Environment Variables
Lioran S3 is configured exclusively through environment variables or a root .env file.
Server Configuration Reference
| Variable | Required | Default | Allowed Values | Purpose & Description |
|---|---|---|---|---|
BASTION_ENV | No | development | development, production | Active runtime profile. In production, strict validation enforces strong passwords and disallows insecure defaults. |
BASTION_HOST | No | 127.0.0.1 | IP Address / Hostname | Bind host for TCP network listener (use 0.0.0.0 inside containers). |
BASTION_PORT | No | 27118 | Port number (1..65535) | TCP listener port. |
BASTION_DATA_DIR | No | ./data | Filesystem Path | Base storage directory for payload volumes (/objects) and metadata (/metadata). |
BASTION_ADMIN_USERNAME | No | admin | String | Bootstrap administrator username. |
BASTION_ADMIN_PASSWORD | Yes (in prod) | admin (dev only) | String (>= 8 chars) | Bootstrap administrator password. Mandatory in production; rejected if set to admin, password, or 123456. |
BASTION_PUBLIC_URL | No | (derived from listener) | URL String | Canonical external HTTPS base URL (e.g. https://s3.example.com). Used for presigned URLs and media links. |
BASTION_CORS_ORIGINS | No | (permissive in dev) | Comma-separated URLs | Allowed CORS origins for web browser clients (e.g. https://app.example.com). |
BASTION_SIGNING_SECRET | No | (auto-generated) | 64 Hex chars (32 bytes) | Cryptographic HMAC-SHA256 secret for presigned URLs. Set explicitly to maintain URL validity across restarts. |
BASTION_MAX_SIGNED_URL_TTL_SECS | No | 604800 (7 days) | Integer seconds | Maximum allowable expiration lifetime for presigned URLs. |
BASTION_DURABILITY | No | strict | strict, balanced | Physical write durability guarantee. strict calls fsync per write; balanced relies on OS writeback caching. |
BASTION_STREAM_CHUNK_KIB | No | 256 | 64..4096 | Streaming I/O buffer chunk size in KiB. |
BASTION_MIN_FREE_SPACE_BYTES | No | 536870912 (512 MiB) | Integer bytes | Minimum free host storage before mutating writes are rejected. |
BASTION_MIN_FREE_SPACE_PERCENT | No | (disabled) | Float (0.0..100.0) | Optional minimum free host storage percentage threshold. |
Caddy & Deployment Variables
These variables are used by the Docker Compose stack and Caddy reverse proxy:
| Variable | Required | Default | Purpose & Description |
|---|---|---|---|
BASTION_DOMAIN | No | localhost | Custom domain name bound by Caddy for automatic Let's Encrypt TLS certificate provisioning. |
CADDY_ACME_EMAIL | No | (empty) | Optional contact email address for Let's Encrypt expiry and certificate notifications. |
Production Validation Rules
When BASTION_ENV=production is set, the server executes strict pre-flight validation on startup:
- Password Hardening:
BASTION_ADMIN_PASSWORDmust be explicitly provided.- Must be at least 8 characters long.
- Common default passwords (
admin,password,123456,root,bastion) are rejected with an immediate exit.
- CORS Enforcement:
- If
BASTION_CORS_ORIGINSis empty, cross-origin browser requests are rejected by default instead of falling back to permissive mode.
- If
- Chunk Sizing:
BASTION_STREAM_CHUNK_KIBmust be within64to4096KiB.