Skip to content

Deploy the S3 Storage with ACLs template with OpenTofu

Deployment · Updated Jun 2026

Coming from another cloud?

▸AWS·Amazon S3

This Quake AI feature maps to AWS’s Amazon S3.

▸DigitalOcean·Spaces

This Quake AI feature maps to DigitalOcean’s Spaces.

▸Google Cloud·GCS

This Quake AI feature maps to Google Cloud’s GCS.

Deploy the S3 Storage with ACLs template with OpenTofu

Stand up a private S3-compatible bucket with configurable ACL using the validated OpenTofu template s3-storage-acl. The template uses the HashiCorp AWS provider against the Quake AI Object Storage endpoint.

Your workstationQuake AI Object StorageOpenTofu CLIAWS CLIS3 bucketprivate ACL applyput / get objects
Click to zoom
S3 storage topology: OpenTofu applies bucket, ACL, and optional versioning resources against Quake AI Object Storage

Prerequisites#

You need:

Step 1: Mint EC2-compatible credentials#

This template uses the AWS provider against Quake AI Object Storage. Mint EC2-compatible credentials and export the standard AWS variables:

bash
openstack ec2 credentials create
export AWS_ACCESS_KEY_ID=YOUR_ACCESS_KEY
export AWS_SECRET_ACCESS_KEY=YOUR_SECRET_KEY
export AWS_ENDPOINT_URL_S3=https://object.us-east-1.rumble.cloud

Replace the key values with the access and secret fields from the command output. Use the endpoint for your project region if it differs; see Service Endpoints.

Step 2: Configure variables#

Copy terraform.tfvars.example to terraform.tfvars and set:

HCL
bucket_name = "YOUR_UNIQUE_BUCKET_NAME"

Defaults for access_policy, cors_origins, and versioning are documented on the S3 Storage with ACLs reference page.

Step 3: Apply the template#

From the template directory, run:

bash
tofu init
tofu plan
tofu apply

Type yes when prompted. Provisioning completes in seconds because the template only creates bucket-level resources.

When the run finishes, note bucket_name from the outputs.

Step 4: Verify object access and ACL behavior#

Upload and download a test object:

bash
echo "deploy-check" > /tmp/acl-test.txt
aws s3 cp /tmp/acl-test.txt "s3://$(tofu output -raw bucket_name)/acl-test.txt" \
  --endpoint-url "$AWS_ENDPOINT_URL_S3"
aws s3 cp "s3://$(tofu output -raw bucket_name)/acl-test.txt" /tmp/acl-test-download.txt \
  --endpoint-url "$AWS_ENDPOINT_URL_S3"
cat /tmp/acl-test-download.txt

Inspect the bucket ACL. With the default access_policy, anonymous read should not appear:

bash
aws s3api get-bucket-acl --bucket "$(tofu output -raw bucket_name)" \
  --endpoint-url "$AWS_ENDPOINT_URL_S3"

Next steps#

Clean up#

Run tofu destroy from the project directory when finished. Delete the EC2-compatible credential with openstack ec2 credentials delete YOUR_ACCESS_KEY if you created one only for this deployment.

Was this page helpful?