Blixt Documentation v2.9

Cloud credentials stay where you put them

BlixtFS uses your cloud credentials only on the servers you give them to. The config server distributes bucket configuration but never distributes credentials, so a compromised gateway or client can’t obtain them through BlixtFS.

Prefer your platform’s workload identity where it exists: AWS IAM roles for service accounts, GCP default credentials, GCP service accounts, GKE Workload Identity, Azure workload identity or OCI instance principals. The server then holds no long-lived key at all.

Grant the narrowest permission that works:

  • Read and write buckets need object read, write and delete on the bucket, plus permission to set up change notifications (or use a topic someone else set up, with the topic= attribute).
  • Read-only buckets need only object read and list.
  • Public datasets can be served with the anonymous attribute and no credentials at all.

Authentication between services

BlixtFS services authenticate every gRPC call with a shared bearer token of 32 to 128 hexadecimal characters. Set it with the AUTH_TOKEN environment variable, or with --auth_token_file. In Kubernetes the Helm chart reads it from the bfs-auth Secret. Generate one with:

openssl rand -hex 32

Always set a token when the gRPC ports can be reached from outside the host. The single-node Docker Compose file binds them to 127.0.0.1 for this reason.

Client access

Protocol Authentication Authorisation
NFS AUTH_SYS (client-asserted UID and GID) POSIX mode bits and ownership
SMB Samba user accounts POSIX mode bits and ownership
SFTP SSH public keys POSIX mode bits and ownership

NFS with AUTH_SYS trusts the client machine. Expose NFS only to networks you trust, and use firewall rules or Kubernetes network policies to restrict it.

Ownership of files that exist only as objects (written by other tools) comes from the configured default UID and GID.

Network exposure

Only the protocol gateway ports need to be reachable by clients. Keep the gRPC, database and metrics ports on a private network. Ports lists them all.