Skip to content

Cloud4You OCS – AWS CLI and S3 API

Cloud4You OCS provides object storage compatible with the Amazon S3 API.

This means that OCS can be used with popular S3-compatible tools and applications, including:

  • AWS CLI,
  • rclone,
  • Veeam,
  • AWS SDK libraries,
  • applications using the S3 API.

This page explains how to use Cloud4You OCS with AWS CLI and covers basic operations available through the S3 API.

If you prefer to manage files from a web browser, you can use OCS Browser:

Open OCS Browser


Key connection details

You need:

Parameter Value
Endpoint https://s3.cloud4you.pl
Region eu-pl-1
Access Key ID your access key
Secret Access Key your secret key
API S3-compatible
Request signing AWS Signature Version 4

We recommend using the main endpoint:

https://s3.cloud4you.pl

Do not use the web panel address as the S3 endpoint.

This:

https://ocs.cloud4you.pl

is the browser-based management panel.

This:

https://s3.cloud4you.pl

is the S3 endpoint for applications, AWS CLI, and SDKs.


What S3 compatibility means

Cloud4You OCS uses Ceph Object Gateway – RGW.

RGW provides an API compatible with a large part of the Amazon S3 API.

In practice, standard operations such as:

creating a bucket
uploading an object
downloading an object
deleting an object
copying an object
multipart upload
versioning
Object Lock
retention
Legal Hold
CORS
tags
lifecycle
bucket policy

can be performed using standard AWS CLI commands.

Cloud4You OCS is not an Amazon AWS service.

Do not assume that every new feature available in Amazon S3 is also available in OCS.

If AWS documentation describes a feature specific to:

S3 Express
Directory Buckets
AWS Organizations
AWS Billing
AWS Access Points
AWS Outposts

this does not automatically mean that the feature is available in Cloud4You OCS.


AWS CLI and s3api – what is the difference?

AWS CLI provides two main sets of S3 commands.

aws s3

These are simpler commands for everyday operations.

Examples:

aws s3 ls
aws s3 cp
aws s3 sync
aws s3 mv
aws s3 rm
aws s3 mb
aws s3 rb

If you simply want to:

  • upload a file,
  • download a file,
  • list bucket contents,
  • synchronize a directory,

use:

aws s3

aws s3api

These are lower-level commands that correspond to specific S3 API operations.

Examples:

aws s3api list-buckets
aws s3api create-bucket
aws s3api put-bucket-versioning
aws s3api get-bucket-cors
aws s3api put-object-retention

If you want to manage:

  • versioning,
  • CORS,
  • Object Lock,
  • retention,
  • tags,
  • lifecycle,
  • bucket policy,

use:

aws s3api

Installing AWS CLI

We recommend AWS CLI version 2.

First check whether it is already installed:

aws --version

If you see output similar to:

aws-cli/2.x.x

you can proceed to configuration.


Windows

Run PowerShell or Command Prompt as Administrator.

Enter:

msiexec.exe /i https://awscli.amazonaws.com/AWSCLIV2.msi

After installation, close the terminal and open it again.

Check:

aws --version

Linux

The simplest system-wide installation method is:

curl -fsSL https://awscli.amazonaws.com/v2/install.sh | sudo bash -s -- --system

Check:

aws --version

If you do not have sudo, you can install AWS CLI only for your user:

curl -fsSL https://awscli.amazonaws.com/v2/install.sh | bash

Then open a new terminal session and check:

aws --version

macOS

Install for the current user:

curl -fsSL https://awscli.amazonaws.com/v2/install.sh | bash

Check:

aws --version

AWS also provides a graphical .pkg installer.


Configuring access credentials

We recommend creating a separate profile:

cloud4you

This keeps the OCS configuration separate from other AWS or S3 accounts.

Run:

aws configure --profile cloud4you

The program asks for:

AWS Access Key ID [None]:
AWS Secret Access Key [None]:
Default region name [None]:
Default output format [None]:

Enter:

AWS Access Key ID:        YOUR_ACCESS_KEY
AWS Secret Access Key:    YOUR_SECRET_KEY
Default region name:      eu-pl-1
Default output format:    json

Example:

AWS Access Key ID [None]: ABCDEFGHIJKLMNOP
AWS Secret Access Key [None]: ********************************
Default region name [None]: eu-pl-1
Default output format [None]: json

Never publish a real Secret Access Key.


Where the keys are stored

Linux and macOS:

~/.aws/credentials
~/.aws/config

Windows:

%USERPROFILE%\.aws\credentials
%USERPROFILE%\.aws\config

The credentials file looks similar to:

[cloud4you]
aws_access_key_id = YOUR_ACCESS_KEY
aws_secret_access_key = YOUR_SECRET_KEY

This file contains access credentials.

Do not:

  • send it by email,
  • paste it into a support ticket,
  • commit it to Git,
  • show it in a screenshot.

Setting the Cloud4You endpoint permanently

By default, AWS CLI tries to connect to Amazon servers.

Therefore, tell it that the cloud4you profile must use:

https://s3.cloud4you.pl

Open the file:

Linux / macOS:

~/.aws/config

Windows:

%USERPROFILE%\.aws\config

Configure:

[profile cloud4you]
region = eu-pl-1
output = json
services = cloud4you-ocs

s3 =
  addressing_style = path

[services cloud4you-ocs]
s3 =
  endpoint_url = https://s3.cloud4you.pl

After this configuration, you do not need to add the following to every command:

--endpoint-url https://s3.cloud4you.pl

The rest of this page assumes that the endpoint has been stored in the profile.


Why we use addressing_style = path

S3 can address buckets in two ways.

Virtual-hosted style:

https://my-bucket.s3.example.com/file.txt

Path style:

https://s3.example.com/my-bucket/file.txt

The Cloud4You documentation uses:

addressing_style = path

This ensures that the client always uses the main endpoint:

https://s3.cloud4you.pl

Testing the configuration

The simplest test is:

aws s3 ls --profile cloud4you

If everything works, you will see a list of buckets.

Example:

2026-08-28 10:15:00 backup-firma
2026-08-28 11:02:31 dokumenty

If you do not have any buckets yet, the result may be empty.

This does not necessarily indicate an error.


Checking the profile

List configured profiles:

aws configure list-profiles

Check the Cloud4You profile:

aws configure list --profile cloud4you

The Secret Access Key should be masked.


Basic aws s3 commands

List buckets

aws s3 ls --profile cloud4you

Create a bucket

aws s3 mb s3://my-bucket \
  --profile cloud4you \
  --region eu-pl-1

Example:

aws s3 mb s3://backup-firma-01 \
  --profile cloud4you \
  --region eu-pl-1

Bucket names are best created using:

  • lowercase letters,
  • numbers,
  • hyphens.

Example:

backup-firma-01

List files in a bucket

aws s3 ls s3://backup-firma-01/ \
  --profile cloud4you

List all files including subfolders

aws s3 ls s3://backup-firma-01/ \
  --recursive \
  --profile cloud4you

Upload one file

A local file:

faktura.pdf

can be uploaded using:

aws s3 cp faktura.pdf s3://backup-firma-01/ \
  --profile cloud4you

Upload a file under a different name

aws s3 cp faktura.pdf s3://backup-firma-01/faktura-2026-08.pdf \
  --profile cloud4you

Upload a file to a folder

aws s3 cp faktura.pdf s3://backup-firma-01/faktury/faktura.pdf \
  --profile cloud4you

In S3, a “folder” is actually part of the object name.

For the user, however, it looks normal:

backup-firma-01
└── faktury
    └── faktura.pdf

Upload an entire directory

aws s3 cp ./dokumenty/ s3://backup-firma-01/dokumenty/ \
  --recursive \
  --profile cloud4you

Synchronize a directory

aws s3 sync ./dokumenty/ s3://backup-firma-01/dokumenty/ \
  --profile cloud4you

sync uploads new and changed files.

By default, it does not delete files from the bucket that no longer exist locally.


Synchronize with deletion

You can force deletion of files at the destination:

aws s3 sync ./dokumenty/ s3://backup-firma-01/dokumenty/ \
  --delete \
  --profile cloud4you

Be careful with --delete.

If a file does not exist in the source directory, it may be deleted from the destination.

First, you can preview the operation:

aws s3 sync ./dokumenty/ s3://backup-firma-01/dokumenty/ \
  --delete \
  --dryrun \
  --profile cloud4you

--dryrun shows what would be done without changing anything.


Download one file

aws s3 cp s3://backup-firma-01/faktura.pdf ./faktura.pdf \
  --profile cloud4you

Download an entire directory

aws s3 cp s3://backup-firma-01/dokumenty/ ./dokumenty/ \
  --recursive \
  --profile cloud4you

Copy an object between buckets

aws s3 cp \
  s3://bucket-a/faktura.pdf \
  s3://bucket-b/faktura.pdf \
  --profile cloud4you

Move an object

aws s3 mv \
  s3://bucket-a/faktura.pdf \
  s3://bucket-b/faktura.pdf \
  --profile cloud4you

Important:

mv is not a magical “move file” operation.

AWS CLI effectively performs:

copy
+
delete source

For important data, first use cp, verify the file at the destination, and only then remove the source.


Delete one object

aws s3 rm s3://backup-firma-01/faktura.pdf \
  --profile cloud4you

Delete an entire path

aws s3 rm s3://backup-firma-01/stare-dane/ \
  --recursive \
  --profile cloud4you

--recursive may delete a very large amount of data.

Before running the command, verify:

  • the bucket name,
  • the path,
  • that you really want to delete all of the content.

Delete an empty bucket

aws s3 rb s3://backup-firma-01 \
  --profile cloud4you

The bucket must be empty.


A link valid for one hour:

aws s3 presign s3://backup-firma-01/faktura.pdf \
  --expires-in 3600 \
  --profile cloud4you \
  --region eu-pl-1

The command returns a URL.

Anyone who has the active link can download the specified object.

The default validity period is:

3600 seconds = 1 hour

The maximum period supported by AWS CLI for presign is:

604800 seconds = 7 days

aws s3api commands

List buckets through the API

aws s3api list-buckets \
  --profile cloud4you

Create a bucket through the API

aws s3api create-bucket \
  --bucket backup-firma-01 \
  --region eu-pl-1 \
  --create-bucket-configuration LocationConstraint=eu-pl-1 \
  --profile cloud4you

Check whether a bucket exists and is accessible

aws s3api head-bucket \
  --bucket backup-firma-01 \
  --profile cloud4you

If the command completes without an error, the bucket is accessible with the credentials being used.


List objects through the API

aws s3api list-objects-v2 \
  --bucket backup-firma-01 \
  --profile cloud4you

Only objects beginning with a specific prefix:

aws s3api list-objects-v2 \
  --bucket backup-firma-01 \
  --prefix dokumenty/ \
  --profile cloud4you

Object information

aws s3api head-object \
  --bucket backup-firma-01 \
  --key dokumenty/faktura.pdf \
  --profile cloud4you

You can see information such as:

  • size,
  • Content-Type,
  • ETag,
  • modification date,
  • metadata.

Upload an object using s3api

aws s3api put-object \
  --bucket backup-firma-01 \
  --key dokumenty/faktura.pdf \
  --body faktura.pdf \
  --profile cloud4you

For normal uploads, however, this is more convenient:

aws s3 cp

Download an object using s3api

aws s3api get-object \
  --bucket backup-firma-01 \
  --key dokumenty/faktura.pdf \
  --profile cloud4you \
  faktura.pdf

Delete an object through the API

aws s3api delete-object \
  --bucket backup-firma-01 \
  --key dokumenty/faktura.pdf \
  --profile cloud4you

Copy an object through the API

aws s3api copy-object \
  --bucket bucket-b \
  --key faktura.pdf \
  --copy-source bucket-a/faktura.pdf \
  --profile cloud4you

Versioning

What versioning does

Versioning allows multiple versions of the same object to be stored.

Without versioning:

raport.pdf

is overwritten.

With versioning, the following may exist:

raport.pdf – version A
raport.pdf – version B
raport.pdf – version C

Each version has its own VersionId.


Check versioning

aws s3api get-bucket-versioning \
  --bucket backup-firma-01 \
  --profile cloud4you

Enabled:

{
  "Status": "Enabled"
}

If versioning has never been configured, the response may not contain Status.


Enable versioning

aws s3api put-bucket-versioning \
  --bucket backup-firma-01 \
  --versioning-configuration Status=Enabled \
  --profile cloud4you

Suspend versioning

aws s3api put-bucket-versioning \
  --bucket backup-firma-01 \
  --versioning-configuration Status=Suspended \
  --profile cloud4you

Suspended does not delete previous versions.

It simply means that new objects are no longer versioned in the same way as with Enabled.


List object versions

aws s3api list-object-versions \
  --bucket backup-firma-01 \
  --profile cloud4you

Delete a specific version

First find the VersionId:

aws s3api list-object-versions \
  --bucket backup-firma-01 \
  --prefix dokumenty/faktura.pdf \
  --profile cloud4you

Then:

aws s3api delete-object \
  --bucket backup-firma-01 \
  --key dokumenty/faktura.pdf \
  --version-id VERSION_ID \
  --profile cloud4you

Check the VersionId before deleting it.


CORS

What CORS does

CORS controls access performed by web browsers.

It is required, among other cases, when a browser directly uploads or downloads data from S3.

CORS is not required for standard clients such as:

AWS CLI
Veeam
rclone
SDK

Check CORS

aws s3api get-bucket-cors \
  --bucket backup-firma-01 \
  --profile cloud4you

If the bucket has no CORS configuration, you will receive information that no configuration exists.


CORS configuration for OCS Browser

Create a file:

cors.json

Contents:

{
  "CORSRules": [
    {
      "AllowedOrigins": [
        "https://ocs.cloud4you.pl"
      ],
      "AllowedMethods": [
        "GET",
        "PUT",
        "POST",
        "DELETE",
        "HEAD"
      ],
      "AllowedHeaders": [
        "*"
      ],
      "ExposeHeaders": [
        "ETag"
      ],
      "MaxAgeSeconds": 3600
    }
  ]
}

Apply the configuration:

aws s3api put-bucket-cors \
  --bucket backup-firma-01 \
  --cors-configuration file://cors.json \
  --profile cloud4you

Check:

aws s3api get-bucket-cors \
  --bucket backup-firma-01 \
  --profile cloud4you

Delete the CORS configuration

aws s3api delete-bucket-cors \
  --bucket backup-firma-01 \
  --profile cloud4you

Object Lock

What Object Lock does

Object Lock protects objects from deletion or modification for a specified period.

It is most commonly used for:

  • backups,
  • immutable data,
  • data that requires retention.

In Cloud4You OCS, this function is provided by Ceph RGW.


Important before creating the bucket

In the Ceph RGW implementation used by OCS, Object Lock must be enabled when the bucket is created.

Therefore, do not create a regular bucket if you already know that it will be used for immutable data.

Create it with Object Lock from the beginning.


Create a bucket with Object Lock

aws s3api create-bucket \
  --bucket immutable-backup \
  --region eu-pl-1 \
  --create-bucket-configuration LocationConstraint=eu-pl-1 \
  --object-lock-enabled-for-bucket \
  --profile cloud4you

Check versioning:

aws s3api get-bucket-versioning \
  --bucket immutable-backup \
  --profile cloud4you

If required, enable it:

aws s3api put-bucket-versioning \
  --bucket immutable-backup \
  --versioning-configuration Status=Enabled \
  --profile cloud4you

Check Object Lock

aws s3api get-object-lock-configuration \
  --bucket immutable-backup \
  --profile cloud4you

Default Object Lock retention

Default retention means:

every new object added to the bucket automatically receives protection.

Create a file:

object-lock.json

Example of 30-day retention:

{
  "ObjectLockEnabled": "Enabled",
  "Rule": {
    "DefaultRetention": {
      "Mode": "COMPLIANCE",
      "Days": 30
    }
  }
}

Apply:

aws s3api put-object-lock-configuration \
  --bucket immutable-backup \
  --object-lock-configuration file://object-lock.json \
  --profile cloud4you

Check:

aws s3api get-object-lock-configuration \
  --bucket immutable-backup \
  --profile cloud4you

GOVERNANCE vs COMPLIANCE

GOVERNANCE

A less restrictive mode.

A user with the appropriate permission can bypass retention.

COMPLIANCE

A more restrictive mode.

The object should not be deleted before the retention period ends.

Do not set COMPLIANCE “just to test it” on an important bucket.

If you configure:

COMPLIANCE + 365 days

you must assume that the data cannot be deleted normally for 365 days.


Retention for a specific object

Object Lock can also be configured for a specific object.

Example:

aws s3api put-object-retention \
  --bucket immutable-backup \
  --key backup01.vbk \
  --retention Mode=GOVERNANCE,RetainUntilDate=2026-12-31T23:59:59Z \
  --profile cloud4you

Check:

aws s3api get-object-retention \
  --bucket immutable-backup \
  --key backup01.vbk \
  --profile cloud4you

If you use versioning, you can specify a particular version:

--version-id VERSION_ID

Legal Hold prevents deletion of an object regardless of the retention date.

Enable:

aws s3api put-object-legal-hold \
  --bucket immutable-backup \
  --key backup01.vbk \
  --legal-hold Status=ON \
  --profile cloud4you

Check:

aws s3api get-object-legal-hold \
  --bucket immutable-backup \
  --key backup01.vbk \
  --profile cloud4you

Disable:

aws s3api put-object-legal-hold \
  --bucket immutable-backup \
  --key backup01.vbk \
  --legal-hold Status=OFF \
  --profile cloud4you

Bucket tags

Add tags

Create a file:

bucket-tags.json

Contents:

{
  "TagSet": [
    {
      "Key": "project",
      "Value": "backup"
    },
    {
      "Key": "environment",
      "Value": "production"
    }
  ]
}

Apply:

aws s3api put-bucket-tagging \
  --bucket backup-firma-01 \
  --tagging file://bucket-tags.json \
  --profile cloud4you

Read bucket tags

aws s3api get-bucket-tagging \
  --bucket backup-firma-01 \
  --profile cloud4you

Delete bucket tags

aws s3api delete-bucket-tagging \
  --bucket backup-firma-01 \
  --profile cloud4you

Object tags

Add tags to a file

aws s3api put-object-tagging \
  --bucket backup-firma-01 \
  --key dokumenty/faktura.pdf \
  --tagging 'TagSet=[{Key=typ,Value=faktura},{Key=rok,Value=2026}]' \
  --profile cloud4you

Read object tags

aws s3api get-object-tagging \
  --bucket backup-firma-01 \
  --key dokumenty/faktura.pdf \
  --profile cloud4you

Delete object tags

aws s3api delete-object-tagging \
  --bucket backup-firma-01 \
  --key dokumenty/faktura.pdf \
  --profile cloud4you

Lifecycle

Lifecycle allows operations to be performed automatically on objects after a specified period.

Example:

delete contents of tmp/ after 30 days

Example rule

Create:

lifecycle.json

Contents:

{
  "Rules": [
    {
      "ID": "delete-temp-after-30-days",
      "Status": "Enabled",
      "Filter": {
        "Prefix": "tmp/"
      },
      "Expiration": {
        "Days": 30
      }
    }
  ]
}

Apply:

aws s3api put-bucket-lifecycle-configuration \
  --bucket backup-firma-01 \
  --lifecycle-configuration file://lifecycle.json \
  --profile cloud4you

Check lifecycle

aws s3api get-bucket-lifecycle-configuration \
  --bucket backup-firma-01 \
  --profile cloud4you

Delete lifecycle

aws s3api delete-bucket-lifecycle \
  --bucket backup-firma-01 \
  --profile cloud4you

Lifecycle performs operations automatically.

Do not configure rules that delete data without checking:

  • the bucket,
  • the prefix,
  • the number of days,
  • the effect on versioning.

Bucket Policy

A Bucket Policy defines access rules for a bucket and its objects.

Ceph RGW Squid supports a subset of the Amazon S3 Bucket Policy language.

This means:

do not copy a random policy from AWS documentation and assume that every element will work identically.


Read Bucket Policy

aws s3api get-bucket-policy \
  --bucket backup-firma-01 \
  --profile cloud4you

Apply Bucket Policy

Assume the valid policy is stored in:

policy.json

Apply it:

aws s3api put-bucket-policy \
  --bucket backup-firma-01 \
  --policy file://policy.json \
  --profile cloud4you

Delete Bucket Policy

aws s3api delete-bucket-policy \
  --bucket backup-firma-01 \
  --profile cloud4you

Important notes about Bucket Policy

An incorrect policy may:

  • block access to data,
  • grant access that is too broad,
  • make data available to a user who should not see it.

If you do not understand what a JSON policy document does:

do not apply it by trial and error to a production bucket.


Multipart Upload

Multipart Upload splits a large file into parts.

It is used to:

  • upload large files more efficiently,
  • upload parts in parallel,
  • retry only part of a transfer instead of the entire file.

Ceph RGW supports S3 Multipart Upload.


Do I need to perform multipart upload manually?

Usually:

no.

The following commands:

aws s3 cp
aws s3 sync

handle multipart automatically for larger files.

Manual s3api operations are mainly required for custom applications or diagnostics.


List incomplete multipart uploads

aws s3api list-multipart-uploads \
  --bucket backup-firma-01 \
  --profile cloud4you

Abort an incomplete multipart upload

First obtain the UploadId:

aws s3api list-multipart-uploads \
  --bucket backup-firma-01 \
  --profile cloud4you

Then:

aws s3api abort-multipart-upload \
  --bucket backup-firma-01 \
  --key duzy-plik.bin \
  --upload-id UPLOAD_ID \
  --profile cloud4you

Aborting a multipart upload removes the incomplete upload, not a correctly completed object.


Transfer performance

AWS CLI allows transfer settings to be changed.

In most cases:

start with the default settings.

Do not change values only because “a larger number looks faster.”


Number of concurrent requests

Example:

aws configure set s3.max_concurrent_requests 20 \
  --profile cloud4you

More concurrent requests may increase performance, but they may also:

  • increase computer load,
  • increase bandwidth usage,
  • reduce performance on a slow connection.

Multipart threshold

Example:

aws configure set s3.multipart_threshold 64MB \
  --profile cloud4you

Multipart chunk size

aws configure set s3.multipart_chunksize 16MB \
  --profile cloud4you

Bandwidth limit

Example limit of approximately 50 MB/s:

aws configure set s3.max_bandwidth 50MB/s \
  --profile cloud4you

File filtering

AWS CLI supports:

--exclude
--include

Example of uploading only .jpg files:

aws s3 cp ./zdjecia/ s3://backup-firma-01/zdjecia/ \
  --recursive \
  --exclude "*" \
  --include "*.jpg" \
  --profile cloud4you

First, exclude everything:

--exclude "*"

then include the required file type:

--include "*.jpg"

Using AWS CLI in scripts

The profile can be set using an environment variable.

Linux / macOS:

export AWS_PROFILE=cloud4you

PowerShell:

$Env:AWS_PROFILE="cloud4you"

Then instead of:

aws s3 ls --profile cloud4you

you can use:

aws s3 ls

Endpoint as an environment variable

AWS CLI also supports the following variable.

Linux / macOS:

export AWS_ENDPOINT_URL_S3=https://s3.cloud4you.pl

PowerShell:

$Env:AWS_ENDPOINT_URL_S3="https://s3.cloud4you.pl"

If the endpoint is already stored in the profile, you do not need to do this.


S3 REST API basics

AWS CLI is only an API client.

Under the hood, it sends HTTP requests to:

https://s3.cloud4you.pl

Typical S3 operations look logically like this:

Operation Method
list buckets GET /
create a bucket PUT /bucket
delete a bucket DELETE /bucket
list objects GET /bucket?list-type=2
upload an object PUT /bucket/object
download an object GET /bucket/object
object information HEAD /bucket/object
delete an object DELETE /bucket/object

Private requests must be signed.

Cloud4You OCS supports standard AWS signatures used by S3 clients, including AWS Signature Version 4.

We do not recommend building SigV4 signatures manually.

In an application, use:

  • an AWS SDK,
  • an S3-compatible library,
  • AWS CLI.

Parameters for S3 applications

If an application asks for S3 settings, normally enter:

Endpoint:
https://s3.cloud4you.pl

Region:
eu-pl-1

Access Key ID:
YOUR_ACCESS_KEY

Secret Access Key:
YOUR_SECRET_KEY

If the application asks for an addressing style, choose:

Path Style

or:

Force Path Style = Enabled

The name of this option varies between applications.


Most common errors

InvalidAccessKeyId

Most commonly:

incorrect Access Key ID

Check the profile:

aws configure list --profile cloud4you

SignatureDoesNotMatch

The most common causes are:

  • incorrect Secret Access Key,
  • incorrect region,
  • incorrect endpoint,
  • incorrect date or time on the computer.

Check:

Endpoint: https://s3.cloud4you.pl
Region:   eu-pl-1

On Linux:

timedatectl

AccessDenied

The connection works, but the key does not have permission to perform the operation.

Example:

you can read files
but you cannot create buckets

This is not an AWS CLI problem.

It is a permissions issue for the key being used.


NoSuchBucket

The specified bucket does not exist or you are using the wrong name.

Check:

aws s3 ls --profile cloud4you

NoSuchKey

The bucket exists, but the specified object does not.

Check:

aws s3 ls s3://BUCKET-NAME/ \
  --recursive \
  --profile cloud4you

BucketAlreadyExists

A bucket with that name already exists.

Choose a different name.


BucketNotEmpty

You are trying to delete a bucket that still contains objects or versions.

Check:

aws s3 ls s3://BUCKET-NAME/ \
  --recursive \
  --profile cloud4you

If the bucket has versioning enabled, also check:

aws s3api list-object-versions \
  --bucket BUCKET-NAME \
  --profile cloud4you

InvalidBucketState

This may appear during operations related to Object Lock.

In Cloud4You OCS, Object Lock should be planned when the bucket is created.


AWS CLI tries to use an Amazon endpoint

Check:

~/.aws/config

or on Windows:

%USERPROFILE%\.aws\config

The profile should contain the service configuration:

[profile cloud4you]
region = eu-pl-1
output = json
services = cloud4you-ocs

s3 =
  addressing_style = path

[services cloud4you-ocs]
s3 =
  endpoint_url = https://s3.cloud4you.pl

The command works only with --endpoint-url

If:

aws s3 ls \
  --endpoint-url https://s3.cloud4you.pl \
  --profile cloud4you

works, but:

aws s3 ls --profile cloud4you

does not, the endpoint has most likely not been stored correctly in the config file.


Diagnostics

Enable debug output

aws s3 ls \
  --profile cloud4you \
  --debug

AWS CLI displays a large amount of diagnostic information.

Before sending a log to technical support, check that it does not contain information you do not want to share.


Save debug output to a file

Linux / macOS:

aws s3 ls \
  --profile cloud4you \
  --debug 2> aws-debug.txt

Security

Secret Access Key

Treat the Secret Access Key like a password.

Do not:

send it by email
paste it into a ticket
include it in a screenshot
commit it to Git
store it in a public script

Pre-signed URL

A pre-signed URL does not reveal the Secret Access Key.

However, it grants access to an object for a specified period.

Therefore:

treat an active pre-signed URL as temporary access to the file.


Delete operations

Be especially careful with:

aws s3 rm --recursive
aws s3 sync --delete
aws s3 rb
aws s3api delete-object
aws s3api delete-bucket

Check the command before running it.

If --dryrun is available, use it before a bulk operation.


Object Lock

Object Lock is specifically designed to make data deletion difficult.

That is its purpose.

If you set a long retention period in COMPLIANCE mode, do not assume that an administrator can “simply remove it.”


Quick reference

Check the connection

aws s3 ls --profile cloud4you

Create a bucket

aws s3 mb s3://BUCKET-NAME \
  --region eu-pl-1 \
  --profile cloud4you

List files

aws s3 ls s3://BUCKET-NAME/ \
  --profile cloud4you

Upload

aws s3 cp file.txt s3://BUCKET-NAME/ \
  --profile cloud4you

Download

aws s3 cp s3://BUCKET-NAME/file.txt ./file.txt \
  --profile cloud4you

Synchronization

aws s3 sync ./data/ s3://BUCKET-NAME/data/ \
  --profile cloud4you

Delete a file

aws s3 rm s3://BUCKET-NAME/file.txt \
  --profile cloud4you

Versioning

aws s3api put-bucket-versioning \
  --bucket BUCKET-NAME \
  --versioning-configuration Status=Enabled \
  --profile cloud4you

CORS

aws s3api get-bucket-cors \
  --bucket BUCKET-NAME \
  --profile cloud4you

Object Lock

aws s3api get-object-lock-configuration \
  --bucket BUCKET-NAME \
  --profile cloud4you

Pre-signed URL

aws s3 presign s3://BUCKET-NAME/file.txt \
  --expires-in 3600 \
  --region eu-pl-1 \
  --profile cloud4you

Help

Cloud4You documentation:

Open documentation

Support portal:

Open Support