How to access buckets via FTP, FTPS, or SFTP
Coming from another cloud?
▸AWS·Amazon S3
This Quake AI feature maps to AWS’s Amazon S3.
▸Azure·Blob Storage
This Quake AI feature maps to Azure’s Blob Storage.
▸DigitalOcean·Space (bucket)
Space (bucket)
- Naming differs: users create a “Space” that is a bucket, and each bucket has a unique URL (virtual-hosted or path style), whereas Swift uses containers within an account namespace. ().
- Bucket addressing uses S3-style endpoints such as `${BUCKET}.${REGION}.digitaloceanspaces.com` (and `${REGION}.digitaloceanspaces.com/${BUCKET}`), which differs from Swift’s account/container/object path conventions. (, ).
- Access keys can be scoped to high-level permission tiers (Read, Read/Write/Delete, All) applied across buckets/objects, which differs from Swift’s typical tenant/user + container ACL model. ().
▸Google Cloud·Storage
This Quake AI feature maps to Google Cloud’s Storage.
▸Hetzner·Buckets
Buckets
- S3 API (PUT Bucket requires specific headers like x-amz-acl limited to private/public-read, LocationConstraint); Swift uses POST/PUT Container with broader ACLs via X-Container-Read/Write.
- Public access via https://bucket.location.your-objectstorage.com/object; Swift public via temp URLs or ACLs.
- Up to 100 buckets per account; Swift has no hard limit.
How to access buckets via FTP, FTPS, or SFTP
Stand up an Ubuntu gateway VM that mounts a Quake AI bucket with s3fs, then serve that mount over SFTP, FTPS, or FTP for clients that cannot speak S3.
Object storage is not a POSIX filesystem. Use this gateway to upload and download whole files. Avoid in-place edits, locking, and random writes on the mount.
For native S3 from a workstation, see How to mount S3 storage on Windows, macOS, and Linux. For S3 and Swift protocol background, see Object Storage.
Prerequisites
- A Quake AI account with object storage capacity and at least one shared vCPU
- An Ubuntu 24.04 instance (this example uses flavor
s1a.micro) and an SSH key - A security group that allows inbound TCP 22 for SSH and SFTP. For FTP, also allow TCP 20 and 21; passive FTP needs extra high ports
- A bucket
- S3 credentials (access key and secret key)
Create the instance, bucket, and keys#
- Create an Ubuntu 24.04 VM. Smaller flavors cap outbound throughput;
s1a.microstill reaches about 500 Mbps. Pick a larger flavor if you need more. - Attach a security group that opens the ports listed in the prerequisites.
- Create a bucket.

- Create S3 credentials.


Install s3fs and mount the bucket#
SSH to the instance as ubuntu, then install s3fs:
sudo apt -y update
sudo apt -y upgrade
sudo apt install -y s3fsWrite the credential file. Replace ACCESS_KEY and SECRET_KEY with the pair from the previous step:
echo "ACCESS_KEY:SECRET_KEY" | sudo tee /etc/passwd-s3fs
sudo chmod 600 /etc/passwd-s3fsCreate the mount point:
sudo mkdir -p /opt/s3storageAdd a line to /etc/fstab. Replace BUCKET_NAME with your bucket and REGION with us-east-1, us-east-2, or us-west-1:
s3fs#BUCKET_NAME /opt/s3storage fuse _netdev,allow_other,passwd_file=/etc/passwd-s3fs,url=https://object.REGION.rumble.cloud/ 0 0| Region | Endpoint |
|---|---|
| US East 1 | https://object.us-east-1.rumble.cloud/ |
| US East 2 | https://object.us-east-2.rumble.cloud/ |
| US West 1 | https://object.us-west-1.rumble.cloud/ |
Reload systemd so it picks up the fstab change, then mount:
sudo systemctl daemon-reload
sudo mount /opt/s3storage/Test SFTP access#
The default Quake AI Ubuntu image serves SFTP on port 22. No extra packages are required.
- Confirm the bucket is empty.

- On your workstation, create a test file and open an SFTP session. Replace
GATEWAY_IPwith the instance address:
echo "This is a test file" > test.txt
sftp ubuntu@GATEWAY_IP- In the SFTP session, upload the file to the mount:
sftp> cd /opt/s3storage
sftp> put test.txt
Uploading test.txt to /opt/s3storage/test.txt
sftp> bye- Confirm the object appears in the bucket.

Optional: FTP with vsftpd#
Install vsftpd on the gateway:
sudo apt install vsftpdEdit /etc/vsftpd.conf and uncomment write_enable=YES so clients can upload files.
Restart the daemon:
sudo systemctl restart vsftpdCreate a dedicated FTP user with a home directory and set a password:
sudo useradd -m -s /bin/bash s3gwftp
sudo passwd s3gwftpFrom a client that has the ftp command, upload a file. Replace GATEWAY_IP with the instance address:
echo "Unencrypted FTP" > test.txt
ftp s3gwftp@GATEWAY_IPConnected to GATEWAY_IP...
220 (vsFTPd 3.0.5)
331 Please specify the password.
Password:
230 Login successful.
ftp> cd /opt/s3storage
250 Directory successfully changed.
ftp> put test.txt
226 Transfer complete.
ftp> exitConfirm the object appears in the bucket.
Optional: FTPS with vsftpd#
Do the FTP steps first. Then enable TLS.
This example uses Ubuntu's default self-signed certificate. For a public hostname, issue a certificate from a public CA such as Let's Encrypt.
Edit /etc/vsftpd.conf:
- Change
ssl_enable=NOtossl_enable=YES - Add
force_local_logins_ssl=YES
Restart vsftpd:
sudo systemctl restart vsftpdThe daemon then accepts FTPS logins only. The stock ftp client does not speak FTPS. Install lftp on the client, then:
sudo apt install lftp
echo "Encrypted FTPS" > test.txt
lftp s3gwftp@GATEWAY_IPPassword:
lftp s3gwftp@GATEWAY_IP:~> set ssl:verify-certificate no
lftp s3gwftp@GATEWAY_IP:~> cd /opt/s3storage
lftp s3gwftp@GATEWAY_IP:/opt/s3storage> put test.txt
lftp s3gwftp@GATEWAY_IP:/opt/s3storage> exitset ssl:verify-certificate no is required for the Ubuntu self-signed certificate. Drop that line when the gateway presents a certificate your client trusts.
Next steps#
- How to mount S3 storage on Windows, macOS, and Linux: mount the same bucket from a workstation with
rclone - How to create S3 credentials: rotate keys used in
/etc/passwd-s3fs - Create security group rules: tighten FTP or FTPS ports to your client networks
The same s3fs mount can back NFS or SMB if you install those servers yourself. Limit those shares to whole-file upload and download; in-place edits on object storage often fail or corrupt objects.
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 01.09.2026
Quick answers
- What is the S3-compatible endpoint hostname?CLIAPI
- Where do I set CORS rules, lifecycle policies, or bucket policies in the Console?Console
- Why do Object Storage API curl examples fail before the first request?API
- Why does my public bucket URL return 404 from the browser after I apply a public-read policy?APIConsole
See Also
How to mount S3 storage on Windows, macOS, and Linux
Shares: S3, Containers
How to Back Up to Quake AI Object Storage
Shares: S3, Object Storage
How to Migrate from Azure blob storage to Quake AI
Shares: S3, Object Storage
How to Migrate from Backblaze B2 to Quake AI
Shares: S3, Object Storage
How to Migrate from DigitalOcean Spaces to Quake AI
Shares: S3, Object Storage