This project provides a small FastAPI service that generates S3 presigned URLs locally (no network call to AWS required). The container still needs AWS credentials to compute signatures; pass them via env vars.
Build the Docker image:
docker build -t s3-presign-api .Run the container (example with dummy creds):
docker run -p 8000:8000 \
-e AWS_ACCESS_KEY_ID=AKIA_TEST_ACCESS_KEY_1234 \
-e AWS_SECRET_ACCESS_KEY=TEST_SECRET_KEY_1234567890abcdef1234567890abcd \
s3-presign-apiExample request (generate a PUT presigned URL):
curl -s -X POST http://localhost:8000/presign \
-H "Content-Type: application/json" \
-d '{"bucket":"my-bucket","key":"uploads/file.txt","operation":"put","expires":3600}' | jqUsing a custom S3 endpoint (MinIO / LocalStack)
Run the container with S3_ENDPOINT_URL pointing at your S3-compatible service:
docker run -p 8000:8000 \
-e AWS_ACCESS_KEY_ID=minio \
-e AWS_SECRET_ACCESS_KEY=minio123 \
-e S3_ENDPOINT_URL=http://host.docker.internal:9000 \
s3-presign-apiThen request a presigned URL as usual; the service will sign URLs against the custom endpoint.
If your S3-compatible service uses path-style addressing (common for some providers), set S3_ADDRESSING_STYLE=path or include "addressing_style":"path" in the request JSON.
Example request forcing path addressing in the request body:
curl -s -X POST http://localhost:8000/presign \
-H "Content-Type: application/json" \
-d '{"bucket":"bucket-name","key":"filename","operation":"get","expires":3600,"addressing_style":"path","endpoint_url":"https://s3.g.s4.mega.io","region":"eu-central-1"}' | jqFiles:
- app/main.py - FastAPI app exposing
POST /presignandGET /health - Dockerfile - Docker image definition
- requirements.txt - Python deps