Theme
Ceph (RADOS Gateway)
Ceph is the distributed storage system behind many private clouds. Its object storage interface, the RADOS Gateway (RGW), speaks the S3 API, so a Ceph cluster is a first class SFTP.cloud storage back end.
Step 1: on the Ceph side
You need an RGW user, its keys, and a bucket. The Ceph Dashboard does all three under Object Gateway; the command line is just as quick, on any node with admin access:
bash
# An RGW user; the output includes its access_key and secret_key
radosgw-admin user create --uid=sftpcloud --display-name="SFTP.cloud connector"
# Optional: a hard quota, so a runaway upload cannot fill the cluster
radosgw-admin quota set --quota-scope=user --uid=sftpcloud --max-size=500G
radosgw-admin quota enable --quota-scope=user --uid=sftpcloudThen create the bucket with any S3 client and those keys, for example the AWS CLI with the keys in AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY:
bash
aws --endpoint-url https://rgw.example.internal s3 mb s3://sftp-dataNote the RGW URL. By default the gateway listens on port 7480 over plain HTTP. In production it sits behind TLS, either its own (rgw_frontends with an ssl_port and a certificate) or a reverse proxy such as HAProxy; use that URL.
That is it for the Ceph side. Now to the SFTP.cloud side.
Step 2: in your SFTP.cloud Storage Connector
Best performance
Deploy the Storage Connector on the same network as the RADOS Gateway, a VM in that subnet or in your DMZ, with outbound access only: no inbound rules on your firewall are necessary.
The first thing to do is to add a new Virtual File System. For Ceph in particular there are a few small but important details:
- Type:
S3(as for any other S3 compatible object store) - Region: leave it empty, unless your zonegroup has a custom
api_name, in which case the signature must carry that name: put it here - Endpoint: the RGW URL, for example
https://rgw.example.internal, orhttp://<rgw-host>:7480on a lab cluster - Use path style addressing: on. RGW serves buckets in the request path unless you configured
rgw_dns_nameand a wildcard DNS record. With the toggle off, the Connector looks up<bucket>.<rgw-host>, and the connection test tells you so. - Skip TLS certificate verification: leave it off. If RGW uses a certificate from your own CA, trust that CA on the machine running the Connector instead.
WARNING
Do not forget to press the Save button next to the Access secret after typing it in, or it will not be saved and nothing will work.
When you save, the Connector tests the storage right away. If it cannot reach it, the form stays open and says why.
Then, still in the Storage Connector UI, go to the Users page and give your users the desired access to the new VFS.
Finally
Test it. Connect through your SFTP.cloud WebClient, create a folder, upload some files, then list the bucket from the Ceph Dashboard or with radosgw-admin bucket stats --bucket=sftp-data to see them land.
In the manual