> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  このドキュメントでは、Server CE および Ayakaleaf Pro における S3 のセットアップについて説明します。既存のデータを S3 互換ストレージに移行する方法については、[別のガイド](/ja/on-premises/maintenance/s3-migration)を参照してください。
</Info>

<Warning>
  [s3.md](/ja/on-premises/configuration/overleaf-toolkit/s3 "mention") ストレージを有効にして Ayakaleaf Pro をデプロイした場合、S3 に保存されるデータは暗号化されますか？

  *<strong>いいえ。</strong>* データは暗号化されません。すべての履歴チャンク、テンプレートファイル、PDF、その他のファイルは平文で保存されます。サードパーティの外部 S3 ストレージプロバイダーを使用する場合は、データのセキュリティとプライバシーに十分注意してください。
</Warning>

## データストレージに S3 の使用を検討すべき場合

シート数が 1000 未満のインスタンスでは、定期的な[整合性のあるバックアップ](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup)とともにローカルディスクストレージを使用することをおすすめします。

シート数が 1000 を超え、ローカルストレージの限界（容量またはスループット）に達する大規模なインスタンスでは、NFS などの他のネットワークベースのストレージソリューションよりも、S3 互換のオブジェクトストレージバックエンドを使用することをおすすめします。

## S3 互換オブジェクトストレージの選択肢

S3 互換オブジェクトストレージの代表的な選択肢は次のとおりです。

* [AWS S3](https://aws.amazon.com/s3/)：マネージド。AWS 上で Overleaf CE/Server Pro を実行している場合は AWS S3 を選ぶことをおすすめします
* [MINIO](https://min.io/)：セルフホスト
* [Ceph](https://ceph.io/en/)：セルフホスト
* 他のホスティングプロバイダーも何らかのマネージド S3 互換オブジェクトストレージを提供しています。すでにそのようなプロバイダーで Overleaf CE/Server Pro を実行している場合は、自前で運用する代わりにそれらを使用するとよいでしょう。

## S3 互換オブジェクトストレージを選ぶ際のレイテンシーに関する考慮事項

Server CE/Server Pro インスタンスと S3 互換オブジェクトストレージ間のレイテンシーは、移行の完了にかかる時間に大きく影響します。レイテンシーは Server CE/Server Pro でのファイルアップロードのパフォーマンスにも影響し、ファイルのダウンロードが遅いと PDF のコンパイル時間にも大きな影響を与える可能性があります。Server CE/Server Pro インスタンスと S3 互換オブジェクトストレージの地理的な距離をできるだけ短くすることをおすすめします。マネージド環境では同じリージョンにバケットをプロビジョニングすること、オンプレミスのソリューションでは両者を同じキャンパス内で運用することを意味します。

## S3 のセットアップ

4 つの「バケット」と 2 つの制限付きユーザーアカウントが必要です。`overleaf-user-files` と `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` は v6 より前のバージョンでのみ必要です。

<Warning>
  バケットはパブリックにアクセス可能にしては**いけません**
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>バケット</td><td>用途</td><td>サービス</td><td>以前の `/var/lib/overleaf/data` 内の場所</td></tr><tr><td>`overleaf-user-files`</td><td>プロジェクトのユーザーファイル</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>テンプレートファイル</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>プロジェクト履歴の blob</td><td>history および読み取り専用の filestore</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>履歴チャンク</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

別の名前を選びたい、または選ぶ必要がある場合は、すべてのコマンドでそのカスタムバケット名を使用してください。

以下では、実際の認証情報の代わりにプレースホルダーを使用します。

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">環境変数</th><th>説明</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>filestore サービスの制限付きユーザーのアクセスキー/ユーザー名。</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>filestore サービスの制限付きユーザーのシークレットキー/パスワード。</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>history サービスの制限付きユーザーのアクセスキー/ユーザー名。</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>history サービスの制限付きユーザーのシークレットキー/パスワード。</td></tr></tbody></table></div>

Server CE と Server Pro が各バケットで必要とする権限はわずかです。

* オブジェクトの作成
* オブジェクトの取得
* オブジェクトの削除
* バケットの一覧表示

### アクセスポリシー

filestore ユーザーのポリシーの例は次のとおりです。

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

history ユーザーのポリシーの例は次のとおりです。

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### 変数の概要

#### AWS S3 を使用する場合

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### セルフホストの選択肢を使用する場合

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### MINIO のセットアップ

<Info>
  `MINIO_ROOT_USER` と `MINIO_ROOT_PASSWORD` は MINIO インスタンスの root 認証情報です。
</Info>

`mc` の入手方法については、[公式ドキュメント](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart)に従ってください。

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.