Data
Object storage
Private S3 buckets for files your Serverless App Services store and serve.
Create a bucket
Cloud → Storage → Create bucket, or create it from a Serverless App Service's Storage tab to link it right away. You need resources:write.
- Name: 3–40 lowercase letters, numbers and dashes.
- Location: the bucket is created in the region the location resolves to for S3 and stays there.
Buckets are private: all public access is blocked, and objects are encrypted at rest. The bucket name (si-…-<org id>-<name>-<suffix>) is shown under its name in Storage. Each bucket gets one CORS rule, si-cloud-uploads, that lets Cloud upload to it from the browser.
Browse files
A bucket's Files tab browses it one folder at a time (reading needs resources:read, changing resources:write):
- Upload files, or drop them on the page. The browser sends each file straight to S3 with links valid for 15 minutes, so uploads don't pass through the platform. Files over 100 MB go in parts (16 MB or more each, four at a time; a failed part is retried on its own), up to 5 TB per file. Canceling discards the parts already sent.
- New Folder creates an empty folder.
- Select a file to see its size, type, storage class, encryption, headers (
Cache-Control,Content-Disposition,Content-Encoding) and metadata, and to download it with a link valid for 5 minutes. - Rename or Move a file or folder by entering its new path, or select several and move them into a folder. Files are copied and the originals deleted; nothing is overwritten, and a folder moves with everything in it.
- Delete files and folders. A folder is deleted with everything in it. With versioning on, previous versions are kept.
With versioning on:
- A file's details list its versions: download any of them, Restore an earlier one (it's copied on top as a new version, so history is kept), or delete one for good.
- Show deleted lists the deleted files of the folder you're in; Restore brings one back.
The size and file count on the bucket's page are what S3 reports once a day.
Settings
| Setting | |
|---|---|
| Access | Shows whether the public access block is in place. |
| Versioning | Keep every version of every file. Turning it off suspends it: existing versions are kept, new writes aren't versioned. |
| CORS | Your own CORS rules (up to 20), for browsers that call the bucket directly. Cloud's si-cloud-uploads rule is kept separately and can't be edited. |
| Expire files | Lifecycle rules (up to 50): S3 deletes files under a path (or the whole bucket) a number of days after they're written, and optionally old versions a number of days after they're replaced. Rules set outside Cloud with transitions or filters are marked, since Cloud doesn't show those parts. Every bucket also gets a rule that discards uploads left unfinished (a closed tab during a large upload) after 7 days; it isn't listed and doesn't count toward the 50. |
Connect
The Connect tab shows the environment variables a linked Serverless App Service gets and code for uploading, downloading, listing and sharing files.
Link it to a Serverless App Service
Link a bucket the same way as a database. From the next deployment, the Serverless App Service's server function gets:
| Variable | Value |
|---|---|
SI_BUCKET_<NAME> | The bucket name. |
SI_BUCKET_<NAME>_REGION | The bucket's region. |
A bucket named uploads becomes SI_BUCKET_UPLOADS.
Use it from your code
npm install @aws-sdk/client-s3 @aws-sdk/s3-request-presignerimport { GetObjectCommand, PutObjectCommand, S3Client } from "@aws-sdk/client-s3"
import { getSignedUrl } from "@aws-sdk/s3-request-presigner"
const Bucket = process.env.SI_BUCKET_UPLOADS!
const s3 = new S3Client({ region: process.env.SI_BUCKET_UPLOADS_REGION })
export async function saveFile(key: string, body: Uint8Array, contentType: string) {
await s3.send(new PutObjectCommand({ Bucket, Key: key, Body: body, ContentType: contentType }))
}
export async function readText(key: string) {
const res = await s3.send(new GetObjectCommand({ Bucket, Key: key }))
return res.Body?.transformToString()
}
/** A link a browser can download from for the next 5 minutes. */
export function downloadUrl(key: string) {
return getSignedUrl(s3, new GetObjectCommand({ Bucket, Key: key }), { expiresIn: 300 })
}The runtime role allows GetObject, PutObject, DeleteObject and ListBucket on every bucket of the organization. Presigned URLs carry the function's temporary credentials, so they stop working when those expire, even if expiresIn is longer.
Buckets aren't served at a public URL. Serve files through your app, or hand out presigned URLs.
Delete a bucket
Delete every file first, then choose Delete bucket in Settings (needs resources:write). Old versions of deleted files are removed with the bucket; this can't be undone. If the bucket was already deleted outside the platform, Remove from Cloud removes the record.