Web console
Manage buckets, objects and keys in the browser.
Open the admin port in a browser, http://127.0.0.1:9001/, and sign in with
the root key or another admin key. The console shows usage and request
activity, creates and deletes buckets, browses, uploads, downloads and deletes
objects, makes presigned share links, and manages keys and their bucket
permissions.
Reaching it from another machine
The admin port listens on loopback by default. From another machine, either:
- use an SSH tunnel:
ssh -L 9001:127.0.0.1:9001 server, then openhttp://127.0.0.1:9001/, or - serve the admin API over HTTPS (
tls.admin = true, see HTTPS) on a reachable address.
Sessions
Sign-in sessions end on sign-out, after 15 minutes idle (automatic page refreshes do not count) or 7 days, when the server restarts, and immediately when the key is disabled or deleted. The browser keeps only a session cookie, never the secret.
Share links
Share links are presigned S3 URLs: whoever has one can download the object until it expires, from the S3 port. They use the host name the console was opened with. When clients reach the S3 API at another address (a load balancer, a reverse proxy), set:
[s3]
public_url = "https://s3.example.com"Notes
- Request charts cover what the server has seen since it started; use the Prometheus metrics for long-term history.
admin.console = falseturns the console off; the admin API is unchanged.