# Deploy the S3 Storage with ACLs template with OpenTofu

Source: https://docs.quake.ai/resources/deployments/deploy-s3-storage-acl-template
Markdown: https://docs.quake.ai/resources/deployments/deploy-s3-storage-acl-template.md
> Stand up a private S3-compatible bucket with configurable ACL using the s3-storage-acl OpenTofu template.

---

# Deploy the S3 Storage with ACLs template with OpenTofu

Stand up a private S3-compatible bucket with configurable ACL using the [validated OpenTofu template](/docs/platform/validation#how-infrastructure-templates-are-checked) `s3-storage-acl`. The template uses the HashiCorp AWS provider against the Quake AI Object Storage endpoint.

<PricingCompanion
  components={[
    { kind: "template", slug: "s3-storage-acl", required: true },
  ]}
/>

<Figure size="md" caption="S3 storage topology: OpenTofu applies bucket, ACL, and optional versioning resources against Quake AI Object Storage">

```d2
direction: right

client: Your workstation {
  tofu: OpenTofu CLI
  awscli: AWS CLI
}

cloud: Quake AI Object Storage {
  bucket: S3 bucket\nprivate ACL
}

client.tofu -> cloud.bucket: apply
client.awscli -> cloud.bucket: put / get objects
```

</Figure>

## Prerequisites

You need:

- A Quake AI account with [application credentials](/docs/tools/generate-app-credentials)
- OpenTofu 1.6.0 or later ([installation guide](https://opentofu.org/docs/intro/install/))
- The AWS CLI installed ([installation guide](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html))
- OpenStack credentials sourced into the shell for minting EC2-compatible keys. See [the OpenStack CLI guide](/docs/tools/openstack-cli).
- A copy of the `s3-storage-acl` template from [the template reference page](/resources/iac-templates/s3-storage-acl)

## Step 1: Mint EC2-compatible credentials

This template uses the AWS provider against Quake AI Object Storage. Mint EC2-compatible credentials and export the standard AWS variables:

```bash
openstack ec2 credentials create
export AWS_ACCESS_KEY_ID=YOUR_ACCESS_KEY
export AWS_SECRET_ACCESS_KEY=YOUR_SECRET_KEY
export AWS_ENDPOINT_URL_S3=https://object.us-east-1.rumble.cloud
```

Replace the key values with the `access` and `secret` fields from the command output. Use the endpoint for your project region if it differs; see [Service Endpoints](/docs/tools/service-endpoints).

## Step 2: Configure variables

Copy `terraform.tfvars.example` to `terraform.tfvars` and set:

```hcl
bucket_name = "YOUR_UNIQUE_BUCKET_NAME"
```

Defaults for `access_policy`, `cors_origins`, and `versioning` are documented on the [S3 Storage with ACLs](/resources/iac-templates/s3-storage-acl) reference page.

## Step 3: Apply the template

From the template directory, run:

```bash
tofu init
tofu plan
tofu apply
```

Type `yes` when prompted. Provisioning completes in seconds because the template only creates bucket-level resources.

When the run finishes, note `bucket_name` from the outputs.

## Step 4: Verify object access and ACL behavior

Upload and download a test object:

```bash
echo "deploy-check" > /tmp/acl-test.txt
aws s3 cp /tmp/acl-test.txt "s3://$(tofu output -raw bucket_name)/acl-test.txt" \
  --endpoint-url "$AWS_ENDPOINT_URL_S3"
aws s3 cp "s3://$(tofu output -raw bucket_name)/acl-test.txt" /tmp/acl-test-download.txt \
  --endpoint-url "$AWS_ENDPOINT_URL_S3"
cat /tmp/acl-test-download.txt
```

Inspect the bucket ACL. With the default `access_policy`, anonymous read should not appear:

```bash
aws s3api get-bucket-acl --bucket "$(tofu output -raw bucket_name)" \
  --endpoint-url "$AWS_ENDPOINT_URL_S3"
```



A single `tofu destroy` against the Quake AI S3 gateway can fail while deleting a bucket policy or CORS configuration. Run `tofu destroy` a second time; the next pass finds those resources already gone and completes. See the [S3 Storage with ACLs](/resources/iac-templates/s3-storage-acl) reference page for manual cleanup commands if you enabled `public-read` or non-empty `cors_origins`.



## Next steps

- [S3 Storage with ACLs template](/resources/iac-templates/s3-storage-acl)
- [Simple VM with Floating IP template](/resources/iac-templates/simple-vm)
- [Media streaming](/resources/solutions/media-streaming)

## Clean up

Run `tofu destroy` from the project directory when finished. Delete the EC2-compatible credential with `openstack ec2 credentials delete YOUR_ACCESS_KEY` if you created one only for this deployment.
