mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-20 13:30:46 +02:00
add externalUrl
@@ -58,6 +58,17 @@ weed mini -dir=/path/to/data
|
||||
weed mini -dir=/data -master.port=9444 -s3.port=8334
|
||||
```
|
||||
|
||||
### S3 with Reverse Proxy
|
||||
|
||||
If `weed mini` is behind a reverse proxy (e.g. Nginx, Cloudflare Tunnel), use the `-s3.externalUrl` flag to ensure S3 signature verification works correctly:
|
||||
|
||||
```bash
|
||||
# SeaweedFS reachable externally at https://s3.example.com
|
||||
weed mini -dir=/data -s3.externalUrl=https://s3.example.com
|
||||
```
|
||||
|
||||
For more configuration details, see the **[[S3 Nginx Proxy]]** page.
|
||||
|
||||
## S3 Credentials Setup
|
||||
|
||||
### Option 1: Environment Variables (Recommended)
|
||||
|
||||
@@ -80,6 +80,24 @@ weed mini -s3.config=/path/to/s3.json
|
||||
| `Read:bucket1` | Read access to specific bucket |
|
||||
| `Write:bucket1` | Write access to specific bucket |
|
||||
|
||||
## S3 with Reverse Proxy
|
||||
|
||||
When SeaweedFS S3 is behind a reverse proxy (Nginx, HAProxy, AWS ALB, etc.), it needs to know the correct host and protocol to verify S3 signatures.
|
||||
|
||||
By default, SeaweedFS automatically detects the following headers from your proxy:
|
||||
- `X-Forwarded-Host` (e.g. `s3.example.com`)
|
||||
- `X-Forwarded-Proto` (e.g. `https`)
|
||||
- `X-Forwarded-Port` (e.g. `443`)
|
||||
|
||||
Alternatively, you can explicitly set the public-facing URL using the `externalUrl` flag. This is recommended for complex proxy setups or when you cannot easily modify proxy headers.
|
||||
|
||||
```bash
|
||||
# Explicitly set the external S3 endpoint
|
||||
weed s3 -s3.externalUrl=https://s3.example.com
|
||||
```
|
||||
|
||||
For detailed configuration examples, see the **[[S3 Nginx Proxy]]** page.
|
||||
|
||||
---
|
||||
|
||||
## Advanced IAM (`-s3.iam.config`)
|
||||
|
||||
@@ -5,6 +5,33 @@ For virtual-hosted style URL buckets, you'll need to add a [wildcard DNS record]
|
||||
|
||||
Make sure the config sets the `X-Forwarded-Host` and optionally the `X-Forwarded-Port` if you are using a non-standard port. SeaweedFS will automatically combine these headers to reconstruct the correct host information for signature verification.
|
||||
|
||||
## Explicit External URL for Signature Verification
|
||||
|
||||
In scenarios where the reverse proxy cannot easily be configured to send the necessary headers, or in complex multi-hop environments, you can use the `-s3.externalUrl` flag to explicitly set the public-facing URL of the S3 service.
|
||||
|
||||
When `-s3.externalUrl` is set, SeaweedFS will use the host and port from this URL for all S3 signature verification, ignoring incoming `Host` or `X-Forwarded-*` headers.
|
||||
|
||||
### Usage Example
|
||||
|
||||
```bash
|
||||
# SeaweedFS S3 is reachable externally at https://s3.example.com:9000
|
||||
weed s3 -s3.externalUrl=https://s3.example.com:9000
|
||||
```
|
||||
|
||||
Alternatively, set the environment variable:
|
||||
```bash
|
||||
export WEED_S3_EXTERNAL_URL=https://s3.example.com:9000
|
||||
```
|
||||
|
||||
This flag is also supported in `weed mini` and `weed filer`:
|
||||
```bash
|
||||
weed mini -s3.externalUrl=http://localhost:9000
|
||||
weed filer -s3 -s3.externalUrl=https://s3.mycorp.internal
|
||||
```
|
||||
|
||||
### Why use this?
|
||||
AWS Signature V4 includes the `Host` header in the signed payload. If SeaweedFS is behind a proxy, the `Host` header it receives might be the internal address (e.g., `localhost:8333`), while the client signed the request with the external address (e.g., `s3.example.com`). Setting `-s3.externalUrl` ensures SeaweedFS uses the correct host for signature validation.
|
||||
|
||||
## Reverse Proxy with URL Path Prefixes
|
||||
|
||||
SeaweedFS S3 API supports the `X-Forwarded-Prefix` header for scenarios where a reverse proxy strips URL path prefixes before forwarding requests. This is common when hosting the S3 API under a subpath like `/s3/` or `/api/s3/`.
|
||||
|
||||
Reference in New Issue
Block a user