
MinIO AIStor Console
Protect access to the current MinIO AIStor Console as an upstream web application.
Overview
MinIO AIStor Console is the current browser-based administration interface for MinIO AIStor. It uses a separate endpoint from the S3 API and can use WebSocket connections. The S3 data API needs a separate route.
MinIO AIStor Console can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to MinIO AIStor Console. MinIO AIStor Console remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Configure the AIStor Console public redirect URL for the Pomerium origin. Preserve WebSocket upgrades and keep the S3 endpoint on its separate reviewed path.
Example
Administrators reach the MinIO AIStor Console through a Pomerium HTTPS route. S3 clients continue to use a separate S3 endpoint and their normal signed requests. AIStor keeps its users, policies, and object permissions.
Considerations
- The AIStor Console and S3 API use different endpoints. A Console route does not protect the S3 endpoint.
- S3 request signing makes a normal path-prefix proxy unsuitable for the S3 API.
- The MinIO Community Server repository was archived on April 25, 2026.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
Sources and official resources
- MinIO AIStorOfficial website
- AIStor ConsoleOfficial documentation
- AIStor Console settingsPrimary source
- Archived MinIO Community Server repositoryOfficial repository
- Pomerium HTTP and WebSocket routingPomerium documentation
- Pomerium route timeoutsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
