以下是在Ubuntu上安全安装MinIO的关键步骤及措施:
sudo apt update && sudo apt install -y wget curl software-properties-common
wget -qO - https://dl.min.io/server/minio/release/linux-amd64/minio-release.gpg | sudo apt-key add -
sudo add-apt-repository 'deb https://dl.min.io/server/minio/release/linux-amd64/ /'
sudo apt install -y minio
minio-user运行服务:sudo useradd -r -s /sbin/nologin minio-user
/etc/default/minio文件设置强密码,避免硬编码:MINIO_ROOT_USER="your-access-key"
MINIO_ROOT_PASSWORD="your-strong-password"
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout minio.key -out minio.crt
minio server --certs-dir /path/to/certs /data
sudo ufw allow 9000/tcp # API端口
sudo ufw allow 9001/tcp # 控制台端口
sudo ufw enable
User和Group为minio-user:sudo nano /etc/systemd/system/minio.service
# 添加以下内容:
User=minio-user
Group=minio-user
export MINIO_SERVER_SERVER_SIDE_ENCRYPTION="AES-256-SSE"
/mnt/data)定期备份至安全位置,并验证备份完整性。sudo systemctl status minio
sudo apt update && sudo apt upgrade -y minio
参考来源: