TLS & HTTPS
In production, Lioran S3 requires HTTPS for all public ingress to ensure credentials, tokens, and binary object streams are encrypted in transit.
1. Automatic Let's Encrypt / ZeroSSL via Caddy
When running the standard Docker Compose deployment, Caddy automatically acquires and renews TLS certificates via the ACME protocol (HTTP-01 and TLS-ALPN-01 challenges).
Setup Steps
- DNS Record: Point your domain or subdomain (e.g.
s3.example.com) to the public IPv4/IPv6 address of your server using standardAandAAAADNS records. - Ports: Ensure ports
80(HTTP) and443(HTTPS) are open and reachable from the public internet. - Environment:
.envBASTION_DOMAIN=s3.example.comBASTION_PUBLIC_URL=https://s3.example.comCADDY_ACME_EMAIL=admin@example.com
- Launch:
docker compose up -d
Caddy will automatically contact the ACME CA, obtain the certificate, and configure automatic background renewals.
2. HTTP to HTTPS Redirection
Caddy automatically issues HTTP 308 Permanent Redirect responses for any incoming plain HTTP requests on port 80, redirecting all traffic to HTTPS on port 443.
3. Strict Transport Security (HSTS)
The production configuration includes standard HSTS headers:
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
This ensures web browsers never attempt unencrypted plaintext connections after their initial visit.