> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  本文档介绍如何在 Server CE 和 Ayakaleaf Pro 中设置 S3。关于将现有数据迁移到 S3 兼容存储，请参阅[单独的指南](/zh-CN/on-premises/maintenance/s3-migration)。
</Info>

<Warning>
  如果你在部署 Ayakaleaf Pro 时启用了 [s3.md](/zh-CN/on-premises/configuration/overleaf-toolkit/s3 "mention") 存储，存储在 S3 中的数据是否加密？

  *<strong>不加密。</strong>* 数据未经加密。所有历史块（history chunks）、模板文件、PDF 和其他文件均以明文形式存储。如果你使用第三方外部 S3 存储服务商，请密切关注数据安全与隐私。
</Warning>

## 何时考虑使用 S3 存储数据

对于少于 1000 个席位的实例，我们建议使用本地磁盘存储，并定期进行[一致性备份](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup)。

对于超过 1000 个席位、且本地存储（容量或吞吐量）已达到上限的较大实例，我们建议使用 S3 兼容的对象存储后端，而非 NFS 等其他基于网络的存储方案。

## S3 兼容对象存储选项

以下是最常用的 S3 兼容对象存储选项：

* [AWS S3](https://aws.amazon.com/s3/)，托管服务，在 AWS 上运行 Overleaf CE/Server Pro 时，我们建议选择 AWS S3
* [MINIO](https://min.io/)，自托管
* [Ceph](https://ceph.io/en/)，自托管
* 其他托管服务商也提供某种形式的托管 S3 兼容对象存储，如果你已在此类服务商上运行 Overleaf CE/Server Pro，可以考虑使用它们，而不是自行运行。

## 选择 S3 兼容对象存储时的延迟考量

Server CE/Server Pro 实例与 S3 兼容对象存储之间的延迟，是影响迁移完成时间的重要因素。延迟还会影响 Server CE/Server Pro 中的文件上传性能，而较慢的文件下载也会显著影响 PDF 编译时间。我们建议尽量缩短 Server CE/Server Pro 实例与 S3 兼容对象存储之间的地理距离。在托管环境中，这意味着在同一区域创建存储桶；对于本地部署方案，则意味着将两者运行在同一园区内。

## S3 设置

我们需要四个"存储桶"（bucket）和两个受限用户账户。仅在 v6 之前才需要 `overleaf-user-files` 和 `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME`。

<Warning>
  存储桶**不应**允许公开访问
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>存储桶</td><td>用途</td><td>服务</td><td>此前位于 `/var/lib/overleaf/data` 中的位置</td></tr><tr><td>`overleaf-user-files`</td><td>项目用户文件</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>模板文件</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>项目历史 blob</td><td>history 和只读 filestore</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>历史块</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

你可能想要或需要使用不同的名称，请确保在所有命令中使用自定义的存储桶名称。

下文将使用占位符代替实际凭据：

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">环境变量</th><th>描述</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>filestore 服务受限用户的访问密钥/用户名。</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>filestore 服务受限用户的私密密钥/密码。</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>history 服务受限用户的访问密钥/用户名。</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>history 服务受限用户的私密密钥/密码。</td></tr></tbody></table></div>

Server CE 和 Server Pro 只需要每个存储桶上的一小部分权限：

* 创建对象
* 获取对象
* 删除对象
* 列出存储桶

### 访问策略

filestore 用户的策略示例如下：

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

history 用户的策略示例如下：

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### 变量概览

#### 使用 AWS S3 时

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### 使用自托管方案时

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### MINIO 设置

<Info>
  `MINIO_ROOT_USER` 和 `MINIO_ROOT_PASSWORD` 是 MINIO 实例的 root 凭据。
</Info>

请按照[官方文档](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart)获取 `mc`。

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.