Skip to content

s3-01

An S3 server VM on XCP-ng running SeaweedFS. OpenTofu creates the VM, nixos-anywhere installs NixOS onto it, and nix/hosts/s3-01/seaweedfs.nix runs a single weed server process — master, volume, filer and S3 in one unit — on the second disk. The S3 API and its AWS-compatible IAM API share port 8333, the only port open in the firewall.

Day to day, root logs in with SSH certificates signed by OpenBao. The only authorized key is a shared break-glass key whose private half lives in the password manager; use it when OpenBao or authentik is down. It is also the key terraform/10_s3-01 installs with, so a reinstall needs it loaded in your SSH agent. Rotating it means changing it in both terraform/10_s3-01/main.tf and nix/hosts/s3-01/default.nix and applying.