Data folders
When they start, the services restrict their data and log folders: on Windows to the service account, SYSTEM and Administrators; on Linux to the service account alone (mode 700). Most of what is in them is patient data.
Defaults
Section titled “Defaults”| Windows | Linux | |
|---|---|---|
| Central data | %ProgramData%\Routes\Central\Data |
/var/lib/routes/central |
| Central logs | %ProgramData%\Routes\Central\Logs |
/var/log/routes/central |
| Node data | %ProgramData%\Routes\Node\Data |
/var/lib/routes/node |
| Node logs | %ProgramData%\Routes\Node\Logs |
/var/log/routes/node |
DataDirectory and LogDirectory change them. A file a day is logged, and 30 are kept.
The central service
Section titled “The central service”The central service keeps almost everything in its database. Its data folder holds only:
| File | What it is |
|---|---|
https-self-signed.pfx |
The self-signed HTTPS certificate, when no other is set. |
https-self-signed-next.pfx |
Its replacement, made 90 days before it ends and used from 30 days before. |
secret-protection.pfx |
The certificate protecting stored secrets (with SecretProtection set to Certificate, the only kind off Windows). Back it up with the database. |
initial-admin-password.txt |
The first administrator’s password (local accounts), until it is changed. |
The key ring that encrypts stored secrets is in the database, itself encrypted by Windows or by
secret-protection.pfx: a copy of the database alone does not reveal the secrets.
A node
Section titled “A node”Everything under the node’s data folder must be on one volume: files move between these folders rather than being copied.
| Folder or file | What it holds |
|---|---|
incoming |
Instances being received. |
queues\<destination> |
Instances waiting for each destination, with its journal. |
deadletter\<destination> |
Instances a destination refused for good, with the reason. |
sent |
The resend cache: delivered instances, kept for Resend cache (hours). |
quarantine |
Refused instances, kept for Quarantine (days); empty by default. |
held |
Instances held until their study is complete. |
reconcile |
Instances waiting in the reconciliation queue. |
commitments, commitments-out |
Storage commitment requests from senders, and to destinations. |
prefetch |
Prior-study requests. |
qr |
Instances being retrieved from archives through the router (C-MOVE, C-GET, WADO-RS, prior studies). |
wado-cache |
Instances retrieved for DICOMweb viewers, kept for Keep retrieved instances. |
ai-pending |
Studies sent to AI services, waiting for their results. |
mpps-out |
Procedure steps waiting to be forwarded. |
hl7-out\<destination> |
HL7 messages waiting for each HL7 destination; dead for those put aside. |
history |
History events not yet sent to the central service. |
patientmaps |
This node’s copy of the patient ID maps. |
worklist.json |
This node’s copy of the modality worklist. |
config-cache.json |
The last configuration, used when the node starts and the central service cannot be reached. |
node-state.json |
Whether an administrator drained the node, and its lifetime counters. |
central-certificates.json |
Central certificates the node has learned to trust (renewed self-signed ones). |
node-key.bin |
The node’s own key, protected. |
secrets.bin |
Secrets the node was given (DICOMweb credentials, de-identification keys), protected. |
data.key |
With Encrypt traffic kept on nodes: the key the node encrypts what it keeps with, protected. Made when encryption is first turned on, and kept. |
protection.key |
Off Windows: the key protecting the three files above, unless ROUTES_PROTECTION_KEY is set. |
What to back up
Section titled “What to back up”- The central database: the configuration, history, audit log and alerts. See Upgrades and backups.
secret-protection.pfx, when it is used.- Nodes need no backup: a new node enrolls and receives everything. Instances in their queues are lost with the node, as with any router. A reinstalled node needs Reset key in the console.
