ErtisAuth

Configuration

Every setting of the server.

ErtisAuth reads its settings with the standard ASP.NET Core configuration system: appsettings.json, appsettings.{Environment}.json, environment variables and command-line arguments, in increasing order of priority.

In environment variables, nested keys are separated with a double underscore: Database:ConnectionString becomes Database__ConnectionString.

Most of ErtisAuth's behaviour (token lifetimes, hash algorithm, mail providers, activation, OTP) is not server configuration: it is set per membership through the API. See Memberships.

Settings#

Database#

KeyDefaultDescription
Database:ConnectionStringnone (required)MongoDB connection string, e.g. mongodb://user:password@host:27017.
Database:DefaultAuthDatabaseauthName of the database ErtisAuth uses.
Database:AllowDiskUsefalseLets MongoDB use temporary files for large sorts and aggregations.

ErtisAuth does not use MongoDB transactions, so a standalone server works as well as a replica set.

Azure Application Insights#

KeyDefaultDescription
ApplicationInsights:ConnectionStringemptyWhen set, traces, metrics and logs are exported to Azure Monitor through OpenTelemetry. When empty, nothing is exported.

Logging#

The standard Logging section of ASP.NET Core:

json
{
	"Logging": {
		"LogLevel": {
			"Default": "Information",
			"Microsoft": "Warning"
		}
	}
}

Hosting#

Standard ASP.NET Core settings apply, for example:

VariableDescription
ASPNETCORE_ENVIRONMENTDevelopment enables the OpenAPI document and the Scalar API reference at /docs.
ASPNETCORE_HTTP_PORTS / ASPNETCORE_URLSThe ports or URLs the server listens on. The Docker image listens on 8080.

Example#

json
{
	"Database": {
		"ConnectionString": "mongodb://ertisauth:<password>@mongo-0:27017",
		"DefaultAuthDatabase": "auth"
	},
	"ApplicationInsights": {
		"ConnectionString": "InstrumentationKey=…;IngestionEndpoint=…"
	}
}

The same with environment variables:

shell
Database__ConnectionString=mongodb://ertisauth:<password>@mongo-0:27017
Database__DefaultAuthDatabase=auth
ApplicationInsights__ConnectionString=InstrumentationKey=…
Note: keep connection strings and keys out of source control. Use environment variables or your platform's secret store.

Built-in behaviour#

These are fixed in the server and are listed here so that you know what to expect:

BehaviourValue
CORSAny origin, method and header is allowed. Restrict it at your gateway if you need to.
Response compressionBrotli and Gzip, also over HTTPS.
HTTPS redirectionEnabled. Terminate TLS at your ingress or configure a certificate for Kestrel.
Graceful shutdownUp to 30 seconds for in-flight requests and queued webhooks and mails.
Prometheus metricsExposed at /metrics (see Operations).
Activation token lifetime72 hours.
Reset password token lifetime2 hours, unless the membership sets reset_password_token_expires_in.
Scoped token lifetime12 hours, unless the membership sets scoped_token_expires_in.
Minimum password length6 characters.

Found a mistake in the docs? Open an issue