fsit
Sign in

Mount from a sandbox

The API key stays on your backend. The sandbox receives only a one-time ticket, which it exchanges for a session certificate.

1. Create an API key and grant it

In the console, open API keys and create a key. Its secret (fsit_…) is shown once; store it in your secret manager. Then open the filesystem and grant the key rw (or ro).

2. Create a session from your backend

curl -X POST "https://$FSIT_HOST/api/v1/mount-sessions" \
  -H "Authorization: Bearer $FSIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"filesystem_id": "k5q2ztr4mvd7wn3xa6jhebcyfu", "mode": "rw", "idempotency_key": "job-4182"}'

The response contains the session id and the ticket. The ticket is single-use and must be exchanged within five minutes.

FieldMeaning
filesystem_idthe filesystem to mount
modero or rw, up to the key's grant
idempotency_keyretries with the same key return the same session; the ticket is never shown twice
max_duration_secondsoptional; default 12 hours, at most 7 days and never past the key's expiry

3. Mount in the sandbox

The sandbox needs the fsit CLI, FUSE (/dev/fuse), and the SeaweedFS weed binary, version 4.48. Point the CLI at your fsit API with FSIT_API_URL, and pass the ticket on stdin, never on the command line or in an image:

mkdir -p /mnt/work
echo "$TICKET" | fsit mount --ticket-stdin /mnt/work &

The ticket names the filesystem and mode. The CLI generates a key pair, exchanges the ticket for a short-lived certificate, keeps renewing it in the foreground (hence &), and unmounts when the session is revoked or expires.

4. Revoke

curl -X DELETE "https://$FSIT_HOST/api/v1/mount-sessions/$SESSION_ID" \
  -H "Authorization: Bearer $FSIT_API_KEY"

You can also revoke live sessions on the filesystem's page in the console. Removing a grant, revoking the key, or deleting the filesystem revokes the affected sessions too.