Skip to content

Data folders

When they start, the services restrict their data and log folders: on Windows to the service account, SYSTEM and Administrators; on Linux to the service account alone (mode 700). Most of what is in them is patient data.

Windows Linux
Central data %ProgramData%\Routes\Central\Data /var/lib/routes/central
Central logs %ProgramData%\Routes\Central\Logs /var/log/routes/central
Node data %ProgramData%\Routes\Node\Data /var/lib/routes/node
Node logs %ProgramData%\Routes\Node\Logs /var/log/routes/node

DataDirectory and LogDirectory change them. A file a day is logged, and 30 are kept.

The central service keeps almost everything in its database. Its data folder holds only:

File What it is
https-self-signed.pfx The self-signed HTTPS certificate, when no other is set.
https-self-signed-next.pfx Its replacement, made 90 days before it ends and used from 30 days before.
secret-protection.pfx The certificate protecting stored secrets (with SecretProtection set to Certificate, the only kind off Windows). Back it up with the database.
initial-admin-password.txt The first administrator’s password (local accounts), until it is changed.

The key ring that encrypts stored secrets is in the database, itself encrypted by Windows or by secret-protection.pfx: a copy of the database alone does not reveal the secrets.

Everything under the node’s data folder must be on one volume: files move between these folders rather than being copied.

Folder or file What it holds
incoming Instances being received.
queues\<destination> Instances waiting for each destination, with its journal.
deadletter\<destination> Instances a destination refused for good, with the reason.
sent The resend cache: delivered instances, kept for Resend cache (hours).
quarantine Refused instances, kept for Quarantine (days); empty by default.
held Instances held until their study is complete.
reconcile Instances waiting in the reconciliation queue.
commitments, commitments-out Storage commitment requests from senders, and to destinations.
prefetch Prior-study requests.
qr Instances being retrieved from archives through the router (C-MOVE, C-GET, WADO-RS, prior studies).
wado-cache Instances retrieved for DICOMweb viewers, kept for Keep retrieved instances.
ai-pending Studies sent to AI services, waiting for their results.
mpps-out Procedure steps waiting to be forwarded.
hl7-out\<destination> HL7 messages waiting for each HL7 destination; dead for those put aside.
history History events not yet sent to the central service.
patientmaps This node’s copy of the patient ID maps.
worklist.json This node’s copy of the modality worklist.
config-cache.json The last configuration, used when the node starts and the central service cannot be reached.
node-state.json Whether an administrator drained the node, and its lifetime counters.
central-certificates.json Central certificates the node has learned to trust (renewed self-signed ones).
node-key.bin The node’s own key, protected.
secrets.bin Secrets the node was given (DICOMweb credentials, de-identification keys), protected.
data.key With Encrypt traffic kept on nodes: the key the node encrypts what it keeps with, protected. Made when encryption is first turned on, and kept.
protection.key Off Windows: the key protecting the three files above, unless ROUTES_PROTECTION_KEY is set.
  • The central database: the configuration, history, audit log and alerts. See Upgrades and backups.
  • secret-protection.pfx, when it is used.
  • Nodes need no backup: a new node enrolls and receives everything. Instances in their queues are lost with the node, as with any router. A reinstalled node needs Reset key in the console.