轩辕镜像 官方专业版
轩辕镜像
专业版
轩辕镜像 官方专业版
轩辕镜像
专业版
首页个人中心搜索镜像
交易
充值流量¥8起我的订单
文档
工具
提交工单页面收录
dcs

ghga/dcs

ghga

Download Controller Service - a GA4GH DRS-compliant service for delivering files from S3 encrypted a

下载次数: 0状态:社区镜像维护者:ghga仓库类型:镜像最近更新:5 天前
让 AI 帮你使用轩辕镜像? · 展开查看说明 · 点击收起说明

如果你使用 DeepSeek、元宝 AI、Copilot、ChatGPT 等 AI 工具,协助配置轩辕镜像、编写 docker pull 命令、修改 Docker Compose 镜像地址、配置镜像加速、排查镜像拉取失败、分析报错日志等问题,请先让 AI 阅读并遵守轩辕镜像的规则文档。

只需在 AI 对话中先发送下面这句话即可:

请先完整阅读并严格遵守以下文档中的全部规则与要求:

https://xuanyuan.cloud/agents.md

在未充分阅读并理解该文档前,不要生成任何命令、配置、修改建议、故障排查方案或技术回答。后续所有输出都必须严格以该文档中的规范为最高优先级执行。

查看 agents.md 用法指南与完整示范。国内用户首推 元宝 AI、DeepSeek 的深度思考模式,不推荐豆包 AI;Cursor 等编辑器可在对话 @ 该链接,或加入 User Rules。 若 AI 无法访问外链,可 打开说明文档 复制全文粘贴。文档会随站点更新,复制内容可能过期,建议定期检查。

镜像简介
下载命令
镜像标签列表与下载命令
轩辕镜像,让镜像更快,让人生更轻。
点击查看

Download Controller Service

a GA4GH DRS-compliant service for delivering files from S3 encrypted according to the GA4GH Crypt4GH standard.

Description

This service implements the https://github.com/ga4gh/data-repository-service-schemas v1.0.0 for serving files that where encrypted according to the GA4GH Crypt4GH from S3-compatible object storages.

Thereby, only the GET /objects/{object_id} is implemented. It always returns an access_method for the object via S3. This makes the second endpoint GET /objects/{object_id}/access/{access_id} that is contained in the DRS spec unnecessary. For more details see the OpenAPI spec described below.

For authorization, a JSON web token is expected via Bearer Authentication that has a format described here.

All files that can be requested are registered in a MongoDB database owned and controlled by this service. Registration of new events happens through a Kafka event.

It serves pre-signed URLs to S3 objects located in a single so-called download bucket. If the file is not already in the bucket when the user calls the object endpoint, an event is published to request staging the file to the download bucket. The staging has to be carried out by a different service.

For more details on the events consumed and produced by this service, see the configuration.

The DRS object endpoint serves files in an encrypted fashion as described by the Crypt4GH standard, but without the evelope. A user-specific envelope can be requested from the GET /objects/{object_id}/envelopes endpoint. The actual envelope creation is delegated to another service via a RESTful call. Please see the configuration for further details.

Installation

We recommend using the provided Docker container.

A pre-built version is available at https://hub.docker.com/repository/docker/ghga/download-controller-service:

bash
docker pull ghga/download-controller-service:10.3.0

Or you can build the container yourself from the ./Dockerfile:

bash
# Execute in the repo's root dir:
docker build -t ghga/download-controller-service:10.3.0 .

For production-ready deployment, we recommend using Kubernetes, however, for simple use cases, you could execute the service using docker on a single server:

bash
# The entrypoint is preconfigured:
docker run -p 8080:8080 ghga/download-controller-service:10.3.0 --help

If you prefer not to use containers, you may install the service from source:

bash
# Execute in the repo's root dir:
pip install .

# To run the service:
dcs --help

Configuration

Parameters

The service requires the following configuration parameters:

  • client_exponential_backoff_max (integer): Maximum number of seconds to wait between retries when using exponential backoff retry strategies. The client timeout might need to be adjusted accordingly. Minimum: 0. Default: 60.

  • client_num_retries (integer): Number of times to retry failed API calls. Minimum: 0. Default: 3.

  • client_retry_status_codes (array): List of status codes that should trigger retrying a request. Default: [408, 429, 500, 502, 503, 504].

    • Items (integer): Minimum: 0.
  • client_reraise_from_retry_error (boolean): Specifies if the exception wrapped in the final RetryError is reraised or the RetryError is returned as is. Default: true.

  • per_request_jitter (number): Max amount of jitter (in seconds) to add to each request. Minimum: 0. Default: 0.0.

  • retry_after_applicable_for_num_requests (integer): Amount of requests after which the stored delay from a 429 response is ignored again. Can be useful to adjust if concurrent requests are fired in quick succession. Exclusive minimum: 0. Default: 1.

  • http_request_timeout_seconds (number): Request timeout setting in seconds. Default: 60.0.

  • ekss_base_url (string, required): URL containing host and port of the EKSS endpoint to retrieve personalized envelope from.

    Examples:

    json
    "http://ekss:8080/"
    
  • enable_opentelemetry (boolean): If set to true, this will run necessary setup code.If set to false, no setup code is run, which leaves tracing disabled. Default: false.

  • otel_trace_sampling_rate (number): Determines which proportion of spans should be sampled. A value of 1.0 means all and is equivalent to the previous behaviour. Setting this to 0 will result in no spans being sampled, but this does not automatically set enable_opentelemetry to False. Minimum: 0. Maximum: 1. Default: 1.0.

  • log_level (string): The minimum log level to capture. Must be one of: "CRITICAL", "ERROR", "WARNING", "INFO", "DEBUG", or "TRACE". Default: "INFO".

  • service_name (string): Default: "dcs".

  • service_instance_id (string, required): A string that uniquely identifies this instance across all instances of this service. A globally unique Kafka client ID will be created by concatenating the service_name and the service_instance_id.

    Examples:

    json
    "germany-bw-instance-001"
    
  • log_format: If set, will replace JSON formatting with the specified string format. If not set, has no effect. In addition to the standard attributes, the following can also be specified: timestamp, service, instance, level, correlation_id, and details. Default: null.

    • Any of

      • string

      • null

    Examples:

    json
    "%(timestamp)s - %(service)s - %(level)s - %(message)s"
    
    json
    "%(asctime)s - Severity: %(levelno)s - %(msg)s"
    
  • log_traceback (boolean): Whether to include exception tracebacks in log messages. Default: true.

  • object_storages (object, required): Can contain additional properties.

    • Additional properties: Refer to #/$defs/S3ObjectStorageNodeConfig.
  • file_deletion_request_topic (string, required): The name of the topic to receive events informing about files to delete.

    Examples:

    json
    "file-deletion-requests"
    
  • file_deletion_request_type (string, required): The type used for events indicating that a request to delete a file has been received.

    Examples:

    json
    "file_deletion_requested"
    
  • file_internally_registered_topic (string, required): Name of the topic used for events indicating that a file has been registered for download.

    Examples:

    json
    "file-registrations"
    
    json
    "file-registrations-internal"
    
  • file_internally_registered_type (string, required): The type used for event indicating that that a file has been registered for download.

    Examples:

    json
    "file_internally_registered"
    
  • files_to_stage_topic (string, required): Name of the topic used for events indicating that a download was requested for a file that is not yet available in the outbox.

    Examples:

    json
    "file-staging-requests"
    
  • files_to_stage_type (string, required): The type used for non-staged file request events.

    Examples:

    json
    "file_staging_requested"
    
  • file_registered_for_download_topic (string, required): Name of the topic used for events indicating that a file has been registered by the DCS for download.

    Examples:

    json
    "file-registrations"
    
    json
    "file-registrations-download"
    
  • file_registered_for_download_type (string, required): The type used for event indicating that a file has been registered by the DCS for download.

    Examples:

    json
    "file_registered_for_download"
    
  • file_deleted_topic (string, required): Name of the topic used for events indicating that a file has been deleted.

    Examples:

    json
    "file-deletions"
    
  • file_deleted_type (string, required): The type used for events indicating that a file has been deleted.

    Examples:

    json
    "file_deleted"
    
  • download_served_topic (string, required): Name of the topic used for events indicating that a download of a specified file happened.

    Examples:

    json
    "file-downloads"
    
  • download_served_type (string, required): The type used for event indicating that a download of a specified file happened.

    Examples:

    json
    "download_served"
    
  • kafka_servers (array, required): A list of connection strings to connect to Kafka bootstrap servers.

    • Items (string)

    Examples:

    json
    [
        "localhost:9092"
    ]
    
  • kafka_security_protocol (string): Protocol used to communicate with brokers. Valid values are: PLAINTEXT, SSL. Must be one of: "PLAINTEXT" or "SSL". Default: "PLAINTEXT".

  • kafka_ssl_cafile (string): Certificate Authority file path containing certificates used to sign broker certificates. If a CA is not specified, the default system CA will be used if found by OpenSSL. Default: "".

  • kafka_ssl_certfile (string): Optional filename of client certificate, as well as any CA certificates needed to establish the certificate's authenticity. Default: "".

  • kafka_ssl_keyfile (string): Optional filename containing the client private key. Default: "".

  • kafka_ssl_password (string, format: password, write-only): Optional password to be used for the client private key. Default: "".

  • generate_correlation_id (boolean): A flag, which, if False, will result in an error when inbound requests don't possess a correlation ID. If True, requests without a correlation ID will be assigned a newly generated ID in the correlation ID middleware function. Default: true.

    Examples:

    json
    true
    
    json
    false
    
  • kafka_max_message_size (integer): The largest message size that can be transmitted, in bytes, before compression. Only services that have a need to send/receive larger messages should set this. When used alongside compression, this value can be set to something greater than the broker's message.max.bytes field, which effectively concerns the compressed message size. Exclusive minimum: 0. Default: 1048576.

    Examples:

    json
    1048576
    
    json
    16777216
    
  • kafka_compression_type: The compression type used for messages. Valid values are: None, gzip, snappy, lz4, and zstd. If None, no compression is applied. This setting is only relevant for the producer and has no effect on the consumer. If set to a value, the producer will compress messages before sending them to the Kafka broker. If unsure, zstd provides a good balance between speed and compression ratio. Default: null.

    • Any of

      • string: Must be one of: "gzip", "snappy", "lz4", or "zstd".

      • null

    Examples:

    json
    null
    
    json
    "gzip"
    
    json
    "snappy"
    
    json
    "lz4"
    
    json
    "zstd"
    
  • kafka_max_retries (integer): The maximum number of times to immediately retry consuming an event upon failure. Works independently of the dead letter queue. Minimum: 0. Default: 0.

    Examples:

    json
    0
    
    json
    1
    
    json
    2
    
    json
    3
    
    json
    5
    
  • kafka_enable_dlq (boolean): A flag to toggle the dead letter queue. If set to False, the service will crash upon exhausting retries instead of publishing events to the DLQ. If set to True, the service will publish events to the DLQ topic after exhausting all retries. Default: false.

    Examples:

    json
    true
    
    json
    false
    
  • kafka_dlq_topic (string): The name of the topic used to resolve error-causing events. Default: "dlq".

    Examples:

    json
    "dlq"
    
  • kafka_retry_backoff (integer): The number of seconds to wait before retrying a failed event. The backoff time is doubled for each retry attempt. Minimum: 0. Default: 0.

    Examples:

    json
    0
    
    json
    1
    
    json
    2
    
    json
    3
    
    json
    5
    
  • mongo_dsn (string, format: multi-host-uri, required): MongoDB connection string. Might include credentials. For more information see: [***] Length must be at least 1.

    Examples:

    json
    "mongodb://localhost:27017"
    
  • db_name (string, required): Name of the database located on the MongoDB server.

    Examples:

    json
    "my-database"
    
  • mongo_timeout: Timeout in seconds for API calls to MongoDB. The timeout applies to all steps needed to complete the operation, including server selection, connection checkout, serialization, and server-side execution. When the timeout expires, PyMongo raises a timeout exception. If set to None, the operation will not time out (default MongoDB behavior). Default: null.

    • Any of

      • integer: Exclusive minimum: 0.

      • null

    Examples:

    json
    300
    
    json
    600
    
    json
    null
    
  • db_version_collection (string, required): The name of the collection containing DB version information for this service.

    Examples:

    json
    "ifrsDbVersions"
    
  • migration_wait_sec (integer, required): The number of seconds to wait before checking the DB version again.

    Examples:

    json
    5
    
    json
    30
    
    json
    180
    
  • migration_max_wait_sec: The maximum number of seconds to wait for migrations to complete before raising an error. Default: null.

    • Any of

      • integer

      • null

    Examples:

    json
    null
    
    json
    300
    
    json
    600
    
    json
    3600
    
  • download_bucket_cache_timeout (integer): Time in days since last access after which a file present in the download bucket should be unstaged and has to be requested from permanent storage again for the next request. Default: 7.

    Examples:

    json
    7
    
    json
    30
    
  • drs_server_uri (string, required): The base of the DRS URI to access DRS objects. Has to start with 'drs://' and end with '/'.

    Examples:

    json
    "drs://localhost:8080/"
    
  • staging_speed (integer): When trying to access a DRS object that is not yet in the download bucket, assume that this many megabytes can be staged per second. Default: 100.

    Examples:

    json
    100
    
    json
    500
    
  • retry_after_min (integer): When trying to access a DRS object that is not yet in the download bucket, wait at least this number of seconds before trying again. Default: 5.

    Examples:

    json
    5
    
    json
    10
    
  • retry_after_max (integer): When trying to access a DRS object that is not yet in the download bucket, wait at most this number of seconds before trying again. Default: 300.

    Examples:

    json
    30
    
    json
    300
    
  • presigned_url_expires_after (integer, required): Expiration time in seconds for presigned URLS. Positive integer required. Exclusive minimum: 0.

    Examples:

    json
    30
    
    json
    60
    
  • auth_key (string, required): The GHGA internal public key for validating the token signature.

    Examples:

    json
    "{\"crv\": \"P-256\", \"kty\": \"EC\", \"x\": \"...\", \"y\": \"...\"}"
    
  • auth_algs (array): A list of all algorithms used for signing GHGA internal tokens. Default: ["ES256"].

    • Items (string)
  • auth_check_claims (object): A dict of all GHGA internal claims that shall be verified. Can contain additional properties. Default: {"work_type": null, "file_id": null, "user_public_crypt4gh_key": null, "iat": null, "exp": null}.

  • auth_map_claims (object): A mapping of claims to attributes in the GHGA auth context. Can contain additional properties. Default: {}.

    • Additional properties (string)
  • host (string): IP of the host. Default: "127.0.0.1".

  • port (integer): Port to expose the server on the specified host. Default: 8080.

  • auto_reload (boolean): A development feature. Set to True to automatically reload the server upon code changes. Default: false.

  • workers (integer): Number of workers processes to run. Default: 1.

  • timeout_keep_alive (integer): The time in seconds to keep an idle connection open for subsequent requests before closing it. This value should be higher than the timeout used by any client or reverse proxy to avoid premature connection closures. Default: 90.

    Examples:

    json
    5
    
    json
    90
    
    json
    5400
    
  • api_root_path (string): Root path at which the API is reachable. This is relative to the specified host and port. Default: "".

  • openapi_url (string): Path to get the openapi specification in JSON format. This is relative to the specified host and port. Default: "/openapi.json".

  • docs_url (string): Path to host the swagger documentation. This is relative to the specified host and port. Default: "/docs".

  • cors_allowed_origins: A list of origins that should be permitted to make cross-origin requests. By default, cross-origin requests are not allowed. You can use ['*'] to allow any origin. Default: null.

    • Any of

      • array

        • Items (string)
      • null

    Examples:

    json
    [
        "https://example.org",
        "https://www.example.org"
    ]
    
  • cors_allow_credentials: Indicate that cookies should be supported for cross-origin requests. Defaults to False. Also, cors_allowed_origins cannot be set to ['*'] for credentials to be allowed. The origins must be explicitly specified. Default: null.

    • Any of

      • boolean

      • null

    Examples:

    json
    [
    

> This README is longer than Docker Hub's 25000-character overview limit, so it has been cut short here. Read the rest on GitHub: https://github.com/ghga-de/ghga/blob/main/services/dcs/README.md

镜像拉取方式

您可以使用以下命令拉取该镜像。请将 <标签> 替换为具体的标签版本。如需查看所有可用标签版本,请访问 标签列表页面。

轩辕镜像加速拉取命令点我查看更多 dcs 镜像标签

docker pull docker.xuanyuan.run/ghga/dcs:<标签>

使用方法:

  • 登录认证方式
  • 免认证方式

DockerHub 原生拉取命令

docker pull ghga/dcs:<标签>

轩辕镜像配置手册

按平台快速找到配置文档

一键安装

一键安装 Docker

Linux Docker 一键安装

AI

用 AI 使用轩辕镜像

agents.md · AI 对话 · 提示词

Docker

登录仓库拉取

登录认证 · 私有仓库

专属域名拉取

免登录 · 高速拉取

Linux

Docker 镜像配置

Windows / Mac

Docker Desktop 配置

MacOS OrbStack

OrbStack 容器

Apple Container

macOS 原生容器

Docker Compose

Compose 项目配置

NAS

群晖

Synology 配置

飞牛

fnOS 镜像配置

绿联

绿联 NAS

威联通

QNAP 配置

极空间

极空间 NAS

Unraid

Unraid NAS

企业仓库

其他仓库

ghcr · Quay · nvcr

Harbor 镜像源

Proxy Repository 对接

Portainer 镜像源

Registries 配置

Nexus 镜像源

Docker Proxy 缓存

开发工具

Dev Containers

VS Code 开发容器

Podman

Podman 配置指南

Singularity / Apptainer

HPC 科学计算容器

Kubernetes

K8s Containerd

Kubernetes · Containerd

K3s

轻量级集群

面板 / 网络

爱快路由

爱快 4.0 · iKuai 镜像加速

宝塔面板

一键配置镜像源

需要其他帮助?请查看我们的 常见问题Docker 镜像访问常见问题解答 或 提交工单

镜像拉取常见问题

功能

版本功能对比

功能对比 · 版本选择

支持的镜像仓库

Docker Hub · GCR · GHCR

专属域名用法

专属域名 · 开启停用 · 多仓库

新手拉取配置

登录 · 专属域名 · 配置

docker search 限制

专属域名 · Hub 搜索

不支持 push

仅支持 pull · 不支持

拉取速度原因

带宽 · 缓存 · 冷热镜像

错误码

402 与流量用尽

402 · 流量包 · 充值

401 认证失败

401 · docker login

manifest unknown

标签错误 · 镜像不存在

410 Gone 排查

410 · Docker 升级

429 限流

免费版 · 专业版 · 企业版 · 请求频率

其他报错

DNS 超时

DNS 解析 · 网络超时

TLS 证书失败

no matching manifest(架构)

docker.sock / daemon

账号

失败是否计费

manifest · blob · 计费

申请开票(企业 / 个人)

开票 · 发票 · 工单

修改登录密码

网站 · 仓库 · 重置

注销账户

工单 · 数据 · 注销

原理

mirrors 不生效

daemon.json · 重启

去掉域名前缀

docker tag · 重命名

指定架构拉取

ARM64 · AMD64 · 多架构

latest 与「最新」

digest · 版本号 · 标签

查看全部问题→

用户好评

来自真实用户的反馈,见证轩辕镜像的优质服务

用户头像

oldzhang

运维工程师

Linux服务器

5

"Docker访问体验非常流畅,大镜像也能快速完成下载。"

轩辕镜像
镜像详情
...
ghga/dcs
定价查看流量套餐与价格
博客Docker 镜像公告与技术博客
专业版 · 高速稳定拉取镜像
高速镜像下载·在线技术支持·99.95% SLA 保障·付费会员免广告
50GB 仅 ¥8/年
专业版 · 高速稳定拉取镜像
50GB 仅 ¥8/年
高速镜像下载·在线技术支持·99.95% SLA 保障·付费会员免广告
用户协议·隐私政策·增值电信业务经营许可证:浙B2-20261007·©2024-2026 源码跳动©2024-2026 杭州源码跳动科技有限公司·商务合作:点击复制邮箱

更多 dcs 镜像推荐

ghga/auth-service logo

ghga/auth-service

ghga
Authentication adapter and services used for the GHGA data portal
1万+ 次下载
5 天前更新
ghga/data-portal logo

ghga/data-portal

ghga
GHGA Data Portal是GHGA数据门户的Web前端应用,支持元数据浏览、数据集提交与上传、访问请求等功能,帮助用户管理和交互数据资源。
1万+ 次下载
5 天前更新
ghga/file-ingest-service logo

ghga/file-ingest-service

ghga
暂无描述
1万+ 次下载
30 天前更新
ghga/internal-file-registry-service logo

ghga/internal-file-registry-service

ghga
暂无描述
1万+ 次下载
30 天前更新
ghga/encryption-key-store-service logo

ghga/encryption-key-store-service

ghga
暂无描述
1万+ 次下载
30 天前更新
ghga/download-controller-service logo

ghga/download-controller-service

ghga
暂无描述
1万+ 次下载
30 天前更新

查看更多 dcs 相关镜像