> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  Este documento aborda a configuração do S3 no Server CE e no Ayakaleaf Pro. Há um [guia separado](/pt/on-premises/maintenance/s3-migration) sobre a migração de dados existentes para um armazenamento compatível com S3.
</Info>

<Warning>
  Se você implantar o Ayakaleaf Pro com o armazenamento [s3.md](/pt/on-premises/configuration/overleaf-toolkit/s3 "mention") ativado, os dados armazenados no S3 são criptografados?

  *<strong>Não.</strong>* Os dados não são criptografados. Todos os chunks de histórico, arquivos de template, PDFs e outros arquivos são armazenados em texto simples. Se você usar um provedor externo de armazenamento S3 de terceiros, preste muita atenção à segurança e à privacidade dos dados.
</Warning>

## Quando considerar o uso do S3 para armazenamento de dados

Para instâncias com menos de 1000 licenças, recomendamos usar armazenamento em disco local com [backups consistentes](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup) regulares.

Para instâncias maiores, com mais de 1000 licenças, que atingem os limites do armazenamento local (tamanho ou taxa de transferência), recomendamos usar um back end de armazenamento de objetos compatível com S3 em vez de outras soluções de armazenamento em rede, como NFS.

## Opções de armazenamento de objetos compatível com S3

Estas são as opções mais populares de armazenamento de objetos compatível com S3:

* [AWS S3](https://aws.amazon.com/s3/), gerenciado; sugerimos escolher o AWS S3 ao executar o Overleaf CE/Server Pro na AWS
* [MINIO](https://min.io/), auto-hospedado
* [Ceph](https://ceph.io/en/), auto-hospedado
* Outros provedores de hospedagem também oferecem algum tipo de armazenamento de objetos gerenciado compatível com S3; você pode preferir usá-lo em vez de manter o seu próprio se já executa o Overleaf CE/Server Pro nesse provedor.

## Considerações sobre latência ao escolher um armazenamento de objetos compatível com S3

A latência entre a instância do Server CE/Server Pro e seu armazenamento de objetos compatível com S3 contribui muito para o tempo necessário para concluir a migração. A latência também afeta o desempenho do upload de arquivos no Server CE/Server Pro, e downloads de arquivos lentos também podem ter um grande impacto nos tempos de compilação de PDF. Sugerimos minimizar a distância geográfica entre sua instância do Server CE/Server Pro e o armazenamento de objetos compatível com S3. Em um ambiente gerenciado, isso significa provisionar um bucket na mesma região e, em uma solução on-premise, executar os dois no mesmo campus.

## Configuração do S3

Precisamos de quatro "buckets" e duas contas de usuário restritas. `overleaf-user-files` e `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` só são necessários antes da v6.

<Warning>
  Os buckets **não** devem ser acessíveis publicamente
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>Bucket</td><td>Uso</td><td>Serviço</td><td>Anteriormente em `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>arquivos de usuário dos projetos</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>arquivos de template</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>blobs do histórico de projetos</td><td>history e filestore somente leitura</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>chunks de histórico</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

Você pode querer/precisar escolher um nome diferente; certifique-se de usar os buckets personalizados em todos os comandos.

A seguir, serão usados placeholders para as credenciais reais:

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">Variável de ambiente</th><th>Descrição</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>A chave de acesso/nome de usuário do usuário restrito do serviço filestore.</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>A chave secreta/senha do usuário restrito do serviço filestore.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>A chave de acesso/nome de usuário do usuário restrito do serviço history.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>A chave secreta/senha do usuário restrito do serviço history.</td></tr></tbody></table></div>

O Server CE e o Server Pro precisam apenas de um pequeno conjunto de permissões em cada bucket:

* criar objeto
* obter objeto
* excluir objeto
* listar bucket

### Políticas de acesso

Veja como poderia ser uma política para o usuário do filestore:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

Veja como poderia ser uma política para o usuário do history:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### Visão geral das variáveis

#### Ao usar o AWS S3

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### Ao usar uma opção auto-hospedada

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### Configuração do MINIO

<Info>
  `MINIO_ROOT_USER` e `MINIO_ROOT_PASSWORD` são as credenciais root da instância MINIO.
</Info>

Siga a [documentação oficial](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart) para obter uma cópia do `mc`.

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.