Skip to content
Stackship documentation Svenska

S3 storageUsers

S3 storage

Store files as objects in S3-compatible storage accounts, each with its own server, volume and HTTPS endpoint.

S3 storage keeps files as objects in buckets and serves them over the S3 API, so the AWS CLI, the AWS SDKs and other S3 clients work with it. In the portal it is under S3 Storage in the sidebar.

Storage accounts

A storage account is the resource you create in a resource group. Each account gets:

  • its own S3 server, running as one pod;
  • its own volume, whose size is the account's quota;
  • its own HTTPS endpoint, by default https://<account>.s3.example.com.

Accounts do not share servers, volumes or buckets. An account's name is part of its endpoint, so it is unique across the whole platform.

Buckets and objects

A bucket holds objects, addressed by a key such as images/2026/logo.png; folders in the portal are key prefixes. Buckets belong to one account, and their names are unique within it. You create buckets in the portal, or — when the account allows it — with the S3 API. See Buckets.

Requests use path-style addresses — https://<endpoint>/<bucket>/<key> — and must be signed with AWS Signature Version 4. Anonymous access is not offered; a presigned URL is the way to hand out a single object. See Connect to a storage account.

Credentials

Every S3 request is signed with a credential:

  • Access keys are long-lived: an access key ID and a secret that is shown once, when you issue the key. Use them for applications and tools. See Access keys.
  • Temporary credentials last from 15 minutes to 12 hours and are issued through the platform's API. The portal's bucket browser uses them for you.

Platform roles decide who may manage accounts, buckets and keys and who may get temporary credentials. They do not narrow what a credential can do once it is used: any valid credential has full access to the buckets and objects of the account, and an access key has that access to every storage account in its boundary — see What a key can do.

Quota and usage

The quota is both the size of the account's volume and the limit for uploads. The server measures how much is stored every five minutes, and refuses an upload that would take the account past 99 % of the quota. See Names and limits.

Data and deletion

The platform takes no backups or snapshots of a storage account; the objects exist only on its volume. When you delete an account, Retain data on delete decides whether the volume is kept or destroyed. See Delete a storage account.

Pages