Manage a storage account
Follow a storage account's usage, change its endpoint, CORS origins and advanced settings, read its audit log, and delete it.
Requires: s3storageaccounts/write, s3/audit/read
Open S3 Storage in the sidebar and choose the storage account. Its tabs are Overview,
Configuration (shown to people who may change the account), Buckets, Access Keys,
Access Control, Audit, Operations, Activity and Danger Zone (shown to people who
may delete it). A storage account has no stop or start. Changes need s3storageaccounts/write.
The overview
| Card | What it shows |
|---|---|
| Endpoint | The Hostname the account is served on |
| Storage | The Backend and the Quota |
| Compute | The server's CPU and Memory |
| Storage usage | A gauge of what is stored against the quota, and the number of buckets |
The server measures its usage every five minutes. Between measurements the card may say Usage data is stale; it says Could not load usage. Storage pod may be unreachable. when the figures cannot be read at all.
The quota and the server's CPU and memory cannot be changed in the portal after creation.
Networking
Configuration → Networking & Security holds:
- Endpoint Hostname — empty for
<account>.s3.example.com, or a custom hostname with a DNS record that points it at the platform's ingress. Clients must use the new endpoint after a change. - HTTP only — serves the endpoint without TLS. Meant for development clusters only.
- Additional CORS origins — see CORS.
Choose Save. Saving a change to the hostname, the TLS settings or the CORS origins restarts the account's server: the old one stops before the new one starts, so the endpoint is briefly unavailable. A change to HTTP only alone does not restart the server.
Advanced settings
Configuration → Advanced holds:
- Allow S3 API bucket lifecycle — whether S3 clients may create and delete buckets. With it
off,
CreateBucketandDeleteBucketare refused and buckets are managed on the Buckets tab. Saving a change restarts the server, as above. - Retain data on delete — whether the volume is kept when the account is deleted; see Delete a storage account.
Read the audit log
The Audit tab lists the S3 requests made against the account, newest first: Time,
Principal, Operation (such as PutObject), Bucket, Object, Status and
Bytes. Principal is the principal ID behind the credential: for an access key, the managed
identity it belongs to — the account's own for keys issued in the portal; for temporary
credentials, the person who got them, which includes your own work in the bucket browser.
Filter by From, To, Principal id and Operation, set the Page size and choose Apply; Load older events pages back in time. The Bucket field does not narrow the list.
Entries are kept for 90 days. The server sends them in batches and, under heavy load, can drop
some, so the log is not a complete record. Reading it needs s3/audit/read, which Owner and
Contributor have; Storage Reader and Storage Operator do not.
Delete a storage account
On the Danger Zone tab, choose Delete and type the account's name to confirm. This needs
s3storageaccounts/delete, which s3storageaccounts/write includes. The server is stopped, the
endpoint stops answering, and the account's identity is deleted. Its access keys are removed
within about 15 minutes and until then still work against the other storage accounts in the
boundary — see Disable or delete a key.
What happens to the data depends on Retain data on delete, which the confirmation repeats:
- On — the volume and every object on it are kept in the resource group, detached from any account. A new account with the same name does not get it back; recovering the data takes a platform administrator. The volume stays until an administrator removes it or the resource group is deleted.
- Off — the volume and all data are destroyed.
Warning
An account that was created with Retain data on delete off loses its volume when it is deleted, even if the setting was turned on later. The setting only protects the data of an account that was created with it on.
With the CLI
stsh s3 account list -g my-resource-group
stsh s3 account get my-storage -g my-resource-group
stsh s3 usage my-storage -g my-resource-group
stsh s3 audit my-storage -g my-resource-group
stsh s3 account delete my-storage -g my-resource-group