I am experiencing issues with Object Storage private access
Object Storage private access makes the Object Storage VPC endpoint, s3-vpc.<REGION>.scw.eu, reachable from the Private Networks you select. It adds a private path to your buckets: it does not remove their public endpoint, and does not change their permissions. Most issues come from a client that still targets the public endpoint, or from a Private Network that is not authorized on the VPC.
My traffic still transits over the public internet
Cause
The client keeps targeting the public endpoint of the bucket, <BUCKET_NAME.s3-vpc.<REGION>.scw.eu. Both endpoints stay available when the feature is enabled, and the feature does not redirect the requests sent to the public endpoint.
Solution
Configure your client with the VPC endpoint, <BUCKET_NAME.s3-vpc.<REGION>.scw.eu. For the AWS CLI, set endpoint_url = https://s3-vpc.<REGION>.scw.eu in your ~/.aws/config file, as described in How to reach a bucket over the VPC endpoint.
Resources in my VPC cannot reach my bucket
Cause
The VPC endpoint is not reachable from the resource, or the credentials of the client do not allow the operation.
Solution
Check the following points:
- Object Storage private access is enabled on the VPC.
- The Private Network of the resource is authorized on the VPC.
- The bucket is in the region of the VPC.
- The client uses the VPC endpoint of the region the bucket is in. A VPC endpoint of another region is not reachable.
- The API key of the client holds the IAM permissions required for the operation.