Configuring S3 after an update
On September 29, 2023, a major S3 update was released. Previously created users, method calls to the Swift API (old) and Object Storage API (old), etc., will stop working on October 5, 2027, at 11:00 (UTC+3). Some features will no longer be supported; for details, see the Unavailable features section.
We recommend using the S3 API. Update your storage settings in advance.
If you had buckets created before the S3 update, transfer them to a project to continue working with S3 in the control panel.
The most significant changes in storage operation are:
- new authorization for all APIs for working with storage and new access endpoints;
- a new bucket public domain (a domain formatted as
<uuid>.selstorage.ru). This domain will replace the account's personal domain (a domain formatted as* ****.selcdn.ru); - migration of S3 to projects;
- a new access management model: full role-based access control support and the introduction of bucket access policies;
- unavailability of some legacy features.
Migrate buckets to a project
Without transferring to a project, you will not be able to work with the storage in the control panel.
You can migrate your storage only once and as a whole (to one project). It is not possible to distribute old buckets across different projects. You will be able to create new buckets in different projects.
If you already have a project, you can migrate the buckets to it or create a new one.
To an existing project
To a new project
- In the control panel, click Products in the top menu and select S3. When you open the section for the first time after September 29, 2023, the bucket transfer page will open.
- Select Use an existing project.
- Select the project to which you want to transfer the buckets and click Transfer.
Configure S3
- Configure storage access for users.
- Configure the bucket access policy.
- If you use the API or FTP, update the access keys and URL.
- If you use CDN, edit the CDN resource.
- Verify that you have replaced the domains with the new ones.
- Delete legacy storage users.
1. Configure storage access for users
S3 now supports user types and roles:
- access to S3 via the control panel will be available to control panel users whose role allows access to the entire account or to the project where the buckets were transferred;
- access to the API is carried out through service users instead of storage users (which were created in S3 → **Users **). Legacy users will continue to work and will be disabled later. Creating new users of this type is no longer supported.
You can add new users in the Control Panel Users and Service Users sections.
For users with the object_storage_user, s3.user, and s3.bucket.user roles, access is determined solely by the access policy; if it is not configured, the user will not have access to the bucket. For more information about how different roles work in the storage, see the Manage access to S3 guide.
2. Configure a bucket policy
You can create a bucket access policy via the control panel. To create an access policy via the API, refer to the AWS S3 documentation.
When configuring the policy, take into account permissions within the role model; for details, see the Manage access to S3 guide.
Learn more about access policies in the Access policy section.
3. Update access keys and URL
S3 API
Swift API
FTP
Learn more about authorization in the S3 API documentation.
-
Issue an S3 key to the service user. You can also issue a key via the IAM API.
-
In your requests, replace the URL and use the key to authenticate using the new scheme:
4. Change the CDN resource
If you use S3 as an origin for CDN, edit the CDN resource.
- In the control panel, click Products in the top menu and select CDN.
- In the CDN resources section, open the CDN resource page → Origin tab.
- In the Domain field, replace the specified domain with the bucket public domain formatted as
<uuid>.selstorage.ru. - In the Hostname block, in the Origin Hostname field, specify the bucket public domain without protocol and port. By default, port 80 is used.
5. Check domains
Make sure you are using the new domains everywhere.
Learn more about domains in the Domains in S3 guide.
6. Delete legacy storage users
- In the control panel, click Products in the top menu and select S3.
- Go to the Control Panel Users section.
- On the user card, click → Delete.
Unavailable features
Method calls to Swift API (old) and Object Storage API (old) will stop working on October 5, 2027, at 11:00 (UTC+3). Use alternative capabilities in the S3 API, Object Storage API, or the control panel.
Swift API (old)
Object Storage API (old)