# Configuring HTTPs for Minio through nginx

**URL:** https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775
**Category:** General Discussion
**Tags:** services
**Created:** [4 May 2023 09:00 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775 "2023-05-04T09:00:29Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![din14970](https://dietpi.com/forum/user_avatar/dietpi.com/din14970/32/3444_2.png) [@din14970](https://dietpi.com/forum/u/din14970)
#### Post date: [4 May 2023 09:00 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/1 "2023-05-04T09:00:30Z")

</div>

I use nginx to redirect easy to remember domains to services on the raspberry pi, for example filebrowser.rpi4.home.local, gitea.rpi4.home.local, nextcloud.rpi4.home.local, etc. I also have a self-signed certificate for the \*.rpi4.home.local and rpi4.home.local names, which I use on all these services to set up an https connection. A typical configuration block might look like:

```auto
server {
    server_name gitea.rpi4.home.local;

    location / {
        proxy_pass http://127.0.0.1:3000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    listen [::]:443 ssl;
    listen 443 ssl;
    include snippets/self-signed.conf;
}

```

I have to modify this a bit depending on how the service is typically accessed; e.g. for nextcloud it looks a bit different.

I’m trying to do a similar thing for minio, but run into the issue that accessing the service on port 9000 actually redirects to some random port \>30000 after a 307 internal redirect. The 307 redirect actually brings me back to using http. I’ve tried using this “real” port in the nginx configuration for `proxy_pass` instead of 9000 which works to keep my https connection. However it seems this port changes periodically so the configuration stops working after a while.

Is there a way to set up nginx so that I can access minio through https with minio.rpi4.home.local, i.e. deal with the 307 redirect? I’ve looked into this obcure post: [How to make Nginx redirect 301 302 307 to new URL on same server - Server Fault](https://serverfault.com/questions/1033204/how-to-make-nginx-redirect-301-302-307-to-new-url-on-same-server) and tried something similar myself:

```auto
server {
    server_name minio.rpi4.home.local;

    listen [::]:443 ssl;
    listen 443 ssl;
    include snippets/self-signed.conf;

    location / {
        proxy_pass http://127.0.0.1:9000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto https;

        proxy_intercept_errors on;
        error_page 301 302 307 = @handle_redirects;
    }

    location @handle_redirects {
        set $minio_port 38991;
        proxy_pass http://127.0.0.1:$minio_port;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto https;
    }
}

```

Then the idea would be to try to capture the port from the `Location` header somehow in the first request and use it in the `handle_redirect` but I haven’t figured out how to do that yet. Still, just hardcoding the current port doesn’t work and I get a black page with some broken links. If I check the console, a bunch of 403 errors.

Anyways, any ideas on what could be done? Maybe there is just a way to fix the port for the minio web page? Thanks in advance.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [4 May 2023 09:18 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/2 "2023-05-04T09:18:03Z")

</div>

did you checked MinIO docs? [Configure NGINX Proxy for MinIO Server — MinIO Object Storage for Linux](https://min.io/docs/minio/linux/integrations/setup-nginx-proxy-with-minio.html)

Maybe better to ask this kind of question to MinIO on how to setup revers proxy for their application.

---

<div class="post-metadata">

### Author: ![din14970](https://dietpi.com/forum/user_avatar/dietpi.com/din14970/32/3444_2.png) [@din14970](https://dietpi.com/forum/u/din14970)
#### Post date: [4 May 2023 11:41 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/3 "2023-05-04T11:41:28Z")

</div>

Yes, I looked at the Minio docs but unfortunately what they propose doesn’t work for my case. I’ve also deployed minio on other systems with docker and have never noticed such a port switch. My gut feeling, which is of course not much to go off of, is that this is something specific to the way minio is deployed on dietpi, which is why I posed the question here.

---

<div class="post-metadata">

### Author: ![din14970](https://dietpi.com/forum/user_avatar/dietpi.com/din14970/32/3444_2.png) [@din14970](https://dietpi.com/forum/u/din14970)
#### Post date: [4 May 2023 12:12 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/4 "2023-05-04T12:12:18Z")

</div>

I think this is the relevant bit of documentation: [MinIO Console — MinIO Object Storage for Linux](https://min.io/docs/minio/linux/administration/minio-console.html#static-vs-dynamic-port-assignment). The console itself is assigned a random port on each startup. So probably on each update, the services are killed and restarted, meaning that a new port is selected. An easy solution would be if the console would always start on a fixed port.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [4 May 2023 12:22 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/5 "2023-05-04T12:22:49Z")

</div>

yes seems to be a behavior of Minio. You would need to add following to `/etc/default/minio`

```auto
MINIO_OPTS="--console-address :9001"

```

This should fix console access to port 9001

---

<div class="post-metadata">

### Author: ![Jappe](https://dietpi.com/forum/user_avatar/dietpi.com/jappe/32/1788_2.png) [@Jappe](https://dietpi.com/forum/u/Jappe)
#### Post date: [4 May 2023 12:23 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/6 "2023-05-04T12:23:15Z")

</div>

From your link:

> MinIO by default selects a random port for the MinIO Console on each server startup

and:

> You can select an explicit static port by passing the [`minio server --console-address`](https://min.io/docs/minio/linux/reference/minio-server/minio-server.html#minio.server.-console-address) commandline option when starting each MinIO Server in the deployment.

---

<div class="post-metadata">

### Author: ![din14970](https://dietpi.com/forum/user_avatar/dietpi.com/din14970/32/3444_2.png) [@din14970](https://dietpi.com/forum/u/din14970)
#### Post date: [4 May 2023 12:38 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/7 "2023-05-04T12:38:06Z")

</div>

Yep I found the answer in the source code:[DietPi/dietpi-software at 9c701dd8e3349694d7d83a6aa8c62cb9fb303b6a · MichaIng/DietPi · GitHub](https://github.com/MichaIng/DietPi/blob/9c701dd8e3349694d7d83a6aa8c62cb9fb303b6a/dietpi/dietpi-software#L10430) but also @Joulinar confirms it. Basically editing `/etc/default/minio` allows me to fix the port to one value after restarting the service, which makes it easy to configure nginx. Thanks a lot all!

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [4 May 2023 13:36 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/8 "2023-05-04T13:36:33Z")

</div>

Just to avoid a missunderstanding. This is a behavoir of MinIO themself and not something related to DietPi. But maybe we should setup a fixed console port 9001 be default 🤔

Not sure what the benefit of the random port should be.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [4 May 2023 18:46 UTC](https://dietpi.com/forum/t/configuring-https-for-minio-through-nginx/16775/9 "2023-05-04T18:46:26Z")

</div>

> [@Joulinar](#):
>
> But maybe we should setup a fixed console port 9001 be default 🤔

PR up to have it included on next release [DietPi-Software | MinIO: Use fixed web UI port and solve conflict with LMS by Joulinar · Pull Request #6364 · MichaIng/DietPi · GitHub](https://github.com/MichaIng/DietPi/pull/6364)
