Skip to content

Latest commit

 

History

History
233 lines (209 loc) · 14.4 KB

File metadata and controls

233 lines (209 loc) · 14.4 KB

Environment Variable

Env
CONSOLE_MINIO_SERVER "http://localhost:9000"
CONSOLE_MINIO_REGION "us-east-1"
CONSOLE_MINIO_SERVER_TLS_SKIP_VERIFY "off"; standalone only, exempts exactly the CONSOLE_MINIO_SERVER HTTPS origin from certificate verification, see TLS.md
CONSOLE_HOSTNAME ""
CONSOLE_PORT 9090
CONSOLE_TLS_PORT 9443
CONSOLE_SUBPATH i.e. /console
CONSOLE_DEBUG_LOGLEVEL 0 - 6; credential-bearing headers, query parameters and path segments are redacted at every level, see Debug.md
CONSOLE_CORRESPONDING_SOURCE_URL "" ; public https URL of the exact corresponding source for a custom or modified build, reported by console version, the page metadata and the License/Login/anonymous pages; must have a host and no credentials, query or fragment, otherwise it is rejected (without suppressing built-in provenance)
CONSOLE_TRUSTED_PROXIES Standalone only: trusted proxy IP/CIDR list; blank falls back to MINIO_API_TRUSTED_PROXIES
CONSOLE_WS_MAX_CONNECTIONS 1024; WebSocket connections the process holds at once, see WebSocket connection limits
CONSOLE_WS_MAX_CONNECTIONS_PER_CLIENT 256; WebSocket connections one client address holds at once
CONSOLE_WS_MAX_ANONYMOUS_CONNECTIONS 64; anonymous WebSocket connections for the process (must be less than the total)
CONSOLE_WS_MAX_ANONYMOUS_CONNECTIONS_PER_CLIENT 8; anonymous WebSocket connections from one client address (must be less than the per-client cap and not exceed the anonymous budget)
CONSOLE_SHARE_MINIO_URL "off"; selects the generated URL format, does not disable sharing
CONSOLE_SECURE_ALLOWED_HOSTS ""
CONSOLE_SECURE_ALLOWED_HOSTS_ARE_REGEX "off"
CONSOLE_SECURE_FRAME_DENY "on"
CONSOLE_SECURE_CONTENT_TYPE_NO_SNIFF "on"
CONSOLE_SECURE_BROWSER_XSS_FILTER "on"
CONSOLE_SECURE_CONTENT_SECURITY_POLICY ""
CONSOLE_SECURE_CONTENT_SECURITY_POLICY_REPORT_ONLY ""
CONSOLE_SECURE_HOSTS_PROXY_HEADERS ""
CONSOLE_SECURE_STS_SECONDS 0
CONSOLE_SECURE_STS_INCLUDE_SUB_DOMAINS "off"
CONSOLE_SECURE_STS_PRELOAD "off"
CONSOLE_SECURE_TLS_REDIRECT "off"
CONSOLE_SECURE_TLS_HOST ""
CONSOLE_SECURE_TLS_TEMPORARY_REDIRECT "off"
CONSOLE_SECURE_FORCE_STS_HEADER "off"
CONSOLE_SECURE_PUBLIC_KEY
CONSOLE_SECURE_REFERRER_POLICY ""
CONSOLE_SECURE_FEATURE_POLICY ""
CONSOLE_SECURE_EXPECT_CT_HEADER
CONSOLE_PROMETHEUS_URL
CONSOLE_PROMETHEUS_AUTH_TOKEN
CONSOLE_PROMETHEUS_AUTH_USERNAME
CONSOLE_PROMETHEUS_AUTH_PASSWORD
CONSOLE_PROMETHEUS_JOB_ID "minio-job"
CONSOLE_PROMETHEUS_EXTRA_LABELS
CONSOLE_LOG_QUERY_URL
CONSOLE_LOG_QUERY_AUTH_TOKEN ""
CONSOLE_MAX_CONCURRENT_UPLOADS "10"
CONSOLE_MAX_CONCURRENT_DOWNLOADS "20"
CONSOLE_DEV_MODE "off"
CONSOLE_BROWSER_REDIRECT_URL
LOGSEARCH_QUERY_AUTH_TOKEN
CONSOLE_IDP_DISPLAY_NAME MINIO_IDENTITY_OPENID_DISPLAY_NAME
CONSOLE_IDP_URL MINIO_IDENTITY_OPENID_CONFIG_URL
CONSOLE_IDP_CLIENT_ID MINIO_IDENTITY_OPENID_CLIENT_ID
CONSOLE_IDP_SECRET MINIO_IDENTITY_OPENID_CLIENT_SECRET
CONSOLE_IDP_CALLBACK MINIO_BROWSER_REDIRECT_URL
CONSOLE_IDP_CALLBACK_DYNAMIC MINIO_IDENTITY_OPENID_REDIRECT_URI_DYNAMIC
CONSOLE_IDP_SCOPES MINIO_IDENTITY_OPENID_SCOPES
CONSOLE_IDP_USERINFO MINIO_IDENTITY_OPENID_CLAIM_USERINFO
CONSOLE_IDP_ROLE_ARN
CONSOLE_IDP_END_SESSION_ENDPOINT
CONSOLE_LDAP_ENABLED
CONSOLE_STS_DURATION time.Duration format, ie: 3600s, 2h45m, 1h, etc
CONSOLE_PBKDF_PASSPHRASE
CONSOLE_PBKDF_SALT
CONSOLE_LOGGER_JSON_ENABLE
CONSOLE_LOGGER_ANONYMOUS_ENABLE
CONSOLE_LOGGER_QUIET_ENABLE
CONSOLE_GLOBAL_DEPLOYMENT_ID
CONSOLE_LOGGER_WEBHOOK_ENABLE
CONSOLE_LOGGER_WEBHOOK_ENDPOINT
CONSOLE_LOGGER_WEBHOOK_AUTH_TOKEN
CONSOLE_LOGGER_WEBHOOK_CLIENT_CERT
CONSOLE_LOGGER_WEBHOOK_CLIENT_KEY
CONSOLE_LOGGER_WEBHOOK_QUEUE_SIZE
CONSOLE_AUDIT_WEBHOOK_ENABLE
CONSOLE_AUDIT_WEBHOOK_ENDPOINT
CONSOLE_AUDIT_WEBHOOK_AUTH_TOKEN
CONSOLE_AUDIT_WEBHOOK_CLIENT_CERT
CONSOLE_AUDIT_WEBHOOK_CLIENT_KEY
CONSOLE_AUDIT_WEBHOOK_QUEUE_SIZE

Trusted proxy source addresses

Console uses the resolved client address when it requests STS credentials or calls SILO on a user's behalf. This address can affect aws:SourceIp policy conditions, so forwarded source headers are ignored unless the request's direct TCP peer is trusted.

CONSOLE_TRUSTED_PROXIES accepts exact IPv4/IPv6 addresses and CIDR blocks separated by commas, semicolons, or whitespace. Bare addresses trust one host. Catch-all 0.0.0.0/0 and ::/0 entries are rejected. Configure proxy addresses, not client networks, and configure the edge proxy to remove every inbound X-Forwarded-For, X-Real-IP, and Forwarded header it does not author.

Standalone Console defaults to trusting no proxy. If neither applicable variable names a trusted peer, Console uses the TCP peer and ignores all three forwarded source headers. This intentionally changes deployments that previously relied on implicit trust. Set the appropriate variable before upgrading when source IP policies or client attribution must pass through a reverse proxy.

Deployment Console inbound policy SILO API policy Required setting
Standalone Console, no reverse proxy Trust no forwarded headers Must trust Console's egress peer to preserve the browser client IP Set CONSOLE_TRUSTED_PROXIES=none whenever MINIO_API_TRUSTED_PROXIES is present in Console's environment; leaving it unset is only equivalent when the SILO setting is absent too
Standalone Console behind a reverse proxy Trust only the Console-facing proxy peers Must trust Console's egress peer to preserve the browser client IP Set CONSOLE_TRUSTED_PROXIES for Console ingress and configure the SILO setting separately
Standalone Console using one shared list Fall back to the SILO setting when the Console setting is absent or blank Trust only listed API peers Set MINIO_API_TRUSTED_PROXIES to every required Console-ingress proxy and Console-egress peer; use this only when one list is correct for both listeners
Console embedded in SILO with the post-0903 proxy fix Trust loopback TCP peers plus explicitly listed peers; none/off disables both Existing Server policy: unset accepts forwarding; a list trusts listed peers plus loopback; none/off ignores forwarding Use MINIO_API_TRUSTED_PROXIES for remote proxies; local loopback proxies need no setting

An absent or blank CONSOLE_TRUSTED_PROXIES falls back to MINIO_API_TRUSTED_PROXIES; the two lists are only interchangeable when the same peers front both listeners. CONSOLE_TRUSTED_PROXIES=none or off explicitly suppresses the fallback. A malformed, separators-only, catch-all, or unreadable remote value is an error and fails closed to trust-none. Standalone Console refuses to start; Server builds with the post-0903 fix also propagate the error and exit instead of relying on normally silenced Console logs.

The embedded repair (silo#147) restores trust in local processes that connect over literal loopback IPs (127.0.0.0/8 or ::1, including IPv4-mapped addresses). Unset or blank trusts only those TCP peers; an explicit list adds remote peers. none/off disables the local exception too. Only explicit list entries are skipped when walking a forwarded chain: a loopback address inside a header is not implicitly trusted. Local proxies must sanitize forwarded headers; proxies on another host or container need their actual peer addresses listed. Standalone Console has no implicit loopback exception.

Forwarded chains are read from the peer backwards. The first address outside the trusted list is the client. The walk stops, and the request is attributed to the TCP peer, at the first element that is not a literal IP address: a host name, an RFC 7239 unknown or obfuscated identifier, malformed quoting, a repeated parameter, or a chain longer than 100 elements. Only one header family is consulted per request, chosen by presence in the order X-Forwarded-For, X-Real-IP, Forwarded, so a client cannot choose which proxy-authored header Console believes; the proxy must remove the families it does not author.

Server builds with the #148 repair keep the four WebSocket limits below; earlier builds, including 0903, remove every CONSOLE_* value before configuring Console. CONSOLE_TRUSTED_PROXIES is therefore standalone-only; embedded deployments must use MINIO_API_TRUSTED_PROXIES. That server setting also governs direct S3 API source attribution, which remains a separate ingress path from standalone Console. With MINIO_API_TRUSTED_PROXIES=none/off, S3 also ignores the browser address forwarded by embedded Console, so source-IP policies through Console see the internal peer.

When a reverse proxy is not trusted, requests are attributed to the proxy itself. This is safe against client spoofing, but a policy that already permits that proxy address may consequently permit every client arriving through it. Review IP allow-lists as well as the proxy setting during migration.

WebSocket origin policy

Browser WebSocket handshakes to /ws/* are accepted only when the Origin authority matches the request Host, matches the authority of CONSOLE_BROWSER_REDIRECT_URL, is asserted by a trusted proxy (the TCP peer is trusted under the source-address policy above, and the first configured CONSOLE_SECURE_HOSTS_PROXY_HEADERS header present carries exactly one host[:port] equal to the Origin authority), or matches CONSOLE_SECURE_ALLOWED_HOSTS (exact, or anchored regular expressions with CONSOLE_SECURE_ALLOWED_HOSTS_ARE_REGEX=on). Requests without an Origin header (non-browser clients) and CONSOLE_DEV_MODE=on are accepted.

Subpath deployments are no longer exempt from this check. A reverse proxy that preserves the full authority (proxy_set_header Host $http_host; for nginx; $host drops a non-default port) needs nothing else; otherwise set CONSOLE_BROWSER_REDIRECT_URL, or trust the proxy and have it overwrite X-Forwarded-Host with CONSOLE_SECURE_HOSTS_PROXY_HEADERS=X-Forwarded-Host, or list the public host in CONSOLE_SECURE_ALLOWED_HOSTS.

The Object Manager WebSocket (/ws/objectManager) allows anonymous connections only when no session cookie is sent at all; an empty or malformed cookie is rejected. Every WebSocket frame is limited to 32 KiB. Object Manager sessions send a ping every 30 seconds and close peers that stay silent for 60 seconds, bound each write to 10 seconds, accept at most 4 concurrent listings, validate every request before allocating anything, and close the session after 10 consecutive invalid frames.

WebSocket connection limits

The per-connection bounds above do not limit how many connections one peer may hold, so Console also caps the number of WebSocket connections. A slot is reserved before the handshake is upgraded and released when the socket closes (including a socket the keepalive deadline declares dead), so the counts are the sockets the process actually holds. A handshake that would exceed a cap is refused before any socket exists, with Retry-After: 5: 429 Too Many Requests when the client's own cap is the one exceeded, 503 Service Unavailable when the process total or the anonymous budget is exhausted.

Variable Default Scope
CONSOLE_WS_MAX_CONNECTIONS 1024 every /ws/* connection the process holds, authenticated and anonymous together
CONSOLE_WS_MAX_CONNECTIONS_PER_CLIENT 256 connections from one client address
CONSOLE_WS_MAX_ANONYMOUS_CONNECTIONS 64 anonymous /ws/objectManager connections for the process; anonymous connections count against the total too, so they can never take more of it than this
CONSOLE_WS_MAX_ANONYMOUS_CONNECTIONS_PER_CLIENT 8 anonymous connections from one client address

Server builds containing the silo#148 repair preserve these four settings, whether supplied directly or loaded with MINIO_CONFIG_ENV_FILE. The 0903 Server release discards them and always uses the defaults. Other CONSOLE_* operator overrides are still removed on the embedded path. Follow silo#148 for release availability.

Anonymous handshakes need no credentials, so their budget is separate and small: public-bucket browsing opens one connection per tab, and nothing else can be opened without a session. Exhausting the anonymous budget therefore never affects signed-in users.

The client address is the trust-resolved one (see Trusted proxy source addresses): IPv4 addresses count individually, IPv6 addresses by their /64, and a peer whose address cannot be parsed shares one key. Behind a reverse proxy that is not trusted, every browser shares the proxy's address and the per-client caps apply to all of them together; configure the trust list, or raise CONSOLE_WS_MAX_CONNECTIONS_PER_CLIENT, for such deployments.

Every value must be an integer between 1 and 1048576. The anonymous budget must be strictly less than the total and the anonymous per-client cap strictly less than the per-client cap, so that signed-in users always keep at least one slot in each; the anonymous per-client cap must not exceed the anonymous budget. An unset variable uses its default. Explicitly blank values and literal env:// references are invalid integers. Standalone Console and Server builds containing the repair return configuration errors before Console serves requests. A Server initialization failure exits the process; its S3 listener may already have started at that point.

Outbound TLS verification

Console verifies every outbound HTTPS peer against the system roots plus the certificates in ~/.console/certs/CAs (standalone) or the server's certs/CAs (embedded). Private or self-signed server certificates belong in that directory. CONSOLE_MINIO_SERVER_TLS_SKIP_VERIFY=on is an explicit opt-out that applies only to the configured CONSOLE_MINIO_SERVER HTTPS origin; identity providers, Prometheus, webhooks and every other destination stay verified. The full behaviour, including the embedded-server certificate requirement, is described in TLS.md.