DEV Community

Cover image for Deploying Lioran S3 with Docker, Caddy and HTTPS
Swaraj Puppalwar
Swaraj Puppalwar

Posted on

Deploying Lioran S3 with Docker, Caddy and HTTPS

Deploying Lioran S3 with Docker, Caddy and HTTPS

This article covers the deployment shape recommended by the current Lioran S3 V1 Pre-Alpha repository: the Rust storage process behind a reverse proxy such as Caddy.

Lioran S3 is developed by Lioran Developer Solutions (LDS) under Lioran Group, led by Swaraj Puppalwar.

Pre-alpha is for evaluation and testing. Harden the host and validate failure behavior before storing anything important.

Architecture

Internet
   |
   | HTTPS :443
   v
Caddy
   |
   | HTTP private network
   v
Lioran S3
   |
   +--> object data directory
   |
   +--> RocksDB metadata
Enter fullscreen mode Exit fullscreen mode

The storage server does not need to own TLS termination itself.

That lets Caddy handle certificate automation and public HTTPS while Bastion focuses on storage.

Clone

git clone   https://github.com/LioranGroupOfficial/LioranBastion-Rust.git

cd LioranBastion-Rust
Enter fullscreen mode Exit fullscreen mode

Production environment

Start from the production example:

cp   .env.production.example   .env
Enter fullscreen mode Exit fullscreen mode

Review every value.

Important categories include:

BASTION_ENV=production
BASTION_HOST=0.0.0.0
BASTION_PORT=27118

BASTION_DATA_DIR=/data

BASTION_ADMIN_USERNAME=admin
BASTION_ADMIN_PASSWORD=REPLACE_ME

BASTION_DURABILITY=strict

BASTION_PUBLIC_URL=https://storage.example.com

BASTION_CORS_ORIGINS=https://app.example.com

BASTION_SIGNING_SECRET=REPLACE_WITH_LONG_RANDOM_SECRET
Enter fullscreen mode Exit fullscreen mode

Do not use default development credentials in production.

Run Docker Compose

docker compose pull
docker compose up -d
Enter fullscreen mode Exit fullscreen mode

Inspect:

docker compose ps
Enter fullscreen mode Exit fullscreen mode

Logs:

docker compose logs -f
Enter fullscreen mode Exit fullscreen mode

Health check

Public:

curl -f   https://storage.example.com/health
Enter fullscreen mode Exit fullscreen mode

Local:

curl -f   http://127.0.0.1:27118/health
Enter fullscreen mode Exit fullscreen mode

Data persistence

The critical rule is simple:

Your object data and metadata must live on persistent storage.

Do not accidentally deploy the service with disposable container-only storage.

Back up configuration and understand what directories are mounted before calling the deployment durable.

Reverse proxy

A reverse proxy should provide:

  • HTTPS termination
  • certificate renewal
  • sane request-size handling
  • appropriate idle/read/write timeouts
  • forwarding of streaming bodies without accidental buffering
  • access logs that do not leak credentials

Large-object storage is a poor place for tiny default proxy limits.

Durability mode

Lioran S3 currently supports two physical write modes.

Strict

BASTION_DURABILITY=strict
Enter fullscreen mode Exit fullscreen mode

Strict mode performs explicit synchronization boundaries before the object is considered durable.

Use this when stronger crash consistency matters more than maximum benchmark throughput.

Balanced

BASTION_DURABILITY=balanced
Enter fullscreen mode Exit fullscreen mode

Balanced mode relies more heavily on operating-system writeback behavior.

It can improve throughput, but changes the durability tradeoff.

Choose deliberately.

Disk headroom

The server includes disk low-watermark protection.

Configure enough free-space headroom to prevent the object store from happily filling the host to 100% and detonating neighboring services.

Storage capacity is not just a quota problem.

It is an operating-system survival problem.

CORS

If browsers connect directly:

BASTION_CORS_ORIGINS=https://app.example.com
Enter fullscreen mode Exit fullscreen mode

Do not use wildcard production origins by habit.

Public URL

Set the externally visible URL:

BASTION_PUBLIC_URL=https://storage.example.com
Enter fullscreen mode Exit fullscreen mode

This is especially relevant when generated links need the public hostname rather than the internal listener.

Signing secret

Configure a persistent secret:

BASTION_SIGNING_SECRET=...
Enter fullscreen mode Exit fullscreen mode

Otherwise signed URL behavior across restarts may not match what your application expects.

Observability

Health:

curl   https://storage.example.com/health
Enter fullscreen mode Exit fullscreen mode

Metrics:

curl   https://storage.example.com/metrics
Enter fullscreen mode Exit fullscreen mode

Or use the CLI:

liorans3 system health
liorans3 system info
liorans3 system metrics
Enter fullscreen mode Exit fullscreen mode

Native build

For local or non-container deployment:

cargo build   --release   --bin bastion-server   --bin bastion
Enter fullscreen mode Exit fullscreen mode

Run:

./target/release/bastion-server
Enter fullscreen mode Exit fullscreen mode

Host requirements include:

  • stable Rust toolchain
  • C++ build tools for RocksDB
  • FFmpeg if media features are used

Deployment checklist

Before exposing the node publicly:

  • change bootstrap credentials
  • enable HTTPS at the reverse proxy
  • restrict CORS
  • configure signing secret
  • verify persistent data mounts
  • validate free-space guardrails
  • choose durability mode
  • test uploads larger than proxy defaults
  • test interrupted transfers
  • test restart behavior
  • monitor disk usage
  • monitor request latency
  • pin pre-alpha image/package versions

A storage deployment is not “Docker Compose returned exit code 0”.

The interesting part starts after that.

Docs: https://docs.liorans3.sbs

Top comments (0)