Skip to main content

Environment Variables

Lioran S3 is configured exclusively through environment variables or a root .env file.


Server Configuration Reference​

VariableRequiredDefaultAllowed ValuesPurpose & Description
BASTION_ENVNodevelopmentdevelopment, productionActive runtime profile. In production, strict validation enforces strong passwords and disallows insecure defaults.
BASTION_HOSTNo127.0.0.1IP Address / HostnameBind host for TCP network listener (use 0.0.0.0 inside containers).
BASTION_PORTNo27118Port number (1..65535)TCP listener port.
BASTION_DATA_DIRNo./dataFilesystem PathBase storage directory for payload volumes (/objects) and metadata (/metadata).
BASTION_ADMIN_USERNAMENoadminStringBootstrap administrator username.
BASTION_ADMIN_PASSWORDYes (in prod)admin (dev only)String (>= 8 chars)Bootstrap administrator password. Mandatory in production; rejected if set to admin, password, or 123456.
BASTION_PUBLIC_URLNo(derived from listener)URL StringCanonical external HTTPS base URL (e.g. https://s3.example.com). Used for presigned URLs and media links.
BASTION_CORS_ORIGINSNo(permissive in dev)Comma-separated URLsAllowed CORS origins for web browser clients (e.g. https://app.example.com).
BASTION_SIGNING_SECRETNo(auto-generated)64 Hex chars (32 bytes)Cryptographic HMAC-SHA256 secret for presigned URLs. Set explicitly to maintain URL validity across restarts.
BASTION_MAX_SIGNED_URL_TTL_SECSNo604800 (7 days)Integer secondsMaximum allowable expiration lifetime for presigned URLs.
BASTION_DURABILITYNostrictstrict, balancedPhysical write durability guarantee. strict calls fsync per write; balanced relies on OS writeback caching.
BASTION_STREAM_CHUNK_KIBNo25664..4096Streaming I/O buffer chunk size in KiB.
BASTION_MIN_FREE_SPACE_BYTESNo536870912 (512 MiB)Integer bytesMinimum free host storage before mutating writes are rejected.
BASTION_MIN_FREE_SPACE_PERCENTNo(disabled)Float (0.0..100.0)Optional minimum free host storage percentage threshold.

Caddy & Deployment Variables​

These variables are used by the Docker Compose stack and Caddy reverse proxy:

VariableRequiredDefaultPurpose & Description
BASTION_DOMAINNolocalhostCustom domain name bound by Caddy for automatic Let's Encrypt TLS certificate provisioning.
CADDY_ACME_EMAILNo(empty)Optional contact email address for Let's Encrypt expiry and certificate notifications.

Production Validation Rules​

When BASTION_ENV=production is set, the server executes strict pre-flight validation on startup:

  1. Password Hardening:
    • BASTION_ADMIN_PASSWORD must be explicitly provided.
    • Must be at least 8 characters long.
    • Common default passwords (admin, password, 123456, root, bastion) are rejected with an immediate exit.
  2. CORS Enforcement:
    • If BASTION_CORS_ORIGINS is empty, cross-origin browser requests are rejected by default instead of falling back to permissive mode.
  3. Chunk Sizing:
    • BASTION_STREAM_CHUNK_KIB must be within 64 to 4096 KiB.