Sign inSign up

kianfar/storage-io

By kianfar

•Updated 9 days ago

One console for all your S3-compatible storage (MinIO, SeaweedFS, AWS S3, Ceph, Garage, R2, Wasabi).

Image
0

212

kianfar/storage-io repository overview

⁠storage-io

One console for all your S3-compatible storage.

Self-hosted web console for MinIO, SeaweedFS, AWS S3, Ceph RGW, Garage, Cloudflare R2, Wasabi and any other S3 endpoint. Connect as many servers as you like, then manage buckets, objects, quotas, S3 users, policies, access keys and bulk jobs from a single place.

CI Release Docker Hub License: MIT

Overview dashboard

Object browser with the inspector openOverview in dark mode
Buckets across all serversServer detail with health and capabilities
Visual IAM policy editorBulk job wizard
One-time access key secret with client snippetsCommand palette

Overview on a phone Object browser on a phone Buckets on a phone

More in docs/screenshots⁠: every page in light, dark, RTL and mobile. Regenerate with pnpm screenshots.


⁠Quick start

docker run -d --name storage-io -p 3000:3000 \
  -e ADMIN_USERNAME=admin \
  -e ADMIN_PASSWORD='choose-a-strong-password' \
  -e APP_SECRET="$(openssl rand -base64 48)" \
  -v storage-io-data:/data \
  kianfar/storage-io:latest

Open http://localhost:3000⁠, sign in, and connect your first server in the welcome wizard.

Keep APP_SECRET safe and constant. It encrypts the stored server credentials; if it changes, every server has to be re-entered.

⁠With Docker Compose
curl -O https://raw.githubusercontent.com/navid-kianfar/storage-io/main/docker-compose.yml
cat > .env <<EOF
ADMIN_USERNAME=admin
ADMIN_PASSWORD=choose-a-strong-password
APP_SECRET=$(openssl rand -base64 48)
EOF
docker compose up -d

⁠Features

  • Many servers, one view. Add any number of S3 endpoints. Each connection is verified (reachability, TLS, auth, admin API) and its capabilities are detected. Health, latency, capacity and traffic are monitored continuously, with maintenance mode and credential rotation.
  • Buckets. Create buckets with versioning, object lock and quotas. Edit access policies (presets or a JSON editor), lifecycle rules, replication, event notifications, CORS and tags. Bulk actions and CSV export.
  • Object browser. Fast virtualised listing, previews (image, video, audio, PDF, text, JSON, Markdown, archive contents), in-place text editing that saves a new version, versions and restore, tags, metadata, retention and legal hold, share links, copy and move across servers, ZIP download, import from URL, and drag-and-drop file and folder uploads.
  • Transfers. Resumable multipart uploads with pause and resume, retries, bandwidth limits, and a live transfer manager.
  • Bulk jobs. Copy, move, delete, tag, change storage class, set retention or restore versions across millions of objects. Filters, estimates, dry runs, live concurrency, cron schedules, and pause/resume that survives restarts.
  • Access management. S3/IAM users, groups, policies (a visual and JSON editor with a simulator and version history) and access keys (expiry, rotation with a grace period, a one-time secret with ready-made .env, AWS CLI, rclone and mc snippets).
  • Quotas. Native hard quotas where the provider supports them, alert-only quotas everywhere else.
  • Operations. Activity log with CSV export and syslog forwarding. Notifications by e-mail, signed webhook and Telegram. Encrypted configuration backup and restore.
  • Interface. Light and dark themes, full right-to-left support, English/Türkçe/فارسی/العربية language switching (translations are in progress), a command palette (⌘K), and a responsive layout down to phones.
⁠Provider support
CapabilityMinIOSeaweedFSAWS S3Ceph RGWGarageWasabiR2 / other S3
Buckets & objects, versioning, presign, multipart✓✓✓✓✓✓✓
S3 users & access keys✓✓✓✓✓✓—
Groups & policies✓—✓——✓—
Key expiry & session policies✓—app-enforced——app-enforced—
Native bucket quotas✓alert-onlyalert-only✓✓alert-onlyalert-only
Nodes & drives, traffic metrics✓——————

SeaweedFS and IAM: keep your admin identity in the filer's identity store (weed shell → s3.configure), not only in the static -s3.config file. SeaweedFS's IAM API replaces the whole store on its first write, so an admin that exists only in -s3.config stops authenticating as soon as the first S3 user is created.

Capabilities are detected per server. Anything unsupported is shown as such in the UI instead of failing. MinIO and SeaweedFS are tested end to end in CI; the other drivers are covered by protocol-level tests.

⁠Configuration

All configuration comes from environment variables. There is a single administrator, whose credentials come from the environment; there is no sign-up.

VariableRequiredDefaultDescription
ADMIN_USERNAME✓Administrator user name
ADMIN_PASSWORD / ADMIN_PASSWORD_HASHone ofPlain password (≥ 8 chars) or an argon2id PHC hash (preferred)
APP_SECRET✓≥ 32 chars; key material for encrypting stored credentials
PORT3000HTTP port
DATABASE_PATH/data/storage-io.sqlite (image)SQLite database file
COOKIE_SECUREfalseSet true when served over HTTPS
TRUST_PROXYfalse1 (one reverse proxy) or a list of proxy CIDRs; leave false without a proxy
TZUTCTime zone for schedules and logs

The full reference, including the scheduler switches and log level, is in apps/api/.env.example⁠.

⁠Development

Requirements: Node.js ≥ 22, pnpm ≥ 10 (via Corepack), Docker (for the local MinIO/SeaweedFS targets).

git clone https://github.com/navid-kianfar/storage-io.git && cd storage-io
corepack enable && pnpm install
cp apps/api/.env.example apps/api/.env          # set ADMIN_PASSWORD and APP_SECRET
docker compose -f docker/docker-compose.dev.yml up -d   # MinIO + SeaweedFS for testing
pnpm dev                                        # API on :3000, web on :5173
pnpm seed:demo                                  # optional: demo servers, buckets, users and jobs
CommandWhat it does
pnpm devRuns the API (watch mode) and the web app (Vite) together
pnpm buildBuilds contracts, API and web
pnpm testUnit and e2e tests for every package
S3_IT=1 pnpm --filter @storage-io/api test:itIntegration tests against the dev MinIO and SeaweedFS
pnpm lint / pnpm typecheckESLint and TypeScript across the workspace
pnpm seed:demoFills a running instance with demo data
pnpm screenshotsRegenerates docs/screenshots/ from a running instance
docker build .Builds the production image (API + web in one container)
⁠Tech stack
APINestJS 11, Drizzle ORM + SQLite (better-sqlite3), zod (shared contracts), AWS SDK v3, pino
WebReact 19, Vite, TypeScript, Tailwind CSS v4, shadcn/ui, TanStack Router/Query/Table, react-hook-form, i18next, CodeMirror 6, Recharts
Shared@storage-io/contracts: zod schemas and types for every endpoint, plus the IAM policy evaluator
⁠Repository layout
apps/api            NestJS REST API + SSE, provider drivers, job engine, SQLite
apps/web            React single-page app (served by the API in production)
packages/contracts  Shared zod schemas and types
docker/             Dev containers (MinIO, SeaweedFS)
docs/               Architecture, API contract, routes, screenshots

More detail is in docs/ARCHITECTURE.md⁠, docs/API.md⁠ and docs/ROUTES.md⁠. While the API runs in development, the OpenAPI UI is served at /api/docs.

⁠Security

  • Server secrets are encrypted at rest with AES-256-GCM, using a key derived from APP_SECRET. The API never returns them.
  • Sessions are opaque tokens stored hashed, in an httpOnly, SameSite=Strict cookie. Mutating requests are Origin-checked, login is rate-limited, and an optional allowed-networks list restricts access.
  • A strict Content-Security-Policy is applied. Object previews are sandboxed and only inert types render inline.

Please report vulnerabilities privately; see SECURITY.md⁠.

⁠Contributing

Issues and pull requests are welcome. See CONTRIBUTING.md⁠.

⁠License

MIT⁠ © storage-io contributors

Tag summary

Content type

Image

Digest

sha256:9a4f31653…

Size

109.9 MB

Last updated

9 days ago

docker pull kianfar/storage-io