Skip to main content

Production Guide

This guide covers deploying, operating, hardening, and maintaining Lioran S3 in production environments.


Production Readiness Checklist​

Before exposing Lioran S3 to production workloads, verify each of the following requirements:

  • Runtime Profile: Set BASTION_ENV=production.
  • Administrator Credentials: Set a strong, non-default BASTION_ADMIN_PASSWORD (minimum 8 characters; default passwords like admin or password will cause startup failure).
  • TLS Termination: Place Lioran S3 behind a reverse proxy (such as Caddy or Nginx) providing valid TLS certificates.
  • Signing Secret: Configure a high-entropy 64-character hex BASTION_SIGNING_SECRET so presigned URLs survive server restarts.
  • Persistent Volumes: Mount dedicated, persistent host storage volumes for /data (including RocksDB metadata and object payload blobs).
  • Durability Mode: Verify BASTION_DURABILITY=strict for crash consistency unless running on battery-backed hardware caches.
  • CORS Origins: Restrict BASTION_CORS_ORIGINS to trusted domains (avoid wildcards in production).
  • Metrics Security: Ensure /metrics and /api/v1/metrics are restricted to internal/private networks via reverse proxy rules.

Production Architecture​

Public Internet / Browser Clients / Microservices
│
▼ (Port 80 / 443 HTTPS)
┌─────────────────────┐
│ Caddy Reverse Proxy │ (Automatic Let's Encrypt TLS)
└──────────┬──────────┘
│ HTTP (Port 27118 Internal Docker Network)
▼
┌─────────────────────┐
│ bastion-server │ (Single-Node Rust Engine)
└──────────┬──────────┘
│
┌───────────────┴───────────────┐
▼ ▼
┌────────────────┐ ┌────────────────┐
│ RocksDB Volume │ │ Payload Volume │
│ /data/metadata │ │ /data/objects │
└────────────────┘ └────────────────┘

Production Sections​

  1. Docker Deployment: Docker Compose stack and official containers.
  2. Environment Configuration: Full environment variable matrix and validation.
  3. Reverse Proxy (Caddy): High-throughput streaming proxy configuration.
  4. TLS & HTTPS: Automatic ACME certificate provisioning and renewal.
  5. Storage Architecture: Filesystem structure, metadata separation, and volume sizing.
  6. Durability & Crash Safety: strict vs balanced modes and atomic commits.
  7. Security Hardening: Access control, credential rotation, and attack mitigation.
  8. Performance & Benchmarks: Benchmark numbers (300+ MB/s) and tuning guidelines.
  9. Backup & Disaster Recovery: Snapshotting RocksDB and syncing data volumes.
  10. Troubleshooting: Diagnosing 401s, 403s, 507s, and container networking.