Skip to content

How to access buckets via FTP, FTPS, or SFTP

How-to · Updated Sep 2026

Coming from another cloud?

▸AWS·Amazon S3

This Quake AI feature maps to AWS’s Amazon S3.

▸Azure·Blob Storage

This Quake AI feature maps to Azure’s Blob Storage.

▸DigitalOcean·Space (bucket)

Space (bucket)high

  • Naming differs: users create a “Space” that is a bucket, and each bucket has a unique URL (virtual-hosted or path style), whereas Swift uses containers within an account namespace. ().
  • Bucket addressing uses S3-style endpoints such as `${BUCKET}.${REGION}.digitaloceanspaces.com` (and `${REGION}.digitaloceanspaces.com/${BUCKET}`), which differs from Swift’s account/container/object path conventions. (, ).
  • Access keys can be scoped to high-level permission tiers (Read, Read/Write/Delete, All) applied across buckets/objects, which differs from Swift’s typical tenant/user + container ACL model. ().
DigitalOcean docs ↗
▸Google Cloud·Storage

This Quake AI feature maps to Google Cloud’s Storage.

▸Hetzner·Buckets

Bucketshigh

  • S3 API (PUT Bucket requires specific headers like x-amz-acl limited to private/public-read, LocationConstraint); Swift uses POST/PUT Container with broader ACLs via X-Container-Read/Write.
  • Public access via https://bucket.location.your-objectstorage.com/object; Swift public via temp URLs or ACLs.
  • Up to 100 buckets per account; Swift has no hard limit.
Hetzner docs ↗
Before this

How to access buckets via FTP, FTPS, or SFTP

Stand up an Ubuntu gateway VM that mounts a Quake AI bucket with s3fs, then serve that mount over SFTP, FTPS, or FTP for clients that cannot speak S3.

Object storage is not a POSIX filesystem. Use this gateway to upload and download whole files. Avoid in-place edits, locking, and random writes on the mount.

For native S3 from a workstation, see How to mount S3 storage on Windows, macOS, and Linux. For S3 and Swift protocol background, see Object Storage.

Prerequisites
  • A Quake AI account with object storage capacity and at least one shared vCPU
  • An Ubuntu 24.04 instance (this example uses flavor s1a.micro) and an SSH key
  • A security group that allows inbound TCP 22 for SSH and SFTP. For FTP, also allow TCP 20 and 21; passive FTP needs extra high ports
  • A bucket
  • S3 credentials (access key and secret key)

Create the instance, bucket, and keys#

  1. Create an Ubuntu 24.04 VM. Smaller flavors cap outbound throughput; s1a.micro still reaches about 500 Mbps. Pick a larger flavor if you need more.
  2. Attach a security group that opens the ports listed in the prerequisites.
  3. Create a bucket.

Object Storage console showing a newly created bucket

  1. Create S3 credentials.

S3 credentials page with a new access key

Create S3 credentials dialog with access key and secret key

Install s3fs and mount the bucket#

SSH to the instance as ubuntu, then install s3fs:

bash
sudo apt -y update
sudo apt -y upgrade
sudo apt install -y s3fs

Write the credential file. Replace ACCESS_KEY and SECRET_KEY with the pair from the previous step:

bash
echo "ACCESS_KEY:SECRET_KEY" | sudo tee /etc/passwd-s3fs
sudo chmod 600 /etc/passwd-s3fs

Create the mount point:

bash
sudo mkdir -p /opt/s3storage

Add a line to /etc/fstab. Replace BUCKET_NAME with your bucket and REGION with us-east-1, us-east-2, or us-west-1:

bash
s3fs#BUCKET_NAME /opt/s3storage fuse _netdev,allow_other,passwd_file=/etc/passwd-s3fs,url=https://object.REGION.rumble.cloud/ 0 0
RegionEndpoint
US East 1https://object.us-east-1.rumble.cloud/
US East 2https://object.us-east-2.rumble.cloud/
US West 1https://object.us-west-1.rumble.cloud/

Reload systemd so it picks up the fstab change, then mount:

bash
sudo systemctl daemon-reload
sudo mount /opt/s3storage/

Test SFTP access#

The default Quake AI Ubuntu image serves SFTP on port 22. No extra packages are required.

  1. Confirm the bucket is empty.

Empty bucket in the Object Storage console

  1. On your workstation, create a test file and open an SFTP session. Replace GATEWAY_IP with the instance address:
bash
echo "This is a test file" > test.txt
sftp ubuntu@GATEWAY_IP
  1. In the SFTP session, upload the file to the mount:
sftp> cd /opt/s3storage
sftp> put test.txt
Uploading test.txt to /opt/s3storage/test.txt
sftp> bye
  1. Confirm the object appears in the bucket.

Bucket listing showing test.txt after the SFTP upload

Optional: FTP with vsftpd#

Install vsftpd on the gateway:

bash
sudo apt install vsftpd

Edit /etc/vsftpd.conf and uncomment write_enable=YES so clients can upload files.

Restart the daemon:

bash
sudo systemctl restart vsftpd

Create a dedicated FTP user with a home directory and set a password:

bash
sudo useradd -m -s /bin/bash s3gwftp
sudo passwd s3gwftp

From a client that has the ftp command, upload a file. Replace GATEWAY_IP with the instance address:

bash
echo "Unencrypted FTP" > test.txt
ftp s3gwftp@GATEWAY_IP
Connected to GATEWAY_IP...
220 (vsFTPd 3.0.5)
331 Please specify the password.
Password:
230 Login successful.
ftp> cd /opt/s3storage
250 Directory successfully changed.
ftp> put test.txt
226 Transfer complete.
ftp> exit

Confirm the object appears in the bucket.

Optional: FTPS with vsftpd#

Do the FTP steps first. Then enable TLS.

This example uses Ubuntu's default self-signed certificate. For a public hostname, issue a certificate from a public CA such as Let's Encrypt.

Edit /etc/vsftpd.conf:

  • Change ssl_enable=NO to ssl_enable=YES
  • Add force_local_logins_ssl=YES

Restart vsftpd:

bash
sudo systemctl restart vsftpd

The daemon then accepts FTPS logins only. The stock ftp client does not speak FTPS. Install lftp on the client, then:

bash
sudo apt install lftp
echo "Encrypted FTPS" > test.txt
lftp s3gwftp@GATEWAY_IP
Password:
lftp s3gwftp@GATEWAY_IP:~> set ssl:verify-certificate no
lftp s3gwftp@GATEWAY_IP:~> cd /opt/s3storage
lftp s3gwftp@GATEWAY_IP:/opt/s3storage> put test.txt
lftp s3gwftp@GATEWAY_IP:/opt/s3storage> exit

set ssl:verify-certificate no is required for the Ubuntu self-signed certificate. Drop that line when the gateway presents a certificate your client trusts.

Next steps#

The same s3fs mount can back NFS or SMB if you install those servers yourself. Limit those shares to whole-file upload and download; in-place edits on object storage often fail or corrupt objects.

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

For the full policy, see Usage Guidelines.

Last validated: 01.09.2026

Quick answers

Was this page helpful?