s3admin

package
v1.801.79 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 18, 2026 License: Apache-2.0 Imports: 6 Imported by: 0

Documentation

Overview

Package s3admin is the ONE shared S3 access path for the unified cloud binary.

Every subsystem that touches the shared object store — clients/projects (the deploy blob store) and clients/s3 (the /v1/s3 file-manager control plane) — builds its *minio.Client here, from the SAME admin credentials (S3_ADMIN_*). There is no second S3 client construction anywhere in the binary: one endpoint, one credential source, one connect path (DRY).

The backend is the SeaweedFS S3 gateway (s3.hanzo.svc:9000), which speaks the S3 API, so minio-go is the client. The gateway is reached over the internal admin endpoint for control operations; a SEPARATE public-host client (PublicClient) is used only to MINT presigned URLs that a browser can follow, since a presign is a pure signature over the client's endpoint and never makes a network call — so the signed host is the browser-routable one.

This package depends on nothing but minio-go: it is a leaf, so both projects and the s3 subsystem import it without any import cycle.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Admin

type Admin struct {
	// contains filtered or unexported fields
}

Admin holds the shared S3 admin connection parameters, sourced once from the environment the operator injects (the k8s secret hanzo-s3 → S3_ADMIN_*). It is a value: construct it with New() and pass it around; it holds no live connection, so it is safe to copy and to build clients from concurrently.

func New

func New() Admin

New reads the shared S3 admin configuration from the environment. It mirrors the exact variables clients/projects/blob.go already consumes, so the two subsystems resolve identical credentials and endpoint with no drift.

S3_ADMIN_ENDPOINT      internal admin host:port (default s3.hanzo.svc:9000)
S3_ADMIN_ACCESS_KEY    access key (no default — absence = not configured)
S3_ADMIN_SECRET_KEY    secret key (no default — absence = not configured)
S3_SECURE              TLS to the internal endpoint (default false)
S3_REGION              signing region (default us-east-1)
S3_PUBLIC_ENDPOINT     browser-routable host for presigned URLs
                             (default s3.hanzo.ai; strips any scheme)
S3_PUBLIC_SECURE       TLS for the public host (default true)

func (Admin) Client

func (a Admin) Client() (*minio.Client, error)

Client builds a minio client bound to the INTERNAL admin endpoint. Use it for every control/data operation the server performs itself (list, create, stat, delete, and streamed put/get through the server).

func (Admin) Configured

func (a Admin) Configured() bool

Configured reports whether admin credentials are present. A subsystem that finds this false must fail closed (honest 503), never fabricate a result.

func (Admin) PresignConfigured

func (a Admin) PresignConfigured() bool

PresignConfigured reports whether a public host is available to sign browser-followable URLs. Absent it, callers must not offer presigned upload or download (they degrade to a server-streamed path or an honest error).

func (Admin) PublicClient

func (a Admin) PublicClient() (*minio.Client, error)

PublicClient builds a minio client bound to the PUBLIC host. Its ONLY use is minting presigned URLs (PresignedGetObject / PresignedPutObject) — those sign over this client's endpoint without any network call, so the URL a browser receives targets the public, routable host and not the in-cluster admin one.

func (Admin) Region

func (a Admin) Region() string

Region is the signing region (exposed so callers can pass it to MakeBucket).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL