Overview
The object store is the S3-compatible service that self-hosted Onyx bundles for file storage: chat attachments, uploads, connector attachments, Craft snapshots and the other files Onyx keeps outside PostgreSQL. It runs SeaweedFS as a single process and replaces the bundled MinIO. Upgrading from MinIO is automatic. See Object Store Migration. You can use AWS S3, Google Cloud Storage, Azure Blob Storage, or any S3-compatible service instead. SetFILE_STORE_BACKEND and the matching variables from the configuration
reference and leave the object store disabled.
Docker Compose
Theobject-store service is part of the s3-filestore compose profile, which .env enables by default.
The app reaches it at S3_ENDPOINT_URL=http://object-store:8333 and authenticates with the S3_AWS_ACCESS_KEY_ID /
S3_AWS_SECRET_ACCESS_KEY pair, which the store uses as its admin credentials. The installer generates that pair.
If you write .env by hand, change it from the minioadmin default before going to production.
Data lives in the object_store_data volume. Only the S3 port leaves the container: the SeaweedFS filer,
master and volume ports accept requests without credentials, so they listen on loopback inside the container.
Helm
TheobjectStore section of values.yaml runs the store as a single-replica Deployment with its own PVC,
<fullname>-object-store,
where <fullname> is the release name when it contains onyx and <release>-onyx otherwise.
objectStore.enabled defaults to the value of minio.enabled,
so an install that already disables MinIO keeps the object store off as well. The examples set both to be explicit.
values.yaml
restricted Pod Security Standard. On OpenShift,
set objectStore.podSecurityContext to an empty map so the cluster assigns the user.
Its admin credentials are the s3_aws_access_key_id and s3_aws_secret_access_key keys of auth.objectstorage,
so no new secrets are needed.
The PVC carries helm.sh/resource-policy: keep and survives upgrade, rollback and uninstall.
Delete it yourself when you no longer need the data.
Using your own storage
To run without the object store, disable it and point the app at your storage:values.yaml
s3-filestore from COMPOSE_PROFILES and set the same variables in .env.