# How to grant access control on an object storage bucket

Source: https://docs.quake.ai/docs/object/how-to/grant-access-control
Markdown: https://docs.quake.ai/docs/object/how-to/grant-access-control.md

---

# How to grant access control on an object storage bucket

Control who can read from and write to an object storage bucket. Quake AI supports two levels of access control:

- **Public/private visibility**: set at bucket creation or changed later via the console
- **S3 bucket policies**: fine-grained JSON policies applied via the S3-compatible API

<PrerequisiteBlock methods={["console", "cli", "api"]}>

- An existing object storage bucket: see [Create an object storage bucket](/docs/object/how-to/create-container)
- For S3 bucket policies: [S3 credentials](/docs/object/how-to/create-s3-credentials) configured

</PrerequisiteBlock>

## Set bucket visibility (public or private)



Set bucket visibility and delete buckets from the object storage list view, not from inside the bucket file browser. Open **Storage** > **Object Storage**, open the row **Settings** menu, and choose **File Operations**. See [Object storage in the Console](/reference/object-storage/console/object-storage) for the full layout.



<MethodTabs>
<Method label="Console">

1. Go to **Storage** > **Object Storage**.
2. In the **Action** column for the bucket, select the gear icon (**File Operations**).
3. Select **Update Access**.
4. In the **Update Access** dialog, toggle public access, then select **OK**.

When creating a new bucket, the **Create Bucket** dialog includes a public/private toggle.

</Method>
<Method label="API">

<ObjectApiEnvironment />

Set the read ACL to make the bucket public:

```bash
curl -X POST "$OS_SWIFT_URL/my-bucket" \
  -H "X-Auth-Token: $OS_TOKEN" \
  -H "X-Container-Read: .r:*,.rlistings"
```

Remove public read access:

```bash
curl -X POST "$OS_SWIFT_URL/my-bucket" \
  -H "X-Auth-Token: $OS_TOKEN" \
  -H "X-Container-Read;"
```

The semicolon in `X-Container-Read;` is curl notation for a header with an empty value, which clears the ACL.

</Method>
</MethodTabs>

## Apply an S3 bucket policy

S3 bucket policies provide fine-grained access control for cross-project or cross-user access. They use JSON policy documents compatible with the AWS S3 policy syntax.

In Quake AI, leave the ARN tenant slot empty or set it to your project tenant ID (the hex project id, not the project name). The examples below use the empty form, which Quake AI accepts and which `s3cmd setpolicy` generates by default. To use the tenant ID instead, retrieve it with `openstack project show -c id -f value <PROJECT_NAME>` and place it in each ARN tenant slot.

### Policy structure

A policy document requires:

- **Version**: always `"2012-10-17"`
- **Statement**: an array of permission rules, each with:
  - **Effect**: `"Allow"` or `"Deny"`
  - **Principal**: the user or account being granted access (ARN format: `arn:aws:iam:::user/USERNAME`, with an empty tenant slot)
  - **Action**: one or more S3 actions (for example, `s3:GetObject`, `s3:PutObject`)
  - **Resource**: the bucket and/or objects the rule applies to

### Example policy: read/write for one user, read-only for another

```json
{
  "Version": "2012-10-17",
  "Id": "S3RWPolicy",
  "Statement": [
    {
      "Sid": "UserRW",
      "Effect": "Allow",
      "Principal": {
        "AWS": ["arn:aws:iam:::user/SecondUser"]
      },
      "Action": [
        "s3:ListBucket",
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": [
        "arn:aws:s3:::mybucket",
        "arn:aws:s3:::mybucket/*"
      ]
    },
    {
      "Sid": "UserRO",
      "Effect": "Allow",
      "Principal": {
        "AWS": ["arn:aws:iam:::user/ThirdUser"]
      },
      "Action": [
        "s3:ListBucket",
        "s3:GetObject"
      ],
      "Resource": [
        "arn:aws:s3:::mybucket",
        "arn:aws:s3:::mybucket/*"
      ]
    }
  ]
}
```

### Apply the policy

<MethodTabs>
<Method label="Console">

Bucket policies cannot be applied directly from the Console. Use the CLI or API.

</Method>
<Method label="CLI">

Save your policy to a file (for example, `policy.json`), then apply it:

```bash
s3cmd setpolicy policy.json s3://my-bucket
```

Verify the applied policy:

```bash
s3cmd info s3://my-bucket
```

</Method>
<Method label="API">

```bash
aws s3api put-bucket-policy \
  --bucket my-bucket \
  --policy file://policy.json \
  --endpoint-url "https://object.us-east-1.rumble.cloud"
```

Retrieve the current policy:

```bash
aws s3api get-bucket-policy \
  --bucket my-bucket \
  --endpoint-url "https://object.us-east-1.rumble.cloud"
```

</Method>
</MethodTabs>

For a complete list of supported S3 actions and policy conditions, see the [Ceph bucket policies documentation](https://docs.ceph.com/en/pacific/radosgw/bucketpolicy/).

## See also

- [Create an object storage bucket](/docs/object/how-to/create-container)
- [Create S3 credentials](/docs/object/how-to/create-s3-credentials)
- [Public read policy example](/reference/object-storage/bucket-policies#public-read)
- [Read-only policy example](/reference/object-storage/bucket-policies#read-only-principal)
- [IP whitelist policy example](/reference/object-storage/bucket-policies#ip-whitelist)
