Skip to main content

Configuring S3 after an update

warning

On September 29, 2023, a major S3 update was released. Previously created users, method calls to the Swift API (old) and Object Storage API (old), etc., will stop working on October 5, 2027, at 11:00 (UTC+3). Some features will no longer be supported; for details, see the Unavailable features section.

We recommend using the S3 API. Update your storage settings in advance.

If you had buckets created before the S3 update, transfer them to a project to continue working with S3 in the control panel.

The most significant changes in storage operation are:

Migrate buckets to a project

Without transferring to a project, you will not be able to work with the storage in the control panel.

You can migrate your storage only once and as a whole (to one project). It is not possible to distribute old buckets across different projects. You will be able to create new buckets in different projects.

If you already have a project, you can migrate the buckets to it or create a new one.

  1. In the control panel, click Products in the top menu and select S3. When you open the section for the first time after September 29, 2023, the bucket transfer page will open.
  2. Select Use an existing project.
  3. Select the project to which you want to transfer the buckets and click Transfer.

Configure S3

  1. Configure storage access for users.
  2. Configure the bucket access policy.
  3. If you use the API or FTP, update the access keys and URL.
  4. If you use CDN, edit the CDN resource.
  5. Verify that you have replaced the domains with the new ones.
  6. Delete legacy storage users.

1. Configure storage access for users

S3 now supports user types and roles:

  • access to S3 via the control panel will be available to control panel users whose role allows access to the entire account or to the project where the buckets were transferred;
  • access to the API is carried out through service users instead of storage users (which were created in S3 → **Users **). Legacy users will continue to work and will be disabled later. Creating new users of this type is no longer supported.

You can add new users in the Control Panel Users and Service Users sections.

For users with the object_storage_user, s3.user, and s3.bucket.user roles, access is determined solely by the access policy; if it is not configured, the user will not have access to the bucket. For more information about how different roles work in the storage, see the Manage access to S3 guide.

2. Configure a bucket policy

You can create a bucket access policy via the control panel. To create an access policy via the API, refer to the AWS S3 documentation.

When configuring the policy, take into account permissions within the role model; for details, see the Manage access to S3 guide.

Learn more about access policies in the Access policy section.

3. Update access keys and URL

Learn more about authorization in the S3 API documentation.

  1. Issue an S3 key to the service user. You can also issue a key via the IAM API.

  2. In your requests, replace the URL and use the key to authenticate using the new scheme:

    • AWS_ACCESS_KEY_ID — value of the Access key field from the S3 key;
    • AWS_SECRET_KEY — value of the Secret key field from the S3 key;
    • URL — s3.<pool>.storage.selcloud.ru, where <pool> is the pool where S3 is located (for example, ru-1).

4. Change the CDN resource

If you use S3 as an origin for CDN, edit the CDN resource.

  1. In the control panel, click Products in the top menu and select CDN.
  2. In the CDN resources section, open the CDN resource page → Origin tab.
  3. In the Domain field, replace the specified domain with the bucket public domain formatted as <uuid>.selstorage.ru.
  4. In the Hostname block, in the Origin Hostname field, specify the bucket public domain without protocol and port. By default, port 80 is used.

5. Check domains

Make sure you are using the new domains everywhere.

Learn more about domains in the Domains in S3 guide.

Used forOld domainNew domain
Public access *****.selcdn.ru<uuid>.selstorage.ru
Swift APIapi.selcdn.ruswift.<pool>.storage.selcloud.ru
S3 API
  • s3.storage.selcloud.ru/<bucket_name> (Path-Style)
  • <bucket_name>.s3.storage.selcloud.ru (Virtual Hosted)
  • s3.<pool>.storage.selcloud.ru/<bucket_name> (Path-Style)
  • <bucket_name>.s3.<pool>.storage.selcloud.ru (Virtual Hosted)
FTPftp.selcdn.ruftp.<pool>.storage.selcloud.ru
Domain for DNS records *****.selcdn.ruaccess.<pool>.storage.selcloud.ru

6. Delete legacy storage users

  1. In the control panel, click Products in the top menu and select S3.
  2. Go to the Control Panel Users section.
  3. On the user card, click → Delete.

Unavailable features

Method calls to Swift API (old) and Object Storage API (old) will stop working on October 5, 2027, at 11:00 (UTC+3). Use alternative capabilities in the S3 API, Object Storage API, or the control panel.

Unavailable featuresAlternative
AuthenticationAuthorization via v1 protocol (GET /auth/v1.0, headers X-Auth-User and X-Auth-Key) Use AWS Signature V4 or AWS Signature Version 2 signatures and S3 keys in the S3 API
Authorization via v2 protocol (POST /v2.0/tokens, passwordCredentials)
Traffic statisticsUploaded and downloaded data volume statistics at the account and container level, response headers X-Received-Bytes and X-Transfered-BytesReceive export of logs via the control panel or Object Storage API
rx_bytes and tx_bytes fields in the JSON response when retrieving a list of containers
Managing HTTP object headers
  • Access-Control-Allow-Origin — allowed origin for cross-domain requests;
  • Access-Control-Max-Age — cache time for preflight requests;
  • Access-Control-Allow-Methods — allowed HTTP methods for CORS;
  • Access-Control-Allow-Credentials — permission to pass credentials;
  • Access-Control-Expose-Headers — headers accessible to the client;
  • Access-Control-Allow-Headers — allowed headers in the request;
  • Strict-Transport-Security — enforced HTTPS usage for the container
Use CORS in the control panel or via the S3 API (Bucket CORS). CORS configuration is performed at the bucket level
DomainsAccount public domain ( * ****.selcdn.ru) — domain with distributed content cachingUse S3 API domains
Temporary download linksGenerating temporary signed download links via HMAC-SHA1 (temp_url_sig, temp_url_expires, secret key via X-Account-Meta-Temp-URL-Key / X-Container-Meta-Temp-URL-Key) Use Presigned URL in the S3 API, which uses a different signing mechanism (AWS Signature V4). Refactoring code that uses TempURL will be required
File query parametersQuery parameter ?filename=file_name — force file download by browser instead of opening (header Content-Disposition: attachment) ✗
XML response format when requesting a file list (?format=xml) ✗