Create a storage account
Create an S3 storage account in a resource group, choose its quota, the resources of its server, its endpoint and who may create buckets.
Requires: s3storageaccounts/write
Creating a storage account needs s3storageaccounts/write in the resource group; the Owner,
Contributor and Storage Operator roles have it.
Open the wizard
In the portal at https://portal.example.com, open S3 Storage in the sidebar and choose Create Storage Accounts. The Create a Storage Account wizard has six steps: Basic Configuration, Storage, Compute, Networking, Settings and Review.
Basic configuration
- Storage Account Name — 3 to 50 characters: lowercase letters, digits and hyphens, starting with a letter and ending with a letter or digit. The name is part of the account's endpoint, so it must be unique across the whole platform; creating an account with a name that is already in use fails. It cannot be changed later.
- Boundary, Cluster and Resource group — where the account runs. Each is filled in for you when there is only one choice.
Storage
- Backend — PVC, a volume in the cluster; it is the only choice.
- Quota — the size of the account's volume and the limit for uploads, as a Kubernetes quantity
such as
100Gi(the default) or500Gi. The volume is created at this size and does not grow later, so choose room to spare. It uses the cluster's default storage class. How the quota is enforced is in Names and limits. - Retain data on delete — on by default. It decides whether the volume, and every object on it, is kept or destroyed when the account is deleted. Decide here: an account created with it off loses its volume on deletion even if you turn it on later — see Delete a storage account.
Compute
CPU (default 500m) and Memory (default 512Mi) are Kubernetes quantities for the
account's S3 server. Each value is both what the server is guaranteed and its limit.
Networking
- Endpoint Hostname — leave it empty to use
<name>.s3.example.com, which the field shows as a hint. A custom hostname needs a DNS record that points it at the platform's ingress. - TLS Provider — Let's Encrypt, the default, has a certificate issued for the hostname by the installation's certificate issuer. The ClusterIssuer field must be filled in, but the platform does not use its value. Existing Secret serves a certificate you already have: TLS Secret Name names the Kubernetes Secret, in the resource group's namespace, that holds it.
- HTTP only — serves the endpoint without TLS. Meant for development clusters only: access keys and data then cross the network unencrypted.
- Additional CORS origins — origins such as
https://app.example.com(scheme, host and an optional port; no path) whose web pages may call the account directly from the browser. The portal's own origin is always allowed. See CORS.
Settings
Allow S3 API bucket lifecycle — on by default: S3 clients may create and delete buckets
through the S3 API. Turn it off to keep bucket management in the portal; S3 clients then get an
error on CreateBucket and DeleteBucket. You can change it later.
Review and create
Review shows the settings. Choose Submit. The account appears in the list as Creating and turns Running when its server is ready, its volume is attached and its endpoint has an address — see Statuses. The platform gives the account an identity of its own while it is created; issuing access keys works once that is done.
With the CLI
The CLI creates an account from a JSON file. The cluster ID is in stsh cluster list.
{
"clusterId": "<cluster-id>",
"spec": {
"storage": { "backend": "pvc", "quota": "100Gi", "storageClass": "", "retainOnDelete": true },
"compute": { "cpu": "500m", "memory": "512Mi" },
"endpoint": { "hostname": "", "provider": "LetsEncrypt", "issuer": "", "httpOnly": false, "sslCertificateSecretName": "" },
"cors": { "additionalOrigins": [] },
"allowS3ApiBucketLifecycle": true
}
}stsh s3 account create my-storage -g my-resource-group --file account.json