Cloud4You OCS – AWS CLI and S3 API¶
Cloud4You OCS provides object storage compatible with the Amazon S3 API.
This means that OCS can be used with popular S3-compatible tools and applications, including:
- AWS CLI,
- rclone,
- Veeam,
- AWS SDK libraries,
- applications using the S3 API.
This page explains how to use Cloud4You OCS with AWS CLI and covers basic operations available through the S3 API.
If you prefer to manage files from a web browser, you can use OCS Browser:
Key connection details¶
You need:
| Parameter | Value |
|---|---|
| Endpoint | https://s3.cloud4you.pl |
| Region | eu-pl-1 |
| Access Key ID | your access key |
| Secret Access Key | your secret key |
| API | S3-compatible |
| Request signing | AWS Signature Version 4 |
We recommend using the main endpoint:
Do not use the web panel address as the S3 endpoint.
This:
is the browser-based management panel.
This:
is the S3 endpoint for applications, AWS CLI, and SDKs.
What S3 compatibility means¶
Cloud4You OCS uses Ceph Object Gateway – RGW.
RGW provides an API compatible with a large part of the Amazon S3 API.
In practice, standard operations such as:
creating a bucket
uploading an object
downloading an object
deleting an object
copying an object
multipart upload
versioning
Object Lock
retention
Legal Hold
CORS
tags
lifecycle
bucket policy
can be performed using standard AWS CLI commands.
Cloud4You OCS is not an Amazon AWS service.
Do not assume that every new feature available in Amazon S3 is also available in OCS.
If AWS documentation describes a feature specific to:
this does not automatically mean that the feature is available in Cloud4You OCS.
AWS CLI and s3api – what is the difference?¶
AWS CLI provides two main sets of S3 commands.
aws s3¶
These are simpler commands for everyday operations.
Examples:
If you simply want to:
- upload a file,
- download a file,
- list bucket contents,
- synchronize a directory,
use:
aws s3api¶
These are lower-level commands that correspond to specific S3 API operations.
Examples:
aws s3api list-buckets
aws s3api create-bucket
aws s3api put-bucket-versioning
aws s3api get-bucket-cors
aws s3api put-object-retention
If you want to manage:
- versioning,
- CORS,
- Object Lock,
- retention,
- tags,
- lifecycle,
- bucket policy,
use:
Installing AWS CLI¶
We recommend AWS CLI version 2.
First check whether it is already installed:
If you see output similar to:
you can proceed to configuration.
Windows¶
Run PowerShell or Command Prompt as Administrator.
Enter:
After installation, close the terminal and open it again.
Check:
Linux¶
The simplest system-wide installation method is:
Check:
If you do not have sudo, you can install AWS CLI only for your user:
Then open a new terminal session and check:
macOS¶
Install for the current user:
Check:
AWS also provides a graphical .pkg installer.
Configuring access credentials¶
We recommend creating a separate profile:
This keeps the OCS configuration separate from other AWS or S3 accounts.
Run:
The program asks for:
AWS Access Key ID [None]:
AWS Secret Access Key [None]:
Default region name [None]:
Default output format [None]:
Enter:
AWS Access Key ID: YOUR_ACCESS_KEY
AWS Secret Access Key: YOUR_SECRET_KEY
Default region name: eu-pl-1
Default output format: json
Example:
AWS Access Key ID [None]: ABCDEFGHIJKLMNOP
AWS Secret Access Key [None]: ********************************
Default region name [None]: eu-pl-1
Default output format [None]: json
Never publish a real Secret Access Key.
Where the keys are stored¶
Linux and macOS:
Windows:
The credentials file looks similar to:
This file contains access credentials.
Do not:
- send it by email,
- paste it into a support ticket,
- commit it to Git,
- show it in a screenshot.
Setting the Cloud4You endpoint permanently¶
By default, AWS CLI tries to connect to Amazon servers.
Therefore, tell it that the cloud4you profile must use:
Open the file:
Linux / macOS:
Windows:
Configure:
[profile cloud4you]
region = eu-pl-1
output = json
services = cloud4you-ocs
s3 =
addressing_style = path
[services cloud4you-ocs]
s3 =
endpoint_url = https://s3.cloud4you.pl
After this configuration, you do not need to add the following to every command:
The rest of this page assumes that the endpoint has been stored in the profile.
Why we use addressing_style = path¶
S3 can address buckets in two ways.
Virtual-hosted style:
Path style:
The Cloud4You documentation uses:
This ensures that the client always uses the main endpoint:
Testing the configuration¶
The simplest test is:
If everything works, you will see a list of buckets.
Example:
If you do not have any buckets yet, the result may be empty.
This does not necessarily indicate an error.
Checking the profile¶
List configured profiles:
Check the Cloud4You profile:
The Secret Access Key should be masked.
Basic aws s3 commands¶
List buckets¶
Create a bucket¶
Example:
Bucket names are best created using:
- lowercase letters,
- numbers,
- hyphens.
Example:
List files in a bucket¶
List all files including subfolders¶
Upload one file¶
A local file:
can be uploaded using:
Upload a file under a different name¶
Upload a file to a folder¶
In S3, a “folder” is actually part of the object name.
For the user, however, it looks normal:
Upload an entire directory¶
Synchronize a directory¶
sync uploads new and changed files.
By default, it does not delete files from the bucket that no longer exist locally.
Synchronize with deletion¶
You can force deletion of files at the destination:
Be careful with --delete.
If a file does not exist in the source directory, it may be deleted from the destination.
First, you can preview the operation:
aws s3 sync ./dokumenty/ s3://backup-firma-01/dokumenty/ \
--delete \
--dryrun \
--profile cloud4you
--dryrun shows what would be done without changing anything.
Download one file¶
Download an entire directory¶
Copy an object between buckets¶
Move an object¶
Important:
mv is not a magical “move file” operation.
AWS CLI effectively performs:
For important data, first use cp, verify the file at the destination, and only then remove the source.
Delete one object¶
Delete an entire path¶
--recursive may delete a very large amount of data.
Before running the command, verify:
- the bucket name,
- the path,
- that you really want to delete all of the content.
Delete an empty bucket¶
The bucket must be empty.
Generate a temporary link¶
A link valid for one hour:
aws s3 presign s3://backup-firma-01/faktura.pdf \
--expires-in 3600 \
--profile cloud4you \
--region eu-pl-1
The command returns a URL.
Anyone who has the active link can download the specified object.
The default validity period is:
The maximum period supported by AWS CLI for presign is:
aws s3api commands¶
List buckets through the API¶
Create a bucket through the API¶
aws s3api create-bucket \
--bucket backup-firma-01 \
--region eu-pl-1 \
--create-bucket-configuration LocationConstraint=eu-pl-1 \
--profile cloud4you
Check whether a bucket exists and is accessible¶
If the command completes without an error, the bucket is accessible with the credentials being used.
List objects through the API¶
Only objects beginning with a specific prefix:
Object information¶
aws s3api head-object \
--bucket backup-firma-01 \
--key dokumenty/faktura.pdf \
--profile cloud4you
You can see information such as:
- size,
- Content-Type,
- ETag,
- modification date,
- metadata.
Upload an object using s3api¶
aws s3api put-object \
--bucket backup-firma-01 \
--key dokumenty/faktura.pdf \
--body faktura.pdf \
--profile cloud4you
For normal uploads, however, this is more convenient:
Download an object using s3api¶
aws s3api get-object \
--bucket backup-firma-01 \
--key dokumenty/faktura.pdf \
--profile cloud4you \
faktura.pdf
Delete an object through the API¶
aws s3api delete-object \
--bucket backup-firma-01 \
--key dokumenty/faktura.pdf \
--profile cloud4you
Copy an object through the API¶
aws s3api copy-object \
--bucket bucket-b \
--key faktura.pdf \
--copy-source bucket-a/faktura.pdf \
--profile cloud4you
Versioning¶
What versioning does¶
Versioning allows multiple versions of the same object to be stored.
Without versioning:
is overwritten.
With versioning, the following may exist:
Each version has its own VersionId.
Check versioning¶
Enabled:
If versioning has never been configured, the response may not contain Status.
Enable versioning¶
aws s3api put-bucket-versioning \
--bucket backup-firma-01 \
--versioning-configuration Status=Enabled \
--profile cloud4you
Suspend versioning¶
aws s3api put-bucket-versioning \
--bucket backup-firma-01 \
--versioning-configuration Status=Suspended \
--profile cloud4you
Suspended does not delete previous versions.
It simply means that new objects are no longer versioned in the same way as with Enabled.
List object versions¶
Delete a specific version¶
First find the VersionId:
aws s3api list-object-versions \
--bucket backup-firma-01 \
--prefix dokumenty/faktura.pdf \
--profile cloud4you
Then:
aws s3api delete-object \
--bucket backup-firma-01 \
--key dokumenty/faktura.pdf \
--version-id VERSION_ID \
--profile cloud4you
Check the VersionId before deleting it.
CORS¶
What CORS does¶
CORS controls access performed by web browsers.
It is required, among other cases, when a browser directly uploads or downloads data from S3.
CORS is not required for standard clients such as:
Check CORS¶
If the bucket has no CORS configuration, you will receive information that no configuration exists.
CORS configuration for OCS Browser¶
Create a file:
Contents:
{
"CORSRules": [
{
"AllowedOrigins": [
"https://ocs.cloud4you.pl"
],
"AllowedMethods": [
"GET",
"PUT",
"POST",
"DELETE",
"HEAD"
],
"AllowedHeaders": [
"*"
],
"ExposeHeaders": [
"ETag"
],
"MaxAgeSeconds": 3600
}
]
}
Apply the configuration:
aws s3api put-bucket-cors \
--bucket backup-firma-01 \
--cors-configuration file://cors.json \
--profile cloud4you
Check:
Delete the CORS configuration¶
Object Lock¶
What Object Lock does¶
Object Lock protects objects from deletion or modification for a specified period.
It is most commonly used for:
- backups,
- immutable data,
- data that requires retention.
In Cloud4You OCS, this function is provided by Ceph RGW.
Important before creating the bucket¶
In the Ceph RGW implementation used by OCS, Object Lock must be enabled when the bucket is created.
Therefore, do not create a regular bucket if you already know that it will be used for immutable data.
Create it with Object Lock from the beginning.
Create a bucket with Object Lock¶
aws s3api create-bucket \
--bucket immutable-backup \
--region eu-pl-1 \
--create-bucket-configuration LocationConstraint=eu-pl-1 \
--object-lock-enabled-for-bucket \
--profile cloud4you
Check versioning:
If required, enable it:
aws s3api put-bucket-versioning \
--bucket immutable-backup \
--versioning-configuration Status=Enabled \
--profile cloud4you
Check Object Lock¶
Default Object Lock retention¶
Default retention means:
every new object added to the bucket automatically receives protection.
Create a file:
Example of 30-day retention:
{
"ObjectLockEnabled": "Enabled",
"Rule": {
"DefaultRetention": {
"Mode": "COMPLIANCE",
"Days": 30
}
}
}
Apply:
aws s3api put-object-lock-configuration \
--bucket immutable-backup \
--object-lock-configuration file://object-lock.json \
--profile cloud4you
Check:
GOVERNANCE vs COMPLIANCE¶
GOVERNANCE¶
A less restrictive mode.
A user with the appropriate permission can bypass retention.
COMPLIANCE¶
A more restrictive mode.
The object should not be deleted before the retention period ends.
Do not set COMPLIANCE “just to test it” on an important bucket.
If you configure:
you must assume that the data cannot be deleted normally for 365 days.
Retention for a specific object¶
Object Lock can also be configured for a specific object.
Example:
aws s3api put-object-retention \
--bucket immutable-backup \
--key backup01.vbk \
--retention Mode=GOVERNANCE,RetainUntilDate=2026-12-31T23:59:59Z \
--profile cloud4you
Check:
aws s3api get-object-retention \
--bucket immutable-backup \
--key backup01.vbk \
--profile cloud4you
If you use versioning, you can specify a particular version:
Legal Hold¶
Legal Hold prevents deletion of an object regardless of the retention date.
Enable:
aws s3api put-object-legal-hold \
--bucket immutable-backup \
--key backup01.vbk \
--legal-hold Status=ON \
--profile cloud4you
Check:
aws s3api get-object-legal-hold \
--bucket immutable-backup \
--key backup01.vbk \
--profile cloud4you
Disable:
aws s3api put-object-legal-hold \
--bucket immutable-backup \
--key backup01.vbk \
--legal-hold Status=OFF \
--profile cloud4you
Bucket tags¶
Add tags¶
Create a file:
Contents:
{
"TagSet": [
{
"Key": "project",
"Value": "backup"
},
{
"Key": "environment",
"Value": "production"
}
]
}
Apply:
aws s3api put-bucket-tagging \
--bucket backup-firma-01 \
--tagging file://bucket-tags.json \
--profile cloud4you
Read bucket tags¶
Delete bucket tags¶
Object tags¶
Add tags to a file¶
aws s3api put-object-tagging \
--bucket backup-firma-01 \
--key dokumenty/faktura.pdf \
--tagging 'TagSet=[{Key=typ,Value=faktura},{Key=rok,Value=2026}]' \
--profile cloud4you
Read object tags¶
aws s3api get-object-tagging \
--bucket backup-firma-01 \
--key dokumenty/faktura.pdf \
--profile cloud4you
Delete object tags¶
aws s3api delete-object-tagging \
--bucket backup-firma-01 \
--key dokumenty/faktura.pdf \
--profile cloud4you
Lifecycle¶
Lifecycle allows operations to be performed automatically on objects after a specified period.
Example:
Example rule¶
Create:
Contents:
{
"Rules": [
{
"ID": "delete-temp-after-30-days",
"Status": "Enabled",
"Filter": {
"Prefix": "tmp/"
},
"Expiration": {
"Days": 30
}
}
]
}
Apply:
aws s3api put-bucket-lifecycle-configuration \
--bucket backup-firma-01 \
--lifecycle-configuration file://lifecycle.json \
--profile cloud4you
Check lifecycle¶
Delete lifecycle¶
Lifecycle performs operations automatically.
Do not configure rules that delete data without checking:
- the bucket,
- the prefix,
- the number of days,
- the effect on versioning.
Bucket Policy¶
A Bucket Policy defines access rules for a bucket and its objects.
Ceph RGW Squid supports a subset of the Amazon S3 Bucket Policy language.
This means:
do not copy a random policy from AWS documentation and assume that every element will work identically.
Read Bucket Policy¶
Apply Bucket Policy¶
Assume the valid policy is stored in:
Apply it:
aws s3api put-bucket-policy \
--bucket backup-firma-01 \
--policy file://policy.json \
--profile cloud4you
Delete Bucket Policy¶
Important notes about Bucket Policy¶
An incorrect policy may:
- block access to data,
- grant access that is too broad,
- make data available to a user who should not see it.
If you do not understand what a JSON policy document does:
do not apply it by trial and error to a production bucket.
Multipart Upload¶
Multipart Upload splits a large file into parts.
It is used to:
- upload large files more efficiently,
- upload parts in parallel,
- retry only part of a transfer instead of the entire file.
Ceph RGW supports S3 Multipart Upload.
Do I need to perform multipart upload manually?¶
Usually:
no.
The following commands:
handle multipart automatically for larger files.
Manual s3api operations are mainly required for custom applications or diagnostics.
List incomplete multipart uploads¶
Abort an incomplete multipart upload¶
First obtain the UploadId:
Then:
aws s3api abort-multipart-upload \
--bucket backup-firma-01 \
--key duzy-plik.bin \
--upload-id UPLOAD_ID \
--profile cloud4you
Aborting a multipart upload removes the incomplete upload, not a correctly completed object.
Transfer performance¶
AWS CLI allows transfer settings to be changed.
In most cases:
start with the default settings.
Do not change values only because “a larger number looks faster.”
Number of concurrent requests¶
Example:
More concurrent requests may increase performance, but they may also:
- increase computer load,
- increase bandwidth usage,
- reduce performance on a slow connection.
Multipart threshold¶
Example:
Multipart chunk size¶
Bandwidth limit¶
Example limit of approximately 50 MB/s:
File filtering¶
AWS CLI supports:
Example of uploading only .jpg files:
aws s3 cp ./zdjecia/ s3://backup-firma-01/zdjecia/ \
--recursive \
--exclude "*" \
--include "*.jpg" \
--profile cloud4you
First, exclude everything:
then include the required file type:
Using AWS CLI in scripts¶
The profile can be set using an environment variable.
Linux / macOS:
PowerShell:
Then instead of:
you can use:
Endpoint as an environment variable¶
AWS CLI also supports the following variable.
Linux / macOS:
PowerShell:
If the endpoint is already stored in the profile, you do not need to do this.
S3 REST API basics¶
AWS CLI is only an API client.
Under the hood, it sends HTTP requests to:
Typical S3 operations look logically like this:
| Operation | Method |
|---|---|
| list buckets | GET / |
| create a bucket | PUT /bucket |
| delete a bucket | DELETE /bucket |
| list objects | GET /bucket?list-type=2 |
| upload an object | PUT /bucket/object |
| download an object | GET /bucket/object |
| object information | HEAD /bucket/object |
| delete an object | DELETE /bucket/object |
Private requests must be signed.
Cloud4You OCS supports standard AWS signatures used by S3 clients, including AWS Signature Version 4.
We do not recommend building SigV4 signatures manually.
In an application, use:
- an AWS SDK,
- an S3-compatible library,
- AWS CLI.
Parameters for S3 applications¶
If an application asks for S3 settings, normally enter:
Endpoint:
https://s3.cloud4you.pl
Region:
eu-pl-1
Access Key ID:
YOUR_ACCESS_KEY
Secret Access Key:
YOUR_SECRET_KEY
If the application asks for an addressing style, choose:
or:
The name of this option varies between applications.
Most common errors¶
InvalidAccessKeyId¶
Most commonly:
Check the profile:
SignatureDoesNotMatch¶
The most common causes are:
- incorrect Secret Access Key,
- incorrect region,
- incorrect endpoint,
- incorrect date or time on the computer.
Check:
On Linux:
AccessDenied¶
The connection works, but the key does not have permission to perform the operation.
Example:
This is not an AWS CLI problem.
It is a permissions issue for the key being used.
NoSuchBucket¶
The specified bucket does not exist or you are using the wrong name.
Check:
NoSuchKey¶
The bucket exists, but the specified object does not.
Check:
BucketAlreadyExists¶
A bucket with that name already exists.
Choose a different name.
BucketNotEmpty¶
You are trying to delete a bucket that still contains objects or versions.
Check:
If the bucket has versioning enabled, also check:
InvalidBucketState¶
This may appear during operations related to Object Lock.
In Cloud4You OCS, Object Lock should be planned when the bucket is created.
AWS CLI tries to use an Amazon endpoint¶
Check:
or on Windows:
The profile should contain the service configuration:
[profile cloud4you]
region = eu-pl-1
output = json
services = cloud4you-ocs
s3 =
addressing_style = path
[services cloud4you-ocs]
s3 =
endpoint_url = https://s3.cloud4you.pl
The command works only with --endpoint-url¶
If:
works, but:
does not, the endpoint has most likely not been stored correctly in the config file.
Diagnostics¶
Enable debug output¶
AWS CLI displays a large amount of diagnostic information.
Before sending a log to technical support, check that it does not contain information you do not want to share.
Save debug output to a file¶
Linux / macOS:
Security¶
Secret Access Key¶
Treat the Secret Access Key like a password.
Do not:
send it by email
paste it into a ticket
include it in a screenshot
commit it to Git
store it in a public script
Pre-signed URL¶
A pre-signed URL does not reveal the Secret Access Key.
However, it grants access to an object for a specified period.
Therefore:
treat an active pre-signed URL as temporary access to the file.
Delete operations¶
Be especially careful with:
aws s3 rm --recursive
aws s3 sync --delete
aws s3 rb
aws s3api delete-object
aws s3api delete-bucket
Check the command before running it.
If --dryrun is available, use it before a bulk operation.
Object Lock¶
Object Lock is specifically designed to make data deletion difficult.
That is its purpose.
If you set a long retention period in COMPLIANCE mode, do not assume that an administrator can “simply remove it.”
Quick reference¶
Check the connection¶
Create a bucket¶
List files¶
Upload¶
Download¶
Synchronization¶
Delete a file¶
Versioning¶
aws s3api put-bucket-versioning \
--bucket BUCKET-NAME \
--versioning-configuration Status=Enabled \
--profile cloud4you
CORS¶
Object Lock¶
Pre-signed URL¶
aws s3 presign s3://BUCKET-NAME/file.txt \
--expires-in 3600 \
--region eu-pl-1 \
--profile cloud4you
Help¶
Cloud4You documentation:
Support portal: