Skip to content

mount.flexfs

mount.flexfs is the FUSE-based mount client that presents a flexFS volume as a local POSIX filesystem. It connects to a metadata server for inode/dentry operations and to object storage (directly or through a proxy group) for block data.

These flags apply to every subcommand.

FlagTypeDefaultDescriptionVisibility
--reportErrorsboolfalseReport errors and panics to Paradigm4. Off by default; a volume or token flag can mandate it for every mount of a volume — see Accepted Volume and Token Flags.Public

What is sent: panic traces, auto-update failures, and abnormal exits. When a mount fails to come up at all — the daemon dies during startup, or does not mount within ten minutes — the child’s entire log file is sent as well, since the trace alone rarely explains a startup failure. Mount logs carry volume names, mount points and paths, so treat enabling this as a decision about what leaves the host.

SubcommandDescriptionVisibility
deinit credsRemove the credentials filePublic
deinit fstabRemove the fstab entryPublic
init credsInitialize the credentials filePublic
init fstabCreate an fstab entry and mount pointPublic
licensePrint license informationPublic
startStart the mount clientPublic
versionPrint the build versionPublic
Terminal window
mount.flexfs deinit creds <name>

Removes the credentials file for a volume. If the credentials file is referenced by an fstab entry or systemd unit, the command refuses unless --force is passed, in which case it removes the references too.

FlagTypeDefaultDescriptionVisibility
--credsFilestring~/.flexfs/mount/creds/<name>Path to the credentials file. The <name> placeholder is replaced with the volume name.Public
--forceboolfalseRemove creds even if referenced by fstab/systemd (removes references too)Public
Terminal window
sudo mount.flexfs deinit fstab <mount-point>

Removes flexFS fstab entries for the given mount point from /etc/fstab. Requires root.

Terminal window
mount.flexfs init creds --adminAddr <admin-addr> [--token <uuid>]

Initializes a credentials file for a volume. If --token is omitted, the command prompts for a volume token interactively. init on its own does the same thing as init creds.

The reporting utilities (analyze.flexfs, dedup.flexfs, find.flexfs) fall back to this file when the user running them has no credentials of their own, so a user who has run this command needs no further setup to query the volume.

FlagTypeDefaultDescriptionVisibility
--adminAddrstring""Admin server address (required)Public
--credsFilestring~/.flexfs/mount/creds/<name>Path to the credentials file. The <name> placeholder is replaced with the volume name.Public
--forceboolfalseOverwrite existing credentials filePublic
--noAdminSSLboolfalseDisable SSL for admin server connectionsInternal
--printNameboolfalsePrint the volume name to stdout after initializationPublic
--secretstring""Volume encryption secret (will prompt if omitted and needed)Public
--tokenstring""Volume auth token (will prompt if omitted)Public
Terminal window
sudo mount.flexfs init fstab <name> <mount-point> [flags]

Creates an /etc/fstab entry and the mount point directory for the volume. Requires root.

FlagTypeDefaultDescriptionVisibility
--credsFilestring~/.flexfs/mount/creds/<name>Path to the credentials file. The <name> placeholder is replaced with the volume name.Public
--forceboolfalseReplace an existing flexFS fstab entry for this mount pointPublic
--mountOptionsstring""Additional mount options to include in the fstab entryPublic
--nowboolfalseMount the volume immediately after creating the fstab entryPublic
Terminal window
mount.flexfs start [flags] <name> <mount-point>

The start subcommand connects to the admin server, retrieves volume settings, and mounts the filesystem at the specified mount point. In the default daemon mode, the process forks into the background and writes logs to a file. Under systemd (detected via the NOTIFY_SOCKET environment variable), it stays in the foreground without forking and logs to standard output. Use --foreground to run in the foreground.

Any user can run start. See Mounting without root for how a mount started by a user other than root differs.

FlagTypeDefaultDescriptionVisibility
--aclboolfalseEnable extended ACL support (implies --xattr)Public
--adminAddrstring""Admin server address (overrides credentials file)Internal
--allSquashboolfalseMap all uids/gids to the anonymous uid/gid (implies --rootSquash). Root only.Public
--anonGIDuint3265534GID squashed callers are mapped to. Root only.Public
--anonUIDuint3265534UID squashed callers are mapped to. Root only.Public
--appendGrantHoldFactorfloat644How long a mount keeps an append turn it has just received from another mount, as a multiple of its recent hand-over time (capped by --appendGrantMaxHold). Higher values raise append throughput under contention at the cost of longer waits for the other mount. Values below 1, including 0, act as 1: shorter holds make mounts spend more time handing the turn over than appending, which can slow concurrent appends to a small fraction of their normal rate.Internal
--appendGrantMaxHoldstring500msUpper bound on the hold derived from --appendGrantHoldFactor, given as a duration (500ms) or whole milliseconds (500). At most 3s. Cannot be 0 when --appendGrantMinHold is 0.Internal
--appendGrantMinHoldstring100msMinimum time a mount keeps an append turn it has just received from another mount, given as a duration (100ms) or whole milliseconds (100). At most 1s. 0 removes the minimum; the hold from --appendGrantHoldFactor still applies, and the mount still keeps a new turn until its first append lands, for up to one second. Each hand-over uploads the file’s last block and commits it, so shorter holds increase object-store PUT requests for files that several mounts append to concurrently. Lock requests and truncations from other mounts are not held back by this minimum. Applies only when the metadata server supports prompt hand-over.Internal
--atTimestring""Mount at a point in time (RFC3339, implies --ro)Public
--attrValidstring1hHow long to cache file attributes, given as a duration (30s, 1h) or whole seconds (3600). Must resolve to a whole number of seconds; use --attrValidNsec for sub-second precision.Internal
--attrValidNsecuint320Nanosecond offset added to --attrValid (0 to 999999999)Internal
--blockRTTboolfalseLog block storage round-trip timesInternal
--credsFilestring~/.flexfs/mount/creds/<name>Path to the credentials file. The <name> placeholder is replaced with the volume name.Public
--diagHolesboolfalseLog a diagnostic line whenever a read returns a zero-filled block because the file has no data stored for it. Costs an extra metadata round trip per zero-filled block and is not rate limited; leave it off outside an investigation.Internal
--dirPageSizeuint325000Directory stream page sizeInternal
--dirtyActiveuint320 = autoMaximum number of active dirty block syncsInternal
--dirtyCapacityuint320 = autoIn-memory dirty block cache capacity (blocks)Internal
--dirValidstring5sHow long a fetched directory page may be reused by a rewind or repeat listing while the directory is unchanged, given as a duration (5s, 1m) or whole seconds (5). Must resolve to a whole number of seconds; 0 refetches on every rewind. A listing in progress always consumes the page it has already fetched.Internal
--diskFolderstring~/.flexfs/mount/cache/<name>/<pid>On-disk block cache folder path. The <name> and <pid> placeholders are replaced at startup.Public
--diskMaxBlockSizestring256KMaximum processed block size that will be cached to disk. Blocks larger than this after processing bypass the disk cache. Given as a size (256K, 1M) or bytes (262144). 0 means no limit.Public
--diskQuotastring"" = disabledMaximum disk usage for the block cache (e.g. 5%, 64M, 10G; empty or 0 = disabled). An unrecognized value is refused. A quota below 32 MiB disables the cache. The mount logs a warning when --diskFolder, --diskMaxBlockSize, --diskSync or --diskWriteback is given without a quota.Public
--diskSyncboolfalseFsync each block the writeback cache takes to local disk before the write is acknowledged, so that fsync() and close() guarantee the block survives a power loss. Adds latency to every such block write. The mount does not start if the file system holding the cache folder cannot flush it. Has no effect unless --diskWriteback is set; the mount then logs a warning.Public
--diskWritebackboolfalseEnable disk cache writeback mode. Has no effect unless --diskQuota enables the disk cache.Public
--entryValidstring1sHow long the kernel caches directory entries, given as a duration (1s, 30s) or whole seconds (1). Must resolve to a whole number of seconds; use --entryValidNsec for sub-second precision. 0 disables name caching. Negative lookups are governed separately by --negEntryValid.Internal
--entryValidNsecuint320Nanosecond offset added to --entryValid (0 to 999999999)Internal
--forceClientDACboolfalseForce extended-ACL enforcement into the mount client (implies --acl)Internal
--foreground, -fboolfalseRun in foreground mode (implies --noRemount)Public
--fuseRTTboolfalseLog FUSE round-trip timesInternal
--invalQueueSlotsuint320 = autoTotal kernel invalidation queue slots across all lanesInternal
--logFilestring~/.flexfs/mount/logs/<name>-<pid>.logLog file path in daemon mode. The <name> and <pid> placeholders are replaced at startup.Public
--maxBopsuint320 = autoMaximum number of parallel block operationsInternal
--memCapacitystring"" = autoIn-memory block cache capacity in blocks or bytes (e.g. 2000, 64M, 2%)Internal
--memLimitstring"" = autoSoft memory limit for the mount process (e.g. 40%, 512M; 0 = disabled). A GOMEMLIMIT environment variable is honored when set. The automatic limit is half of RAM for each mount, regardless of other mounts on the hostInternal
--memStatsboolfalseLog buffer pool and LRU cache statsInternal
--metaRTTboolfalseLog metadata store round-trip timesInternal
--metricsboolfalseEnable the Prometheus metrics endpoint (see Metrics Reference)Public
--metricsPortint6075Metrics server portPublic
--negEntryValidstring1sHow long the kernel caches negative lookups (names found not to exist), given as a duration (1s, 30s) or whole seconds (1). Must resolve to a whole number of seconds; use --negEntryValidNsec for sub-second precision. 0 disables negative caching.Internal
--negEntryValidNsecuint320Nanosecond offset added to --negEntryValid (0 to 999999999)Internal
--noAdminSSLboolfalseDisable SSL for admin server connections, auto-update downloads includedInternal
--noAppendBarrierboolfalseSkip the cache synchronization each append performs for same-mount readers (readers may transiently see NUL bytes inside the file)Internal
--noAppendDirectReadsboolfalseLet reads of actively-appended files use normal OS caching instead of always-fresh reads (racing readers may transiently see NUL bytes)Internal
--noAppendGrantboolfalseDisable serialized append grants (peer reads may observe zeros for in-flight appends)Internal
--noAtimeboolfalseMount with noatime optionPublic
--noCreateConflictDACboolfalseSkip permission checks when a create finds an existing fileInternal
--noExecboolfalseMount with noexec optionPublic
--noLockCoherenceboolfalseSkip the cache barriers a cross-mount lock carries (peers may lose updates made under a lock)Internal
--noMaxPagesboolfalseLimit FUSE max_pages to 32Internal
--noMetaSSLboolfalseDisable SSL for metadata server connectionsInternal
--nonEmptyboolfalseAllow mounting over a non-empty directoryPublic
--noOpenCoherenceboolfalseSkip the open() cross-mount freshness checkInternal
--noPrefetchboolfalseDisable block prefetchingInternal
--noProxyboolfalseDisable block proxyingInternal
--noProxyReadsboolfalseDisable proxy readsInternal
--noProxySSLboolfalseDisable SSL for proxy server connectionsInternal
--noProxyWritesboolfalseDisable proxy writesInternal
--noRemountboolfalseDisable remount after auto-updatePublic
--noSUIDboolfalseMount with nosuid optionPublic
--noUpdateboolfalseDisable auto-update mechanism (implies --noRemount)Public
--numReadersuint320 = autoNumber of FUSE readersInternal
--poolCapacityuint320 = autoBlock buffer pool capacity (blocks)Internal
--pprofboolfalseEnable pprof profilerInternal
--pprofPortint6065Pprof server portInternal
--prefetchActiveuint320 = autoMaximum number of active prefetchesInternal
--prefetchDepthuint320 = autoMaximum number of queued prefetchesInternal
--proxyProbeTOstring125msHealth check timeout for each proxy server, given as a duration (125ms, 1s) or whole milliseconds (125).Internal
--readAheadstring"" = autoKernel readahead window (e.g. 4M)Internal
--roboolfalseMount read-only (implies --noAtime)Public
--rootSquashboolfalseMap uid/gid 0 to the anonymous uid/gid (implies --acl). Root only.Public
--secretstring""Volume encryption secret (overrides credentials file)Internal
--sseboolfalseRequest S3 server-side encryption (AES256)Public
--stagingboolfalseAuto-update from staged buildsPublic
--statFsValidstring3sHow long to serve statfs answers from cache, given as a duration (3s, 1m) or whole seconds (3). Must resolve to a whole number of seconds. 0 = disabled.Internal
--storeRTTboolfalseLog store subsystem round-trip timesInternal
--subTypestringflexfsIgnored; accepted for compatibility. Mounts always use the fuse.flexfs type.Internal
--testVersionstring""Override build version to exercise auto-update handoffInternal
--tokenstring""Volume auth token (overrides credentials file)Internal
--umaskstring""Umask override (octal, with or without a leading 0 — 22 and 0022 mean the same thing; max 0777)Public
--updateIntervalstring6mAuto-update check interval, given as a duration (6m, 1h) or whole seconds (360). Must resolve to a whole number of seconds, at least 1s. Use --noUpdate to disable auto-update.Internal
--verbose, -vboolfalseEnable verbose loggingPublic
--xattrboolfalseEnable extended attribute supportPublic

The credentials file is a TOML file stored at the path specified by --credsFile. It contains the admin server address, volume token, and optionally an encryption secret:

adminAddr = "admin.example.com:443"
secret = "<secret>"
token = "<volume-token>"