Quick start
Requires Node 22+ (or Docker).
1. Generate an encryption key
Profile secret access keys are encrypted at rest with this key (AES-256-GCM, 32 bytes). Generate one and keep it safe — see Security for what happens if it's lost:
openssl rand -hex 32
2. Register an OIDC client
Orbit has no local passwords — sign-in is always via an external OIDC provider.
The redirect URI is always <origin>/auth/callback, e.g.
http://localhost:3000/auth/callback in dev. See OIDC setup for
worked examples with Keycloak and Google.
3. Choose a database
SQLite is the default — no setup, data lands in ./data/app.db (override with
SQLITE_PATH). Set DATABASE_URL to a PostgreSQL connection string to use
Postgres instead; migrations run automatically for whichever driver is active.
4. Run it
With Docker Compose (also starts a local MinIO for storage):
export ENCRYPTION_KEY=$(openssl rand -hex 32)
export OIDC_ISSUER_URL=... OIDC_CLIENT_ID=... OIDC_CLIENT_SECRET=...
export OIDC_REDIRECT_URI=http://localhost:3000/auth/callback
docker compose up --build
Or directly with Node:
npm ci
npm run build
ENCRYPTION_KEY=... OIDC_ISSUER_URL=... OIDC_CLIENT_ID=... OIDC_CLIENT_SECRET=... \
OIDC_REDIRECT_URI=http://localhost:3000/auth/callback \
npm start
Then sign in, add a connection profile pointing at your storage endpoint, and browse.
Container image
Released images are published to the GitHub Container Registry on every v*
tag:
docker pull ghcr.io/tinyorbitvn/orbit-object-console:latest
# or pin a version
docker pull ghcr.io/tinyorbitvn/orbit-object-console:0.2.2
docker run -p 3000:3000 -v "$PWD/data:/app/data" \
-e ENCRYPTION_KEY=... \
-e OIDC_ISSUER_URL=... -e OIDC_CLIENT_ID=... -e OIDC_CLIENT_SECRET=... \
-e OIDC_REDIRECT_URI=http://localhost:3000/auth/callback \
ghcr.io/tinyorbitvn/orbit-object-console:latest
The image bundles the built frontend and runs the single Node process. Mount
/app/data to persist the SQLite database, or set DATABASE_URL for Postgres.
orbit-object-console images are only published under that name starting with
the release that introduced the rename. Older v0.1.x tags remain published
under the previous name, ghcr.io/tinyorbitvn/s3-object-client, and are not
republished under the new name.
Next steps
- Configuration for the full environment variable reference.
- Kubernetes to deploy with the Helm chart.