Web interface for StorageLink. Requires thorntech/storagelink-backend
403
thorntech/storagelink-backend:1.3.1, a security patch. The web interface is unchanged; upgrade both images together.restricted pod security standard and supports OpenShift arbitrary UIDs and readOnlyRootFilesystem.EXTERNAL_TLS_TERMINATION)frame-ancestors header, configurable with FRAME_ANCESTORSFor the full changelog, see the CHANGELOGā .
This is the web interface for StorageLink. Users browse, upload, download, and preview files in their cloud and local storage; administrators manage users, folder permissions, storage connections, transfer jobs, single sign-on, and licensing.
This image is one component of a multi-container deployment. You need both images to run StorageLink:
| Image | Description |
|---|---|
| thorntech/storagelink-backendā | REST API and cloud storage integration |
| thorntech/storagelink-ui (this image) | Web interface for users and administrators |
š See thorntech/storagelink-backendā for complete deployment instructions and docker-compose configuration.
| Variable | Description | Required |
|---|---|---|
BACKEND_URL | URL of the backend API, with a trailing slash (e.g., http://backend:8080/) | Yes |
SECURITY_CLIENT_ID | OAuth client ID (must match the backend) | Yes |
SECURITY_CLIENT_SECRET | OAuth client secret (must match the backend) | Yes |
WEBSITE_BUNDLE_CRT | TLS certificate (PEM), when the certificate is not mounted as a file | No |
WEBSITE_KEY | TLS private key (PEM), when the key is not mounted as a file | No |
EXTERNAL_TLS_TERMINATION | Set to true when a load balancer or reverse proxy terminates TLS (default: false) | No |
FRAME_ANCESTORS | Content-Security-Policy frame-ancestors allowlist (default: 'self'). Set it to permit embedding StorageLink in an iframe, e.g. 'self' https://portal.example.com. | No |
CLOUD_PROVIDER | Default cloud provider shown in the admin dashboard's help: aws, azure, or gcp | No |
| Port | Protocol | Description |
|---|---|---|
| 8080 | TCP | HTTP. Serves a landing page that helps users trust a self-signed certificate, or the web interface itself when EXTERNAL_TLS_TERMINATION is true |
| 8443 | TCP | HTTPS web interface (not used when EXTERNAL_TLS_TERMINATION is true) |
Map HTTPS to host port 443. The HTTP landing page links to https://<host> without a port.
When the container terminates TLS (the default), it needs a certificate and private key in PEM format. Supply them in one of two ways:
/etc/nginx/ssl/website.bundle.crt and the key at /etc/nginx/ssl/website.key, for example from a Kubernetes Secret. The key must be readable by UID 1000 or GID 0. Mount both files or neither; the container refuses to start with only one.WEBSITE_BUNDLE_CRT and WEBSITE_KEY to those paths at startup. The quick start on the backend image uses this method.If you use a certificate chain, put the server certificate first, followed by the intermediate certificates.
To terminate TLS at a load balancer or reverse proxy instead, set EXTERNAL_TLS_TERMINATION=true and route traffic to port 8080. The container then serves the web interface over HTTP and needs no certificate.
To run with readOnlyRootFilesystem: true, give the container writable (for example emptyDir or tmpfs) mounts at:
/etc/nginx/conf.d/etc/nginx/templates/var/cache/nginx/var/run/nginx/var/run/swiftgw-webconfigWhen TLS terminates in the container, /etc/nginx/ssl must also be writable unless the certificate and key are mounted as files.
StorageLink container images are built on Docker Hardened Imagesā base images, run as a non-root user, and listen only on non-privileged ports. Every release includes an SBOM (Software Bill of Materials) and SLSAā provenance attestations.
For instructions on inspecting image attestations, see the backend image documentationā .
StorageLink is commercial software. Use is governed by the End User License Agreementā . A 30-day free trial is included, with no credit card required.
Licensing is administered from the web interface. While the instance is unlicensed, administrators see a Start a 30-day free trial card, and an existing license can be activated at any time from the License card in Settings. A license activated there is stored in the backend's database and is shared by every instance in a clustered deployment. Trial registration is carried out by the browser rather than by the container, so the machine viewing the web interface needs to reach https://licensing.thorntech.com.
If the backend sets the LICENSE_CONTENT environment variable, that value takes precedence over any license activated here, so leave it unset when you intend to manage licensing from the web interface. See the backend image documentationā for the full activation steps.
To purchase a license, visit storagelink.co/purchaseā or contact [email protected]ā .
For technical support, contact [email protected]ā .
StorageLink is developed by Thorn Technologiesā , specialists in secure file transfer and cloud integration solutions.
Content type
Image
Digest
sha256:28ed0941aā¦
Size
24.6 MB
Last updated
2 days ago
docker pull thorntech/storagelink-ui