> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  이 문서는 Server CE 및 Ayakaleaf Pro에서 S3를 설정하는 방법을 다룹니다. 기존 데이터를 S3 호환 스토리지로 마이그레이션하는 방법은 [별도 가이드](/ko/on-premises/maintenance/s3-migration)를 참조하세요.
</Info>

<Warning>
  [s3.md](/ko/on-premises/configuration/overleaf-toolkit/s3 "mention") 스토리지를 활성화한 상태로 Ayakaleaf Pro를 배포하면 S3에 저장된 데이터가 암호화되나요?

  *<strong>아니요.</strong>* 데이터는 암호화되지 않습니다. 모든 기록 청크, 템플릿 파일, PDF 및 기타 파일은 평문으로 저장됩니다. 서드파티 외부 S3 스토리지 제공업체를 사용하는 경우 데이터 보안과 개인정보 보호에 각별히 주의하세요.
</Warning>

## 데이터 저장에 S3 사용을 고려해야 하는 경우

사용자 수가 1000석 미만인 인스턴스에는 정기적인 [일관된 백업](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup)과 함께 로컬 디스크 스토리지를 사용하는 것을 권장합니다.

1000석 이상의 대규모 인스턴스에서 로컬 스토리지의 한계(용량 또는 처리량)에 도달한 경우, NFS 같은 다른 네트워크 기반 스토리지 솔루션보다 S3 호환 객체 스토리지 백엔드를 사용하는 것을 권장합니다.

## S3 호환 객체 스토리지 옵션

가장 많이 사용되는 S3 호환 객체 스토리지 옵션은 다음과 같습니다.

* [AWS S3](https://aws.amazon.com/s3/), 관리형. AWS에서 Overleaf CE/Server Pro를 실행하는 경우 AWS S3를 선택하는 것을 권장합니다.
* [MINIO](https://min.io/), 자체 호스팅
* [Ceph](https://ceph.io/en/), 자체 호스팅
* 다른 호스팅 제공업체도 일종의 관리형 S3 호환 객체 스토리지를 제공합니다. 이미 해당 제공업체에서 Overleaf CE/Server Pro를 실행 중이라면 직접 운영하는 대신 이를 사용하는 것이 좋을 수 있습니다.

## S3 호환 객체 스토리지 선택 시 지연 시간 고려 사항

Server CE/Server Pro 인스턴스와 S3 호환 객체 스토리지 간의 지연 시간은 마이그레이션 완료에 걸리는 시간에 큰 영향을 미칩니다. 지연 시간은 Server CE/Server Pro의 파일 업로드 성능에도 영향을 주며, 파일 다운로드가 느리면 PDF 컴파일 시간에도 큰 영향을 줄 수 있습니다. Server CE/Server Pro 인스턴스와 S3 호환 객체 스토리지 간의 지리적 거리를 최소화하는 것을 권장합니다. 관리형 환경에서는 같은 리전에 버킷을 프로비저닝하고, 온프레미스 솔루션에서는 두 시스템을 같은 캠퍼스에서 운영하는 것을 의미합니다.

## S3 설정

네 개의 "버킷"과 두 개의 제한된 사용자 계정이 필요합니다. `overleaf-user-files`와 `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME`은 v6 이전 버전에서만 필요합니다.

<Warning>
  버킷은 공개적으로 접근할 수 **없어야** 합니다.
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>버킷</td><td>용도</td><td>서비스</td><td>이전 위치 `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>프로젝트 사용자 파일</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>템플릿 파일</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>프로젝트 기록 blob</td><td>history 및 읽기 전용 filestore</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>기록 청크</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

다른 이름을 선택하고 싶거나 선택해야 할 수도 있습니다. 그런 경우 모든 명령에서 사용자 지정 버킷 이름을 사용하세요.

다음은 실제 자격 증명 대신 자리 표시자를 사용합니다.

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">환경 변수</th><th>설명</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>filestore 서비스용 제한된 사용자의 액세스 키/사용자 이름입니다.</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>filestore 서비스용 제한된 사용자의 시크릿 키/비밀번호입니다.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>history 서비스용 제한된 사용자의 액세스 키/사용자 이름입니다.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>history 서비스용 제한된 사용자의 시크릿 키/비밀번호입니다.</td></tr></tbody></table></div>

Server CE와 Server Pro는 각 버킷에 대해 다음과 같은 최소한의 권한만 필요합니다.

* 객체 생성
* 객체 가져오기
* 객체 삭제
* 버킷 나열

### 액세스 정책

filestore 사용자의 정책은 다음과 같이 구성할 수 있습니다.

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

history 사용자의 정책은 다음과 같이 구성할 수 있습니다.

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### 변수 개요

#### AWS S3를 사용하는 경우

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### 자체 호스팅 옵션을 사용하는 경우

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### MINIO 설정

<Info>
  `MINIO_ROOT_USER` 및 `MINIO_ROOT_PASSWORD`는 MINIO 인스턴스의 루트 자격 증명입니다.
</Info>

`mc`를 설치하려면 [공식 문서](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart)를 따르세요.

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.