Deploying Lioran S3 with Docker, Caddy and HTTPS
This article covers the deployment shape recommended by the current Lioran S3 V1 Pre-Alpha repository: the Rust storage process behind a reverse proxy such as Caddy.
Lioran S3 is developed by Lioran Developer Solutions (LDS) under Lioran Group, led by Swaraj Puppalwar.
Pre-alpha is for evaluation and testing. Harden the host and validate failure behavior before storing anything important.
Architecture
Internet
|
| HTTPS :443
v
Caddy
|
| HTTP private network
v
Lioran S3
|
+--> object data directory
|
+--> RocksDB metadata
The storage server does not need to own TLS termination itself.
That lets Caddy handle certificate automation and public HTTPS while Bastion focuses on storage.
Clone
git clone https://github.com/LioranGroupOfficial/LioranBastion-Rust.git
cd LioranBastion-Rust
Production environment
Start from the production example:
cp .env.production.example .env
Review every value.
Important categories include:
BASTION_ENV=production
BASTION_HOST=0.0.0.0
BASTION_PORT=27118
BASTION_DATA_DIR=/data
BASTION_ADMIN_USERNAME=admin
BASTION_ADMIN_PASSWORD=REPLACE_ME
BASTION_DURABILITY=strict
BASTION_PUBLIC_URL=https://storage.example.com
BASTION_CORS_ORIGINS=https://app.example.com
BASTION_SIGNING_SECRET=REPLACE_WITH_LONG_RANDOM_SECRET
Do not use default development credentials in production.
Run Docker Compose
docker compose pull
docker compose up -d
Inspect:
docker compose ps
Logs:
docker compose logs -f
Health check
Public:
curl -f https://storage.example.com/health
Local:
curl -f http://127.0.0.1:27118/health
Data persistence
The critical rule is simple:
Your object data and metadata must live on persistent storage.
Do not accidentally deploy the service with disposable container-only storage.
Back up configuration and understand what directories are mounted before calling the deployment durable.
Reverse proxy
A reverse proxy should provide:
- HTTPS termination
- certificate renewal
- sane request-size handling
- appropriate idle/read/write timeouts
- forwarding of streaming bodies without accidental buffering
- access logs that do not leak credentials
Large-object storage is a poor place for tiny default proxy limits.
Durability mode
Lioran S3 currently supports two physical write modes.
Strict
BASTION_DURABILITY=strict
Strict mode performs explicit synchronization boundaries before the object is considered durable.
Use this when stronger crash consistency matters more than maximum benchmark throughput.
Balanced
BASTION_DURABILITY=balanced
Balanced mode relies more heavily on operating-system writeback behavior.
It can improve throughput, but changes the durability tradeoff.
Choose deliberately.
Disk headroom
The server includes disk low-watermark protection.
Configure enough free-space headroom to prevent the object store from happily filling the host to 100% and detonating neighboring services.
Storage capacity is not just a quota problem.
It is an operating-system survival problem.
CORS
If browsers connect directly:
BASTION_CORS_ORIGINS=https://app.example.com
Do not use wildcard production origins by habit.
Public URL
Set the externally visible URL:
BASTION_PUBLIC_URL=https://storage.example.com
This is especially relevant when generated links need the public hostname rather than the internal listener.
Signing secret
Configure a persistent secret:
BASTION_SIGNING_SECRET=...
Otherwise signed URL behavior across restarts may not match what your application expects.
Observability
Health:
curl https://storage.example.com/health
Metrics:
curl https://storage.example.com/metrics
Or use the CLI:
liorans3 system health
liorans3 system info
liorans3 system metrics
Native build
For local or non-container deployment:
cargo build --release --bin bastion-server --bin bastion
Run:
./target/release/bastion-server
Host requirements include:
- stable Rust toolchain
- C++ build tools for RocksDB
- FFmpeg if media features are used
Deployment checklist
Before exposing the node publicly:
- change bootstrap credentials
- enable HTTPS at the reverse proxy
- restrict CORS
- configure signing secret
- verify persistent data mounts
- validate free-space guardrails
- choose durability mode
- test uploads larger than proxy defaults
- test interrupted transfers
- test restart behavior
- monitor disk usage
- monitor request latency
- pin pre-alpha image/package versions
A storage deployment is not “Docker Compose returned exit code 0”.
The interesting part starts after that.
Top comments (0)