Documentation
If you have used S3, you already know most of this. The parts that differ are listed first.
Endpoints
Path-style and virtual-host style both work. Use the regional endpoint — the global one exists for discovery and adds a redirect.
https://s3.eu-central.main.13381338.xyz # regional, use this
https://<bucket>.s3.eu-central.main.13381338.xyz # virtual-host
https://s3.main.13381338.xyz # global, redirectsCredentials
SigV4 with access key and secret. Keys are scoped to a project and optionally to a bucket prefix and source network.
Compatibility matrix
| Feature | Status | Notes |
|---|---|---|
| Multipart upload | ✓ | 5 MiB–5 GiB parts, 10,000 max |
| Versioning | ✓ | including MFA delete |
| Object lock | ✓ | governance and compliance modes |
| Lifecycle | ✓ | transition and expiration |
| Presigned URLs | ✓ | GET, PUT, up to 7 days |
| SSE-S3 / SSE-KMS / SSE-C | ✓ | KMS keys are per-project |
| Cross-region replication | ✓ | with backlog metric |
| Conditional requests | ✓ | ETag and modified-since |
| Select (S3 Select) | ✗ | not implemented |
| Static website hosting | ✗ | use a CDN in front |
| Requester pays | ✗ | egress is free, so it has no meaning |
Multipart tuning
The defaults in most SDKs are conservative. These settings saturate a 10 Gbit/s line on a single machine.
# aws-cli
aws configure set default.s3.max_concurrent_requests 64
aws configure set default.s3.multipart_chunksize 64MB
aws configure set default.s3.multipart_threshold 128MB
# rclone
--transfers 24 --s3-chunk-size 64M --s3-upload-concurrency 32Lifecycle rules
{
"Rules": [{
"ID": "tier-then-expire",
"Status": "Enabled",
"Filter": {"Prefix": "logs/"},
"Transitions": [
{"Days": 30, "StorageClass": "INFREQUENT"},
{"Days": 180, "StorageClass": "ARCHIVE"}
],
"Expiration": {"Days": 2555}
}]
}Object lock
Compliance mode cannot be shortened by anyone, including our operators. Governance mode can, with dual authorisation, and every override lands in the audit log.
Metrics
Scrape /metrics on the regional endpoint with your credentials. Request counts, latency histograms, error codes and replication backlog, per bucket.
Replication
Rules are per prefix, destination can be any region, and the backlog metric tells you how many objects and bytes are behind. RPO is typically under 60 seconds and is never guessed — it is computed from the oldest unreplicated object.