> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  Tài liệu này trình bày cách thiết lập S3 trong Server CE và Ayakaleaf Pro. Bạn có thể tìm thấy [hướng dẫn riêng](/vi/on-premises/maintenance/s3-migration) về việc di chuyển dữ liệu hiện có sang bộ lưu trữ tương thích S3.
</Info>

<Warning>
  Nếu bạn triển khai Ayakaleaf Pro với bộ lưu trữ [s3.md](/vi/on-premises/configuration/overleaf-toolkit/s3 "mention") được bật, dữ liệu lưu trong S3 có được mã hóa không?

  *<strong>Không.</strong>* Dữ liệu không được mã hóa. Tất cả các history chunk, tệp mẫu, PDF và các tệp khác đều được lưu dưới dạng văn bản thuần. Nếu bạn sử dụng nhà cung cấp lưu trữ S3 bên ngoài của bên thứ ba, hãy đặc biệt chú ý đến bảo mật và quyền riêng tư của dữ liệu.
</Warning>

## Khi nào nên cân nhắc dùng S3 để lưu trữ dữ liệu

Đối với các phiên bản có ít hơn 1000 người dùng (seat), chúng tôi khuyến nghị sử dụng bộ lưu trữ trên đĩa cục bộ kết hợp với [sao lưu nhất quán](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup) thường xuyên.

Đối với các phiên bản lớn hơn với trên 1000 người dùng đã chạm đến giới hạn của bộ lưu trữ cục bộ (về dung lượng hoặc thông lượng), chúng tôi khuyến nghị sử dụng backend lưu trữ đối tượng tương thích S3 thay vì các giải pháp lưu trữ qua mạng khác như NFS.

## Các lựa chọn lưu trữ đối tượng tương thích S3

Dưới đây là các lựa chọn phổ biến nhất cho lưu trữ đối tượng tương thích S3:

* [AWS S3](https://aws.amazon.com/s3/), dịch vụ được quản lý; chúng tôi khuyên dùng AWS S3 khi chạy Overleaf CE/Server Pro trên AWS
* [MINIO](https://min.io/), tự lưu trữ (self-hosted)
* [Ceph](https://ceph.io/en/), tự lưu trữ (self-hosted)
* Các nhà cung cấp hosting khác cũng có dịch vụ lưu trữ đối tượng tương thích S3 được quản lý; bạn có thể muốn dùng chúng thay vì tự vận hành khi đã chạy Overleaf CE/Server Pro tại nhà cung cấp đó.

## Lưu ý về độ trễ khi chọn bộ lưu trữ đối tượng tương thích S3

Độ trễ giữa phiên bản Server CE/Server Pro và bộ lưu trữ đối tượng tương thích S3 là yếu tố lớn ảnh hưởng đến thời gian hoàn tất quá trình di chuyển. Độ trễ cũng ảnh hưởng đến hiệu năng tải tệp lên trong Server CE/Server Pro, và việc tải tệp xuống chậm cũng có thể ảnh hưởng lớn đến thời gian biên dịch PDF. Chúng tôi khuyên bạn nên giảm thiểu khoảng cách địa lý giữa phiên bản Server CE/Server Pro và bộ lưu trữ đối tượng tương thích S3. Trong môi trường được quản lý, điều này có nghĩa là tạo bucket trong cùng một region; còn với giải pháp on-premise, hãy chạy cả hai trong cùng một khu vực (campus).

## Thiết lập S3

Chúng ta cần bốn "bucket" và hai tài khoản người dùng bị giới hạn quyền. `overleaf-user-files` và `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` chỉ cần thiết với các phiên bản trước v6.

<Warning>
  Các bucket **không** được phép truy cập công khai
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>Bucket</td><td>Mục đích sử dụng</td><td>Dịch vụ</td><td>Trước đây nằm trong `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>tệp người dùng của dự án</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>tệp mẫu</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>blob lịch sử dự án</td><td>history và filestore chỉ đọc</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>history chunk</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

Bạn có thể muốn/cần chọn tên khác; khi đó hãy đảm bảo sử dụng các bucket tùy chỉnh trong tất cả các lệnh.

Phần sau sẽ dùng các placeholder thay cho thông tin đăng nhập thực tế:

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">Biến môi trường</th><th>Mô tả</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>Access key/tên người dùng của người dùng bị giới hạn quyền của dịch vụ filestore.</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>Secret key/mật khẩu của người dùng bị giới hạn quyền của dịch vụ filestore.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>Access key/tên người dùng của người dùng bị giới hạn quyền của dịch vụ history.</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>Secret key/mật khẩu của người dùng bị giới hạn quyền của dịch vụ history.</td></tr></tbody></table></div>

Server CE và Server Pro chỉ cần một tập quyền nhỏ trên mỗi bucket:

* tạo đối tượng (create object)
* lấy đối tượng (get object)
* xóa đối tượng (delete object)
* liệt kê bucket (list bucket)

### Chính sách truy cập

Dưới đây là ví dụ về chính sách cho người dùng filestore:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

Dưới đây là ví dụ về chính sách cho người dùng history:

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### Tổng quan về các biến

#### Khi sử dụng AWS S3

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### Khi sử dụng giải pháp tự lưu trữ

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### Thiết lập MINIO

<Info>
  `MINIO_ROOT_USER` và `MINIO_ROOT_PASSWORD` là thông tin đăng nhập root của phiên bản MINIO.
</Info>

Vui lòng làm theo [tài liệu chính thức](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart) để tải về `mc`.

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.