Configuration Editing Rules for App Config
Double-clicking any configuration entry enters edit mode. Behavior differs based on the persistence setting:
- Unchecking persistence: Changes take effect immediately for the current runtime, but are lost after application restart. Modified values are marked with a
[temp]suffix to indicate temporary status. - Checking persistence: Changes are saved to disk and persist across application restarts. Modified values are marked with a
[durable]suffix.
By default, the interface loads Mvc configuration first. The .NET Core version of Taurus adds a dedicated Kestrel configuration node that is not present in the .NET Framework version; all other configuration sections are identical across both versions.
Core Kestrel Configuration (HTTPS Support Included)
Any configuration entry marked [Restart] in its description requires an application restart after modification too take effect. All other entries apply changes immediately.
Core Configuration Options
| Option | Description |
|---|---|
| Urls | Follows .NET Core's native configuration format, used to set the default port for HTTP requests. If you only enable HTTPS and do not need HTTP, you can leave this parameter empty. |
| AllowSynchronousIO | Controls whether synchronous IO reads are allowed. The framework reads the request body stream when processing POST data. This setting has no noticeable impact on Windows environments, but must be set to true for Linux deployments. |
| AddServerHeader | Determines whether Kestrel adds the Server: kestrel response header to outgoing responses. |
| SslPort | The HTTPS listen port, defaults to 443 and can be modified as needed. |
| SslPath | The directory where SSL certificates are stored. Once certificates are placed in this directory, HTTPS is automatically enabled. This directory path can be adjusted through the configuration. |
HTTPS Enablement Walkthrough
After requesting a certificate from a trusted certificate authority, download the PFX-format certificate package intended for IIS deployment, usually provided as a ZIP archive named after your domain.
- Unzip the package
- Rename the included
keystorePass.txtto match your full domain (e.g.gateway.cyqdata.com.txtfor domaingateway.cyqdata.com) - Place both the renamed text file and the PFX certificate file into the directory configured for
SslPath
The framework handles all remaining HTTPS configuration automatically, greatly simplifying the traditionally complex setup process.
Kestrel HostFilter Configuration
Configuration Options
| Option | Description |
|---|---|
| AllowedHosts | Configures allowed request host headers. Defaults to * which accepts all host headers. To restrict access to specific domains, update this value to your domain names, separated by commas. Example: gateway.cyqdata.com |
| AllowEmptyHosts | Controls whether requests without a Host header are allowed. This setting exists for backward compatibility with HTTP/1.0, and can be left at default if you do not need to handle legacy clients. |
| IncludeFailureMessage | Determines whether to return a descriptive error message (400 Bad Request: Invalid Host Header) when a request is blocked due to host filtering. |
Kestrel Connection Limits Configuration
The default maximum connection count is long.MaxValue, which means no connection limit. This native Kestrel configuration requires an application restart to take effect due to Kestrel's internal implementation. As a more flexible alternative, the framework adds a Limit.Rate.MaxConcurrentConnections setting that provides the same concurrent connection limiting functionality, and applies changes immediately without a restart.
Kestrel Request Size Limits Configuration
| Option | Description |
|---|---|
| MaxRequestBodySize | Restricts the maximum size of the request body in bytes, defaults to long.MaxValue (unlimited). |
| MaxRequestBufferSize | Restricts the total size of the entire HTTP request in bytes, including the request line, headers, and body, defaults to long.MaxValue. |
| MaxRequestLineSize | Restricts the maximum length of the request line (e.g. GET /api/users HTTP/1.1) in bytes. |
| MaxRequestHeaderCount | Restricts the maximum number of request headers allowed per request. |
| MaxRequestHeadersTotalSize | Restricts the total combined size of all request headers in bytes. |
MaxRequestBodySize and MaxRequestBufferSize require a restart after modification to take effect. Incorrect values for the last three parameters can easily break application access, so the framework enforces internal minimum value limits for these settings.
Kestrel Response Limits Configuration
| Option | Description |
|---|---|
| MaxResponseBufferSize | Restricts the maximum response buffer size in bytes that the server can output. |
Kestrel Timeout Limits Configuration
| Option | Description |
|---|---|
| KeepAliveTimeout | The maximum duration to keep an idle connection alive with a client, measured in minutes. |
| RequestHeadersTimeout | The maximum duration allowed to receive the full request header from a client, measured in seconds. |
A small number of less commonly used Kestrel parameters (such as HTTP/2 and HTTP/3 specific configuration) are not yet exposed in the interface, and will be added in future updates.