The stellar.yaml file shared by every component, each of its keys, and its environment overrides.
Every service of the core, the CLI, the language server and the editor read one global YAML file
at start. It describes the deployment (where NATS is, which port the API listens on, how long a
leadership lease lasts), not the mission: catalogues, topology and procedures live in the
configuration repository.
Every key has a default. An empty file, or no file at all, gives the defaults; a file lists only
what it changes. config/stellar.example.yaml in the repository of Stellar Control lists every key
with its default and a comment.
Any value can be overridden by an environment variable named STELLAR__<SECTION>__<KEY>: two
underscores between levels, upper or lower case. The value is parsed as YAML, so numbers,
booleans, lists and maps work:
Credentials file (JWT and NKey seed) of the component; unset, no authentication
tls.ca
path
unset
CA certificates (PEM): TLS required and the server checked against them
tls.cert
path
unset
Client certificate (PEM), for mTLS; goes with tls.key
tls.key
path
unset
Private key of the client certificate; goes with tls.cert
partitions
integer ≥ 1
64
Number of partitions of the future partitioning of the compute stage and value table by target; must exceed the maximum number of instances of a component. Reserved: no service partitions its subjects yet (see Running the Services).
Lifetime of a leadership lease: a standby instance takes over at most this long after the leader dies. Also used by the compute stage, alarm service and transfer manager for their own leases.
leader_renew
duration
1s
Renewal period of the lease; greater than zero and shorter than leader_ttl
jwt_ttl
duration
10min
Lifetime of the JWTs issued to bound drivers, transports, gateways and connectors, renewed at half-life
signing_key_file
path
unset
Seed of the account signing key (readable by its owner only). Without it and account, no JWT is issued.
account
string
unset
Public key of the NATS account the signing key belongs to
Retry policy of eligible steps that declare no retry: times retries after the first attempt, for a total duration, every an interval. At least times or for.
ack_timeout
duration
10s
Longest wait for ACK 1, ACK 2, an echo and the first samples of a verification without within; a telecommand not uplinked within this time after PENDING is refused
default_retry is also a compilation parameter: stellar check, lock and compile, the
language server and dry runs read it (see Retries).
JWK set of the OIDC identity provider (the file its jwks_uri serves). Unset with jwks_url, tokens are refused and only declared identities work.
jwks_url
URL
unset
The jwks_uri of the provider, read at start (a failure stops the service) and every hour; takes precedence over jwks_file
issuer
string
unset
Expected iss; unset, not checked
audience
string
unset
Expected aud; unset, not checked
roles_claim
dotted path
roles
Claim holding the roles, such as realm_access.roles: a list, or a string of roles separated by spaces (scope)
roles_prefix
string
empty
Prefix of the roles of the MCS in that claim, taken off; the others are ignored. Empty: every role
required
bool
false
Every request of the API needs a checked token (401 auth::token-required), but GET /v1/auth/config and GET /v1/openapi.json; a WebSocket gives it as its token parameter
client_id
string
unset
Public client of the web console at the provider; with issuer, the console signs its users in
cli_client_id
string
unset
Public client of the CLI at the provider (native, device flow); with issuer and client_id, stellar login signs in
organization
string
unset
Organization (Logto) whose token the console asks for
nats_ttl
duration
1h
Validity of the NATS credentials of follow-up exchanged against a token
Read by the API, the executor (it checks again the token sent with an answer) and the editor.
See Identity and Roles.
Retention of the continuous stream archive (STREAMS)
streams.max_bytes
size > 0
2TB
Its volume bound; the first limit reached applies
The reconciler applies them when it starts. JetStream reserves max_bytes on the disk of the
server; when it cannot, the archive is bounded by max_age only, with a warning in the logs.