Mount from a sandbox
The API key stays on your backend. The sandbox receives only a one-time ticket, which it exchanges for a session certificate.
1. Create an API key and grant it
In the console, open API keys and create a key. Its secret
(fsit_…) is shown once; store it in your secret manager. Then open the
filesystem and grant the key rw (or ro).
2. Create a session from your backend
curl -X POST "https://$FSIT_HOST/api/v1/mount-sessions" \
-H "Authorization: Bearer $FSIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{"filesystem_id": "k5q2ztr4mvd7wn3xa6jhebcyfu", "mode": "rw", "idempotency_key": "job-4182"}'The response contains the session id and the ticket. The ticket is
single-use and must be exchanged within five minutes.
| Field | Meaning |
|---|---|
filesystem_id | the filesystem to mount |
mode | ro or rw, up to the key's grant |
idempotency_key | retries with the same key return the same session; the ticket is never shown twice |
max_duration_seconds | optional; default 12 hours, at most 7 days and never past the key's expiry |
3. Mount in the sandbox
The sandbox needs the fsit CLI, FUSE (/dev/fuse), and the SeaweedFS
weed binary, version 4.48. Point the CLI at your fsit API with
FSIT_API_URL, and pass the ticket on stdin, never on the command line or in
an image:
mkdir -p /mnt/work
echo "$TICKET" | fsit mount --ticket-stdin /mnt/work &The ticket names the filesystem and mode. The CLI generates a key pair,
exchanges the ticket for a short-lived certificate, keeps renewing it in the
foreground (hence &), and unmounts when the session is revoked or expires.
4. Revoke
curl -X DELETE "https://$FSIT_HOST/api/v1/mount-sessions/$SESSION_ID" \
-H "Authorization: Bearer $FSIT_API_KEY"You can also revoke live sessions on the filesystem's page in the console. Removing a grant, revoking the key, or deleting the filesystem revokes the affected sessions too.