> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  У цьому документі описано налаштування S3 у Server CE та Ayakaleaf Pro. Про перенесення наявних даних до S3-сумісного сховища читайте в [окремому посібнику](/uk/on-premises/maintenance/s3-migration).
</Info>

<Warning>
  Якщо ви розгортаєте Ayakaleaf Pro з увімкненим сховищем [s3.md](/uk/on-premises/configuration/overleaf-toolkit/s3 "mention"), чи шифруються дані, що зберігаються в S3?

  *<strong>Ні.</strong>* Дані не шифруються. Усі фрагменти історії, файли шаблонів, PDF та інші файли зберігаються у відкритому вигляді. Якщо ви використовуєте сторонній зовнішній S3-сервіс зберігання, приділіть особливу увагу безпеці та конфіденційності даних.
</Warning>

## Коли варто розглянути використання S3 для зберігання даних

Для екземплярів із менш ніж 1000 місць ми рекомендуємо використовувати локальне дискове сховище з регулярними [узгодженими резервними копіями](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup).

Для більших екземплярів із понад 1000 місць, які досягають меж свого локального сховища (за обсягом або пропускною здатністю), ми рекомендуємо використовувати S3-сумісне об'єктне сховище замість інших мережевих рішень для зберігання, як-от NFS.

## Варіанти S3-сумісного об'єктного сховища

Ось найпопулярніші варіанти S3-сумісного об'єктного сховища:

* [AWS S3](https://aws.amazon.com/s3/), керований сервіс; радимо обирати AWS S3, якщо Overleaf CE/Server Pro працює в AWS
* [MINIO](https://min.io/), власне розміщення
* [Ceph](https://ceph.io/en/), власне розміщення
* Інші хостинг-провайдери також пропонують певні керовані S3-сумісні об'єктні сховища; якщо ви вже запускаєте Overleaf CE/Server Pro в такого провайдера, можливо, варто використовувати їх замість власного.

## Затримка під час вибору S3-сумісного об'єктного сховища

Затримка між екземпляром Server CE/Server Pro і вашим S3-сумісним об'єктним сховищем значною мірою впливає на час, потрібний для завершення міграції. Затримка також впливає на швидкість завантаження файлів у Server CE/Server Pro, а повільне отримання файлів може суттєво збільшити час компіляції PDF. Радимо мінімізувати географічну відстань між екземпляром Server CE/Server Pro і S3-сумісним об'єктним сховищем. У керованому середовищі це означає створення бакета в тому самому регіоні, а для локального рішення — розміщення обох систем в одному кампусі.

## Налаштування S3

Нам потрібні чотири "бакети" та два облікові записи користувачів з обмеженими правами. `overleaf-user-files` і `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` потрібні лише для версій до v6.

<Warning>
  Бакети **не** повинні бути загальнодоступними
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>Бакет</td><td>Призначення</td><td>Сервіс</td><td>Раніше в `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>файли користувачів проєкту</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>файли шаблонів</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>blob-об'єкти історії проєкту</td><td>history і filestore лише для читання</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>фрагменти історії</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

Можливо, ви захочете або муситимете обрати інші назви — у такому разі використовуйте свої бакети в усіх командах.

Далі замість справжніх облікових даних використовуються заповнювачі:

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">Змінна середовища</th><th>Опис</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>Ключ доступу/ім'я користувача з обмеженими правами для сервісу filestore.</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>Секретний ключ/пароль користувача з обмеженими правами для сервісу filestore.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>Ключ доступу/ім'я користувача з обмеженими правами для сервісу history.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>Секретний ключ/пароль користувача з обмеженими правами для сервісу history.</td></tr></tbody></table></div>

Server CE і Server Pro потребують лише невеликого набору дозволів для кожного бакета:

* створення об'єкта
* отримання об'єкта
* видалення об'єкта
* перегляд вмісту бакета

### Політики доступу

Ось як може виглядати політика для користувача filestore:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

Ось як може виглядати політика для користувача history:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### Огляд змінних

#### У разі використання AWS S3

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### У разі використання варіанта з власним розміщенням

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### Налаштування MINIO

<Info>
  `MINIO_ROOT_USER` і `MINIO_ROOT_PASSWORD` — це облікові дані root для екземпляра MINIO.
</Info>

Щоб отримати `mc`, дотримуйтеся [офіційної документації](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart).

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.