> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  Este documento cubre la configuración de S3 en Server CE y Ayakaleaf Pro. Existe una [guía aparte](/es/on-premises/maintenance/s3-migration) sobre la migración de datos existentes a un almacenamiento compatible con S3.
</Info>

<Warning>
  Si despliegas Ayakaleaf Pro con el almacenamiento [s3.md](/es/on-premises/configuration/overleaf-toolkit/s3 "mention") habilitado, ¿se cifran los datos almacenados en S3?

  *<strong>No.</strong>* Los datos no se cifran. Todos los fragmentos del historial, los archivos de plantillas, los PDF y demás archivos se almacenan en texto plano. Si utilizas un proveedor externo de almacenamiento S3, presta mucha atención a la seguridad y la privacidad de los datos.
</Warning>

## Cuándo considerar el uso de S3 para el almacenamiento de datos

Para instancias con menos de 1000 puestos, recomendamos usar almacenamiento en disco local con [copias de seguridad consistentes](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup) periódicas.

Para instancias más grandes, con más de 1000 puestos, que alcanzan los límites de su almacenamiento local (tamaño o rendimiento), recomendamos usar un backend de almacenamiento de objetos compatible con S3 en lugar de otras soluciones de almacenamiento en red como NFS.

## Opciones de almacenamiento de objetos compatibles con S3

Estas son las opciones más populares de almacenamiento de objetos compatible con S3:

* [AWS S3](https://aws.amazon.com/s3/), gestionado; te sugerimos elegir AWS S3 cuando ejecutes Overleaf CE/Server Pro en AWS
* [MINIO](https://min.io/), autoalojado
* [Ceph](https://ceph.io/en/), autoalojado
* Otros proveedores de alojamiento también ofrecen algún tipo de almacenamiento de objetos gestionado compatible con S3; si ya ejecutas Overleaf CE/Server Pro en uno de ellos, puede que prefieras usarlo en lugar de mantener el tuyo propio.

## Consideraciones de latencia al elegir un almacenamiento de objetos compatible con S3

La latencia entre la instancia de Server CE/Server Pro y tu almacenamiento de objetos compatible con S3 influye mucho en el tiempo necesario para completar la migración. La latencia también afecta al rendimiento de la subida de archivos en Server CE/Server Pro, y las descargas lentas de archivos pueden tener un gran impacto en los tiempos de compilación de PDF. Te sugerimos minimizar la distancia geográfica entre tu instancia de Server CE/Server Pro y el almacenamiento de objetos compatible con S3. En un entorno gestionado, esto significa aprovisionar un bucket en la misma región y, en una solución on-premise, ejecutar ambos en el mismo campus.

## Configuración de S3

Necesitamos cuatro "buckets" y dos cuentas de usuario restringidas. `overleaf-user-files` y `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` solo son necesarios antes de la v6.

<Warning>
  Los buckets **no** deben ser accesibles públicamente
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>Bucket</td><td>Uso</td><td>Servicio</td><td>Antes en `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>archivos de usuario del proyecto</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>archivos de plantillas</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>blobs del historial del proyecto</td><td>history y filestore de solo lectura</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>fragmentos del historial</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

Puede que quieras o necesites elegir un nombre distinto; asegúrate de usar tus buckets personalizados en todos los comandos.

A continuación se usarán marcadores de posición en lugar de las credenciales reales:

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">Variable de entorno</th><th>Descripción</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>La clave de acceso/nombre de usuario del usuario restringido del servicio filestore.</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>La clave secreta/contraseña del usuario restringido del servicio filestore.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>La clave de acceso/nombre de usuario del usuario restringido del servicio history.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>La clave secreta/contraseña del usuario restringido del servicio history.</td></tr></tbody></table></div>

Server CE y Server Pro solo necesitan un pequeño conjunto de permisos en cada bucket:

* crear objeto
* obtener objeto
* eliminar objeto
* listar bucket

### Políticas de acceso

Así podría ser una política para el usuario de filestore:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

Así podría ser una política para el usuario de history:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### Resumen de variables

#### Al usar AWS S3

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### Al usar una opción autoalojada

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### Configuración de MINIO

<Info>
  `MINIO_ROOT_USER` y `MINIO_ROOT_PASSWORD` son las credenciales root de la instancia de MINIO.
</Info>

Sigue la [documentación oficial](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart) para obtener una copia de `mc`.

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.