Security & Hardening
This guide covers security best practices for hardening Lioran S3 deployments.
1. Credential Bootstrap & Rotation
- Never use default passwords: In
BASTION_ENV=production, Lioran S3 will refuse to boot ifBASTION_ADMIN_PASSWORDis empty, fewer than 8 characters, or matches default values (admin,password,123456,root,bastion). - Rotate Bootstrap Admin Password: Change the initial administrator password immediately after first launch using
liorans3 user passwdorclient.users.changePassword(). - Use Programmatic Access Keys: Instead of embedding admin or user passwords in application configurations, issue dedicated Access Keys with the
readwriteorreadonlyrole.
2. Cryptographic Signing Secret
Signed URLs require a high-entropy secret configured via BASTION_SIGNING_SECRET:
# Generate a 64-character hex secret (32 random bytes)
openssl rand -hex 32
Set this variable consistently across container restarts. If omitted, Bastion generates an ephemeral secret on startup, which will invalidate previously issued presigned URLs whenever the container restarts.
3. CORS Hardening
In development, Lioran S3 allows permissive cross-origin requests. In production, explicit origins must be defined in BASTION_CORS_ORIGINS:
# Production: Specify exact origins separated by commas (no trailing slashes)
BASTION_CORS_ORIGINS=https://s3.example.com,https://app.example.com,https://admin.example.com
Do not use wildcards (*) in production unless the bucket serves solely public, read-only assets.
4. Reverse Proxy Hardening
- Internal Port Binding: Never map container port
27118to0.0.0.0:27118on the public host. Expose port27118exclusively to the internal Docker bridge network (bastion-net). - Protect Metrics: Block public access to
/metricsand/api/v1/metrics. Only allow internal scraping from monitoring agents (e.g. Prometheus). - HSTS Headers: Enforce HTTP Strict Transport Security (
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload).
5. Defense-in-Depth Protections
- Automatic Header Stripping: Reverse proxy strips the
Serverheader to prevent leaking software versions to attackers. - Argon2id Hashing: Passwords stored in RocksDB use modern Argon2id password hashing with random salts.
- Path Traversal Shield: Object keys are sanitized; path traversal sequences (
../,..\\) are stripped to prevent filesystem breakout. - Credential Masking: Server logs, CLI outputs, and SDK error serialization automatically redact passwords and secret keys.