Common Errors¶
Below you will find the most common error messages encountered when working with Cloud4You Object Storage S3 and basic ways to diagnose them.
AccessDenied¶
Example:
This means that the user does not have permission to perform the requested operation or is trying to access a resource they are not authorized to use.
Check:
- whether you are using the correct Access Key,
- whether you are using the correct AWS CLI profile,
- whether the bucket name is correct,
- whether the user has permission for the requested operation,
- whether the bucket belongs to another user or tenant,
- whether you are attempting anonymous access to a private resource.
Example of checking the profile:
Example of listing buckets:
InvalidAccessKeyId¶
Example:
This usually means that the Access Key is incorrect, inactive, or does not exist.
Check:
Then make sure you are using the correct profile:
If the credentials were recently changed, check whether the application is still using the old key.
SignatureDoesNotMatch¶
Example:
The most common causes are:
- incorrect Secret Key,
- incorrect region,
- incorrect endpoint,
- incorrect system date or time,
- the application signs the request in a way that does not match the endpoint configuration.
Check:
Also check the system time.
Linux:
Windows PowerShell:
The Secret Key is the most common cause
If the Access Key is correct but SignatureDoesNotMatch appears, first verify the Secret Key, region, and system time.
NoSuchBucket¶
Example:
This means that the specified bucket does not exist or the application is referring to an incorrect bucket name.
List available buckets:
Then compare the bucket name with the application configuration.
Example of a valid name:
Pay attention to:
- typos,
- uppercase and lowercase letters,
- extra spaces,
- an incorrect endpoint,
- an incorrect bucket addressing method.
NoSuchKey¶
Example:
This means that the specified object does not exist under the given key.
List objects:
aws \
--profile cloud4you \
--endpoint-url https://s3.cloud4you.pl \
s3 ls s3://firma-backup/ --recursive
Remember that the Object Key is the full name of the object.
Example:
is a different key from:
BucketAlreadyExists¶
Example:
The bucket name is already in use and cannot be used to create a new bucket.
Choose another name.
Example:
BucketAlreadyOwnedByYou¶
Example:
A bucket with this name already exists and belongs to your user.
Check the bucket list:
You do not need to create it again.
BucketNotEmpty¶
Example:
The bucket contains data and cannot be deleted.
Check its contents:
aws \
--profile cloud4you \
--endpoint-url https://s3.cloud4you.pl \
s3 ls s3://firma-backup/ --recursive
If you want to delete all currently visible objects:
aws \
--profile cloud4you \
--endpoint-url https://s3.cloud4you.pl \
s3 rm s3://firma-backup/ --recursive
Destructive operation
This command deletes objects from the bucket.
Carefully verify the bucket name before running it.
Bucket with versioning enabled¶
If versioning is enabled, the bucket may still contain:
- older object versions,
- Delete Markers.
Check:
aws \
--profile cloud4you \
--endpoint-url https://s3.cloud4you.pl \
s3api list-object-versions \
--bucket firma-backup
EntityTooLarge¶
Example:
This error may occur when the client tries to upload an object in a way that is not supported for its size.
For large files, use a client that supports Multipart Upload.
AWS CLI automatically uses multipart upload for large files.
Example:
aws \
--profile cloud4you \
--endpoint-url https://s3.cloud4you.pl \
s3 cp duzy-plik.tar.gz s3://firma-backup/
InvalidBucketName¶
Example:
The bucket name does not meet the requirements.
We recommend using:
- lowercase letters,
- numbers,
- hyphens.
Valid example:
Invalid examples:
InvalidArgument¶
Example:
This means that one of the values passed to the API is invalid.
Check:
- region name,
- bucket name,
- command parameters,
- application configuration,
- values passed by the SDK.
For Cloud4You, use the region:
InvalidRequest¶
Example:
The request is syntactically valid but cannot be executed in the supplied form.
Check:
- the bucket addressing method,
- endpoint configuration,
- region,
- options used by the S3 client.
If the application provides an option such as:
or:
try changing its setting.
RequestTimeTooSkewed¶
Example:
The device's system time differs significantly from the server time.
S3 uses time when verifying signed requests.
Linux¶
Check:
If time synchronization is disabled:
Windows¶
Check time synchronization:
You can force synchronization:
Could not connect to the endpoint URL¶
AWS CLI example:
Check the endpoint:
Then check DNS.
Linux/macOS:
Windows:
Check HTTPS:
Info
Receiving an HTTP response from the endpoint means that network connectivity is working.
For a full authentication test, use an S3 client with a valid Access Key and Secret Key.
SSL certificate verify failed¶
Example:
Check:
- whether the endpoint is entered correctly,
- whether you are using
https://, - system time,
- whether CA certificates are up to date,
- whether a firewall or proxy is intercepting TLS traffic.
Correct endpoint:
Do not disable TLS verification as a permanent solution
Disabling certificate verification may hide the real problem and reduce connection security.
Connection timed out¶
Example:
This usually indicates a network problem.
Check:
- Internet connectivity,
- DNS,
- firewall,
- proxy,
- access to TCP/443,
- endpoint correctness.
Test:
Connection reset¶
Example:
This may indicate that the TCP session was interrupted by an intermediate device or that a temporary problem occurred.
Check:
- firewall,
- proxy,
- IDS/IPS,
- VPN connection,
- whether the problem also occurs from another network,
- whether it affects one operation or all requests.
If the problem is repeatable, record the time of occurrence and Request ID and provide them to support.
403 Forbidden¶
HTTP 403 most commonly corresponds to:
Check:
- credentials,
- permissions,
- bucket name,
- addressing method,
- whether the request is anonymous.
404 Not Found¶
HTTP 404 may indicate, among other things:
Check:
- bucket name,
- Object Key,
- endpoint,
- whether the resource actually exists.
HTTP 500¶
HTTP 500 indicates a server-side error or a temporary problem while processing the request.
If the problem occurs once:
- retry the operation,
- check whether subsequent requests work correctly.
If the problem repeats, record:
- exact time,
- endpoint,
- operation name,
- error code,
- Request ID.
Then contact Cloud4You.
HTTP 502 / 503 / 504¶
Errors:
may indicate a temporary service availability problem or communication issue between infrastructure components.
For a single occurrence, retry the operation.
If the problem repeats:
- record the exact time,
- record the endpoint used,
- note the HTTP code,
- keep the Request ID if the client displays it,
- report the problem to Cloud4You.
SlowDown¶
Example:
The service may ask the client to reduce the request rate.
The application should retry requests with a delay.
If you are developing your own S3 API integration, implement retries with increasing backoff.
Problem occurs only in one application¶
If AWS CLI works correctly but another application cannot connect, the problem usually lies in that application's configuration.
Compare:
Also check options such as:
If the application supports AWS Signature Version 4, use that mode.
Simplest diagnostic test¶
If you do not know whether the problem is related to the account or the application, run this AWS CLI test:
aws \
--profile cloud4you \
--endpoint-url https://s3.cloud4you.pl \
--region eu-pl-1 \
s3api list-buckets
If this command works:
- the endpoint works,
- DNS works,
- TLS works,
- the Access Key is recognized,
- the Secret Key is correct,
- the request signature is accepted.
In that case, the configuration of the specific application requires further diagnosis.
AWS CLI debug mode¶
To obtain more information:
aws \
--profile cloud4you \
--endpoint-url https://s3.cloud4you.pl \
--region eu-pl-1 \
s3api list-buckets \
--debug
Do not publish the full log without checking it
A debug log may contain technical information about the configuration and requests.
Review it before sending it to a third party.
What should I include in a support ticket?¶
To speed up diagnostics, provide:
- endpoint used,
- region,
- application or S3 client name,
- application version,
- error code,
- full error message,
- date and exact time when the problem occurred,
- bucket name, if relevant,
- Request ID, if the client displays it.
Example:
Endpoint: https://s3.cloud4you.pl
Region: eu-pl-1
Client: AWS CLI 2.x
Operation: ListBuckets
Error: AccessDenied
Time: 2026-08-27 14:32 CEST
Do not send the Secret Key
The Secret Key is not required for standard diagnostics and should not be included in a support ticket.