Amazon S3
FlexFS stores file data as compressed blocks in object storage (optionally encrypted end-to-end with AES-256). Amazon S3 is the most commonly used backend and serves as the reference implementation for S3-compatible services such as MinIO, Wasabi, Backblaze B2, and Ceph RGW.
Bucket creation
Section titled “Bucket creation”Create a dedicated S3 bucket for flexFS block storage. FlexFS writes opaque binary blocks — there is no reason to enable versioning or lifecycle rules.
aws s3api create-bucket \ --bucket <bucket> \ --region us-east-1For regions other than us-east-1, include a location constraint:
aws s3api create-bucket \ --bucket <bucket> \ --region eu-west-1 \ --create-bucket-configuration LocationConstraint=eu-west-1Recommended bucket settings
Section titled “Recommended bucket settings”- Block Public Access: Enable all four “Block Public Access” settings. FlexFS never requires public access.
- Versioning: Not required. FlexFS manages its own block lifecycle.
- Object Lock: Not required.
- Encryption: See the Server-Side Encryption section below if you want S3-managed encryption at rest.
IAM policy
Section titled “IAM policy”FlexFS requires the following S3 permissions on the bucket:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject", "s3:DeleteObject", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::<bucket>", "arn:aws:s3:::<bucket>/*" ] } ]}Attach this policy to the IAM user or role that flexFS will authenticate as.
Authentication
Section titled “Authentication”FlexFS supports two authentication methods for S3. The method is determined by whether static credentials are provided.
Static access keys
Section titled “Static access keys”Provide an IAM access key ID and secret access key:
- Enterprise: pass them as
--username(access key ID) and--password(secret access key) when creating the block store withconfigure.flexfs. They are stored in the admin server’s database and passed to the metadata server and mount clients. - Community: pass them as
--blockUserand--blockPasstofree.flexfs init creds.
The metadata server and proxy servers also accept blockUser and blockPass in their own credentials files, set with --blockUser and --blockPass on init creds. The metadata server uses them only for block stores that have no password, and passes them to mount clients in that case. A proxy server always uses its own credentials for its storage access. For example, a metadata server credentials file at ~/.flexfs/meta/creds would contain:
adminAddr = "admin.example.com:443"blockPass = "<password>"blockUser = "<username>"token = "<meta-token>"Instance roles (EC2 / ECS / EKS)
Section titled “Instance roles (EC2 / ECS / EKS)”When no password is configured, flexFS first tries EC2 instance role credentials from the instance metadata service (IMDS). If those are unavailable, it falls back to the AWS SDK default credential chain: environment variables, the shared ~/.aws files, web identity (such as EKS IAM roles for service accounts), and container credentials (ECS task roles, EKS Pod Identity).
Instance roles are the recommended authentication method for production deployments on AWS, as they eliminate the need to manage static credentials.
S3-compatible stores
Section titled “S3-compatible stores”FlexFS uses the AWS SDK v2 with path-style addressing for any endpoint that does not end in amazonaws.com. This enables compatibility with S3-compatible object storage services.
Point the block store address at your MinIO server:
- API code:
s3 - Address:
https://minio.example.com:9000(orhttp://for non-TLS) - Username: MinIO access key
- Password: MinIO secret key
Wasabi
Section titled “Wasabi”Wasabi provides an S3-compatible API with regional endpoints:
- API code:
s3 - Address:
https://s3.wasabisys.com(or the region-specific endpoint, e.g.https://s3.us-east-2.wasabisys.com) - Region: The Wasabi region (e.g.
us-east-2) - Username: Wasabi access key
- Password: Wasabi secret key
Backblaze B2
Section titled “Backblaze B2”Use Backblaze B2’s S3-compatible API:
- API code:
s3 - Address:
https://s3.us-west-004.backblazeb2.com(use your account’s regional endpoint) - Username: B2 application key ID
- Password: B2 application key
Ceph RGW
Section titled “Ceph RGW”For Ceph RADOS Gateway deployments:
- API code:
s3 - Address: Your RGW endpoint (e.g.
https://rgw.example.com) - Username: RGW access key
- Password: RGW secret key
Server-side encryption
Section titled “Server-side encryption”Amazon S3 encrypts every new object with Amazon S3-managed keys (SSE-S3) by default, so blocks written to AWS S3 are encrypted at rest without any flexFS setting. The --sse flag on the proxy server or mount client sends x-amz-server-side-encryption: AES256 on every upload, which also applies to S3-compatible stores that support the header. This overrides a bucket’s default SSE-KMS encryption for flexFS blocks, and a bucket policy that requires SSE-KMS rejects the uploads.
Block store configuration
Section titled “Block store configuration”When creating a block store via configure.flexfs (Enterprise) or the installer, provide:
| Field | Value |
|---|---|
| Provider | aws |
| Region | AWS region code (e.g. us-east-1) |
| API | s3 |
| Bucket | Your S3 bucket name |
| Prefix | Optional key prefix for multi-tenant buckets |
| Address | Leave empty for standard AWS S3; set for S3-compatible stores |
Username (--username) | Access key ID (or leave empty for instance roles) |
Password (--password) | Secret access key (or leave empty for instance roles) |