Configure Object Storage private access
Object Storage private access allows resources in your Private Networks to reach Object Storage over the internal Scaleway network, instead of the public internet.
Buckets are always served on 2 endpoints, whether the feature is enabled or not:
| Endpoint | Regional URL | Bucket URL |
|---|---|---|
| Public | s3.<region>.scw.cloud | <bucket_name>.s3.<region>.scw.cloud |
| Private | s3-vpc.<region>.scw.eu | <bucket_name>.s3-vpc.<region>.scw.eu |
Enabling Object Storage private access on a VPC makes the private endpoint reachable from the Private Networks you authorize, for all buckets in the region of the VPC. Without it, the private endpoint is not reachable from a Private Network.
The feature adds a private path to your buckets. It does not remove the public path, and it does not change the permissions of your buckets.
Before you start
To complete the actions presented below, you must have:
- A Scaleway account logged into the console
- Owner status or IAM permissions allowing you to perform actions in the intended Organization
- A valid API key
- A VPC with at least one Private Network
- An Object Storage bucket in the region of the VPC
Enable Object Storage private access on a VPC
-
Enable Object Storage private access on the VPC, listing the Private Networks to authorize:
curl -X POST \ -H "X-Auth-Token: $SCW_SECRET_KEY" \ -H "Content-Type: application/json" \ -d '{"private_network_ids":["example-7363-616c-6577-61792e636f6d"]}' \ "https://api.scaleway.com/vpc/v2/regions/{region}/object-storage-private-access/{vpc_id}/enable" -
Add another Private Network, if needed:
curl -X POST \ -H "X-Auth-Token: $SCW_SECRET_KEY" \ -H "Content-Type: application/json" \ -d '{"private_network_id":"example-717b-6045-74503301df334"}' \ "https://api.scaleway.com/vpc/v2/regions/{region}/object-storage-private-access/{vpc_id}/private-networks"
Refer to the VPC API documentation for more information.
Reach a bucket over the VPC endpoint
Resources in an authorized Private Network reach Object Storage privately only when they target the VPC endpoint. A client configured with the public endpoint keeps sending its requests over the public internet.
-
Connect to an Instance attached to an authorized Private Network of the VPC.
-
Configure your Object Storage client to point at the VPC endpoint of the region. For the AWS CLI, set the
endpoint_urlin your~/.aws/configfile:[default] region = fr-par output = json services = scw-fr-par [services scw-fr-par] s3 = endpoint_url = https://s3-vpc.fr-par.scw.eu -
Run the following command to list your buckets present in the specified region:
aws s3 lsThe same command run from a machine outside the VPC fails, as the VPC endpoint is not reachable from the public internet.
Key considerations
Buckets remain publicly reachable
Enabling the feature on a VPC does not restrict public connectivity. Every bucket keeps its public endpoint, and its existing permissions remain unchanged.
The feature applies to all buckets of the region
Enabling Object Storage private access makes every bucket of the region reachable over the private endpoint, from the Private Networks you select. You cannot enable it for a single bucket.
Access rights are managed at bucket level
Object Storage private access controls connectivity only. The requests allowed on a bucket are managed via IAM permissions and bucket policies.
Troubleshooting
See I am experiencing issues with Object Storage private access for solutions to the most common issues, such as traffic that still transits over the public internet, or resources in a VPC that cannot reach a bucket.