Skip to navigationSkip to main contentSkip to footerScaleway Docs HomepageAsk our AI
Ask our AI

Configure Object Storage private access

Important

Object Storage private access is currently in private beta, and is available in the Paris (fr-par) region only.

Object Storage private access allows resources in your Private Networks to reach Object Storage over the internal Scaleway network, instead of the public internet.

Buckets are always served on 2 endpoints, whether the feature is enabled or not:

EndpointRegional URLBucket URL
Publics3.<region>.scw.cloud<bucket_name>.s3.<region>.scw.cloud
Privates3-vpc.<region>.scw.eu<bucket_name>.s3-vpc.<region>.scw.eu

Enabling Object Storage private access on a VPC makes the private endpoint reachable from the Private Networks you authorize, for all buckets in the region of the VPC. Without it, the private endpoint is not reachable from a Private Network.

The feature adds a private path to your buckets. It does not remove the public path, and it does not change the permissions of your buckets.

Before you start

To complete the actions presented below, you must have:

Enable Object Storage private access on a VPC

Note

Enabling Object Storage private access on a VPC triggers billing for the feature.

  1. Enable Object Storage private access on the VPC, listing the Private Networks to authorize:

    curl -X POST \
      -H "X-Auth-Token: $SCW_SECRET_KEY" \
      -H "Content-Type: application/json" \
      -d '{"private_network_ids":["example-7363-616c-6577-61792e636f6d"]}' \
      "https://api.scaleway.com/vpc/v2/regions/{region}/object-storage-private-access/{vpc_id}/enable"
  2. Add another Private Network, if needed:

    curl -X POST \
      -H "X-Auth-Token: $SCW_SECRET_KEY" \
      -H "Content-Type: application/json" \
      -d '{"private_network_id":"example-717b-6045-74503301df334"}' \
      "https://api.scaleway.com/vpc/v2/regions/{region}/object-storage-private-access/{vpc_id}/private-networks"

Refer to the VPC API documentation for more information.

Reach a bucket over the VPC endpoint

Resources in an authorized Private Network reach Object Storage privately only when they target the VPC endpoint. A client configured with the public endpoint keeps sending its requests over the public internet.

  1. Connect to an Instance attached to an authorized Private Network of the VPC.

  2. Configure your Object Storage client to point at the VPC endpoint of the region. For the AWS CLI, set the endpoint_url in your ~/.aws/config file:

    [default]
    region = fr-par
    output = json
    services = scw-fr-par
    
    [services scw-fr-par]
    s3 =
      endpoint_url = https://s3-vpc.fr-par.scw.eu
  3. Run the following command to list your buckets present in the specified region:

    aws s3 ls

    The same command run from a machine outside the VPC fails, as the VPC endpoint is not reachable from the public internet.

Key considerations

Buckets remain publicly reachable

Enabling the feature on a VPC does not restrict public connectivity. Every bucket keeps its public endpoint, and its existing permissions remain unchanged.

The feature applies to all buckets of the region

Enabling Object Storage private access makes every bucket of the region reachable over the private endpoint, from the Private Networks you select. You cannot enable it for a single bucket.

Access rights are managed at bucket level

Object Storage private access controls connectivity only. The requests allowed on a bucket are managed via IAM permissions and bucket policies.

Troubleshooting

See I am experiencing issues with Object Storage private access for solutions to the most common issues, such as traffic that still transits over the public internet, or resources in a VPC that cannot reach a bucket.

Still need help?

Create a support ticket
No Results