Basalts3 api

Documentation

If you have used S3, you already know most of this. The parts that differ are listed first.

Endpoints

Path-style and virtual-host style both work. Use the regional endpoint — the global one exists for discovery and adds a redirect.

bash
https://s3.eu-central.main.13381338.xyz        # regional, use this
https://<bucket>.s3.eu-central.main.13381338.xyz  # virtual-host
https://s3.main.13381338.xyz                   # global, redirects

Credentials

SigV4 with access key and secret. Keys are scoped to a project and optionally to a bucket prefix and source network.

Compatibility matrix

FeatureStatusNotes
Multipart upload✓5 MiB–5 GiB parts, 10,000 max
Versioning✓including MFA delete
Object lock✓governance and compliance modes
Lifecycle✓transition and expiration
Presigned URLs✓GET, PUT, up to 7 days
SSE-S3 / SSE-KMS / SSE-C✓KMS keys are per-project
Cross-region replication✓with backlog metric
Conditional requests✓ETag and modified-since
Select (S3 Select)✗not implemented
Static website hosting✗use a CDN in front
Requester pays✗egress is free, so it has no meaning

Multipart tuning

The defaults in most SDKs are conservative. These settings saturate a 10 Gbit/s line on a single machine.

bash
# aws-cli
aws configure set default.s3.max_concurrent_requests 64
aws configure set default.s3.multipart_chunksize 64MB
aws configure set default.s3.multipart_threshold 128MB

# rclone
--transfers 24 --s3-chunk-size 64M --s3-upload-concurrency 32
Above about 25 Gbit/s a single host usually becomes the bottleneck before we do. Split the transfer across machines by prefix; request rate is per prefix, so a flat namespace is the usual culprit when throughput plateaus.

Lifecycle rules

json
{
  "Rules": [{
    "ID": "tier-then-expire",
    "Status": "Enabled",
    "Filter": {"Prefix": "logs/"},
    "Transitions": [
      {"Days": 30, "StorageClass": "INFREQUENT"},
      {"Days": 180, "StorageClass": "ARCHIVE"}
    ],
    "Expiration": {"Days": 2555}
  }]
}

Object lock

Compliance mode cannot be shortened by anyone, including our operators. Governance mode can, with dual authorisation, and every override lands in the audit log.

Setting a compliance retention of ten years on a petabyte is a ten-year financial commitment. The console asks you to type the resulting cost before it accepts.

Metrics

Scrape /metrics on the regional endpoint with your credentials. Request counts, latency histograms, error codes and replication backlog, per bucket.

Replication

Rules are per prefix, destination can be any region, and the backlog metric tells you how many objects and bytes are behind. RPO is typically under 60 seconds and is never guessed — it is computed from the oldest unreplicated object.