> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  Questo documento descrive la configurazione di S3 in Server CE e Ayakaleaf Pro. Una [guida separata](/it/on-premises/maintenance/s3-migration) spiega come migrare i dati esistenti su uno storage compatibile con S3.
</Info>

<Warning>
  Se distribuisci Ayakaleaf Pro con lo storage [s3.md](/it/on-premises/configuration/overleaf-toolkit/s3 "mention") abilitato, i dati memorizzati in S3 sono cifrati?

  *<strong>No.</strong>* I dati non sono cifrati. Tutti i chunk della cronologia, i file dei modelli, i PDF e gli altri file sono memorizzati in chiaro. Se usi un provider di storage S3 esterno di terze parti, presta molta attenzione alla sicurezza e alla privacy dei dati.
</Warning>

## Quando valutare l'uso di S3 per l'archiviazione dei dati

Per le istanze con meno di 1000 postazioni consigliamo di usare lo storage su disco locale con regolari [backup consistenti](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup).

Per le istanze più grandi, con più di 1000 postazioni, che raggiungono i limiti del proprio storage locale (dimensione o throughput), consigliamo di usare un backend di object storage compatibile con S3 anziché altre soluzioni di storage di rete come NFS.

## Opzioni di object storage compatibili con S3

Ecco le opzioni più diffuse di object storage compatibile con S3:

* [AWS S3](https://aws.amazon.com/s3/), gestito; consigliamo di scegliere AWS S3 quando esegui Overleaf CE/Server Pro su AWS
* [MINIO](https://min.io/), self-hosted
* [Ceph](https://ceph.io/en/), self-hosted
* Anche altri provider di hosting offrono qualche forma di object storage gestito compatibile con S3; se esegui già Overleaf CE/Server Pro presso uno di questi provider, potresti volerlo usare invece di gestirne uno tuo.

## Considerazioni sulla latenza nella scelta di un object storage compatibile con S3

La latenza tra l'istanza di Server CE/Server Pro e il tuo object storage compatibile con S3 incide notevolmente sul tempo necessario per completare la migrazione. La latenza influisce anche sulle prestazioni di caricamento dei file in Server CE/Server Pro, e download lenti dei file possono avere un forte impatto anche sui tempi di compilazione dei PDF. Consigliamo di ridurre al minimo la distanza geografica tra la tua istanza di Server CE/Server Pro e l'object storage compatibile con S3. In un ambiente gestito, ciò significa creare un bucket nella stessa regione; per una soluzione on-premise, eseguire entrambi nello stesso campus.

## Configurazione di S3

Servono quattro "bucket" e due account utente con permessi limitati. `overleaf-user-files` e `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` sono necessari solo nelle versioni precedenti alla v6.

<Warning>
  I bucket **non** devono essere accessibili pubblicamente
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>Bucket</td><td>Utilizzo</td><td>Servizio</td><td>In precedenza in `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>file utente dei progetti</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>file dei modelli</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>blob della cronologia dei progetti</td><td>history e filestore in sola lettura</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>chunk della cronologia</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

Potresti volere o dover scegliere un nome diverso: in tal caso assicurati di usare i bucket personalizzati in tutti i comandi.

Di seguito verranno usati dei segnaposto al posto delle credenziali reali:

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">Variabile d'ambiente</th><th>Descrizione</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>La access key/nome utente dell'utente con permessi limitati del servizio filestore.</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>La secret key/password dell'utente con permessi limitati del servizio filestore.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>La access key/nome utente dell'utente con permessi limitati del servizio history.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>La secret key/password dell'utente con permessi limitati del servizio history.</td></tr></tbody></table></div>

Server CE e Server Pro necessitano solo di un piccolo insieme di permessi su ciascun bucket:

* creare oggetti
* leggere oggetti
* eliminare oggetti
* elencare il bucket

### Policy di accesso

Ecco come potrebbe apparire una policy per l'utente del filestore:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

Ecco come potrebbe apparire una policy per l'utente della cronologia:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### Panoramica delle variabili

#### Se usi AWS S3

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### Se usi un'opzione self-hosted

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### Configurazione di MINIO

<Info>
  `MINIO_ROOT_USER` e `MINIO_ROOT_PASSWORD` sono le credenziali root dell'istanza MINIO.
</Info>

Segui la [documentazione ufficiale](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart) per ottenere una copia di `mc`.

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.