How to grant access control on an object storage bucket
How to grant access control on an object storage bucket
Control who can read from and write to an object storage bucket. Quake AI supports two levels of access control:
- Public/private visibility: set at bucket creation or changed later via the console
- S3 bucket policies: fine-grained JSON policies applied via the S3-compatible API
Prerequisites
- ConsoleLogged in to the Quake AI console
- CLIOpenStack CLI installed and authenticated (
clouds.yamloropenrcsourced) - APIAPI token generated with
$OS_TOKENand service endpoint variables set
Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.
- An existing object storage bucket: see Create an object storage bucket
- For S3 bucket policies: S3 credentials configured
Set bucket visibility (public or private)#
Apply an S3 bucket policy#
S3 bucket policies provide fine-grained access control for cross-project or cross-user access. They use JSON policy documents compatible with the AWS S3 policy syntax.
In Quake AI, leave the ARN tenant slot empty or set it to your project tenant ID (the hex project id, not the project name). The examples below use the empty form, which Quake AI accepts and which s3cmd setpolicy generates by default. To use the tenant ID instead, retrieve it with openstack project show -c id -f value <PROJECT_NAME> and place it in each ARN tenant slot.
Policy structure#
A policy document requires:
- Version: always
"2012-10-17" - Statement: an array of permission rules, each with:
- Effect:
"Allow"or"Deny" - Principal: the user or account being granted access (ARN format:
arn:aws:iam:::user/USERNAME, with an empty tenant slot) - Action: one or more S3 actions (for example,
s3:GetObject,s3:PutObject) - Resource: the bucket and/or objects the rule applies to
- Effect:
Example policy: read/write for one user, read-only for another#
{
"Version": "2012-10-17",
"Id": "S3RWPolicy",
"Statement": [
{
"Sid": "UserRW",
"Effect": "Allow",
"Principal": {
"AWS": ["arn:aws:iam:::user/SecondUser"]
},
"Action": [
"s3:ListBucket",
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject"
],
"Resource": [
"arn:aws:s3:::mybucket",
"arn:aws:s3:::mybucket/*"
]
},
{
"Sid": "UserRO",
"Effect": "Allow",
"Principal": {
"AWS": ["arn:aws:iam:::user/ThirdUser"]
},
"Action": [
"s3:ListBucket",
"s3:GetObject"
],
"Resource": [
"arn:aws:s3:::mybucket",
"arn:aws:s3:::mybucket/*"
]
}
]
}Apply the policy#
For a complete list of supported S3 actions and policy conditions, see the Ceph bucket policies documentation.
See also#
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 10.07.2026