files.example.com, and an HTTPS reverse proxy on the Docker host. The API and every user’s browser must be able to reach that hostname.
1. Add the storage service
Add this service and volume to your existingcompose.yml. Merge them into the existing services and volumes sections; do not create duplicate top-level keys.
silo.env with a unique administrator name and a secret generated with openssl rand -hex 32:
MINIO_* configuration names. Use the exact origin of your Kaneo instance, including its port if it has one. This global CORS setting applies to buckets without their own CORS configuration. See Silo’s compatibility notes.
2. Put the S3 API behind HTTPS
Pointfiles.example.com at your server. Configure your proxy to send that hostname to http://127.0.0.1:9000, preserving the request host, path, query string, and body.
For host-installed Nginx with an existing certificate, use:
sudo nginx -t before reloading Nginx.
Keep port 9001, the administration console, private. On a remote server, open an SSH tunnel from your computer:
http://localhost:9001 and sign in with the administrator credentials from silo.env.
3. Create the bucket and a Kaneo credential
In the Silo console:- Create a private bucket named kaneo-uploads.
- Create a policy named kaneo-uploads with the JSON below.
- Create a dedicated user for Kaneo and attach that policy. Use that user’s access key and secret in Kaneo, not the root administrator credential.
4. Connect Kaneo
Add these values to Kaneo’s.env:
Moving from MinIO
Back up the existing storage and configuration first. Follow Silo’s migration guide for your exact source and target versions. Keep existing volume names, mounts, bucket names, and object keys. Do not rename a liveminio_data volume to silo_data just to match this example, as Compose would create a different volume. Existing MINIO_* variables keep their spelling.
Test uploads and downloads before switching your team over. Image rollback alone may not reverse changes to persistent storage metadata or permissions.
Local-only trials
A local setup still needs one storage hostname that both Docker and the browser can resolve.localhost inside the Kaneo container points to Kaneo, while silo usually resolves only inside Docker. Configure shared DNS and routing for your environment instead of copying either address into S3_ENDPOINT.
For the least setup, try Kaneo without attachments first and add storage on a host with a reachable domain.