Skip to main content
See All Integrations

MinIO AIStor Console

Protect access to the current MinIO AIStor Console as an upstream web application.

Standard protected service pattern

Categories
AI and Data, Upstream Applications

Overview

MinIO AIStor Console is the current browser-based administration interface for MinIO AIStor. It uses a separate endpoint from the S3 API and can use WebSocket connections. The S3 data API needs a separate route.

MinIO AIStor Console can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to MinIO AIStor Console. MinIO AIStor Console remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Configure the AIStor Console public redirect URL for the Pomerium origin. Preserve WebSocket upgrades and keep the S3 endpoint on its separate reviewed path.

Example

Administrators reach the MinIO AIStor Console through a Pomerium HTTPS route. S3 clients continue to use a separate S3 endpoint and their normal signed requests. AIStor keeps its users, policies, and object permissions.

Considerations

  • The AIStor Console and S3 API use different endpoints. A Console route does not protect the S3 endpoint.
  • S3 request signing makes a normal path-prefix proxy unsuitable for the S3 API.
  • The MinIO Community Server repository was archived on April 25, 2026.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Protect access to Portainer container administration as an upstream web application.

  • Protect access to internal administration panels as upstream web applications.

  • Protect access to Backstage developer portals and software catalogs as an upstream web application.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo