namespace; required for --api oci, rejected otherwise. Stored as its own namespace keyPublic
--prefixstringflexfsBlock storage key prefixPublic
--providerstring""Storage provider, such as aws, gcp, azure or oci, or a name of your choice for other S3-compatible storage (required)Public
--regionstring""Region (e.g. us-east-1; required). Lowercased for aws, gcp, azure and oci; kept as given for other providersPublic
--retentionstring7dRetention duration (e.g. 7d, 168h, 30m) or seconds; -1 = foreverPublic
--volumeFlagsstringadminFlags carried by the volume token. The default lets it run reporting queries against the metadata server; set it to an empty string to withhold thatPublic

The server reads these values from the credentials file each time it starts. It refuses to start if the file’s retention or volumeFlags value is invalid; a file with no retention uses 7 days, and one with no volumeFlags uses admin.

Terminal window
sudo free.flexfs init systemd [flags]

Creates and enables a systemd service unit (flexfs-free.service) for the server. Requires root. Optional: the server can also be run directly with start by any user. The service runs as root, so it uses root’s /root/.flexfs defaults, credentials included, unless --startFlags names other paths.

FlagTypeDefaultDescriptionVisibility
--forceboolfalseOverwrite existing systemd unit filePublic
--nowboolfalseStart the service immediately after enablingPublic
--startFlagsstring""Additional flags to pass to the start commandPublic
Terminal window
free.flexfs start [flags]

Starts the Community server, binding the endpoint for the volume it serves. Any user can run it, and ~ in the defaults is that user’s home folder. A non-root user needs a --bindAddr port above 1023.

FlagTypeDefaultDescriptionVisibility
--accessFilestring~/.flexfs/free/accessAPI access file path — whitelists the source addresses allowed to reach each endpoint. Absent = all endpoints unrestrictedPublic
--bindAddrstring0.0.0.0:443Address and port to bindPublic
--credsFilestring~/.flexfs/free/credsCredentials file pathPublic
--noInstallerboolfalseDisable the /deploy/install-mount.sh installer endpointPublic
--noSSLboolfalseServe over plain HTTP instead of HTTPS. Every client must then use its Internal --noAdminSSL flag: mount.flexfs (start and init creds), meta.flexfs (start and missing-objects), and analyze.flexfs, dedup.flexfs, and find.flexfs (queries and init creds). The CSI driver has no such flag and needs HTTPS.Public
--reportMountErrorsboolfalseRequire error reporting on the mount clients of the volume this server serves. The reporterrors flag is added to the volume settings the server hands out (see Accepted Volume and Token Flags). Independent of --reportErrors, which covers only this server’s own panicsPublic
--sslCertstring~/.flexfs/ssl/certSSL certificate file path. A self-signed certificate and key are created if neither exists.Public
--sslKeystring~/.flexfs/ssl/keySSL private key file pathPublic

--accessFile names a TOML file listing the IP addresses and CIDR blocks allowed to reach each endpoint. There is no file by default and nothing creates one, so every endpoint is unrestricted until you write it. It is re-read every two seconds, so a change takes effect within seconds without a restart; deleting it lifts all restrictions.

Most callers of this API are machines rather than people — mount clients fetch volume settings and rotate secret ids, and the metadata server posts stats and reads rate bins — so a rule written to fence off volume administration gates those endpoints too unless they are opened back up. Read the global rule gates: line the server logs whenever it loads a file with a global list. The /deploy/ tree is the exception: its URLs are baked into published install commands, so it is reached only by a rule naming it explicitly — and one [endpoint."/deploy/"] rule covers the whole tree, the installer script included.

A file that cannot be parsed, or that names an endpoint this server does not serve, is refused: the server will not start on one, and a running server keeps the rules already in force. Blocked requests are answered 403 with the usual {"code":403,"text":"forbidden"} body.

See API Access Control for the file format and the rule precedence.