Clusterward
Object Storage

Object Storage with a dedicated key per application

Clusterward creates Scaleway buckets, mints a dedicated IAM key per application with a matching bucket policy and copies existing S3 buckets into them. Only empty buckets are ever deleted.

Object Storage in the Clusterward Cockpit
Simplified view in the Clusterward cockpit: Object Storage
Illustration: a simplified view. The product shows more details and options.
In brief

What Object Storage in Clusterward is

Object Storage in Clusterward is the management of Scaleway S3 buckets from the cockpit. A provider is a Scaleway project, registered by its IAM key; the key determines which project buckets are created in. Buckets are created as private or public and, on request, get a dedicated IAM key consisting of an IAM application, a project policy and an API key. The bucket policy admits exactly that application and, for public buckets, anonymous reads. One key can serve several buckets of the same application.

At a glance

Provider
One Scaleway project = one IAM key, verified before saving
Buckets
Private or public, visibility set at creation
Key
Dedicated IAM key per application, readable in the cockpit
Policy
Bucket policy with application, provider and console
Import
Copy from any external S3 bucket, never delete
Deletion
Only empty, registered buckets, after typing the name
How it works

From project to bucket

  1. 01

    Create a provider

    Enter the project’s IAM key; Clusterward verifies it with ListBuckets and detects the project and organization.

  2. 02

    Create a bucket

    Choose name, region and visibility. An existing bucket is never silently taken over.

  3. 03

    Mint a key

    A new dedicated key or an existing one of the same application.

  4. 04

    Write the policy

    Bucket policy with the application, the provider principal and, optionally, anonymous reads.

  5. 05

    Connect

    Copy access key, secret key, endpoint and region in the cockpit.

What’s included

What Object Storage in Clusterward brings

The IAM details that easily go wrong on Scaleway are solved properly here, once.

Provider with detected project

The IAM key is verified via ListBuckets before saving, stored encrypted and never displayed. Clusterward detects the project, organization and principal via the IAM API.

Dedicated key per application

IAM application, policy and API key are created together. One key serves both the public and the private bucket of the same application.

A bucket policy that works

Scaleway needs both sides: an IAM policy and a bucket policy. The policy names the application, the provider and your console users – otherwise the Files tab stays empty.

Public or private

A public bucket gets the public-read ACL and anonymous reads in its policy. Visibility is set at creation.

Import from existing buckets

Copy objects from an external S3 bucket under a prefix into a bucket of your own, with progress and cancellation. Copy and overwrite, never delete.

Archive before deletion

During tenant offboarding, a bucket that still holds data is uploaded as a ZIP to your backup bucket and only then emptied. Without a confirmed archive, it stays in place.

Standards, not DIY

S3-compatible, no SDK

  • SigV4

    Signed requests straight to the Scaleway endpoints, tested against the AWS test vectors.

  • Scaleway IAM

    Applications, policies and API keys via the IAM API.

  • Bucket policy

    Version 2023-04-17, with a console access statement for your users.

  • Streaming

    Objects are copied as a stream, Content-Type included.

What changes

Buckets with and without Clusterward

Facts

Import limits

The import runs in the Clusterward service because Object Storage is publicly reachable. The limits keep it predictable.

LimitValueBehavior
Single object2 GiBLarger objects are skipped and counted
Total volumeapprox. 20 GiB per runAbove that, the run is rejected before it starts
Object countapprox. 50,000 per runAbove that, the run is rejected before it starts
Parallelism2 copies at a timeAdditional runs wait in the queue
RerunCopy and overwriteA second run is idempotent
Further reading

How Object Storage fits in

In a pipeline, the bucket building block creates a bucket pair with its own key for each tenant and hands over the credentials only at runtime, as described under Tenant pipelines. The credentials end up in the encrypted variables of the deployment.

Database dumps and bucket archives from offboarding are stored in your workspace’s backup bucket, see Managed databases.

Related features

What goes with it

FAQ

Frequently asked questions about Object Storage

  • A Scaleway project, registered by its IAM key. Because an IAM key belongs to exactly one Object Storage project, registering the key is also selecting the project. Clusterward verifies the key via ListBuckets, stores it encrypted and shows the project and organization on the card.

Can’t find your question? Write to us – we usually reply on the same business day.

Ask a question

Create buckets in the demo

We register your project, create a bucket pair with its own key and check the policy in the Scaleway console.