# How to access buckets via FTP, FTPS, or SFTP

Source: https://docs.quake.ai/docs/object/how-to/access-via-ftp-sftp
Markdown: https://docs.quake.ai/docs/object/how-to/access-via-ftp-sftp.md

---

# How to access buckets via FTP, FTPS, or SFTP

Stand up an Ubuntu gateway VM that mounts a Quake AI bucket with `s3fs`, then serve that mount over SFTP, FTPS, or FTP for clients that cannot speak S3.

Object storage is not a POSIX filesystem. Use this gateway to upload and download whole files. Avoid in-place edits, locking, and random writes on the mount.

For native S3 from a workstation, see [How to mount S3 storage on Windows, macOS, and Linux](/docs/object/how-to/mount-s3-storage). For S3 and Swift protocol background, see [Object Storage](/docs/object/concepts/object-storage).

<PrerequisiteBlock>

- A Quake AI account with object storage capacity and at least one shared vCPU
- An [Ubuntu 24.04 instance](/docs/compute/how-to/create-instance) (this example uses flavor `s1a.micro`) and an SSH key
- A [security group](/docs/network/how-to/create-security-group-rules) that allows inbound TCP 22 for SSH and SFTP. For FTP, also allow TCP 20 and 21; passive FTP needs extra high ports
- A [bucket](/docs/object/how-to/create-container)
- [S3 credentials](/docs/object/how-to/create-s3-credentials) (access key and secret key)

</PrerequisiteBlock>



FTP sends passwords in plain text. Restrict FTP to a private network. Prefer SFTP, or the S3 API, when the client reaches the gateway over the public internet. FTPS encrypts the session but needs a TLS certificate and extra firewall ports for passive mode.



## Create the instance, bucket, and keys

1. Create an Ubuntu 24.04 VM. Smaller flavors cap outbound throughput; `s1a.micro` still reaches about 500 Mbps. Pick a larger flavor if you need more.
2. Attach a security group that opens the ports listed in the prerequisites.
3. Create a bucket.

![Object Storage console showing a newly created bucket](/images/docs/object/articles/ftp-sftp-access/2025-05-16-15-13-10.png)

4. Create S3 credentials.

![S3 credentials page with a new access key](/images/docs/object/articles/ftp-sftp-access/2025-05-16-15-14-54.png)

![Create S3 credentials dialog with access key and secret key](/images/docs/object/articles/ftp-sftp-access/2025-05-16-15-15-28.png)

## Install s3fs and mount the bucket

SSH to the instance as `ubuntu`, then install `s3fs`:

```bash
sudo apt -y update
sudo apt -y upgrade
sudo apt install -y s3fs
```

Write the credential file. Replace `ACCESS_KEY` and `SECRET_KEY` with the pair from the previous step:

```bash
echo "ACCESS_KEY:SECRET_KEY" | sudo tee /etc/passwd-s3fs
sudo chmod 600 /etc/passwd-s3fs
```

Create the mount point:

```bash
sudo mkdir -p /opt/s3storage
```

Add a line to `/etc/fstab`. Replace `BUCKET_NAME` with your bucket and `REGION` with `us-east-1`, `us-east-2`, or `us-west-1`:

```bash
s3fs#BUCKET_NAME /opt/s3storage fuse _netdev,allow_other,passwd_file=/etc/passwd-s3fs,url=https://object.REGION.rumble.cloud/ 0 0
```

| Region | Endpoint |
|--------|----------|
| US East 1 | `https://object.us-east-1.rumble.cloud/` |
| US East 2 | `https://object.us-east-2.rumble.cloud/` |
| US West 1 | `https://object.us-west-1.rumble.cloud/` |

Reload systemd so it picks up the fstab change, then mount:

```bash
sudo systemctl daemon-reload
sudo mount /opt/s3storage/
```

## Test SFTP access

The default Quake AI Ubuntu image serves SFTP on port 22. No extra packages are required.

1. Confirm the bucket is empty.

![Empty bucket in the Object Storage console](/images/docs/object/articles/ftp-sftp-access/2025-05-16-22-51-43.png)

2. On your workstation, create a test file and open an SFTP session. Replace `GATEWAY_IP` with the instance address:

```bash
echo "This is a test file" > test.txt
sftp ubuntu@GATEWAY_IP
```

3. In the SFTP session, upload the file to the mount:

```text
sftp> cd /opt/s3storage
sftp> put test.txt
Uploading test.txt to /opt/s3storage/test.txt
sftp> bye
```

4. Confirm the object appears in the bucket.

![Bucket listing showing test.txt after the SFTP upload](/images/docs/object/articles/ftp-sftp-access/2025-05-16-22-59-37.png)

## Optional: FTP with vsftpd

Install `vsftpd` on the gateway:

```bash
sudo apt install vsftpd
```

Edit `/etc/vsftpd.conf` and uncomment `write_enable=YES` so clients can upload files.

Restart the daemon:

```bash
sudo systemctl restart vsftpd
```

Create a dedicated FTP user with a home directory and set a password:

```bash
sudo useradd -m -s /bin/bash s3gwftp
sudo passwd s3gwftp
```

From a client that has the `ftp` command, upload a file. Replace `GATEWAY_IP` with the instance address:

```bash
echo "Unencrypted FTP" > test.txt
ftp s3gwftp@GATEWAY_IP
```

```text
Connected to GATEWAY_IP...
220 (vsFTPd 3.0.5)
331 Please specify the password.
Password:
230 Login successful.
ftp> cd /opt/s3storage
250 Directory successfully changed.
ftp> put test.txt
226 Transfer complete.
ftp> exit
```

Confirm the object appears in the bucket.

## Optional: FTPS with vsftpd

Do the FTP steps first. Then enable TLS.

This example uses Ubuntu's default self-signed certificate. For a public hostname, issue a certificate from a public CA such as Let's Encrypt.

Edit `/etc/vsftpd.conf`:

- Change `ssl_enable=NO` to `ssl_enable=YES`
- Add `force_local_logins_ssl=YES`

Restart vsftpd:

```bash
sudo systemctl restart vsftpd
```

The daemon then accepts FTPS logins only. The stock `ftp` client does not speak FTPS. Install `lftp` on the client, then:

```bash
sudo apt install lftp
echo "Encrypted FTPS" > test.txt
lftp s3gwftp@GATEWAY_IP
```

```text
Password:
lftp s3gwftp@GATEWAY_IP:~> set ssl:verify-certificate no
lftp s3gwftp@GATEWAY_IP:~> cd /opt/s3storage
lftp s3gwftp@GATEWAY_IP:/opt/s3storage> put test.txt
lftp s3gwftp@GATEWAY_IP:/opt/s3storage> exit
```

`set ssl:verify-certificate no` is required for the Ubuntu self-signed certificate. Drop that line when the gateway presents a certificate your client trusts.

## Next steps

- [How to mount S3 storage on Windows, macOS, and Linux](/docs/object/how-to/mount-s3-storage): mount the same bucket from a workstation with `rclone`
- [How to create S3 credentials](/docs/object/how-to/create-s3-credentials): rotate keys used in `/etc/passwd-s3fs`
- [Create security group rules](/docs/network/how-to/create-security-group-rules): tighten FTP or FTPS ports to your client networks

The same `s3fs` mount can back NFS or SMB if you install those servers yourself. Limit those shares to whole-file upload and download; in-place edits on object storage often fail or corrupt objects.
