Skip to content
Stackship documentation Svenska

S3 storageUsers

Buckets

Create buckets in a storage account, browse and upload objects in the portal, and delete buckets.

Requires: s3buckets/write, s3sts/issue

Open S3 Storage in the sidebar, choose the storage account and go to its Buckets tab. It lists the account's buckets with their Source — Portal or S3Api, depending on how they were created — the first characters of their Owner's principal ID, and when they were Created.

Create a bucket

Creating a bucket needs s3buckets/write; the Owner, Contributor and Storage Operator roles have it.

  1. On the Buckets tab, choose Create bucket.
  2. Enter the Name: 3 to 63 characters, lowercase letters, digits and hyphens, starting and ending with a letter or digit. Dots are not allowed, and neither is a name shaped like an IPv4 address. The name must be unique in the account.
  3. Choose Create.

The bucket is empty and ready at once. There are no settings per bucket: no versioning, no bucket policy and no lifecycle rules. Who can use it is decided by credentials — see Access keys.

S3 clients can create buckets too, with CreateBucket, while the account's Allow S3 API bucket lifecycle is on — see Advanced settings. Those buckets show the source S3Api.

Browse a bucket

Choose a bucket on the Buckets tab to open it. The portal gets temporary credentials for you and talks to the account's endpoint straight from your browser, so browsing needs s3sts/issue (Storage Operator, Contributor, Owner). Until the account's endpoint is ready, the page says The storage endpoint is still being provisioned. Objects will appear once it is ready.

  • Folders are key prefixes: choose one to open it. New folder creates one in the current location. A folder's actions rename it — its objects are moved to the new name — or delete it with everything inside.
  • Upload, or drag files onto the page, uploads to the current folder. Files of 100 MB and more are sent in parts; Uploads shows the progress, and such an upload can be cancelled while it runs.
  • An object's actions download or delete it. Select several objects and choose Delete (n) to delete them together.
  • Refresh reloads the list.

Bucket permissions

Permissions, in the bucket's page, lists role assignments on the bucket and lets you add them.

Warning

Role assignments on a single bucket are not applied: they neither grant nor restrict anything, in the portal or through the S3 API. Assign roles on the storage account's resource group or the boundary instead — see Permissions.

Delete a bucket

Deleting a bucket needs s3buckets/delete, which s3buckets/write includes.

  1. Empty the bucket first — delete its objects in the bucket browser, or with an S3 client, for example aws s3 rm s3://<bucket> --recursive.
  2. On the Buckets tab, choose the delete button on the bucket's row, then Delete.

With Allow S3 API bucket lifecycle on, S3 clients can delete buckets with DeleteBucket as well.

Important

The platform does not check that the bucket is empty. Deleting a bucket that still holds objects removes the bucket, but its objects stay on the account's volume and keep counting toward the account's usage. They are out of reach until a bucket with the same name is created in the account again; that bucket then holds them. A DeleteBucket through the S3 API removes the bucket from the platform before the server looks at its contents, so the same applies there.

With the CLI

bash
stsh s3 bucket list my-storage -g my-resource-group
stsh s3 bucket create my-storage my-bucket -g my-resource-group
stsh s3 bucket get my-storage my-bucket -g my-resource-group
stsh s3 bucket delete my-storage my-bucket -g my-resource-group