Access Credentials¶
To use Cloud4You Object Storage S3, you need the following credentials:
They are used by S3 applications and clients to sign requests sent to the service.
Access Key¶
The Access Key identifies the user.
You can think of it as similar to a username.
Example:
The Access Key is used together with the Secret Key.
Secret Key¶
The Secret Key is a private key used to sign requests.
You can think of it as similar to a password.
The Secret Key is confidential
Do not share the Secret Key with unauthorized persons.
Anyone who has a valid Access Key and Secret Key can perform operations according to the permissions assigned to that user.
Required configuration data¶
A typical S3 client configuration requires four values:
Endpoint:
https://s3.cloud4you.pl
Region:
eu-pl-1
Access Key:
<your Access Key>
Secret Key:
<your Secret Key>
Where to store access credentials¶
We recommend storing keys in locations designed for sensitive data.
For example:
- an AWS CLI profile,
- environment variables,
- a secrets management system,
- a protected application configuration file,
- a password manager,
- a secure operating system credential store.
What not to do¶
Do not place the Secret Key directly in:
- a public Git repository,
- publicly available documentation,
- source code published on the Internet,
- screenshots,
- unsecured text files,
- support tickets available to unauthorized persons.
Example of an unsafe configuration:
If such code is committed to a repository or shared with a third party, the credentials may be compromised.
AWS CLI¶
The simplest way to store credentials for AWS CLI is to use a separate profile.
Create the profile:
Enter:
AWS Access Key ID:
<Access Key>
AWS Secret Access Key:
<Secret Key>
Default region name:
eu-pl-1
Default output format:
json
Then use the profile:
AWS CLI configuration files¶
AWS CLI normally stores profile data in the user's home directory.
On Linux and macOS:
On Windows, they are stored in the user's profile directory under:
Protect credential files
Make sure files containing the Secret Key are not accessible to unauthorized system users.
Environment variables¶
Some applications and libraries support standard AWS environment variables.
Example for Linux/macOS:
export AWS_ACCESS_KEY_ID="<Access Key>"
export AWS_SECRET_ACCESS_KEY="<Secret Key>"
export AWS_DEFAULT_REGION="eu-pl-1"
Shell history
Entering a Secret Key directly in the terminal may cause it to be stored in shell history.
In production environments, we recommend using safer mechanisms for passing secrets.
Key rotation¶
If a key needs to be replaced, we recommend rotating it in a controlled manner.
Typical process:
- obtain a new Access Key and Secret Key pair,
- configure the new key in the application,
- verify that the application works with the new credentials,
- remove or disable the old credentials,
- verify that no system still uses the old key.
Do not remove the old key before all applications have been migrated.
Suspected Secret Key exposure¶
If you suspect that a Secret Key has been exposed:
- stop using the compromised key,
- generate or request a new credential pair,
- update applications using the old credentials,
- remove or disable the compromised key,
- review logs and usage if available.
Treat an exposed Secret Key the same way you would treat an exposed password.
Support requests¶
Do not include a Secret Key in a support ticket.
For diagnostics, you can provide information such as:
with part of the value masked if necessary.
You can also provide:
- the endpoint,
- region,
- bucket name,
- exact error message,
- date and time of the error,
- Request ID if available.
If Cloud4You Support needs additional information, the team will provide a secure method for sharing it.
One key for multiple applications¶
Technically, the same key can be used by multiple applications.
However, for production environments it is better to separate credentials when possible.
This makes it easier to:
- identify which application uses a key,
- rotate credentials,
- disable access for one application,
- troubleshoot incidents,
- reduce the impact of a credential leak.
Summary¶
To connect to Cloud4You Object Storage S3, you need:
Endpoint:
https://s3.cloud4you.pl
Region:
eu-pl-1
Access Key:
<your Access Key>
Secret Key:
<your Secret Key>
Treat the Secret Key as confidential data and never publish it.