Skip to main content

MinIO β€” S3-Compatible Object Storage

MinIO runs on the controller (not inside the k3s cluster) as a Docker container managed by systemd. It provides S3-compatible object storage used by Velero for cluster backups and available as a general-purpose bucket store for workloads that need object storage.


Architecture​

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Controller (ktayl-ThinkPad-X390) β”‚
β”‚ β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ systemd: minio.service β”‚ β”‚
β”‚ β”‚ Docker: quay.io/minio/minio:latest β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ S3 API β†’ 10.0.0.1:9000 (in-cluster) β”‚ β”‚
β”‚ β”‚ 100.88.123.8:9000 (Tailscale) β”‚ β”‚
β”‚ β”‚ Console β†’ 100.88.123.8:9001 (Tailscale) β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ Data β†’ /srv/backups/minio/ (19 GiB) β”‚ β”‚
β”‚ β”‚ Config β†’ /srv/config/minio/ β”‚ β”‚
β”‚ β”‚ Secret β†’ /home/ktayl/.minio-admin (mode 600) β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”‚ S3 API (http://10.0.0.1:9000)
β–Ό
k3s cluster β€” Velero BackupStorageLocation
bucket: velero β”‚ region: minio β”‚ s3ForcePathStyle: true

Running on the controller rather than inside k3s is intentional: Velero needs its backup target to survive a complete cluster failure.


Access​

EndpointURLUse
S3 API (in-cluster)http://10.0.0.1:9000Velero, workloads inside k3s
S3 API (Tailscale)http://100.88.123.8:9000External tools, mc CLI from Mac
Console UIhttp://100.88.123.8:9001Browser admin β€” requires Tailscale

Admin credentials are in ~/.minio-admin on the controller (mode 600, never committed).


Buckets​

BucketCreated byContents
veleroPhase 14Velero cluster backups (Kopia snapshots)

Systemd Service​

# Check status
systemctl status minio

# Restart (e.g. after config change)
sudo systemctl restart minio

# View logs
journalctl -u minio -f

The service is enabled at boot and runs docker run --rm β€” the container is recreated on each start, state lives in the volume mounts.


mc CLI Quick Reference​

# Add the controller as an alias (from Mac over Tailscale)
mc alias set minicloud http://100.88.123.8:9000 admin <password>

# List buckets
mc ls minicloud/

# List Velero backups
mc ls minicloud/velero/

# Check disk usage
mc du minicloud/velero/

# Download a specific backup
mc cp minicloud/velero/<backup-name>/ ./ --recursive

Velero Integration​

Velero was configured in Phase 14 to use this MinIO instance as its BackupStorageLocation:

# BackupStorageLocation (default)
provider: aws # S3-compatible
objectStorage:
bucket: velero
config:
s3Url: http://10.0.0.1:9000
publicUrl: http://10.0.0.1:9000
region: minio
s3ForcePathStyle: "true"
# Check BSL is healthy
kubectl get backupstoragelocation -n velero
# Expected: phase = Available

# List all backups
kubectl get backups -n velero

# Trigger a manual backup
velero backup create manual-$(date +%Y%m%d) --wait

Authentik SSO (Phase 23)​

MinIO's console authenticates via Authentik OIDC. The Docker container is started with:

MINIO_IDENTITY_OPENID_CONFIG_URL=https://auth.10.0.0.200.nip.io/application/o/minio/.well-known/openid-configuration
MINIO_IDENTITY_OPENID_CLIENT_ID=3Zk8cVuqEprRJpzeFIaaSkIWLsdgDRpLd305VUnR
MINIO_IDENTITY_OPENID_DISPLAY_NAME=Authentik
MINIO_IDENTITY_OPENID_SCOPES=openid,profile,email,groups
MINIO_IDENTITY_OPENID_CLAIM_NAME=policy
MINIO_IDENTITY_OPENID_REDIRECT_URI=http://100.88.123.8:9001/oauth_callback

:::note OIDC startup race MinIO fetches the OIDC discovery document at container start. If Authentik is not yet ready (e.g., right after a controller reboot), MinIO logs Unable to initialize OpenID: status(404 Not Found). Restart MinIO after Authentik is fully up: sudo systemctl restart minio. :::


Health Check​

# From Mac (Tailscale connected)
curl -s http://100.88.123.8:9000/minio/health/live && echo "MinIO API OK"

# From inside the cluster
kubectl run -it --rm minio-check --image=curlimages/curl --restart=Never -- \
curl -s http://10.0.0.1:9000/minio/health/live && echo "MinIO API reachable from cluster"

# Check backup storage is Available
kubectl get backupstoragelocation -n velero