Skip to main content

Security & Hardening

This guide covers security best practices for hardening Lioran S3 deployments.


1. Credential Bootstrap & Rotation​

  • Never use default passwords: In BASTION_ENV=production, Lioran S3 will refuse to boot if BASTION_ADMIN_PASSWORD is empty, fewer than 8 characters, or matches default values (admin, password, 123456, root, bastion).
  • Rotate Bootstrap Admin Password: Change the initial administrator password immediately after first launch using liorans3 user passwd or client.users.changePassword().
  • Use Programmatic Access Keys: Instead of embedding admin or user passwords in application configurations, issue dedicated Access Keys with the readwrite or readonly role.

2. Cryptographic Signing Secret​

Signed URLs require a high-entropy secret configured via BASTION_SIGNING_SECRET:

# Generate a 64-character hex secret (32 random bytes)
openssl rand -hex 32

Set this variable consistently across container restarts. If omitted, Bastion generates an ephemeral secret on startup, which will invalidate previously issued presigned URLs whenever the container restarts.


3. CORS Hardening​

In development, Lioran S3 allows permissive cross-origin requests. In production, explicit origins must be defined in BASTION_CORS_ORIGINS:

# Production: Specify exact origins separated by commas (no trailing slashes)
BASTION_CORS_ORIGINS=https://s3.example.com,https://app.example.com,https://admin.example.com

Do not use wildcards (*) in production unless the bucket serves solely public, read-only assets.


4. Reverse Proxy Hardening​

  • Internal Port Binding: Never map container port 27118 to 0.0.0.0:27118 on the public host. Expose port 27118 exclusively to the internal Docker bridge network (bastion-net).
  • Protect Metrics: Block public access to /metrics and /api/v1/metrics. Only allow internal scraping from monitoring agents (e.g. Prometheus).
  • HSTS Headers: Enforce HTTP Strict Transport Security (Strict-Transport-Security: max-age=31536000; includeSubDomains; preload).

5. Defense-in-Depth Protections​

  • Automatic Header Stripping: Reverse proxy strips the Server header to prevent leaking software versions to attackers.
  • Argon2id Hashing: Passwords stored in RocksDB use modern Argon2id password hashing with random salts.
  • Path Traversal Shield: Object keys are sanitized; path traversal sequences (../, ..\\) are stripped to prevent filesystem breakout.
  • Credential Masking: Server logs, CLI outputs, and SDK error serialization automatically redact passwords and secret keys.