Skip to content

Defaults and Limits

ComponentPort
API3000
STS8080
Gateway8081
Audit9090
Coordinator4000
Postgres5432
Redis6379
LimitDefault
STS resource mandate cap15 minutes
STS session mandate cap60 minutes
STS MAX_GRANT_TTL_SECONDS3600
DCR application lifetime default and maximum3600 seconds
caracal run injected credential TTL900 seconds
Runtime step-up pollingevery 2 seconds for up to 5 minutes
Gateway expiring-token preflight window35 seconds
LimitDefault
API body limit1_048_576 bytes
API request timeout30_000 ms
Gateway max request bytes10 MiB
Gateway STS timeout5 seconds
Gateway upstream timeout30 seconds
Gateway STS circuit failure limit3 failures
Gateway STS circuit open window10 seconds
STS OPA_POLL_SECONDS60 seconds, max 300
Control body limit64 KiB
Control rate capacity60 per window
Control rate window60 seconds
Control replay TTL3600 seconds
LimitDefault
Concurrent agent sessions per zone50
Concurrent agent sessions per application200
Child agents per parent session10
Delegation depth10
Agent labels per session32
Agent label length64 characters
STS request rate per zone, resource, and acting application1000 per minute
DefaultValue
Audit retention365 days
Audit max deliveries before DLQ8
Audit claim idle30 seconds
Audit tamper rolling window4 hours
Redis audit stream intended max length1,000,000
Redis audit DLQ intended max length100,000
Redis policy/revocation/key stream intended max length10,000
ServiceReplicasMax HPA replicas
API28
STS28
Gateway216
Audit28
Coordinator28
Controldisabled2 when enabled

Use CLI Exit Codes when automating top-level caracal runtime commands.