Theme
Virtual file systems
A virtual file system maps one piece of your storage into a name your users can be given access to.
It is the unit everything else refers to:
- In the Connector, permissions are granted per virtual file system.
- In the Portal, a user's What they see list maps a path onto a virtual file system by name.
Nothing on your storage is reachable until a virtual file system points at it.
Create one
Storage, then Virtual file systems, then create.
Name
Pick a name your Portal administrator will recognize, because that is where it appears next. Company files is a better name than vfs1.
Type
| Type | Points at |
|---|---|
| Disk | A path on this machine or a network share |
| S3 | An S3 bucket, or an S3 compatible store |
| Azure | An Azure Blob Storage container |
| Google Cloud Storage | A GCS bucket |
| SFTP | Another SFTP server |
Each type asks only for its own fields. Full detail on each: Storage backends.
At rest encryption
This choice is permanent
The encryption setting of a virtual file system cannot change after creation.
To encrypt or decrypt data later, you create a new virtual file system with the setting you want and migrate the data across.
Read Encryption at rest before you decide, not after.
At rest encryption is not available for the SFTP type: the remote server owns that storage.
Transfer speed
Transfer speed sets how many parallel connections this Connector runs to your cloud site for this virtual file system.
| Setting | Connections |
|---|---|
| Standard | 1 |
| Quicker | 2 |
| Fast | 4 |
| Maximum | 8 |
More connections move more files at the same time. The trade off is bandwidth: during large transfers they also use more of your internet connection's upload capacity, and the fastest settings can take most of it, slowing down everything else at your site.
Start with Standard. Raise it only when transfers feel slow and you know your connection has room. The setting is per virtual file system, so one busy folder can run fast while the others stay light.
Saving the change reconciles this virtual file system like any other edit: its connections reconnect within moments, and other virtual file systems are untouched.
While more than one connection is configured, the storage list shows how many of them are currently up next to the virtual file system's name.
The advanced panel
The create form shows the target and credential payload it will generate from the fields above.
Secret values are never shown there. They are masked or labelled:
| Label | Meaning |
|---|---|
(set; hidden, kept on save) | A secret is stored and will be preserved |
(not set) | No secret is stored |
(will be removed) | Saving will clear the stored secret |
The Connector cannot show you a stored secret. It does not hold it in a readable form.
Saving changes
Saving reconciles that virtual file system's live connections immediately. Other virtual file systems are untouched, and sessions on them are not interrupted.
Deleting one
The virtual file system is removed and its live connections are torn down. Users whose access points at it lose that folder.
The storage itself is not touched. Deleting a virtual file system never deletes a file.
Before deleting, check who is using it: the Access pages show which users and which folder sets reference it.
After creating one
Two things have to happen before anybody can use it.
- In the Connector: grant users access to it, either directly or through a folder set. See Permissions.
- In the Portal: put it in a user's What they see list, so it appears at a path in their session. See Users.
Doing only the first means the user has permission to a folder that never appears. Doing only the second means the folder appears and will not open.
Moves and renames across virtual file systems
A move never crosses a virtual file system boundary. Renaming or moving a file from one virtual file system to another is refused, including between two on the same Connector.
Clients fall back to copy and delete, which produces the right result and takes longer.
Plan around this when you lay out your storage: things that get moved between each other belong in the same virtual file system, under different folders.
A first link
A Connector that has enrolled but has no virtual file system has nothing to serve, so it never links to your site. The Portal shows it as Not seen yet.
Creating the first virtual file system is what brings the link up.