# Deploy Silo on RHEL-Compatible Linux

LLMS index: [llms.txt](/llms.txt)

---

<a id="deploy-minio-on-redhat-linux"></a>
<a id="deploy-minio-rhel"></a>

This page documents deploying Silo on RHEL and binary-compatible Linux distributions.

Silo publishes RPM packages and standalone Linux archives for x86-64 and ARM64. The project does not publish a separate RHEL support-lifecycle matrix, so the inherited point-in-time release list has been removed. Use a distribution release still supported by its vendor, keep the kernel and system libraries current, and validate the exact storage and workload configuration before production use.

The procedure focuses on production-grade Multi-Node Multi-Drive (MNMD) “Distributed” configurations. <abbr title="Multi-Node Multi-Drive">MNMD</abbr> deployments provide enterprise-grade performance, availability, and scalability and are the recommended topology for all production workloads.

The procedure includes guidance for deploying Single-Node Multi-Drive (SNMD) and Single-Node Single-Drive (SNSD) topologies in support of early development and evaluation environments.

## Considerations {#considerations}

### Review Checklists {#review-checklists}

Ensure you have reviewed our published Hardware, Software, and Security checklists before attempting this procedure.

### Erasure Coding Parity {#erasure-coding-parity}

MinIO automatically determines the default [erasure coding](/operations/concepts/erasure-coding/#minio-erasure-coding) configuration for the cluster based on the total number of nodes and drives in the topology. You can configure the per-object [parity](/glossary/#term-parity) setting when you set up the cluster *or* let MinIO select the default (`EC:4` for production-grade clusters).

Parity controls the relationship between object availability and storage on disk. Use the MinIO [Erasure Code Calculator](https://min.io/product/erasure-code-calculator) for guidance in selecting the appropriate erasure code parity level for your cluster.

While you can change erasure parity settings at any time, objects written with a given parity do **not** automatically update to the new parity settings.

### Capacity-Based Planning {#capacity-based-planning}

MinIO recommends planning storage capacity sufficient to store **at least** 2 years of data before reaching 70% usage. Performing [server pool expansion](/operations/deployments/baremetal-expand-minio-deployment/#expand-minio-distributed) more frequently or on a “just-in-time” basis generally indicates an architecture or planning issue.

For example, consider an application suite expected to produce at least 100 TiB of data per year and a 3 year target before expansion. By ensuring the deployment has ~500TiB of usable storage up front, the cluster can safely meet the 70% threshold with additional buffer for growth in data storage output per year.

Consider using the MinIO [Erasure Code Calculator](https://min.io/product/erasure-code-calculator) for guidance in planning capacity around specific erasure code settings.

## Procedure {#procedure}

### 1. Download the Silo RPM {#download-the-minio-rpm}

Download the x86-64 or ARM64 RPM from [Download & Install](/download/#server), verify its published checksum, and install it:

```shell
sudo dnf install ./silo-*.rpm
```

Current Silo releases do not publish the inherited `ppc64le` or `s390x` package variants.

### 2. Review the `systemd` Service File {#review-the-systemd-service-file}

The `.rpm` package installs the following [systemd](https://www.freedesktop.org/wiki/Software/systemd/) service file to `/usr/lib/systemd/system/silo.service`:

```ini
[Unit]
Description=Silo Object Storage Server
Documentation=https://silo.pgsty.com/docs/
Wants=network-online.target
After=network-online.target minio.service
Conflicts=minio.service
AssertFileIsExecutable=/usr/bin/silo

[Service]
Type=notify

User=silo
Group=silo
ProtectProc=invisible

EnvironmentFile=-/etc/default/minio
EnvironmentFile=-/etc/default/silo
ExecStart=/usr/bin/silo server $MINIO_OPTS $MINIO_VOLUMES

# Let systemd restart this service always
Restart=always

# Specifies the maximum file descriptor number that can be opened by this process
LimitNOFILE=1048576

# Turn-off memory accounting by systemd, which is buggy.
MemoryAccounting=no

# Specifies the maximum number of threads this process can create
TasksMax=infinity

# Disable timeout logic and wait until process is stopped
TimeoutSec=infinity

# Disable killing of Silo by the kernel's OOM killer
OOMScoreAdjust=-1000

SendSIGKILL=no

[Install]
WantedBy=multi-user.target
```

### 3. Check the Service Account and Permissions {#create-a-user-and-group-for-minio}

The package installer creates `silo:silo` but does not start or enable the service. For a new deployment, give that account access to the intended data and certificate directories.

When migrating MinIO, preserve the existing data owner and configure a `silo.service` user/group drop-in using the [package migration guide](/compatibility/binary/#user). Do not recursively change existing data ownership just to rename the service. The following `silo:silo` examples apply to new deployments; use the selected existing account for a migration.

### 4. Enable TLS Connectivity {#enable-tls-connectivity}

Create or provide [Transport Layer Security (TLS)](/operations/network-encryption/#minio-tls) certificates to MinIO to automatically enable HTTPS-secured connections between the server and clients.

Place the certificates in a directory accessible by the `silo` user/group:

```shell
sudo install -d -o silo -g silo -m 0750 /opt/minio/certs
sudo install -o silo -g silo -m 0600 private.key /opt/minio/certs/private.key
sudo install -o silo -g silo -m 0644 public.crt /opt/minio/certs/public.crt
```

For local testing or development environments, you can use the MinIO [certgen](https://github.com/minio/certgen) to mint self-signed certificates. For example, the following command generates a self-signed certificate with a set of IP and DNS Subject Alternate Names (SANs) associated to the MinIO Server hosts:

```shell
certgen -host "localhost,minio-*.example.net"
```

Place the generated `public.crt` and `private.key` into the `/path/to/certs` directory to enable TLS for the MinIO deployment. Applications can use the `public.crt` as a trusted Certificate Authority to allow connections to the MinIO deployment without disabling certificate validation.

SILO uses the operating system trust store and the configured `CAs` directory to verify TLS peers when connecting to other services, such as nodes and replication targets. For a private CA, place its CA certificate in `/opt/minio/certs/CAs` and make it readable by the service account. Enabling server TLS alone does not enable client-certificate authentication.

For more specific guidance on configuring MinIO for TLS, including multi-domain support via Server Name Indication (SNI), see [Network Encryption (TLS)](/operations/network-encryption/#minio-tls). You can optionally skip this step to deploy without TLS enabled. MinIO strongly recommends *against* non-TLS deployments outside of early development.

### 5. Create the MinIO Environment File {#create-the-minio-environment-file}

Create an environment file at `/etc/default/silo`. The MinIO service uses this file as the source of all [environment variables](/reference/minio-server/settings/#minio-server-environment-variables) used by MinIO *and* the `silo.service` file.

Modify the example to reflect your deployment topology.

**Multi\-Node Multi\-Drive**

Use Multi-Node Multi-Drive (“Distributed”) deployment topologies in production environments.

```shell
# Set the hosts and volumes MinIO uses at startup
# The command uses MinIO expansion notation {x...y} to denote a
# sequential series.
#
# The following example covers four MinIO hosts
# with 4 drives each at the specified hostname and drive locations.
#
# The command includes the port that each MinIO server listens on
# (default 9000).
# If you run without TLS, change https -> http

MINIO_VOLUMES="https://minio{1...4}.example.net:9000/mnt/disk{1...4}/minio"

# Set all MinIO server command-line options
#
# The following explicitly sets the MinIO Console listen address to
# port 9001 on all network interfaces.
# The default behavior is dynamic port selection.

MINIO_OPTS="--console-address :9001 --certs-dir /opt/minio/certs"

# Set the root username.
# This user has unrestricted permissions to perform S3 and
# administrative API operations on any resource in the deployment.
#
# Defer to your organizations requirements for superadmin user name.

MINIO_ROOT_USER=minioadmin

# Set the root password
#
# Use a long, random, unique string that meets your organizations
# requirements for passwords.

MINIO_ROOT_PASSWORD=minio-secret-key-CHANGE-ME
```

**Single\-Node Multi\-Drive**

Use Single-Node Multi-Drive deployments in development and evaluation environments. You can also use them for smaller storage workloads which can tolerate data loss or unavailability due to node downtime.

```shell
# Set the volumes MinIO uses at startup
# The command uses MinIO expansion notation {x...y} to denote a
# sequential series.
#
# The following specifies a single host with 4 drives at the specified location
#
# The command includes the port that the MinIO server listens on
# (default 9000).
# If you run without TLS, change https -> http

MINIO_VOLUMES="https://minio1.example.net:9000/mnt/drive{1...4}/minio"

# Set all MinIO server command-line options
#
# The following explicitly sets the MinIO Console listen address to
# port 9001 on all network interfaces.
# The default behavior is dynamic port selection.

MINIO_OPTS="--console-address :9001 --certs-dir /opt/minio/certs"

# Set the root username.
# This user has unrestricted permissions to perform S3 and
# administrative API operations on any resource in the deployment.
#
# Defer to your organizations requirements for superadmin user name.

MINIO_ROOT_USER=minioadmin

# Set the root password
#
# Use a long, random, unique string that meets your organizations
# requirements for passwords.

MINIO_ROOT_PASSWORD=minio-secret-key-CHANGE-ME
```

**Single\-Node Single\-Drive**

Use Single-Node Single-Drive (“Standalone”) deployments in early development and evaluation environments. MinIO does not recommend Standalone deployments in production, as the loss of the node or its storage medium results in data loss.

> [!WARNING]
> **Important**
>
> SNSD deployments do not support storage expansion through adding new server pools.

```shell
# Set the volume MinIO uses at startup
#
# The following specifies the drive or folder path

MINIO_VOLUMES="/mnt/drive1/minio"

# Set all MinIO server command-line options
#
# The following explicitly sets the MinIO Console listen address to
# port 9001 on all network interfaces.
# The default behavior is dynamic port selection.

MINIO_OPTS="--console-address :9001 --certs-dir /opt/minio/certs"

# Set the root username.
# This user has unrestricted permissions to perform S3 and
# administrative API operations on any resource in the deployment.
#
# Defer to your organizations requirements for superadmin user name.

MINIO_ROOT_USER=minioadmin

# Set the root password
#
# Use a long, random, unique string that meets your organizations
# requirements for passwords.

MINIO_ROOT_PASSWORD=minio-secret-key-CHANGE-ME
```

Specify any other [environment variables](/reference/minio-server/settings/#minio-server-environment-variables) or server command-line options as required by your deployment.

For distributed deployments, all nodes **must** have matching `/etc/default/silo` environment files. Use a utility such as `shasum -a 256 /etc/default/silo` on each node to verify an exact match across all nodes.

### 6. Start the MinIO Deployment {#start-the-minio-deployment}

Use `systemctl start silo` to start each node in the deployment.

You can track the status of the startup using `journalctl -u silo` on each node.

On successful startup, the MinIO process emits a summary of the deployment that resembles the following output:

```shell
Silo Object Storage Server
Copyright: 2015-2025 MinIO, Inc.
Modifications: Copyright 2025-2026 PGSTY
License: GNU AGPLv3 - https://www.gnu.org/licenses/agpl-3.0.html
Version: RELEASE.2026-09-16T00-00-00Z (go1.27.1 linux/amd64)

API: https://minio-1.example.net:9000 https://203.0.113.10:9000 https://127.0.0.1:9000
   RootUser: minioadmin
   RootPass: minioadmin

WebUI: https://minio-1.example.net:9001 https://203.0.113.10:9001 https://127.0.0.1:9001
   RootUser: minioadmin
   RootPass: minioadmin

CLI: https://silo.pgsty.com/reference/minio-mc/#quickstart
   $ mc alias set 'myminio' 'https://minio-1.example.net:9000' 'minioadmin' 'minioadmin'

Docs: https://silo.pgsty.com/docs/
Status:         16 Online, 0 Offline.
```

You may see increased log churn as the cluster starts up and synchronizes.

Common reasons for startup failure include:

- The MinIO process does not have read-write-list access to the specified drives
- The drives are not empty or contain non-MinIO data
- The drives are not formatted or mounted properly
- One or more hosts are not reachable over the network

Following our checklists typically mitigates the risk of encountering those or similar issues.

### 7. Connect to the Deployment {#connect-to-the-deployment}

**Console**

Open your browser and access any of the MinIO hostnames at port `:9001` to open the [MinIO Console](/administration/minio-console/#minio-console) login page. For example, `https://minio1.example.com:9001`.

Log in with the **MINIO_ROOT_USER** and **MINIO_ROOT_PASSWORD** from the previous step.

<img src="/images/silo-console/console-login.webp" alt="MinIO Console Login Page" style="max-width: 600px; height: auto;" />

You can use the MinIO Console for general administration tasks like Identity and Access Management, Metrics and Log Monitoring, or Server Configuration. Each MinIO server includes its own embedded MinIO Console.

**CLI**

Follow the [installation instructions](/reference/minio-mc/#mc-install) for `mcli` on your local host. Run `mcli --version` to verify the installation. Substitute the installed `mcli` for the `mc` examples below; the arguments are unchanged.

If your MinIO deployment uses third-party or self-signed TLS certificates, copy the <abbr title="Certificate Authority">CA</abbr> files to `~/.mc/certs/CAs` to allow `mc`

Once installed, create an alias for the MinIO deployment:

```shell
mc alias set myminio https://minio-1.example.net:9000 USERNAME PASSWORD
```

Change the hostname, username, and password to reflect your deployment. The hostname can be any MinIO node in the deployment. You can also specify the hostname load balancer, reverse proxy, or similar network control plane that handles connections to the deployment.

### 8. Next Steps {#next-steps}

- [Enable TLS](/operations/network-encryption/enable-minio-tls/) before exposing the service beyond a trusted network.
- Create least-privilege users and policies through [Identity and Access Management](/administration/identity-access-management/).
- Configure [monitoring and alerting](/operations/monitoring/), then test drive, node, and site recovery procedures before production use.
