How to use Object Storage with Private Networks
By default, resources attached to a Private Network reach Object Storage over the public internet, which requires them to hold a public IP address or to transit through a gateway.
Object Storage private access keeps the traffic between your Private Networks and your buckets on the internal Scaleway network.
Alternatively, you can use a Public Gateway to route traffic from resources in a Private Network to the public endpoint of an Object Storage bucket.
Before you start
To complete the actions presented below, you must have:
- A Scaleway account logged into the console
- Owner status or IAM permissions allowing you to perform actions in the intended Organization
- An Object Storage bucket
Use Object Storage private access
Object Storage private access is the recommended method to securely reach a bucket from a Private Network.
Object Storage private access allows resources in your Private Networks to reach Object Storage over the internal Scaleway network, instead of the public internet.
Buckets are always served on 2 endpoints, whether the feature is enabled or not:
| Endpoint | Regional URL | Bucket URL |
|---|---|---|
| Public | s3.<region>.scw.cloud | <bucket_name>.s3.<region>.scw.cloud |
| Private | s3-vpc.<region>.scw.eu | <bucket_name>.s3-vpc.<region>.scw.eu |
Enabling Object Storage private access on a VPC makes the private endpoint reachable from the Private Networks you authorize, for all buckets in the region of the VPC. Without it, the private endpoint is not reachable from a Private Network.
The feature adds a private path to your buckets. It does not remove the public path, and it does not change the permissions of your buckets.
-
Enable Object Storage private access on the VPC, and select the Private Networks within this VPC you want to authorize, using the VPC API.
-
Configure your Object Storage client on the resources of the authorized Private Networks to use the private regional endpoint
s3-vpc.<YOUR_REGION>.scw.eu.
See Configuring Object Storage private access for more information.
Use Object Storage with a Public Gateway
Public Gateways allow resources in a Private Network to securely reach the public internet without using a public IP address. Traffic to your buckets then transits over the public internet, and each resource requires a routing configuration. Use this method for the use cases that Object Storage private access does not cover.
The procedure below shows how to create an Instance without a public IP address, attach it to a Private Network with a Public Gateway, and configure a route from the Instance to an Object Storage bucket.
Create an Instance and attach it to a Private Network
-
Follow the instructions for creating an Instance in the same Region as your Object storage bucket. Make sure you disable public connectivity for your Instance.
-
Follow the instructions for creating a Private Network. Make sure you create it in the region that encompasses the Availability Zone of the Instance you previously created.
-
Follow the instructions to attach your Instance to the Private Network.
Create a Public Gateway and attach it to the Private Network
-
Follow the instructions for creating a Public Gateway:
- Select the same Availability Zone as for your previously created Instance.
- Select a Public Gateway type according to your needs.
- Select Allocate a new IP.
- Enter a name and optional tags for your Public Gateway.
-
Click the name of the new Public Gateway. The dashboard of the gateway opens.
-
Click the Private Networks tab.
-
Click Attach to a new Private Network. A dialog appears.
-
Select Attach to an existing Private Network and pick a Private Network from the drop-down list.
-
Click Attach to Private Network.
Set the Object Storage route
-
Connect to your Instance via SSH, replacing
<INSTANCE_IP>with the IP address of the Instance:ssh root@<INSTANCE_IP> -
Configure the following route to the Object Storage platform:
# set this to keep the network on the instance ip route add 10.0.0.0/8 via `ip route | grep default | awk '{print $3} '` dev ens2 # dhcp on pn interface dhclient ens5 # change the default route ip route del default via `ip route | grep default | awk '{print $3} '` dev ens2 ip route add default via 192.168.42.1 dev ens5 # use the IP address of the gateway, shown on the gateway dashboard curl https://s3.nl-ams.scw.cloudThe Instance now reaches Object Storage through the Public Gateway, which handles the exchange of data between the Private Network and the public internet.