Production Guide
This guide covers deploying, operating, hardening, and maintaining Lioran S3 in production environments.
Production Readiness Checklist
Before exposing Lioran S3 to production workloads, verify each of the following requirements:
- Runtime Profile: Set
BASTION_ENV=production. - Administrator Credentials: Set a strong, non-default
BASTION_ADMIN_PASSWORD(minimum 8 characters; default passwords likeadminorpasswordwill cause startup failure). - TLS Termination: Place Lioran S3 behind a reverse proxy (such as Caddy or Nginx) providing valid TLS certificates.
- Signing Secret: Configure a high-entropy 64-character hex
BASTION_SIGNING_SECRETso presigned URLs survive server restarts. - Persistent Volumes: Mount dedicated, persistent host storage volumes for
/data(including RocksDB metadata and object payload blobs). - Durability Mode: Verify
BASTION_DURABILITY=strictfor crash consistency unless running on battery-backed hardware caches. - CORS Origins: Restrict
BASTION_CORS_ORIGINSto trusted domains (avoid wildcards in production). - Metrics Security: Ensure
/metricsand/api/v1/metricsare restricted to internal/private networks via reverse proxy rules.
Production Architecture
Public Internet / Browser Clients / Microservices
│
▼ (Port 80 / 443 HTTPS)
┌─────────────────────┐
│ Caddy Reverse Proxy │ (Automatic Let's Encrypt TLS)
└──────────┬──────────┘
│ HTTP (Port 27118 Internal Docker Network)
▼
┌─────────────────────┐
│ bastion-server │ (Single-Node Rust Engine)
└──────────┬──────────┘
│
┌───────────────┴───────────────┐
▼ ▼
┌────────────────┐ ┌────────────────┐
│ RocksDB Volume │ │ Payload Volume │
│ /data/metadata │ │ /data/objects │
└────────────────┘ └────────────────┘
Production Sections
- Docker Deployment: Docker Compose stack and official containers.
- Environment Configuration: Full environment variable matrix and validation.
- Reverse Proxy (Caddy): High-throughput streaming proxy configuration.
- TLS & HTTPS: Automatic ACME certificate provisioning and renewal.
- Storage Architecture: Filesystem structure, metadata separation, and volume sizing.
- Durability & Crash Safety:
strictvsbalancedmodes and atomic commits. - Security Hardening: Access control, credential rotation, and attack mitigation.
- Performance & Benchmarks: Benchmark numbers (300+ MB/s) and tuning guidelines.
- Backup & Disaster Recovery: Snapshotting RocksDB and syncing data volumes.
- Troubleshooting: Diagnosing 401s, 403s, 507s, and container networking.