> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  Dokumen ini membahas penyiapan S3 di Server CE dan Ayakaleaf Pro. [Panduan terpisah](/id/on-premises/maintenance/s3-migration) tersedia untuk memigrasikan data yang sudah ada ke penyimpanan yang kompatibel dengan S3.
</Info>

<Warning>
  Jika Anda men-deploy Ayakaleaf Pro dengan penyimpanan [s3.md](/id/on-premises/configuration/overleaf-toolkit/s3 "mention") diaktifkan, apakah data yang disimpan di S3 terenkripsi?

  *<strong>Tidak.</strong>* Data tidak dienkripsi. Semua history chunk, file template, PDF, dan file lainnya disimpan dalam bentuk plaintext. Jika Anda menggunakan penyedia penyimpanan S3 eksternal pihak ketiga, harap perhatikan dengan saksama keamanan dan privasi data.
</Warning>

## Kapan sebaiknya menggunakan S3 untuk penyimpanan data

Untuk instans dengan kurang dari 1000 seat, kami menyarankan penggunaan penyimpanan disk lokal dengan [pencadangan yang konsisten](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup) secara rutin.

Untuk instans yang lebih besar dengan lebih dari 1000 seat yang mencapai batas penyimpanan lokalnya (ukuran atau throughput), kami menyarankan penggunaan backend object storage yang kompatibel dengan S3 dibandingkan solusi penyimpanan berbasis jaringan lainnya seperti NFS.

## Opsi object storage yang kompatibel dengan S3

Berikut adalah opsi paling populer untuk object storage yang kompatibel dengan S3:

* [AWS S3](https://aws.amazon.com/s3/), terkelola; kami menyarankan memilih AWS S3 saat menjalankan Overleaf CE/Server Pro di AWS
* [MINIO](https://min.io/), self-hosted
* [Ceph](https://ceph.io/en/), self-hosted
* Penyedia hosting lain juga memiliki semacam object storage terkelola yang kompatibel dengan S3; Anda mungkin ingin menggunakannya alih-alih menjalankan sendiri jika Anda sudah menjalankan Overleaf CE/Server Pro di penyedia tersebut.

## Pertimbangan latensi saat memilih object storage yang kompatibel dengan S3

Latensi antara instans Server CE/Server Pro dan object storage yang kompatibel dengan S3 sangat memengaruhi waktu yang dibutuhkan untuk menyelesaikan migrasi. Latensi juga memengaruhi kinerja unggah file di Server CE/Server Pro, dan unduhan file yang lambat juga dapat berdampak besar pada waktu kompilasi PDF. Kami menyarankan untuk meminimalkan jarak geografis antara instans Server CE/Server Pro Anda dan object storage yang kompatibel dengan S3. Dalam lingkungan terkelola, ini berarti menyediakan bucket di region yang sama, dan untuk solusi on-premise, menjalankan keduanya di kampus yang sama.

## Penyiapan S3

Kita membutuhkan empat "bucket" dan dua akun pengguna dengan akses terbatas. `overleaf-user-files` dan `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` hanya diperlukan sebelum v6.

<Warning>
  Bucket **tidak boleh** dapat diakses secara publik
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>Bucket</td><td>Penggunaan</td><td>Layanan</td><td>Sebelumnya di `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>file pengguna proyek</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>file template</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>blob riwayat proyek</td><td>history dan filestore baca saja</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>history chunk</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

Anda mungkin ingin/perlu memilih nama yang berbeda; pastikan untuk menggunakan bucket kustom tersebut di semua perintah.

Bagian berikut akan menggunakan placeholder untuk kredensial yang sebenarnya:

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">Variabel lingkungan</th><th>Deskripsi</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>Access key/nama pengguna dari pengguna terbatas layanan filestore.</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>Secret key/kata sandi dari pengguna terbatas layanan filestore.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>Access key/nama pengguna dari pengguna terbatas layanan history.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>Secret key/kata sandi dari pengguna terbatas layanan history.</td></tr></tbody></table></div>

Server CE dan Server Pro hanya memerlukan sejumlah kecil izin pada setiap bucket:

* membuat objek (create object)
* mengambil objek (get object)
* menghapus objek (delete object)
* menampilkan daftar bucket (list bucket)

### Kebijakan Akses

Berikut adalah contoh kebijakan untuk pengguna filestore:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

Berikut adalah contoh kebijakan untuk pengguna history:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### Ikhtisar variabel

#### Saat menggunakan AWS S3

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### Saat menggunakan opsi self-hosted

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### Penyiapan MINIO

<Info>
  `MINIO_ROOT_USER` dan `MINIO_ROOT_PASSWORD` adalah kredensial root dari instans MINIO.
</Info>

Silakan ikuti [dokumentasi resmi](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart) untuk mendapatkan salinan `mc`.

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.