-
Notifications
You must be signed in to change notification settings - Fork 315
TLS
The gateway can use TLS connections between S3 client and server if the TLS certs are provided. The cert and key must be provided to the gateway to enable TLS connections. If the server is only hosting traffic on a local network, then self signed credentials can be generated. For hosting a public facing service, it is recommended to generate official credentials using Let's Encrypt or some other CA service.
To enable TLS, see Global-Options for specifying TLS cert and key files.
To generate self signed certificates, follow the direction for mkcert:
$ mkcert -install
$ mkcert localhost 127.0.0.1 ::1
Add any local IPs and hostnames to the list as needed, or to generate a wildcard cert for the local domain:
$ mkcert "*.local.test"
Or you can use openssl to generate the certs, for example:
# interactive and 1 year expiration
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 365 -nodes
# non-interactive and 10 years expiration
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 3650 -nodes -subj "/C=XX/ST=StateName/L=CityName/O=CompanyName/OU=CompanySectionName/CN=CommonNameOrHostname"
--cert and --key cover the S3 endpoint only. The admin server and the WebUI have their own certificate options — --admin-cert/--admin-cert-key and --webui-cert/--webui-key/--webui-no-tls — listed with their environment variables and defaults in Global Options.
The standalone IAM service has two listeners with independent TLS configuration. The public IAM API uses the same global --cert/--key as the S3 endpoint, applied to the iam command.
The private endpoint, which only the S3 gateway talks to, requires mutual TLS whenever it listens on a TCP address: --private-cert, --private-cert-key and --private-client-ca on the IAM service, --iam-standalone-client-cert, --iam-standalone-client-cert-key and --iam-standalone-server-ca on the gateway. Each side is all-or-nothing. The gateway verifies the service's certificate with standard Go hostname verification and no override, so a certificate for an IP endpoint needs a matching IP SAN. See Setup & Gateway Integration for the full option reference.
Warning
A unix socket private endpoint needs no certificates — the socket's file permissions are the isolation. Do not set both: a unix socket configured together with --private-cert is TLS-wrapped, and the gateway's plain-HTTP unix client will then refuse to connect.
genmtlscerts.sh in the repository generates a CA and a matching server/client pair for the private endpoint. It is test material only; production deployments must issue these from their own CA.
Home · Quickstart · Configuration · Operations · Testing · Developer Guide · GitHub · Discussions · Issues
Apache 2.0 · @versitysoftware · LinkedIn · X · Facebook · Instagram
- Home
- Key Features
- User Guide
- Getting Started
- Networking and Deployment
- Access Control / IAM
- Features
- Backends
- Compatibility
- Operations
- Metrics
- Admin APIs
- Logging
- S3 RDMA
- Developer Guide
- Articles