Skip to main content

S3 Storage (RustFS)

DockNimbus deploys RustFS (rustfs/rustfs:1.0.0) as a Docker Swarm service for S3-compatible object storage. Each instance serves two domains through the swarm's EasyHAProxy:

DomainPortServes
<name>.<swarm>.<local_domain>9000S3 API
console-<name>.<swarm>.<local_domain>9001Web console (under /rustfs/console/)

Prerequisites​

  • An active Docker Swarm with at least one node
  • An NFS volume for data persistence

RustFS runs as a non-root user (uid 10001). When the instance is created, Nimbus makes that user the owner of the volume's folder on the volume's node, so the folder should be dedicated to the instance.

Deploy an S3 instance​

# Create a volume for the data
nimbus volume create --name s3-data --node NODE_ID --folder /srv/nimbus/s3

# Deploy RustFS on the swarm
nimbus s3 create --name my-store --swarm SWARM_ID --volume VOL_ID

If you omit --password, a root password is auto-generated and displayed in the output. A password you choose must be at least 8 characters.

Optional flags​

FlagDescription
--passwordRoot secret key, at least 8 characters
--oidc-certCertificate ID to enable console SSO through Nimbus via that domain

Authentication​

To enable SSO on the console, pass the ID of a TLS certificate registered with nimbus certificate create. Nimbus registers an OAuth2 client for the instance and configures RustFS to use that certificate's domain as the issuer. The console then offers to sign in through Nimbus.

# First register a certificate for your public domain
nimbus certificate create \
--domain nimbus.example.com \
--cert /etc/letsencrypt/live/nimbus.example.com/fullchain.pem \
--key /etc/letsencrypt/live/nimbus.example.com/privkey.pem

# Deploy RustFS with console SSO on that domain
nimbus s3 create --name my-store --swarm SWARM_ID --volume VOL_ID \
--oidc-cert <CERT_ID>

The OIDC issuer URL is resolved dynamically: when a request arrives at nimbus.example.com, Nimbus automatically uses that domain as the issuer — no config file changes or restarts required. See TLS Certificates for details. RustFS must trust the certificate, so use one from a public CA (e.g. Let's Encrypt).

Console access is granted with the instance's IAM scopes. The OAuth2 client's ID is the S3 instance ID, and the token sent to the console carries the RustFS policy for the permission the user holds:

IAM scopeRustFS policyConsole access
nimbus:s3:<id>:adminconsoleAdminFull admin
nimbus:s3:<id>:readwritereadwriteRead and write data
nimbus:s3:<id>:readreadonlyRead-only

The wildcards nimbus:s3:*:admin, nimbus:s3:*:readwrite and nimbus:s3:*:read cover every instance. Admin users hold nimbus:s3:*:admin through the built-in admin group, and the admin-read group holds nimbus:s3:*:read. A user without any of these scopes cannot sign in to the console. Assign scopes in IAM or with nimbus iam; see IAM.

Deleting the instance removes its OAuth2 client and every nimbus:s3:<id>:* scope assigned to users and groups.

See OIDC / OAuth2 for the full provider documentation.

Static credentials​

The S3 API is also accessible with the root credentials — useful for API clients, CLIs, or SDKs:

  • Access key: admin
  • Secret key: the password given at creation time (or the auto-generated value printed in the nimbus s3 create output)
  • Region: us-east-1
aws --endpoint-url http://<S3_DOMAIN> s3 ls

The API supports path-style addressing (http://<S3_DOMAIN>/<bucket>/<key>); configure SDKs with force_path_style = true.

List and delete​

nimbus s3 list
nimbus s3 delete S3_ID

nimbus s3 list shows both the S3 domain and the console domain of each instance.