TAC-3 tactical S3-compatible object storage node (FIPS 140-3, post-quantum, clustered).
2.8K
TAC-3 is a self-contained, S3-compatible object storage node built for tactical and air-gapped environments. FIPS 140-3 validated cryptography, post-quantum (CNSA 2.0) protection, clustering with synchronous replication, and built-in data pipelines — in a single container.
Private image. Targeted for defense/tactical deployments. Not for general distribution.
/api/v1/docs (/api/v1/openapi.json).docker run -d --name tac3 \
-p 9000:9000 -p 9001:9001 \
-e TAC3_MASTER_KEY=$(openssl rand -hex 32) \
-v tac3-data:/var/lib/tac3 \
-v tac3-cfg:/etc/tac3 \
tychoncorp/tac3:latest
A default /etc/tac3/node.toml is generated on first boot if none is mounted. The one-time admin password is printed to the container logs on first start and must be changed at first login:
docker logs tac3 | grep -A3 "FIRST BOOT"
Then open the console at https://localhost:9001 (self-signed TLS by default; replace via Settings → Security → TLS).
| Port | Purpose |
|---|---|
| 9000 | S3 API (HTTPS, SigV4) |
| 9001 | Management API + web console |
| 9002 | Cluster / Raft RPC |
| 9003/udp | QUIC transport |
| 9004 | WebDAV gateway (when enabled) |
| Path | Purpose |
|---|---|
/var/lib/tac3 | Object data, metadata, keys |
/etc/tac3 | Node configuration (node.toml) |
Provide the 32-byte at-rest master key via one of (checked in order): HashiCorp Vault Transit, AWS KMS, a mounted key file, the TAC3_MASTER_KEY env var (64 hex chars), or a TPM/DMI hardware-sealed blob. A node generates and persists its own identity on first boot.
latest — most recent buildYYYY-MM-DD — dated, immutable snapshotThe default image seals the master key to a TPM automatically when /dev/tpmrm0 and the tools are present, and falls back gracefully otherwise. Build with --build-arg WITH_TPM=true to bundle tpm2-tools, opensc, and softhsm2.
Content type
Image
Digest
sha256:3ae91bb33…
Size
98 MB
Last updated
1 day ago
docker pull tychoncorp/tac3