Object Storage (S3)
Aral Cloud Object Storage is an S3-compatible store for files, backups, media and any other unstructured data. You create buckets, get per-bucket credentials, and talk to them with the AWS CLI, any S3 SDK or the built-in object browser in the console.
Find it under Storage → S3 in the console.
S3 bucket and access keys0:36Buckets
A bucket is a named container for your objects. Each bucket lives in a zone and comes with its own scoped credentials — an access key and secret key that work for that one bucket and nothing else.
Create a bucket
- Open Storage → S3 and click Create bucket.
- Pick a zone — the geographic location where the data is stored.
- Enter a name. Names must be 3–63 characters, lowercase letters, digits or hyphens, and may not start or end with a hyphen (S3/DNS-safe naming).
- Optionally set a quota in GB. Leave it at
0for no limit. - Click Create.
When the bucket is created, the console shows you its endpoint, access key and secret key.
WARNING
The secret key is shown only once, right after creation. Copy it and store it somewhere safe. If you lose it, you cannot retrieve it again — you have to rotate the credentials to get a new pair.
The bucket list shows each bucket's endpoint, zone, storage used (against its quota), object count, access mode (public/private), estimated monthly cost and creation date.
Credentials
Each bucket has its own access key and secret key, scoped so they can only access that single bucket. Open a bucket's menu to:
- Copy endpoint — the S3 endpoint host to point your client at.
- View credentials — retrieve the access key and secret key for the bucket.
Rotate credentials
If a key is leaked or you simply want to roll it, choose Rotate credentials. A fresh access key and secret key are generated and the new secret is shown once.
WARNING
Rotating immediately revokes the old credentials. Any application still using the previous keys will stop working until you update it with the new ones.
Public vs private
By default a bucket is private — only requests signed with the bucket's credentials can read its objects.
Toggle Make public to allow anonymous read access (objects can be downloaded and listed without credentials). Toggle Make private to turn it off again.
TIP
Use public buckets for assets you want to serve directly, like images or static downloads. Keep everything else private.
Delete a bucket
Deleting a bucket from its menu empties it, removes its objects and revokes its credentials, then removes the bucket itself. This cannot be undone.
Object browser
Click a bucket to open the built-in browser. From here you can manage objects without any external tooling:
- Browse — objects and folders are shown for the current path, with breadcrumbs to navigate. Folders are derived from
/in object keys. Large buckets page with a Load more button. - Upload — click Upload or drag and drop files. Uploads go straight to storage using a short-lived presigned PUT URL, so your files never pass through the console backend.
- Download — opens the object through a time-limited presigned GET URL.
- New folder — creates a folder (a zero-byte marker) at the current path.
- Delete — removes a single object.
TIP
Presigned URLs are time-limited. Generate a fresh one (re-open the browser or click Download again) if a link has expired.
Using it with the AWS CLI and SDKs
Because the service speaks the S3 API, any S3-compatible tool works — you just point it at your bucket's endpoint and use its access key and secret key. The bucket's zone is its region.
Configure a profile with the AWS CLI:
aws configure --profile aral
# AWS Access Key ID: <your-bucket-access-key>
# AWS Secret Access Key: <your-bucket-secret-key>
# Default region name: <your-bucket-zone>
# Default output format: jsonThen pass your bucket's endpoint with --endpoint-url:
# List objects
aws --profile aral --endpoint-url https://<your-bucket-endpoint> \
s3 ls s3://my-bucket/
# Upload a file
aws --profile aral --endpoint-url https://<your-bucket-endpoint> \
s3 cp ./photo.jpg s3://my-bucket/images/photo.jpg
# Download a file
aws --profile aral --endpoint-url https://<your-bucket-endpoint> \
s3 cp s3://my-bucket/images/photo.jpg ./photo.jpgAny S3 SDK works the same way — set the endpoint, region, access key and secret key. For example, with the Python boto3 SDK:
import boto3
s3 = boto3.client(
"s3",
endpoint_url="https://<your-bucket-endpoint>",
aws_access_key_id="<your-bucket-access-key>",
aws_secret_access_key="<your-bucket-secret-key>",
region_name="<your-bucket-zone>",
)
s3.upload_file("photo.jpg", "my-bucket", "images/photo.jpg")WARNING
Never hardcode your secret key in source code or commit it to a repository. Load it from an environment variable or a secrets manager instead.
TIP
You can also manage buckets and objects from the terminal with the aral s3 commands. See the CLI guide.