Theme
Garage
Garage is a lightweight, geo distributed, S3 compatible object store built for self hosting on modest hardware. Everything is administered with the garage command line tool.
Step 1: on the Garage side
bash
# A bucket and a key, then the grant that ties them together
garage bucket create sftp-data
garage key create sftpcloud
garage bucket allow --read --write --owner sftp-data --key sftpcloud
# The key id (GK...) and its secret
garage key info sftpcloud --show-secretTwo values from garage.toml matter on the SFTP.cloud side, both under [s3_api]: s3_region (the default is garage) and api_bind_addr, the address of the S3 API (port 3900 by default). Garage checks the region in every request's signature and refuses a mismatch, so read the actual value from your configuration.
That is it for the Garage side. Now to the SFTP.cloud side.
Step 2: in your SFTP.cloud Storage Connector
Best performance
Deploy the Storage Connector on the same network as a Garage node, a VM in that subnet or in your DMZ, with outbound access only: no inbound rules on your firewall are necessary.
The first thing to do is to add a new Virtual File System. For Garage in particular there are a few small but important details:
- Type:
S3(as for any other S3 compatible object store) - Region: the
s3_regionof yourgarage.toml,garageunless you changed it. This one is not optional: a wrong region is refused. - Endpoint:
http://<garage-host>:3900, or thehttps://URL of the reverse proxy in front of it - Use path style addressing: on. Garage can also serve buckets as host names under its
root_domain, but that needs a wildcard DNS record; the path style works everywhere. - Skip TLS certificate verification: leave it off. If the reverse proxy uses a certificate from your own CA, trust that CA on the machine running the Connector instead.
WARNING
Do not forget to press the Save button next to the Access secret after typing it in, or it will not be saved and nothing will work.
When you save, the Connector tests the storage right away. If it cannot reach it, the form stays open and says why.
Then, still in the Storage Connector UI, go to the Users page and give your users the desired access to the new VFS.
Finally
Test it. Connect through your SFTP.cloud WebClient, create a folder, upload some files, then run garage bucket info sftp-data to see the object count grow.
In the manual