Skip to content

Node settings

A node needs very little of its own: where the central service is, how to prove it may join, and where to keep its files. Everything else (ports, AE title, sources, destinations, routes) comes from the central service.

Later sources override earlier ones:

  1. appsettings.json next to the program, in a "Node" section.
  2. The registry, HKLM\SOFTWARE\Routes\Node (Windows; written by the installer).
  3. Environment variables, Routes__Node__<Setting>, such as Routes__Node__CentralUrl.
  4. The command line, --Node:<Setting>=<value>.

Restart the node after changing them.

Setting Installer property Default What it does
CentralUrl CENTRALURL https://localhost:5080/ The central service’s address. Several central servers: ; separated, the preferred one first; the node fails over to the next.
ApiKey APIKEY The enrollment key from Configuration › Node enrollment. Used to enroll; the node then gets a key of its own.
CentralCertificateThumbprints CENTRALTHUMBPRINT Thumbprints (SHA-1 or SHA-256) of central certificates to trust although the operating system does not, such as the self-signed one. ; separated.
CentralCertificatePath A file with the central service’s certificate (PEM or DER), trusted like a thumbprint and read again when it changes (containers).
NodeName NODENAME the computer name The node’s name in the console. Must be unique.
DataDirectory DATADIR %ProgramData%\Routes\Node\Data, /var/lib/routes/node Everything in transit. One volume: see Data folders.
LogDirectory LOGDIR %ProgramData%\Routes\Node\Logs, /var/log/routes/node A file a day, node-<yyyymmdd>.log, 30 kept.
LogLevel Information Verbose, Debug, Information, Warning or Error.
TlsCertificateThumbprint This node’s DICOM TLS certificate in LocalMachine\My; overrides the console’s Node certificate.
TlsCertificatePath The certificate as a file instead: PKCS#12 or PEM. Read again every hour, for renewals.
TlsCertificateKeyPath The PEM private key, when it is not in the certificate file.
TlsCertificatePassword The PKCS#12 file’s password, or the encrypted PEM key’s.
HeartbeatInterval 00:00:02 How often the node reports to the central service.
PortOffset 0 Added to every listen port, to run several nodes on one machine for testing. Routing still sees the configured ports.
Variable What it does
ROUTES_PROTECTION_KEY Off Windows: a 32-byte key (base64) that protects the node’s key and secrets, instead of protection.key in the data folder.

When it first enrolls, a node receives a key of its own and keeps it, protected, in node-key.bin. From then on it signs in with that key, and the enrollment key can be changed without touching the node. A node that loses its data folder must be given a new key: Nodes › Reset key. See Adding nodes.