> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# S3

<Info>
  本文件說明如何在 Server CE 與 Ayakaleaf Pro 中設定 S3。關於將既有資料遷移至 S3 相容儲存空間，請參閱[另一份指南](/zh-TW/on-premises/maintenance/s3-migration)。
</Info>

<Warning>
  如果你在部署 Ayakaleaf Pro 時啟用了 [s3.md](/zh-TW/on-premises/configuration/overleaf-toolkit/s3 "mention") 儲存，存放在 S3 中的資料是否有加密？

  *<strong>沒有。</strong>* 資料並未加密。所有歷史區塊（history chunks）、範本檔案、PDF 及其他檔案都以明文儲存。若你使用第三方外部 S3 儲存服務供應商，請特別留意資料安全與隱私。
</Warning>

## 何時應考慮使用 S3 儲存資料

對於少於 1000 個席次的執行個體，我們建議使用本機磁碟儲存，並定期進行[一致性備份](https://docs.overleaf.com/on-premises/maintenance/data-and-backups#performing-a-consistent-backup)。

對於超過 1000 個席次、且已達到本機儲存空間限制（容量或傳輸量）的大型執行個體，我們建議使用 S3 相容的物件儲存後端，而非 NFS 等其他網路型儲存方案。

## S3 相容物件儲存方案

以下是最常見的 S3 相容物件儲存方案：

* [AWS S3](https://aws.amazon.com/s3/)，代管服務；若你在 AWS 上執行 Overleaf CE/Server Pro，建議選擇 AWS S3
* [MINIO](https://min.io/)，自行託管
* [Ceph](https://ceph.io/en/)，自行託管
* 其他雲端服務供應商也提供某種代管的 S3 相容物件儲存；若你已在這類供應商上執行 Overleaf CE/Server Pro，可以考慮使用這些服務，而不必自行架設。

## 選擇 S3 相容物件儲存時的延遲考量

Server CE/Server Pro 執行個體與 S3 相容物件儲存之間的延遲，是影響遷移完成時間的重要因素。延遲也會影響 Server CE/Server Pro 中的檔案上傳效能，而緩慢的檔案下載也會大幅影響 PDF 編譯時間。我們建議盡量縮短 Server CE/Server Pro 執行個體與 S3 相容物件儲存之間的地理距離。在代管環境中，這代表在同一區域中建立 bucket；若是本地部署方案，則代表將兩者部署在同一園區內。

## S3 設定

我們需要四個「bucket」以及兩個受限的使用者帳號。`overleaf-user-files` 與 `OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME` 僅在 v6 之前需要。

<Warning>
  Bucket **不應**允許公開存取
</Warning>

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="279" /><th width="152" /><th width="97" /><th /></tr></thead><tbody><tr><td>Bucket</td><td>用途</td><td>服務</td><td>先前位於 `/var/lib/overleaf/data`</td></tr><tr><td>`overleaf-user-files`</td><td>專案使用者檔案</td><td>filestore</td><td>`user_files`</td></tr><tr><td>`overleaf-template-files`</td><td>範本檔案</td><td>filestore</td><td>`template_files`</td></tr><tr><td>`overleaf-project-blobs`</td><td>專案歷史 blob</td><td>history 與唯讀 filestore</td><td>`history/overleaf-project-blobs`</td></tr><tr><td>`overleaf-chunks`</td><td>歷史區塊</td><td>history</td><td>`history/overleaf-chunks`</td></tr></tbody></table></div>

你可能想要或需要使用不同的名稱，請務必在所有指令中使用你自訂的 bucket 名稱。

以下將以預留位置代替實際的憑證：

<div style={{ overflowX: "auto" }}><table style={{ display: "table", width: "100%" }}><thead><tr><th width="431">環境變數</th><th>說明</th></tr></thead><tbody><tr><td>`OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID`</td><td>filestore 服務受限使用者的存取金鑰／使用者名稱。</td></tr><tr><td>`OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY`</td><td>filestore 服務受限使用者的私密金鑰／密碼。</td></tr><tr><td>`OVERLEAF_HISTORY_S3_ACCESS_KEY_ID`</td><td>history 服務受限使用者的存取金鑰／使用者名稱。</td></tr><tr><td>`OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY`</td><td>history 服務受限使用者的私密金鑰／密碼。</td></tr></tbody></table></div>

Server CE 與 Server Pro 在每個 bucket 上只需要一小組權限：

* 建立物件（create object）
* 取得物件（get object）
* 刪除物件（delete object）
* 列出 bucket（list bucket）

### 存取原則

以下是 filestore 使用者原則的範例：

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-user-files/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-template-files/*"
    }
  ]
}
```

以下是 history 使用者原則的範例：

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-project-blobs/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::overleaf-chunks/*"
    }
  ]
}
```

### 變數總覽

#### 使用 AWS S3 時

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# Bucket region you picked when creating the buckets.
OVERLEAF_HISTORY_S3_REGION=""
```

#### 使用自行託管方案時

```bash theme={null}
# Enable S3 backend for filestore
OVERLEAF_FILESTORE_BACKEND=s3

# Bucket name for project files
OVERLEAF_FILESTORE_USER_FILES_BUCKET_NAME=overleaf-user-files

# Bucket name for template files
OVERLEAF_FILESTORE_TEMPLATE_FILES_BUCKET_NAME=overleaf-template-files

# Key for filestore user
OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID=...

# Secret for filestore user
OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_FILESTORE_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_FILESTORE_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_FILESTORE_S3_REGION=""

# Enable S3 backend for history
OVERLEAF_HISTORY_BACKEND=s3

# Bucket name for project history blobs
OVERLEAF_HISTORY_PROJECT_BLOBS_BUCKET=overleaf-project-blobs

# Bucket name for history chunks
OVERLEAF_HISTORY_CHUNKS_BUCKET=overleaf-chunks

# Key for history user
OVERLEAF_HISTORY_S3_ACCESS_KEY_ID=...

# Secret for history user
OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY=...

# S3 provider endpoint
OVERLEAF_HISTORY_S3_ENDPOINT=http://10.10.10.10:9000

# Path style addressing of buckets. Most likely you need to set this to "true".
OVERLEAF_HISTORY_S3_PATH_STYLE="true"

# Bucket region. Most likely you do not need to configure this.
OVERLEAF_HISTORY_S3_REGION=""
```

### MINIO 設定

<Info>
  `MINIO_ROOT_USER` 與 `MINIO_ROOT_PASSWORD` 是 MINIO 執行個體的 root 憑證。
</Info>

請依照[官方文件](https://min.io/docs/minio/linux/reference/minio-mc.html#quickstart)取得 `mc`。

```bash theme={null}
mc alias set s3 http://10.10.10.10:9000 MINIO_ROOT_USER MINIO_ROOT_PASSWORD

# Put the contents of the policies from the previous section in the
# respective json file policy-filestore.json and policy-history.json.

# Reminder: Replace the bucket names and credentials accordingly.

# filestore buckets, user and policy
mc mb --ignore-existing s3/overleaf-user-files
mc mb --ignore-existing s3/overleaf-template-files
mc admin user add s3 \
  OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID \
  OVERLEAF_FILESTORE_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-filestore policy-filestore.json
mc admin policy attach s3 overleaf-filestore \
  --user=OVERLEAF_FILESTORE_S3_ACCESS_KEY_ID

# history buckets, user and policy
mc mb --ignore-existing s3/overleaf-project-blobs
mc mb --ignore-existing s3/overleaf-chunks
mc admin user add s3 \
  OVERLEAF_HISTORY_S3_ACCESS_KEY_ID \
  OVERLEAF_HISTORY_S3_SECRET_ACCESS_KEY
mc admin policy create s3 overleaf-history policy-history.json
mc admin policy attach s3 overleaf-history \
  --user=OVERLEAF_HISTORY_S3_ACCESS_KEY_ID
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.