mrkeyoor.com_
Thu 01 Oct 20:43 UTC
Self-Hostedevaluationupdated 26 Aug 2026

rustfs review

RustFS is an Apache-licensed object store that speaks the S3 API and also supports OpenStack Swift. It targets teams that want to keep object data on their own hardware without adopting MinIO's AGPL license.

+313stars / 7d
Verdict

Our RustFS build and test commands each spent 900 seconds compiling without finishing, while the README still marks distributed mode under testing, so it is an evaluation candidate rather than a safe drop-in storage replacement. Its Apache 2.0 license, S3 surface, Docker image, and active development justify a lab trial. Keep durable production data on a more established system until RustFS passes your failure, recovery, and upgrade tests.

We ran it

Lab card: what happened when we ran rustfsScreenshot of rustfs (rustfs.com/download)
Install✓ · 43s1222 packages
Build✗ timed out · 900s
Tests✗ timed out · 900sran, no count parsed
Repo2385 files~1,221,515 lines of source · 53.2 MB · 28 CI workflows · Dockerfile

Answers from our run

Does rustfs build from source?

Dependencies installed in 43 seconds (1222 packages), and the build failed. We cloned commit 3b0a28d into a clean Debian container with 3 CPUs and no project-specific setup.

Do rustfs's tests pass?

We could not finish them: the suite was still running after 15 minutes in our container.

Who should not use rustfs?

Teams replacing proven storage without a long acceptance test: the README labels distributed mode and lifecycle management as under testing.

What are the alternatives to rustfs?

MinIO, Ceph, SeaweedFS. Our RustFS build and test commands each spent 900 seconds compiling without finishing, while the README still marks distributed mode under testing, so it is an evaluation candidate rather than a safe drop-in storage replacement.

Setup2/5Docker is short, but source build exceeded 900 seconds
Docs4/5Good deployment choices and unusually clear mount warnings
Community4/5Fresh push and detailed, actively discussed operational reports
Maturity2/5Release candidate with core distributed features under testing

Discussed on

  1. hnRust MinIO Alternative38 points
  2. hnShow HN: RustFS – Migrate from MinIO via simple binary replacement10 points
  3. hnRustFS vulnerability: Hardcoded token with privileged access6 points
  4. hnHardcoded Auth Token in RustFS (CVE-2025-68926)5 points
  5. hnRustFS: High-performance distributed object storage for MinIO alternative5 points

Who it’s for

Storage teams evaluating an Apache 2.0 S3-compatible server for private infrastructure.
Rust shops willing to test a release candidate against their exact clients and failure modes.
Operators who need single-node object storage now and can stage distributed use separately.
OpenStack users who need Swift access and Keystone authentication in the same server.

Who it’s NOT for

Teams replacing proven storage without a long acceptance test: the README labels distributed mode and lifecycle management as under testing.
Operators who require unattended KMS recovery today: issue #6574 reports API-configured KMS becoming unconfigured after a restart on 1.0.0-rc.3.
Clusters that cannot tolerate a node-loss regression: issue #6286 reports one unreachable host causing every surviving Kubernetes endpoint to fail readiness.
Workloads where listed objects must always be immediately readable: issue #6218 documents keys that appeared in listings while HEAD and GET returned 404.
Developers expecting a quick source build on modest CI machines: both our build and test commands were still compiling when they reached 900 seconds.

Setup reality

Our sandbox installed 1,222 Rust packages in 43 seconds. The build did not finish within the 900-second limit, and the test command also timed out at 900 seconds. Its final lines were still compiling RustFS crates, the e2e_test crate, and tokio-test; the log did not show a test failure.

The Docker path needs writable data, log, and optional TLS mounts for UID/GID 10001. A real deployment also needs admin credentials, persistent disks, TLS, and deliberate choices around erasure coding, identity, notifications, and monitoring. The full Compose file can add Grafana, Prometheus, and Jaeger.

Single-node Docker is short. Distributed mode, lifecycle management, and KMS are marked under testing in the README, so production evaluation should include node loss, restart, healing, upgrade, and client compatibility drills.

RustFS is an S3 server still proving its distributed path

RustFS stores objects behind an S3-compatible API and includes a browser console, bucket versioning, replication, notifications, bitrot protection, and OpenStack Swift access. The code is Apache 2.0, which is a concrete reason to consider it if MinIO's AGPL terms do not suit your distribution or hosting model. RustFS also documents Keystone authentication and optional OIDC role claims for organizations already invested in those identity systems.

The status table deserves more attention than the feature list. Single-node mode, core S3 operations, versioning, and replication are marked available. Distributed mode, lifecycle management, and KMS are marked under testing, while some Swift metadata operations are partial. That is an unusually useful admission for a storage project. It also means the safest first deployment is a disposable or replicated workload, not the only copy of business data.

Docker starts quickly if UID 10001 owns every mount

The shortest path maps ports 9000 and 9001, plus data and log directories, into the official container. RustFS runs there as non-root UID and GID 10001. Host bind mounts must be writable by that account. TLS certificate directories need the same treatment. Podman users can apply its relabel and ownership flags, while the simple Compose file includes a helper for named volumes.

That setup detail is easy to miss and likely to produce a permission error before the server opens a port. The README repeats the warning for data, logs, and TLS, which is good documentation. Default console credentials are rustfsadmin for both user and password, so changing them and putting TLS in front of the service belong in the first serious deployment, not a later hardening pass.

The larger Compose definition is a platform bundle. It can include Grafana, Prometheus, Jaeger, Redis, and Nginx through services or profiles. Kubernetes users get Helm charts, while Nix and a one-line installation script cover other routes. Those choices still leave operators responsible for drives, erasure sets, scanner behavior, health endpoints, outbound notification policy, and persistent configuration.

What happened when we ran it

Our run installed 1,222 packages in 43 seconds on a fresh container with 3 CPUs and 12 GB of RAM. RustFS is a very large workspace: the checked-out repository contained 2,385 files and about 1,221,515 lines of source. It included 28 CI workflow files, a Dockerfile, and a Compose file. The installation step was quick for that scale.

Compilation was another matter. The build command reached our 900-second limit and timed out. The test command also timed out after 900 seconds. Its final output was still compiling dependencies and project crates, including rustfs, rustfs-log-analyzer, rustfs-scanner, rustfs-s3select-query, rustfs-rio-v2, and e2e_test, followed by tokio-test. We saw no assertion failure or compiler error in the supplied tail. The suite simply did not reach execution before the cutoff.

That result does not prove the project cannot build. It says a clean build and test cycle exceeded 15 minutes each on our constrained machine, which is material for contributor setup and CI sizing. The repository had no top-level tests directory, though test-related crates and extensive workflows were present. Use binary images for evaluation, and budget a much larger runner or cached Rust build for source work.

Open reports hit the failure modes storage buyers care about

Issue #6218 describes 16 keys on a versioned, object-locked bucket that appeared through list operations but returned 404 to HEAD and GET. The reporter saw some of them during normal operation on release candidates rc.1 and rc.2, and background healing did not restore them. This evidence comes from one user's environment rather than our lab. The list-versus-read disagreement is serious enough to add an automated consistency scan to any trial.

Issue #6286 covers a 4-node Kubernetes deployment where powering off one host slowed readiness on the surviving nodes beyond a 3-second probe timeout. Kubernetes then removed all 4 endpoints and S3 traffic returned 503, even though the erasure set retained quorum. Stopping only the peer process did not cause the same result. That specificity makes node and network failure drills mandatory before accepting the distributed mode claim.

Encryption operations need the same skepticism. Issue #6574 reports that KMS configured through the admin API worked and persisted to storage, then came back as unconfigured after a restart on 1.0.0-rc.3. The report includes a startup warning showing that configuration loading occurred before storage initialization. RustFS already labels KMS under testing, so encrypted buckets should remain out of scope until restart recovery passes in your environment.

The August 26 push is fresh, while GitHub has no release object

The repository was pushed on August 26, 2026, and current issues and pull requests were moving on August 25 and 26. GitHub reported 31 open issues and pull requests. There was no object returned by the latest-release API, although repository tags included 1.0.0-rc.3 and the README's Docker example used that tag. Operators should pin an image digest or explicit tag rather than rely on latest.

RustFS is worth testing for teams that want an Apache-licensed S3 server and can keep an established store as the source of truth during evaluation. The console, container, observability pieces, and detailed runbooks show real operational intent. The current status table and issue evidence point to the same conclusion: single-node trials are reasonable, while distributed durability claims still need independent proof with your data shape, clients, upgrades, and failure schedule.

Alternatives

ProjectWhat it isPick it when
MinIO gh↗A widely deployed S3-compatible object store with mature operational tooling under AGPLv3.pick this instead when operational history and S3 ecosystem familiarity outweigh the license difference.
CephA distributed storage system covering object, block, and file workloads.pick this instead when you need a mature multi-protocol storage platform and can operate its larger cluster footprint.
SeaweedFS gh↗A distributed storage system with S3 access, file serving, and a simpler scaling model.pick this instead when mixed file and object access matters more than RustFS's Rust implementation.

What people are saying

  1. [github-trending] rustfs/rustfs

Sources

  1. RustFS README
  2. Ghost object report
  3. Distributed readiness outage report
  4. KMS restart persistence report

More self-hosted reviews

Spun · bankmcp · 8086-xcheck-system · fanzha-ai-proxy · homarr · search-plugins · the whole board →