Theme
Google Cloud Storage
Google Cloud Storage (GCS) is Google's object storage. The Storage Connector talks to it natively, through its own Google Cloud Storage VFS type and a service account key, so you do not need the HMAC keys of its S3 compatibility layer.
Step 1: in the Google Cloud console
- Create a bucket. Open Cloud Storage, then Buckets, and choose Create. Pick a globally unique name and the location you want the data in. Keep Uniform access control and Enforce public access prevention on.
- Create a service account. Open IAM & Admin, then Service accounts, and choose Create service account. Give it a name and grant it no project wide role.
- Grant it access to the bucket only. Back in the bucket, open Permissions, choose Grant access, enter the service account's email address as the principal, and assign the Storage Object User role: it can create, read, list, overwrite and delete objects, and nothing else. The Connector needs no bucket level permission.
- Create a JSON key. Open the service account, go to the Keys tab, choose Add key, then Create new key, and pick JSON. The file downloads once; keep it safe.
That is it for the Google Cloud side. Now to the SFTP.cloud side.
Step 2: in your SFTP.cloud Storage Connector
Best performance
Deploy the Storage Connector as close as possible to the storage it handles. For Google Cloud Storage, a Compute Engine VM or a pod in Google Kubernetes Engine in the bucket's region are the ideal choices.
Add a new Virtual File System of type Google Cloud Storage. The fields are:
- Bucket name: the bucket you created
- Path inside: optional; a folder prefix inside the bucket, if you do not want the VFS at its root
- Service account credentials (JSON): paste the whole content of the downloaded key file
WARNING
Do not forget to press the Save button next to the credentials after pasting them, or they will not be saved and nothing will work.
When you save, the Connector tests the storage right away. If it cannot reach it, the form stays open and says why.
Then, still in the Storage Connector UI, go to the Users page and give your users the desired access to the new VFS.
Finally
Test it. Connect through your SFTP.cloud WebClient, create a folder, upload some files, then open the bucket in the console to see them land.
In the manual