Theme
SeaweedFS
SeaweedFS is a fast distributed file store for very many small and large files. Its S3 gateway (weed s3, or the -s3 flag of weed server) puts an S3 API in front of it, and that is what the Storage Connector talks to.
Step 1: on the SeaweedFS side
Make sure the S3 gateway is running. By default it listens on port 8333: on an all in one deployment that is weed server -s3, on a cluster weed s3 -filer=<filer-host>:8888.
Then, in weed shell, create a bucket and an identity whose credentials are limited to it:
> s3.bucket.create -name sftp-data
> s3.configure -user sftpcloud -access_key AKIAEXAMPLEKEY -secret_key SECRETEXAMPLE \
-buckets sftp-data -actions Read,Write,List,Tagging -applyThe -apply flag writes the identity to the filer, where every S3 gateway picks it up. A gateway with no identities at all accepts anonymous requests, so do configure one.
For TLS, give the gateway a certificate (weed s3 -cert.file=... -key.file=...) or put it behind a reverse proxy, and use that URL.
That is it for the SeaweedFS side. Now to the SFTP.cloud side.
Step 2: in your SFTP.cloud Storage Connector
Best performance
Deploy the Storage Connector on the same network as the S3 gateway, a VM in that subnet or in your DMZ, with outbound access only: no inbound rules on your firewall are necessary.
The first thing to do is to add a new Virtual File System. For SeaweedFS in particular there are a few small but important details:
- Type:
S3(as for any other S3 compatible object store) - Region: leave it empty
- Endpoint:
http://<seaweedfs-host>:8333, or thehttps://URL if the gateway has a certificate or sits behind a reverse proxy - Use path style addressing: on. SeaweedFS serves buckets in the request path unless the gateway was started with
-domainNameand a wildcard DNS record. With the toggle off, the Connector looks up<bucket>.<seaweedfs-host>, and the connection test tells you so. - Skip TLS certificate verification: leave it off. If the gateway uses a certificate from your own CA, trust that CA on the machine running the Connector instead.
WARNING
Do not forget to press the Save button next to the Access secret after typing it in, or it will not be saved and nothing will work.
When you save, the Connector tests the storage right away. If it cannot reach it, the form stays open and says why.
Then, still in the Storage Connector UI, go to the Users page and give your users the desired access to the new VFS.
Finally
Test it. Connect through your SFTP.cloud WebClient, create a folder, upload some files, then browse the bucket in the filer UI (port 8888 by default, under /buckets/sftp-data/) to see them land.
In the manual