Skip to main content

TLS & HTTPS

In production, Lioran S3 requires HTTPS for all public ingress to ensure credentials, tokens, and binary object streams are encrypted in transit.


1. Automatic Let's Encrypt / ZeroSSL via Caddy​

When running the standard Docker Compose deployment, Caddy automatically acquires and renews TLS certificates via the ACME protocol (HTTP-01 and TLS-ALPN-01 challenges).

Setup Steps​

  1. DNS Record: Point your domain or subdomain (e.g. s3.example.com) to the public IPv4/IPv6 address of your server using standard A and AAAA DNS records.
  2. Ports: Ensure ports 80 (HTTP) and 443 (HTTPS) are open and reachable from the public internet.
  3. Environment:
    .env
    BASTION_DOMAIN=s3.example.com
    BASTION_PUBLIC_URL=https://s3.example.com
    CADDY_ACME_EMAIL=admin@example.com
  4. Launch:
    docker compose up -d

Caddy will automatically contact the ACME CA, obtain the certificate, and configure automatic background renewals.


2. HTTP to HTTPS Redirection​

Caddy automatically issues HTTP 308 Permanent Redirect responses for any incoming plain HTTP requests on port 80, redirecting all traffic to HTTPS on port 443.


3. Strict Transport Security (HSTS)​

The production configuration includes standard HSTS headers:

Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"

This ensures web browsers never attempt unencrypted plaintext connections after their initial visit.