# # Copyright 2017-2018 Amazon.com, Inc. and its affiliates. All Rights Reserved. # # Licensed under the MIT License. See the LICENSE accompanying this file # for the specific language governing permissions and limitations under # the License. # [DEFAULT] logging_level = INFO logging_max_bytes = 1048576 logging_file_count = 10 # mode for /var/run/efs and subdirectories in octal state_file_dir_mode = 750 [mount] dns_name_format = {az}.{fs_id}.efs.{region}.{dns_name_suffix} dns_name_suffix = amazonaws.com #The region of the file system when mounting from on-premises or cross region. #region = us-east-1 stunnel_debug_enabled = false #Uncomment the below option to save all stunnel logs for a file system to the same file #stunnel_logs_file = /var/log/amazon/efs/{fs_id}.stunnel.log stunnel_cafile = /etc/amazon/efs/efs-utils.crt # Validate the certificate hostname on mount. This option is not supported by certain stunnel versions. stunnel_check_cert_hostname = true # Use OCSP to check certificate validity. This option is not supported by certain stunnel versions. stunnel_check_cert_validity = false # Define the port range that the TLS tunnel will choose from port_range_lower_bound = 20049 port_range_upper_bound = 20449 [mount.cn-north-1] dns_name_suffix = amazonaws.com.cn [mount.cn-northwest-1] dns_name_suffix = amazonaws.com.cn [mount.us-iso-east-1] dns_name_suffix = c2s.ic.gov stunnel_cafile = /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem [mount.us-isob-east-1] dns_name_suffix = sc2s.sgov.gov stunnel_cafile = /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem [mount-watchdog] enabled = true poll_interval_sec = 1 unmount_grace_period_sec = 30 # Set client auth/access point certificate renewal rate. Minimum value is 1 minute. tls_cert_renewal_interval_min = 60 [cloudwatch-log] # enabled = true log_group_name = /aws/efs/utils # Possible values are : 1, 3, 5, 7, 14, 30, 60, 90, 120, 150, 180, 365, 400, 545, 731, 1827, and 3653 # Comment this config to prevent log deletion retention_in_days = 14