Sign inSign up

forkzero/s3proxy

By forkzero

•Updated 3 months ago

Front AWS S3 with a web server you control

Image
0

10K+

forkzero/s3proxy repository overview

⁠s3proxy

Front a private AWS S3 bucket with a web server you control. s3proxy streams objects straight from S3 to the client — no local buffering — using s3proxy⁠ v4 and Hono⁠.

⁠Quick start

$ docker run --rm -p 8080:8080 -e BUCKET=my-bucket forkzero/s3proxy

Then request any object by its key:

$ curl http://localhost:8080/index.html

In production, credentials come from the standard AWS SDK credential chain (IAM instance/task role, AWS_* env vars, etc.) — nothing to configure beyond the bucket. Missing or forbidden keys return an honest 404 / 403 (no v3-style empty 200).

⁠Configuration

VariableDefaultDescription
BUCKET(required)S3 bucket to serve.
PORT8080Port the server listens on.
AWS_REGION–AWS region (per the AWS SDK).
NODE_ENVproductiondevelopment enables the dev credentials file.

⁠Endpoints

RouteDescription
GET | HEAD /*Stream the object at that key from S3 (supports Range).
GET /healthLiveness + S3 connectivity (drives the container healthcheck).
GET /versionReports the s3proxy and Node versions.
GET /Redirects to /index.html.

⁠Local development against a private bucket

Mint a short-lived session token and bind-mount it (only read when NODE_ENV is not production):

$ aws sts get-session-token --duration 900 > credentials.json
$ docker run --rm -p 8080:8080 \
    -e BUCKET=my-bucket -e NODE_ENV=development \
    -v "$PWD/credentials.json:/src/credentials.json:ro" \
    forkzero/s3proxy

⁠About the image

Multi-stage Alpine build running as a non-root user with tini as PID 1 and a built-in healthcheck. The base image is pinned by digest and kept current by Dependabot. Conformance-tested against @forkzero/s3-website-test-kit⁠.

⁠License

Apache-2.0 — https://github.com/forkzero/s3proxy-docker/blob/main/LICENSE⁠

Tag summary

Content type

Image

Digest

sha256:e2a97b2e9…

Size

57.2 MB

Last updated

3 months ago

docker pull forkzero/s3proxy