Skip to content
Stackship documentation Svenska

S3 storageUsers

Manage a storage account

Follow a storage account's usage, change its endpoint, CORS origins and advanced settings, read its audit log, and delete it.

Requires: s3storageaccounts/write, s3/audit/read

Open S3 Storage in the sidebar and choose the storage account. Its tabs are Overview, Configuration (shown to people who may change the account), Buckets, Access Keys, Access Control, Audit, Operations, Activity and Danger Zone (shown to people who may delete it). A storage account has no stop or start. Changes need s3storageaccounts/write.

The overview

Card What it shows
Endpoint The Hostname the account is served on
Storage The Backend and the Quota
Compute The server's CPU and Memory
Storage usage A gauge of what is stored against the quota, and the number of buckets

The server measures its usage every five minutes. Between measurements the card may say Usage data is stale; it says Could not load usage. Storage pod may be unreachable. when the figures cannot be read at all.

The quota and the server's CPU and memory cannot be changed in the portal after creation.

Networking

Configuration → Networking & Security holds:

  • Endpoint Hostname — empty for <account>.s3.example.com, or a custom hostname with a DNS record that points it at the platform's ingress. Clients must use the new endpoint after a change.
  • HTTP only — serves the endpoint without TLS. Meant for development clusters only.
  • Additional CORS origins — see CORS.

Choose Save. Saving a change to the hostname, the TLS settings or the CORS origins restarts the account's server: the old one stops before the new one starts, so the endpoint is briefly unavailable. A change to HTTP only alone does not restart the server.

Advanced settings

Configuration → Advanced holds:

  • Allow S3 API bucket lifecycle — whether S3 clients may create and delete buckets. With it off, CreateBucket and DeleteBucket are refused and buckets are managed on the Buckets tab. Saving a change restarts the server, as above.
  • Retain data on delete — whether the volume is kept when the account is deleted; see Delete a storage account.

Read the audit log

The Audit tab lists the S3 requests made against the account, newest first: Time, Principal, Operation (such as PutObject), Bucket, Object, Status and Bytes. Principal is the principal ID behind the credential: for an access key, the managed identity it belongs to — the account's own for keys issued in the portal; for temporary credentials, the person who got them, which includes your own work in the bucket browser.

Filter by From, To, Principal id and Operation, set the Page size and choose Apply; Load older events pages back in time. The Bucket field does not narrow the list.

Entries are kept for 90 days. The server sends them in batches and, under heavy load, can drop some, so the log is not a complete record. Reading it needs s3/audit/read, which Owner and Contributor have; Storage Reader and Storage Operator do not.

Delete a storage account

On the Danger Zone tab, choose Delete and type the account's name to confirm. This needs s3storageaccounts/delete, which s3storageaccounts/write includes. The server is stopped, the endpoint stops answering, and the account's identity is deleted. Its access keys are removed within about 15 minutes and until then still work against the other storage accounts in the boundary — see Disable or delete a key.

What happens to the data depends on Retain data on delete, which the confirmation repeats:

  • On — the volume and every object on it are kept in the resource group, detached from any account. A new account with the same name does not get it back; recovering the data takes a platform administrator. The volume stays until an administrator removes it or the resource group is deleted.
  • Off — the volume and all data are destroyed.

Warning

An account that was created with Retain data on delete off loses its volume when it is deleted, even if the setting was turned on later. The setting only protects the data of an account that was created with it on.

With the CLI

bash
stsh s3 account list -g my-resource-group
stsh s3 account get my-storage -g my-resource-group
stsh s3 usage my-storage -g my-resource-group
stsh s3 audit my-storage -g my-resource-group
stsh s3 account delete my-storage -g my-resource-group