> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  يتناول هذا المستند إعداد S3 في Server CE و Ayakaleaf Pro. ويمكنك العثور على [دليل منفصل](/ar/on-premises/maintenance/s3-migration) حول ترحيل البيانات الموجودة إلى تخزين متوافق مع S3.
</Info>

<Warning>
  إذا قمت بنشر Ayakaleaf Pro مع تفعيل تخزين [s3.md](/ar/on-premises/configuration/overleaf-toolkit/s3 "mention")، فهل تكون البيانات المخزّنة في S3 مشفّرة؟

  *<strong>لا.</strong>* البيانات غير مشفّرة. جميع أجزاء السجل (history chunks) وملفات القوالب وملفات PDF وغيرها من الملفات مخزّنة كنص صريح. إذا كنت تستخدم مزوّد تخزين S3 خارجيًا تابعًا لجهة خارجية، فيُرجى إيلاء اهتمام كبير لأمن البيانات وخصوصيتها.
</Warning>

## متى يجب التفكير في استخدام S3 لتخزين البيانات

بالنسبة للنسخ التي تضم أقل من 1000 مقعد، نوصي باستخدام التخزين على القرص المحلي مع [نسخ احتياطية متّسقة](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup) بشكل منتظم.

أما بالنسبة للنسخ الأكبر التي تضم أكثر من 1000 مقعد وتصل إلى حدود تخزينها المحلي (من حيث الحجم أو الإنتاجية)، فنوصي باستخدام واجهة خلفية لتخزين الكائنات متوافقة مع S3 بدلًا من حلول التخزين الأخرى القائمة على الشبكة مثل NFS.

## خيارات تخزين الكائنات المتوافقة مع S3

فيما يلي أشهر خيارات تخزين الكائنات المتوافقة مع S3:

* [AWS S3](https://aws.amazon.com/s3/)، خدمة مُدارة، ونقترح اختيار AWS S3 عند تشغيل Overleaf CE/Server Pro على AWS
* [MINIO](https://min.io/)، استضافة ذاتية
* [Ceph](https://ceph.io/en/)، استضافة ذاتية
* يوفّر مزوّدو استضافة آخرون أيضًا نوعًا من تخزين الكائنات المُدار المتوافق مع S3، وقد ترغب في استخدامه بدلًا من تشغيل حلّك الخاص إذا كنت تشغّل Overleaf CE/Server Pro بالفعل لدى أحد هؤلاء المزوّدين.

## اعتبارات زمن الاستجابة عند اختيار تخزين كائنات متوافق مع S3

يُعد زمن الاستجابة بين نسخة Server CE/Server Pro وتخزين الكائنات المتوافق مع S3 عاملًا رئيسيًا في المدة التي يستغرقها إكمال الترحيل. كما يؤثر زمن الاستجابة على أداء رفع الملفات في Server CE/Server Pro، ويمكن أن يكون لبطء تنزيل الملفات تأثير كبير على أوقات ترجمة PDF أيضًا. نقترح تقليل المسافة الجغرافية بين نسخة Server CE/Server Pro وتخزين الكائنات المتوافق مع S3. في البيئة المُدارة، يعني ذلك إنشاء الحاوية (bucket) في المنطقة نفسها، وفي الحلول المحلية يعني تشغيل الاثنين في الموقع نفسه.

## إعداد S3

نحتاج إلى أربع "حاويات" (buckets) وحسابَي مستخدم مقيّدين. لا حاجة إلى `overleaf-user-files` و`OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` إلا في الإصدارات السابقة للإصدار v6.

<Warning>
  يجب **ألا** تكون الحاويات (buckets) متاحة للعموم
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>الحاوية (Bucket)</td><td>الاستخدام</td><td>الخدمة</td><td>الموقع السابق في `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>ملفات المستخدم في المشاريع</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>ملفات القوالب</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>كائنات سجل المشاريع (blobs)</td><td>history و filestore للقراءة فقط</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>أجزاء السجل (chunks)</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

قد ترغب أو تحتاج إلى اختيار اسم مختلف، فاحرص على استخدام الحاويات المخصصة في جميع الأوامر.

سيستخدم ما يلي نصوصًا نائبة بدلًا من بيانات الاعتماد الفعلية:

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">متغير البيئة</th><th>الوصف</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>مفتاح الوصول/اسم المستخدم للمستخدم المقيّد لخدمة filestore.</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>المفتاح السري/كلمة المرور للمستخدم المقيّد لخدمة filestore.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>مفتاح الوصول/اسم المستخدم للمستخدم المقيّد لخدمة history.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>المفتاح السري/كلمة المرور للمستخدم المقيّد لخدمة history.</td></tr></tbody></table></div>

لا يحتاج Server CE و Server Pro إلا إلى مجموعة صغيرة من الأذونات على كل حاوية:

* إنشاء كائن
* جلب كائن
* حذف كائن
* سرد محتويات الحاوية

### سياسات الوصول

إليك كيف يمكن أن تبدو سياسة مستخدم filestore:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

وإليك كيف يمكن أن تبدو سياسة مستخدم history:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### نظرة عامة على المتغيرات

#### عند استخدام AWS S3

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### عند استخدام خيار ذاتي الاستضافة

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### إعداد MINIO

<Info>
  `MINIO_ROOT_USER` و `MINIO_ROOT_PASSWORD` هما بيانات اعتماد الجذر (root) لنسخة MINIO.
</Info>

يُرجى اتباع [التوثيق الرسمي](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart) للحصول على نسخة من `mc`.

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.