Create S3 compatible buckets from Object Storage in my.cubepath.com. Any S3 client works with them: the AWS CLI, rclone, restic, boto3 and the other AWS SDKs, or cubecli.
https://eu.cubestorage.io (region eu)
NoteYour account must be verified before you can create a bucket, and Object Storage is only available in projects billed hourly.
What it's for
Object Storage keeps files (objects) in buckets and serves them over HTTPS with the S3 API. It fits data you write through an application or a tool rather than a mounted disk:
- Backups and archives: database dumps, server backups with restic or rclone, logs you need to keep.
- Application data: user uploads, generated reports, exports.
- Static assets and media served to the public through the CDN.
Buckets are always private. There are no public buckets and no static website hosting: to publish files, connect the bucket to a CDN zone (see Serve files to the public below).
Tiers
| Tier | Media | Best for |
|---|---|---|
| Infrequent Access | HDD | Backups, archives, logs and data that is written once and rarely read |
| Standard | SSD | Coming soon. Content that is read often: media, CDN assets, application data |
Every tier of a region shares the same endpoint. A bucket cannot change tier after it's created.
Create a bucket
- 1Choose a storage tierPick the tier that matches how often the data will be read. The card shows its prices and the free allowance.
- 2Name the bucket3 to 63 lowercase letters, numbers and hyphens, starting and ending with a letter or number. Names are unique across all CubePath customers, so a common name may already be taken.
- 3Versioning (optional)Turn on Enable versioning to keep previous versions of overwritten or deleted objects. You can also turn it on later.
- 4CreateClick Create Bucket. It's ready in 10 to 20 seconds.
NoteYour first bucket may require a balance of at least $5. Each organization can have up to 20 buckets.
Create an access key
S3 clients authenticate with an access key, not with your CubePath login or API token. Open Object Storage → Access keys → Create access key:
- Name: what the key is for (e.g.
backups-db01). - Tier: keys work on the buckets of one tier.
- Permission: Read and write, or Read only.
- Bucket access: All buckets of the project in that tier (including ones you create later), or Only selected buckets.
- Expiration (optional): the key stops working at the end of that day (UTC) and is then deleted.
WarningThe secret access key is shown only once. Copy it or download one of the ready to use files (
.env,rclone.confor~/.aws/credentials) before closing the dialog. If you lose it, delete the key and create a new one.
The key starts working a few seconds after it's created, once its status is Active.
TipCreate one key per application, give it only the buckets it needs, and make it read only if it never writes. A leaked key then exposes one bucket instead of all of them.
Connect an S3 client
Use the endpoint https://eu.cubestorage.io, the region eu and your access key.
AWS CLI
aws configure set aws_access_key_id CPXXXXXXXXXXXXXXXXXX
aws configure set aws_secret_access_key YOUR_SECRET
aws configure set region eu
aws s3 cp backup.tar.gz s3://my-bucket/ --endpoint-url https://eu.cubestorage.io
aws s3 ls s3://my-bucket/ --endpoint-url https://eu.cubestorage.io
rclone (~/.config/rclone/rclone.conf)
[cubepath]
type = s3
provider = Other
access_key_id = CPXXXXXXXXXXXXXXXXXX
secret_access_key = YOUR_SECRET
endpoint = https://eu.cubestorage.io
region = eu
rclone copy ./backups cubepath:my-bucket/backups
cubecli
cubecli s3 bucket create my-bucket --tier ia
cubecli s3 key create --name backups --tier ia --bucket my-bucket --output rclone >> ~/.config/rclone/rclone.conf
Both URL styles work: https://eu.cubestorage.io/my-bucket/file.txt (path style) and https://my-bucket.eu.cubestorage.io/file.txt (virtual host). Uploads straight from a browser (CORS) only work with the path style URL.
The bucket tabs
| Tab | What it's for |
|---|---|
| Overview | Size, object count, this month's usage and cost, and the connection details (endpoint, region, URLs) |
| Files | Browse, upload, download and delete files, and create folders |
| CDN | Serve the bucket's files to the public through a CDN zone |
| Settings | Versioning, deletion protection and billing details |
| Activity | Every change to the bucket and who made it |
Size counts every stored version and refreshes about every 15 minutes.
Files
The Files tab is a file browser in the dashboard: open folders, Upload (or drag and drop onto the panel), Download, Delete files or whole folders, and create a New folder. Large files are uploaded in parts automatically.
The browser works with your dashboard session; scripts and applications use an access key and any S3 client instead. Its requests are billed like any other request to the bucket.
Settings
- Versioning keeps every version of an object, so overwritten or deleted files can be recovered. Old versions are stored and billed like any other data. Once enabled, versioning can be suspended but never turned off.
- Deletion protection stops the bucket from being deleted from the dashboard, the API or the CLI until you disable it.
Serve files to the public
Buckets stay private. To publish their files, add the bucket as an origin of a CDN zone: open the zone → Origins → Add origin and pick the bucket. The CDN tab of the bucket links you there and shows the public URL once it's connected.
The CDN reads the bucket with a dedicated read only key that only works from the CDN edges, and caches the files close to your visitors. Your bucket's own access keys never leave your applications.
- Traffic from the bucket to the CDN is not billed as egress: you pay the CDN zone instead.
- Requests from the CDN edges count as class B requests of the bucket.
- One CDN origin per bucket. To stop serving it, delete that origin from the zone.
Pricing
Billing is hourly in arrears, from the moment a bucket is active until it's deleted. Nothing is charged while it's being created.
| Infrequent Access | Price |
|---|---|
| Storage | $0.004 per GiB-month |
| Egress (to the Internet) | $0.01 per GiB |
| Class A requests (writes and listings: PUT, POST, COPY, LIST) | $0.006 per 1,000 |
| Class B requests (reads: GET and HEAD of an object) | $0.0006 per 1,000 |
| Deletes, ListBuckets, OPTIONS | Free |
Free every month, per organization and tier: 5 GiB-month of storage, 5 GiB of egress and 20,000 requests. You get an email when the free allowance runs out.
The Usage tab shows storage, egress and requests per bucket for the month, what has been billed so far and a projection for the full month. Failed requests (4xx and 5xx) are never billed.
Limits
- 20 buckets per organization and 20 access keys per project and tier.
- 5 GiB per single upload; larger files go in parts (multipart, up to 10,000 parts). The dashboard handles that for you.
- 1 TiB per bucket as a soft limit: you get an email when a bucket goes above it, and if it's still above after 72 hours, uploads to that bucket are paused (reads, listings and deletes keep working) until it's back under. Contact support if a bucket needs more.
- Presigned URLs last at most 24 hours. Unfinished multipart uploads are cleaned up after 7 days.
Delete a bucket
From Settings → Delete bucket, type the bucket name to confirm.
- By default the bucket is only deleted if it's empty. Tick Also delete every object in the bucket to delete all objects, versions and unfinished uploads first. This can't be undone and takes a while for large buckets.
- A protected bucket, or one that is still served by a CDN origin, can't be deleted until you disable protection or remove the origin.
- Billing stops once the deletion finishes. The name stays reserved for your organization for 90 days.
NoteIf a bucket shows as suspended, your data is kept but can't be reached. When it's because your organization is suspended, topping up your balance restores access.