On-site S3-compatible ZARR data server for microscopy imaging.
2.0K
On-site S3-compatible HTTP server for streaming OME-ZARRā microscopy data to the Find Nuclei Viewerā .
Deploy on your lab network, NAS, or HPC cluster. The browser fetches ZARR chunks directly from this server ā your data never leaves your infrastructure.
š¬ Viewer: find-nuclei.github.ioā
mkdir -p ~/.findnuclei
docker run -d \
-p 3333:3333 \
-p 3334:3334 \
-v /path/to/your/zarr/data:/data/storage \
-v ~/.findnuclei:/data/config \
-e FN_ADMIN_PASSWORD=changeme \
fn0000/fn-data-server
Two mount points:
/data/storagefor your ZARR data (read-only is fine),/data/configfor the token database and signing key. Tokens persist across container restarts.
Open the viewer with a direct URL to your data:
https://find-nuclei.github.io?url=http://localhost:3333/my-bucket/sample.zarr
If auth is enabled, add your token:
https://find-nuclei.github.io?url=http://localhost:3333/my-bucket/sample.zarr&token=YOUR_JWT
āāāāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāāāāāā
ā Find Nuclei ā ā User's Browser ā ā Data Server ā
ā Platform āāāāāāŗā (Viewer) āāāāāāŗā (Your Network) ā
ā metadata only ā ā ā ā ZARR chunks ā
āāāāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāāāāāā
The browser is the bridge. The data server only needs to be reachable from the user's browser (corporate network, VPN). The cloud platform never connects to it directly.
| Port | Process | Purpose |
|---|---|---|
| 3333 | Data Server | Pure S3-compatible HTTP |
| 3334 | Admin Console | Token management UI, health check, bucket browser |
All data endpoints require a JWT Bearer token. Create tokens via the admin console and scope them to specific buckets.
docker run -d \
-e FN_AUTH_ENABLED=true \
-e FN_ADMIN_PASSWORD=mypass \
...
fn0000/fn-data-server
No authentication on data endpoints. Use only on trusted networks.
docker run -d \
-e FN_AUTH_ENABLED=false \
...
fn0000/fn-data-server
Each JWT token is scoped to a bucket prefix:
my-project ā access only objects under /my-project/* ā access all buckets (wildcard)Tokens also support:
*.lab.internal)192.168.1.*)| Variable | Default | Description |
|---|---|---|
FN_AUTH_ENABLED | true | true = secure mode, false = open mode |
FN_ADMIN_PASSWORD | admin | Admin console password |
FN_DATA_PORT | 3333 | Data server port |
FN_ADMIN_PORT | 3334 | Admin console port |
FN_DATA_WORKERS | 4 | Worker processes (increase for more concurrent users) |
FN_CORS_ORIGINS | * | Comma-separated allowed CORS origins |
Place your OME-ZARR datasets in the storage directory. Each top-level directory becomes a bucket:
/your/zarr/data/
āāā project-alpha/
ā āāā sample1.zarr/
ā āāā sample2.zarr/
āāā project-beta/
āāā experiment.zarr/
The admin console's bucket browser shows all top-level directories. Click a bucket to pre-fill the prefix when creating a token.
-e FN_DATA_WORKERS=8| Method | Endpoint | Description |
|---|---|---|
GET | / | List buckets (S3 XML) |
GET | /{bucket} | List objects in bucket |
GET | /{bucket}/{key} | Download object (supports Range headers) |
HEAD | /{bucket}/{key} | Object metadata |
PUT | /{bucket} | Create bucket |
PUT | /{bucket}/{key} | Upload object |
DELETE | /{bucket}/{key} | Delete object |
| Method | Endpoint | Description |
|---|---|---|
GET | /health | Health check + server info |
GET | /admin | Token management UI |
GET | /api/buckets | List buckets with item count |
POST | /admin/api/tokens | Create new token |
POST | /admin/api/tokens/{id}/revoke | Revoke a token |
http://your-server:3333/project-alpha/sample1.zarrMIT
Content type
Image
Digest
sha256:8aac7911bā¦
Size
24.4 MB
Last updated
6 months ago
docker pull fn0000/fn-data-server