Object storage
NuPaaS provides S3-compatible object storage. Buckets belong to your organization, can be linked to one or more projects, and are reached with ordinary S3 tooling using credentials the platform issues.
Buckets
Manage buckets at /orgs/<org>/storage, or from the CLI:
platform storage buckets list
platform storage buckets create --project <projectId>
platform storage buckets credentials --bucket <bucketId>
platform storage buckets usage --bucket <bucketId>
platform storage buckets delete --bucket <bucketId>A bucket is badged by how it came to exist: org for a general organization bucket, project for one derived from a project, and custom for one you named yourself. Buckets can also be linked to and unlinked from projects after creation, so one bucket can serve several projects.
Working with objects
The Objects tab lists a bucket's contents with prefix and delimiter filtering, so a key layout using / browses like folders. Listing is paginated by continuation token. Objects can be deleted, and copied to a new key within the same bucket.
Presigned URLs
Rather than proxying bytes through the platform, uploads and downloads use presigned URLs: the platform issues a time-limited URL and your client transfers directly to storage.
- A presigned PUT URL for uploading to a key.
- A presigned GET URL for downloading a key.
Both accept an expiry in seconds and return the URL together with the time it expires.
Credentials and access keys
Requesting a bucket's credentials returns the S3 endpoint, an access key, a secret key, the bucket name and its region — enough to configure any S3 client.
Beyond that single credential, named access keys can be issued per bucket with one of three scopes:
| Parameter | Type | Description |
|---|---|---|
| read | scope | Read objects only. |
| readwrite | scope | Read and write objects. |
| admin | scope | Full control of the bucket. |
Keys can be revoked individually, and a bucket's own credentials can be rotated wholesale.
Wiring a bucket into a service
Rather than copying keys into environment variables by hand, sync a bucket's credentials into an environment. The platform writes the credential keys into that environment and reports how many variables it set and which keys they were.
Usage
Usage reporting today covers two numbers, and both are real:
| Parameter | Type | Description |
|---|---|---|
| Stored data | bytes | Total size of the objects in the bucket. |
| Objects | count | Number of objects in the bucket. |
If the bucket's active access key has become invalid, the panel says so explicitly and usage figures are shown as unavailable rather than as zero. Rotate the key from the Credentials tab and redeploy.
Not yet persisted
Three tabs in the storage panel are presentational at the moment. They accept input and update on screen, but nothing is sent to the server and changes are lost on reload:
| Parameter | Type | Description |
|---|---|---|
| Access | not persisted | Bucket access policy editing is UI-only. |
| Lifecycle | not persisted | Lifecycle rules are UI-only. No expiry or transition rule is applied to your objects. |
| CORS | not persisted | CORS rules are UI-only. Configuring one here does not permit browser access to the bucket. |
platform storage admin and platform storage publish also exist, but they are platform-operator operations and are not available to tenant organizations.