Manage S3 access
Access to S3 resources is regulated by:
- projects — determine access within an isolated resource group;
- roles — determine access for control panel users, service users, and groups within an account and a project.
- access policy — determines access within a bucket.
When an S3 action request is received, the user role is checked first. If the role is:
-
does not allow the action — access is denied;
-
allows the action — the presence and settings of the bucket policy are checked. If the bucket policy:
- not created — access will be granted to all users with access within roles, except users with the object_storage_user, s3.user, and s3.bucket.user roles;
- is created — everything not allowed by the policy rules is denied.
To access via API, automation tools, and FTP, use keys.
Learn more about access management in the Access management in Selectel products instructions.
Access within projects
All resources in S3 are created in a specific project. You can group resources by different projects and configure user permissions depending on which projects they need access to.
Access within roles
Access to S3 is provided by S3 roles and global roles. Learn more about role types in the Role reference instructions.
S3 roles
s3.admin
The s3.admin role provides access to manage S3 within a project. It does not have access to S3 in other projects or to other products in its project.
* Managing access policies and bypassing temporary Object Lock retention in the control panel is unavailable.
s3.user
The s3.user role provides access to an S3 bucket if an access policy is configured in it that allows access to the bucket for this user. The level of access is determined by the access policy settings. It does not have access to S3 in other projects or to other products in its project.
s3.bucket.user
The s3.bucket.user role provides access to an S3 bucket if an access policy is configured in it that allows access to the bucket for this user. The level of access is determined by the access policy settings. It does not have access to S3 in other projects or to other products in its project.
object_storage.admin
The object_storage:admin role will soon be removed, and it cannot be assigned to new users. Existing users with the object_storage:admin role continue to work.
Legacy version of the s3.admin role. Has identical permissions.
object_storage_user
The object_storage_user role will soon be removed, and it cannot be assigned to new users. Existing users with the object_storage_user role continue to work.
Legacy version of the s3.user role. Has identical permissions.
Global roles
member
The member role provides full access to all services. It does not provide access to managing control panel users, service users, user groups, and federations.
billing
The billing role provides access to billing management without access to service management.
iam.admin
The iam.admin role provides access to user management and does not provide access to product and billing management. It does not allow you to manage your own account: change permissions, manage notifications, or delete a user. The first user with the iam.admin role is created by the Account owner.
iam.viewer
The iam.viewer role provides access to view everything managed by iam.admin.
reader
The reader role provides access to view everything managed by member in the same scope.
Keys for API access
Depending on the API type, you will need:
- IAM token for a project (X-Auth-Token). Used for access via Object Storage API and Swift API. Can be issued to service users and control panel users. To issue an IAM token to a service user, use the Get an IAM token for a project subsection in the Request authentication section of the API documentation. We recommend using an IAM token for a control panel user only for testing; learn more in the Manage IAM tokens subsection in the Manage access keys instructions;
- S3 key (EC2 key). Used to sign S3 API requests and for access via FTP. Consists of a value pair: Access Key ID and Secret Key. S3 keys can be issued to service users and control panel users. You can add it to yourself or issue it to another user.