Katta: transform your S3 storage into a secure, team-friendly workspace with client-side encryption.
Docker Compose environment to run Katta Server with Keycloak, PostgreSQL and MinIO.
docker compose --profile demo up --wait
docker compose --profile demo downTip
Open Katta Web at http://hub.localhost:8280 and log in with username admin and password admin.
Warning
This environment is for development, testing and demos only. It uses well-known passwords and client secrets, a committed TLS key for Keycloak, and runs Keycloak and Katta Server in development mode.
| Profile | Description |
|---|---|
local |
Katta Server, Keycloak, PostgreSQL and MinIO. |
demo |
Same as local, and creates storage profiles for MinIO with static and STS storage access in Katta Server. |
hybrid |
Katta Server and PostgreSQL only, using an existing Keycloak and MinIO configured in the env file. |
All variables are set in .env, which Compose loads automatically.
To provide your own values, pass a complete copy with --env-file, which replaces .env.
| Variable | Default | Description |
|---|---|---|
KATTA_CHART |
oci://ghcr.io/shift7-ch/katta-helm/katta-server |
Helm chart of Katta Server to render the Keycloak realm from. See Keycloak Realm. |
KATTA_CHART_VERSION |
^1 |
Version or version range of the Helm chart. Keep at the version of KATTA_SERVER_IMAGE. Leave empty for the latest version. |
SETUP_DIR |
./setup |
Directory with the MinIO policies, using the layout of setup. |
KATTA_SERVER_IMAGE |
ghcr.io/shift7-ch/katta-server:latest |
Image to build Katta Server from. |
HUB_INITIAL_LICENSE, HUB_INITIAL_ID |
License of Katta Server. .env sets a test license. |
|
CSP_CONNECT_SRC_EXTRA |
Additional connect-src sources for the Content-Security-Policy header of Katta Server, such as the S3 and STS endpoints of storage profiles. |
Relative paths resolve against the directory containing compose.yaml.
Use absolute paths to provide setup files from another project.
The service keycloak-realm renders the realm with helm template from the realm template
_realm.tpl of the Katta Server Helm chart from katta-helm
using the variables of the env file, and Keycloak imports it on start. There is no realm file in this project.
To render the realm from a local checkout of katta-helm instead, mount it into keycloak-realm with a
Compose override file and set KATTA_CHART to the mount path.
After the import, the service keycloak-allow-http sets sslRequired to NONE for the master and the Katta realm, so that
Keycloak accepts plain HTTP requests from the host. The realm does not enable direct access grants.
The demo profile creates the storage profiles with the service account of client cryptomatorhub-system.
Compose resolves variables when it creates a container, so docker compose restart keeps the previous values.
For example, after changing CSP_CONNECT_SRC_EXTRA, recreate only Katta Server with the profile the environment was started with:
docker compose --profile demo up -d --no-deps hubTo verify the Content-Security-Policy header, run:
curl -sI http://hub.localhost:8280/ | grep -i content-security-policy| User | Password | Description |
|---|---|---|
admin |
admin |
Katta administrator and Keycloak realm administrator. |
minioadmin |
minioadmin |
MinIO root user. |
testuser |
top-secret |
MinIO user for static storage access. |
The realm also contains the service account of the cryptomatorhub-system client used by Katta Server.
| Component | URL | Discovery |
|---|---|---|
| Katta Web | http://hub.localhost:8280 | |
| Katta API | http://hub.localhost:8280 | http://hub.localhost:8280/api/config |
| Keycloak | http://keycloak.localhost:8380 | http://keycloak.localhost:8380/realms/cryptomator/.well-known/openid-configuration |
| MinIO Console | http://minio.localhost:9101 | |
| MinIO S3 API | http://minio.localhost:9100 |
The hostnames are subdomains of localhost, which resolve to the loopback address on the host as specified in
RFC 6761, and to the containers through network aliases
inside the Docker network. Therefore, the same URLs work in the browser on the host and in the containers, such as for the issuer of tokens.
Browsers and recent versions of curl resolve subdomains of localhost without DNS, but the system resolver of macOS does not. For other clients on the host, add the hostnames to /etc/hosts:
127.0.0.1 hub.localhost keycloak.localhost minio.localhost
Tip
To access with Katta Desktop over plain HTTP (no HTTPS/TLS required) in a development or test environment, install the Katta Server (HTTP) connection profile from Preferences → Profiles.
To configure MinIO for STS storage access with the local profile, use the setup minio command of the
Katta Admin CLI:
katta setup minio --hubUrl http://hub.localhost:8280 --endpointUrl http://minio.localhost:9100 --accessKey=minioadmin --secretKey=minioadmin| Path | Description |
|---|---|
compose.yaml |
Services for Katta Server, Keycloak, PostgreSQL and MinIO. |
.env |
Variables for running all services locally. |
hub |
Image for Katta Server. |
minio |
Image for MinIO. |
minio-setup |
Image for the jobs configuring and tracing MinIO. |
keycloak |
Self-signed certificate for HTTPS of Keycloak. For development only. |
setup |
Default MinIO policies. |
Licensed under the GNU Affero General Public License v3.0.