CLI Configuration & Precedence
The CLI manages local configuration profiles and stored credentials securely on disk.
1. On-Disk Configuration Storage
Configuration profiles are stored in an atomically managed JSON file:
- Windows:
%APPDATA%\liorans3\config.json
(e.g.,C:\Users\<username>\AppData\Roaming\liorans3\config.json) - Linux & macOS:
$XDG_CONFIG_HOME/liorans3/config.jsonor~/.config/liorans3/config.json
File Security & Atomic Writes
- On POSIX systems,
config.jsonis created with restricted owner permissions (chmod 0o600). - Writes are executed atomically using unique temporary staging files and
fsyncbefore file replacement, preventing corruption during system crashes.
2. Interactive Setup (liorans3 configure)
Run liorans3 configure to launch the interactive setup wizard:
liorans3 configure
Interactive Walkthrough
=== Configuring Lioran S3 Profile: [default] ===
? Server Endpoint URI: http://127.0.0.1:27118
? Authentication Method: Basic Authentication (Username & Password)
? Username: admin
? Password: [hidden]
? Request Timeout (ms): 30000
Verifying connection to http://127.0.0.1:27118...
Connection verified: Server status 'ok', version '0.1.0'.
Profile 'default' configured and active.
Non-Interactive Setup
In scripts or automated environments, pass flags directly:
# Basic Authentication
liorans3 configure --profile prod --endpoint https://s3.example.com --username admin -P "MySecurePassword123!" --non-interactive
# Access Key Authentication
liorans3 configure --profile ci --endpoint https://s3.example.com --access-key bk_live_0192a7b8 --secret-key sk_live_9f83a21b --non-interactive
3. Environment Variables
The CLI reads the following environment variables:
| Variable | Description |
|---|---|
LIORANS3_URI | Full connection URI (e.g. bastion://admin:pass@127.0.0.1:27118). |
LIORANS3_ENDPOINT | Server endpoint URL (e.g. https://s3.example.com). |
LIORANS3_USERNAME | Username for Basic authentication. |
LIORANS3_PASSWORD | Password for Basic authentication. |
LIORANS3_ACCESS_KEY | Programmatic Access Key ID (bk_...). |
LIORANS3_SECRET_KEY | Programmatic Access Key Secret (sk_...). |
LIORANS3_PROFILE | Named configuration profile to select. |
BASTION_URI | Legacy fallback connection URI. |
4. 4-Level Credential Precedence Engine
When executing any command, liorans3 resolves connection parameters and credentials following a strict 4-level hierarchy:
Level 1: Explicit Command-Line Flags
(-e, -u, -P, -k, -s, -p)
│
▼ (if not specified)
Level 2: Environment Variables
(LIORANS3_URI, LIORANS3_ENDPOINT, LIORANS3_*, BASTION_URI)
│
▼ (if not specified)
Level 3: Explicit Profile Selection
(--profile <name> or LIORANS3_PROFILE)
│
▼ (if not specified)
Level 4: Default Profile from Local Configuration File
:::caution Ambiguity Detection
If you pass both username/password and accessKey/secretKey simultaneously via command-line flags or environment variables, the CLI halts immediately with an InvalidInputError to prevent ambiguous authentication attempts.
:::