Sign inSign up

thorntech/storagelink-ui

By thorntech

•Updated 2 days ago

Web interface for StorageLink. Requires thorntech/storagelink-backend

Image
Security
Integration & delivery
Databases & storage
0

403

thorntech/storagelink-ui repository overview

⁠What's New in 1.3.1

  • Released with thorntech/storagelink-backend:1.3.1, a security patch. The web interface is unchanged; upgrade both images together.

⁠What's New in 1.3.0

  • First container release. The web interface for StorageLink users and administrators, served by nginx
  • The container runs as a non-root user (UID 1000, GID 0) on non-privileged in-container ports (HTTP 8080, HTTPS 8443). The image passes the Kubernetes restricted pod security standard and supports OpenShift arbitrary UIDs and readOnlyRootFilesystem.
  • TLS can be terminated in the container, with the certificate and key supplied as mounted files or environment variables, or upstream by a load balancer (EXTERNAL_TLS_TERMINATION)
  • Clickjacking protection through a Content-Security-Policy frame-ancestors header, configurable with FRAME_ANCESTORS
  • A self-service 30-day free trial and license activation from the admin dashboard

For the full changelog, see the CHANGELOG⁠.


This is the web interface for StorageLink. Users browse, upload, download, and preview files in their cloud and local storage; administrators manage users, folder permissions, storage connections, transfer jobs, single sign-on, and licensing.

⁠Important

This image is one component of a multi-container deployment. You need both images to run StorageLink:

ImageDescription
thorntech/storagelink-backend⁠REST API and cloud storage integration
thorntech/storagelink-ui (this image)Web interface for users and administrators

šŸ‘‰ See thorntech/storagelink-backend⁠ for complete deployment instructions and docker-compose configuration.

⁠Configuration

⁠Environment Variables
VariableDescriptionRequired
BACKEND_URLURL of the backend API, with a trailing slash (e.g., http://backend:8080/)Yes
SECURITY_CLIENT_IDOAuth client ID (must match the backend)Yes
SECURITY_CLIENT_SECRETOAuth client secret (must match the backend)Yes
WEBSITE_BUNDLE_CRTTLS certificate (PEM), when the certificate is not mounted as a fileNo
WEBSITE_KEYTLS private key (PEM), when the key is not mounted as a fileNo
EXTERNAL_TLS_TERMINATIONSet to true when a load balancer or reverse proxy terminates TLS (default: false)No
FRAME_ANCESTORSContent-Security-Policy frame-ancestors allowlist (default: 'self'). Set it to permit embedding StorageLink in an iframe, e.g. 'self' https://portal.example.com.No
CLOUD_PROVIDERDefault cloud provider shown in the admin dashboard's help: aws, azure, or gcpNo
⁠Ports
PortProtocolDescription
8080TCPHTTP. Serves a landing page that helps users trust a self-signed certificate, or the web interface itself when EXTERNAL_TLS_TERMINATION is true
8443TCPHTTPS web interface (not used when EXTERNAL_TLS_TERMINATION is true)

Map HTTPS to host port 443. The HTTP landing page links to https://<host> without a port.

⁠TLS Configuration

When the container terminates TLS (the default), it needs a certificate and private key in PEM format. Supply them in one of two ways:

  • As files (recommended for production). Mount the certificate at /etc/nginx/ssl/website.bundle.crt and the key at /etc/nginx/ssl/website.key, for example from a Kubernetes Secret. The key must be readable by UID 1000 or GID 0. Mount both files or neither; the container refuses to start with only one.
  • As environment variables. When neither file is mounted, the container writes WEBSITE_BUNDLE_CRT and WEBSITE_KEY to those paths at startup. The quick start on the backend image uses this method.

If you use a certificate chain, put the server certificate first, followed by the intermediate certificates.

To terminate TLS at a load balancer or reverse proxy instead, set EXTERNAL_TLS_TERMINATION=true and route traffic to port 8080. The container then serves the web interface over HTTP and needs no certificate.

⁠Read-Only Root Filesystem

To run with readOnlyRootFilesystem: true, give the container writable (for example emptyDir or tmpfs) mounts at:

  • /etc/nginx/conf.d
  • /etc/nginx/templates
  • /var/cache/nginx
  • /var/run/nginx
  • /var/run/swiftgw-webconfig

When TLS terminates in the container, /etc/nginx/ssl must also be writable unless the certificate and key are mounted as files.

⁠Security

StorageLink container images are built on Docker Hardened Images⁠ base images, run as a non-root user, and listen only on non-privileged ports. Every release includes an SBOM (Software Bill of Materials) and SLSA⁠ provenance attestations.

For instructions on inspecting image attestations, see the backend image documentation⁠.

⁠License & Terms

StorageLink is commercial software. Use is governed by the End User License Agreement⁠. A 30-day free trial is included, with no credit card required.

Licensing is administered from the web interface. While the instance is unlicensed, administrators see a Start a 30-day free trial card, and an existing license can be activated at any time from the License card in Settings. A license activated there is stored in the backend's database and is shared by every instance in a clustered deployment. Trial registration is carried out by the browser rather than by the container, so the machine viewing the web interface needs to reach https://licensing.thorntech.com.

If the backend sets the LICENSE_CONTENT environment variable, that value takes precedence over any license activated here, so leave it unset when you intend to manage licensing from the web interface. See the backend image documentation⁠ for the full activation steps.

To purchase a license, visit storagelink.co/purchase⁠ or contact [email protected]⁠.

⁠Support

For technical support, contact [email protected]⁠.

⁠About Thorn Technologies

StorageLink is developed by Thorn Technologies⁠, specialists in secure file transfer and cloud integration solutions.

Tag summary

Content type

Image

Digest

sha256:28ed0941a…

Size

24.6 MB

Last updated

2 days ago

docker pull thorntech/storagelink-ui