# S3 Storage with ACLs

Source: https://docs.quake.ai/resources/iac-templates/s3-storage-acl
Markdown: https://docs.quake.ai/resources/iac-templates/s3-storage-acl.md

---

# S3 storage with ACLs

This pattern composes Object Storage.

## What this template does

Provisions an S3-compatible object storage bucket with credentials and access policies:

- Object storage container with configurable access policy
- S3 credentials (access key + secret key) for programmatic access
- Bucket policy for read/write or read-only access patterns
- CORS configuration for web application access

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `bucket_name` | Storage container name | No default |
| `access_policy` | Bucket access policy | `private` |
| `cors_origins` | Allowed CORS origins | `[]` |
| `versioning` | Enable object versioning | `false` |
| `s3_endpoint` | Quake AI S3-compatible endpoint URL | `https://object.us-east-1.rumble.cloud` |
| `s3_region` | S3 region identifier | `us-east-1` |

## When to use this pattern

Create an S3-compatible bucket with a canned ACL through the AWS provider. Choose compute-backed patterns when the workload needs VMs; this pattern covers object storage only.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "s3-storage-acl", required: true },
  ]}
/>

## Template source

<TemplateSource slug="s3-storage-acl" />

<TemplateResourceMap template="s3-storage-acl" format="opentofu" />

## Tearing down


A single `tofu destroy` against the Quake AI S3 gateway can fail while deleting the bucket policy and CORS configuration, reporting `waiting for S3 Bucket Policy delete: found resource` or `waiting for S3 Bucket CORS Configuration delete: found resource`. The gateway removes the policy and CORS server-side, but its read-after-delete is eventually consistent, so the provider's verification loop still sees the resource inside its retry window. Run `tofu destroy` a second time: the next pass finds the resources already gone and completes. You can also empty the bucket and remove the resources directly with `aws s3api delete-bucket-policy`, `aws s3api delete-bucket-cors`, and `aws s3 rb`.


## Customize this pattern

- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy the S3 Storage with ACLs template with OpenTofu](/resources/deployments/deploy-s3-storage-acl-template): end-to-end tutorial for this template
- [Object Storage overview](/docs/object)
- [S3 credentials](/docs/object/how-to/s3-credentials)
