Skip to content

Access Credentials

To use Cloud4You Object Storage S3, you need the following credentials:

Access Key
Secret Key

They are used by S3 applications and clients to sign requests sent to the service.

Access Key

The Access Key identifies the user.

You can think of it as similar to a username.

Example:

ABCDEFGHIJKLMNOPQRST

The Access Key is used together with the Secret Key.

Secret Key

The Secret Key is a private key used to sign requests.

You can think of it as similar to a password.

The Secret Key is confidential

Do not share the Secret Key with unauthorized persons.

Anyone who has a valid Access Key and Secret Key can perform operations according to the permissions assigned to that user.

Required configuration data

A typical S3 client configuration requires four values:

Endpoint:
https://s3.cloud4you.pl

Region:
eu-pl-1

Access Key:
<your Access Key>

Secret Key:
<your Secret Key>

Where to store access credentials

We recommend storing keys in locations designed for sensitive data.

For example:

  • an AWS CLI profile,
  • environment variables,
  • a secrets management system,
  • a protected application configuration file,
  • a password manager,
  • a secure operating system credential store.

What not to do

Do not place the Secret Key directly in:

  • a public Git repository,
  • publicly available documentation,
  • source code published on the Internet,
  • screenshots,
  • unsecured text files,
  • support tickets available to unauthorized persons.

Example of an unsafe configuration:

ACCESS_KEY = "ABCDEFGHIJKLMNOPQRST"
SECRET_KEY = "secret_key_hardcoded_in_source"

If such code is committed to a repository or shared with a third party, the credentials may be compromised.

AWS CLI

The simplest way to store credentials for AWS CLI is to use a separate profile.

Create the profile:

aws configure --profile cloud4you

Enter:

AWS Access Key ID:
<Access Key>

AWS Secret Access Key:
<Secret Key>

Default region name:
eu-pl-1

Default output format:
json

Then use the profile:

aws \
  --profile cloud4you \
  --endpoint-url https://s3.cloud4you.pl \
  s3api list-buckets

AWS CLI configuration files

AWS CLI normally stores profile data in the user's home directory.

On Linux and macOS:

~/.aws/credentials
~/.aws/config

On Windows, they are stored in the user's profile directory under:

.aws

Protect credential files

Make sure files containing the Secret Key are not accessible to unauthorized system users.

Environment variables

Some applications and libraries support standard AWS environment variables.

Example for Linux/macOS:

export AWS_ACCESS_KEY_ID="<Access Key>"
export AWS_SECRET_ACCESS_KEY="<Secret Key>"
export AWS_DEFAULT_REGION="eu-pl-1"

Shell history

Entering a Secret Key directly in the terminal may cause it to be stored in shell history.

In production environments, we recommend using safer mechanisms for passing secrets.

Key rotation

If a key needs to be replaced, we recommend rotating it in a controlled manner.

Typical process:

  1. obtain a new Access Key and Secret Key pair,
  2. configure the new key in the application,
  3. verify that the application works with the new credentials,
  4. remove or disable the old credentials,
  5. verify that no system still uses the old key.

Do not remove the old key before all applications have been migrated.

Suspected Secret Key exposure

If you suspect that a Secret Key has been exposed:

  1. stop using the compromised key,
  2. generate or request a new credential pair,
  3. update applications using the old credentials,
  4. remove or disable the compromised key,
  5. review logs and usage if available.

Treat an exposed Secret Key the same way you would treat an exposed password.

Support requests

Do not include a Secret Key in a support ticket.

For diagnostics, you can provide information such as:

Access Key:
ABCD...QRST

with part of the value masked if necessary.

You can also provide:

  • the endpoint,
  • region,
  • bucket name,
  • exact error message,
  • date and time of the error,
  • Request ID if available.

If Cloud4You Support needs additional information, the team will provide a secure method for sharing it.

One key for multiple applications

Technically, the same key can be used by multiple applications.

However, for production environments it is better to separate credentials when possible.

This makes it easier to:

  • identify which application uses a key,
  • rotate credentials,
  • disable access for one application,
  • troubleshoot incidents,
  • reduce the impact of a credential leak.

Summary

To connect to Cloud4You Object Storage S3, you need:

Endpoint:
https://s3.cloud4you.pl

Region:
eu-pl-1

Access Key:
<your Access Key>

Secret Key:
<your Secret Key>

Treat the Secret Key as confidential data and never publish it.