Lioran S3 V1 Pre-Alpha
On October 1, 2026, Lioran Developer Solutions (LDS) launched Lioran S3 V1 Pre-Alpha, also known internally as Lioran Bastion.
I’m Swaraj Puppalwar, Founder & CTO at Lioran Group and Lioran Developer Solutions. Lioran S3 is part of our broader effort to build developer infrastructure from India, with storage, databases, authentication, and related infrastructure treated as first-class engineering products rather than thin wrappers around external platforms.
Lioran S3 V1 Pre-Alpha is intentionally a foundational release. It is not positioned as a finished AWS S3 replacement and it is not yet a distributed object store. The current release focuses on proving the single-node storage engine, API surface, durability model, client tooling, security primitives, and media pipeline.
Pre-alpha warning: APIs, storage formats, protocol details, SDK behavior, and operational assumptions may change before stable releases. Do not use this release for mission-critical workloads without rigorous validation.
What Lioran S3 is
Lioran S3 is a self-hosted object storage server written primarily in Rust.
The current architecture provides:
- bucket and object semantics
- streaming
PUT,GET,HEAD,DELETE, and listing operations - bounded-memory object transfers
- RocksDB-backed metadata
- resumable multipart uploads
- byte-range downloads
- expiring HMAC-SHA256 signed URLs
- quota enforcement
- disk-space guardrails
- user roles and access keys
- Prometheus metrics
- health and system diagnostics
- experimental image optimization
- experimental video transcoding and HLS generation
- an official TypeScript driver
- an official command-line interface
The storage server currently exposes a native REST API and a Bastion connection URI format.
It does not currently expose a drop-in AWS S3 API compatibility layer. That compatibility layer is planned separately.
Why V1 is single-node
Distributed storage is attractive because it gives you an impressive architecture diagram very early.
It also gives you replication, membership, failure detection, quorum behavior, consensus, partition handling, repair, and a fresh collection of ways to corrupt data.
For Lioran S3, V1 deliberately focuses on the deterministic behavior of one storage node first.
The engineering priorities are:
- object writes must be crash-aware
- large objects must never require loading the full payload into memory
- object bytes and metadata must remain separate
- partial uploads must never appear as committed objects
- metadata must not intentionally reference missing committed data
- durability must be explicit
- performance work must be measurement-driven
Distributed replication will make more sense after these invariants are boringly reliable.
Workspace structure
The Rust workspace separates the major responsibilities of the system:
Lioran Bastion Workspace
├── crates/bastion-server
├── crates/bastion-object
├── crates/bastion-metadata
├── crates/bastion-protocol
├── crates/bastion-media
├── crates/bastion-common
├── crates/bastion-cli
└── sdk/
The key architectural split is between the metadata plane and the object data plane.
RocksDB stores metadata such as bucket configuration, object records, multipart state, indexes, and media state.
The object payload itself lives on the filesystem and is streamed directly through bounded buffers.
TypeScript developer experience
The official package for the current pre-alpha driver is:
npm install @liorans3/driver@prealpha
A minimal connection looks like this:
import { BastionClient } from "@liorans3/driver";
const client = new BastionClient(
process.env.LIORAN_S3_URI ??
"bastion://admin:YOUR_PASSWORD@127.0.0.1:27118"
);
const health = await client.health();
console.log(health);
Create a bucket:
await client.buckets.create("assets", {
quotaBytes: 20 * 1024 * 1024 * 1024,
});
Upload an object:
const bucket = client.bucket("assets");
await bucket.put(
"hello.txt",
"Hello from Lioran S3",
{ contentType: "text/plain" }
);
Read it back:
const object = await bucket.get("hello.txt");
console.log(await object.text());
CLI
The official CLI is installed separately:
npm install -g @liorans3/cli@prealpha
Then:
liorans3 --help
liorans3 configure
liorans3 ping
liorans3 whoami
liorans3 bucket ls
The CLI is implemented on top of the official driver instead of duplicating networking logic.
That means authentication behavior, multipart orchestration, protocol handling, and error behavior have one primary implementation path.
Security model
The current release supports:
- Basic authentication
- Argon2id password hashing
-
admin,readwrite, andreadonlyroles - mandatory bootstrap password rotation
- programmatic access keys
- secret redaction in errors and logs
- configurable production CORS policy
- signed URLs with explicit expirations
- production checks that reject unsafe default credentials
Lioran S3 itself does not terminate TLS in the storage process. For public deployment, put it behind a reverse proxy such as Caddy or Nginx.
What is experimental
The media subsystem is useful, but it remains experimental in V1 Pre-Alpha.
It can orchestrate FFmpeg to provide:
- video uploads
- transcoding
- HLS playlists
- poster extraction
- playback URLs
- public or unlisted share links
- image resize and format conversion
It requires ffmpeg and ffprobe to be available on the host.
What comes next
The next planned Lioran S3 version is scheduled for November 17, 2026.
The broader roadmap includes:
- AWS S3 compatibility
- lifecycle rules
- object event webhooks
- finer-grained IAM-style policies
- improved operational tooling
- future clustering and replication
The current release is about establishing the storage core first.
Links
- Product: https://liorans3.sbs
- Documentation: https://docs.liorans3.sbs
- GitHub: https://github.com/LioranGroupOfficial/LioranBastion-Rust
- Lioran Group: https://lioran.group
Lioran S3 is being developed by Lioran Developer Solutions, under Lioran Group, with engineering led by Swaraj Puppalwar.
This article begins a technical series documenting the system from installation and TypeScript usage to storage internals, security, media processing, deployment, and durability.
Top comments (0)