<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloudpods –
Object Storage</title><link>/docs/en/docs/web_ui/resource-mgmt/storage/object/</link><description>Recent content in Object Storage on Cloudpods</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><atom:link href="/docs/en/docs/web_ui/resource-mgmt/storage/object/index.xml" rel="self" type="application/rss+xml"/><item><title>Docs: Buckets</title><link>/docs/en/docs/web_ui/resource-mgmt/storage/object/bucket/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/storage/object/bucket/</guid><description>
&lt;p&gt;Object storage is a distributed storage service for storing arbitrary files. A bucket stores object files. Users must create a bucket before storing files. The cloud management platform allocates object storage resources to projects in bucket units. Users can conveniently upload, download, and share files in object storage over the network.&lt;/p&gt;
&lt;p&gt;The cloud management platform currently supports integrating and importing S3-protocol object storage services such as MinIO and Ceph Radio, as well as object storage services provided by public clouds.&lt;/p&gt;
&lt;p&gt;Usage flow:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;(Choose one) In multi-cloud management, integrate and import public cloud account resources with object storage enabled, and sync buckets from the public cloud platform;&lt;/li&gt;
&lt;li&gt;(Choose one) In multi-cloud management, integrate and import account resources of a locally deployed object storage server;&lt;/li&gt;
&lt;li&gt;Create a bucket and assign it to a project.&lt;/li&gt;
&lt;li&gt;Users in the project can upload, download, and share files in the bucket.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Entry&lt;/strong&gt;: On the cloud management platform, click the &lt;img src="/docs/en/docs/web_ui/images/intro/nav.png" alt=""&gt; navigation menu in the upper left corner, then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Resource Management/Storage/Object Storage/Buckets&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the left sidebar to open the Buckets page.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/storage/bucket.png" alt=""&gt;&lt;h2 id="create-a-bucket"&gt;Create a bucket&lt;/h2&gt;
&lt;p&gt;This feature creates a bucket.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;p&gt;On the create bucket page, click the &amp;ldquo;On-premises IDC&amp;rdquo; or &amp;ldquo;Public cloud&amp;rdquo; tab at the top to switch between creating buckets on different platforms.&lt;/p&gt;
&lt;/div&gt;
&lt;h3 id="create-an-on-premises-idc-bucket"&gt;Create an on-premises IDC bucket&lt;/h3&gt;
&lt;p&gt;Before creating an on-premises IDC bucket, ensure you have an object storage S3/Ceph/XSKY cloud account.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the &amp;ldquo;All&amp;rdquo; or &amp;ldquo;On-premises IDC&amp;rdquo; tab at the top, then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Create&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, and the create bucket dialog box appears.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Specify project: Administrators and domain administrators must specify the project that the bucket belongs to when creating it.&lt;/li&gt;
&lt;li&gt;Region: Select the region of the bucket.&lt;/li&gt;
&lt;li&gt;Name: Set the bucket name. Bucket names are globally unique. Avoid common names such as test to prevent creation failure.&lt;/li&gt;
&lt;li&gt;Specify cloud subscription: Specify the cloud subscription used to create the bucket.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to create the bucket.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="create-a-public-cloud-bucket"&gt;Create a public cloud bucket&lt;/h3&gt;
&lt;p&gt;Before creating a public cloud elastic IP, ensure you have a cloud account for the corresponding platform.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;p&gt;Currently only creating buckets in Alibaba Finance Cloud public network regions is supported.&lt;/p&gt;
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the &amp;ldquo;Public cloud&amp;rdquo; tab at the top, then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Create&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, and the create bucket dialog box appears.&lt;/li&gt;
&lt;li&gt;Set the following parameters:
&lt;ul&gt;
&lt;li&gt;Specify project: Administrators and domain administrators must specify the project that the bucket belongs to when creating it.&lt;/li&gt;
&lt;li&gt;Region: Select the region of the elastic IP. You can quickly filter suitable regions by city or platform.&lt;/li&gt;
&lt;li&gt;Name: Set the bucket name.&lt;/li&gt;
&lt;li&gt;Specify cloud subscription: Specify the cloud subscription used to create the bucket.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to create the bucket.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="sync-status"&gt;Sync status&lt;/h2&gt;
&lt;p&gt;This feature retrieves the current status of a bucket.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sync status for one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Sync status&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the bucket to sync the bucket status.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Sync status for multiple&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the bucket list, select one or more buckets, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Batch actions&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, then select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Sync status&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to sync bucket status in batch.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="set-limits"&gt;Set limits&lt;/h2&gt;
&lt;p&gt;This feature sets the capacity and object count limits for files stored in a bucket.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, based on the number of buckets for which you want to set limits, choose how to set limits.
&lt;ul&gt;
&lt;li&gt;Set limits for one bucket: Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the bucket, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set limits&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the set limits dialog box appears.&lt;/li&gt;
&lt;li&gt;Set limits for multiple buckets: In the bucket list, select one or more buckets, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Batch actions&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set limits&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the set limits dialog box appears.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Set the capacity limit and object limit for the bucket (0 means unlimited), then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="set-sharing"&gt;Set sharing&lt;/h2&gt;
&lt;p&gt;This feature sets the sharing scope of storage.&lt;/p&gt;
&lt;p&gt;Project resources have five sharing scopes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Not shared (private): Only users in the project can use the project resource.&lt;/li&gt;
&lt;li&gt;Project sharing - partial (shared across multiple projects in this domain): The project resource can be shared with specified projects (one or more) in the same domain. Only users in this project and the shared projects can use the project resource.&lt;/li&gt;
&lt;li&gt;Project sharing - all (shared within this domain): The project resource can be shared with all projects in the domain. Users in the domain of the project can use the project resource.&lt;/li&gt;
&lt;li&gt;Domain sharing - partial (shared across multiple domains): The project resource can be shared with specified domains (one or more). Only users in the domain of the project resource and the shared domains can use the project resource.&lt;/li&gt;
&lt;li&gt;Domain sharing - all (global sharing): The project resource can be shared with all domains. All users in the system can use the project resource.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;p&gt;Conditions for setting domain sharing:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Three-level permissions are enabled on the OneCloud platform.&lt;/li&gt;
&lt;li&gt;The user is in the admin console.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Conditions for setting project sharing:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The user is in the admin console or domain admin console.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="alert alert-warning" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Caution&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;The sharing scope of a bucket is related to the sharing scope of the cloud account.
&lt;ul&gt;
&lt;li&gt;When the cloud account is not shared, resources synced from the cloud account also cannot be shared.&lt;/li&gt;
&lt;li&gt;When the cloud account has sharing enabled, resources synced from the cloud account also have sharing enabled with the cloud account.&lt;/li&gt;
&lt;li&gt;When the cloud account has sharing enabled, resources synced from the cloud account can change their sharing scope. Ensure the sharing scope is within the cloud account&amp;rsquo;s sharing scope.&lt;/li&gt;
&lt;li&gt;When the cloud account&amp;rsquo;s sharing scope is modified, the sharing scope of resources synced from the cloud account must always remain within the cloud account&amp;rsquo;s sharing scope. For example, if the cloud account shares domains A, B, C, and D, and a domain resource shares domains A and C, and the cloud account&amp;rsquo;s sharing scope is changed to A and B, the domain resource can only share domain A.&lt;/li&gt;
&lt;li&gt;When the cloud account shares cloud subscriptions, domain resources synced from the cloud account cannot be shared.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Set sharing for one bucket&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the bucket, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set sharing&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; from the drop-down menu, and the set sharing dialog box appears.&lt;/li&gt;
&lt;li&gt;Configure the following parameters.
&lt;ul&gt;
&lt;li&gt;When the sharing scope is &amp;ldquo;Not shared&amp;rdquo;, the project resource is private and only users in this project can use it.&lt;/li&gt;
&lt;li&gt;When the sharing scope is &amp;ldquo;Project sharing&amp;rdquo;, select the projects in this domain that can share it.
&lt;ul&gt;
&lt;li&gt;When one or more projects in the same domain are selected, the sharing scope is Project sharing - partial. Only users in the project of the resource and the shared projects can use the project resource.&lt;/li&gt;
&lt;li&gt;When all projects are selected, the sharing scope is Project sharing - all. Users in the domain of the project can use the project resource.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;When the sharing scope is &amp;ldquo;Domain sharing&amp;rdquo;, select the domains to share with.
&lt;ul&gt;
&lt;li&gt;When one or more domains are selected, the sharing scope is Domain sharing - partial. Only users in the domain of the project resource and the shared domains can use the domain resource.&lt;/li&gt;
&lt;li&gt;When all domains are selected, the sharing scope is Domain sharing - all. All users in the system can use the project resource.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Set sharing in batch&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;When setting sharing for multiple buckets in batch, the sharing scope must be the same. Otherwise, set sharing for each bucket separately.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the bucket list, select one or more buckets, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Batch actions&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set sharing&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; from the drop-down menu, and the set sharing dialog box appears.&lt;/li&gt;
&lt;li&gt;Configure the following parameters.
&lt;ul&gt;
&lt;li&gt;When the sharing scope is &amp;ldquo;Not shared&amp;rdquo;, the project resource is private and only users in this project can use it.&lt;/li&gt;
&lt;li&gt;When the sharing scope is &amp;ldquo;Project sharing&amp;rdquo;, select the projects in this domain that can share it.
&lt;ul&gt;
&lt;li&gt;When one or more projects in the same domain are selected, the sharing scope is Project sharing - partial. Only users in the project of the resource and the shared projects can use the project resource.&lt;/li&gt;
&lt;li&gt;When all projects are selected, the sharing scope is Project sharing - all. Users in the domain of the project can use the project resource.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;When the sharing scope is &amp;ldquo;Domain sharing&amp;rdquo;, select the domains to share with.
&lt;ul&gt;
&lt;li&gt;When one or more domains are selected, the sharing scope is Domain sharing - partial. Only users in the domain of the project resource and the shared domains can use the domain resource.&lt;/li&gt;
&lt;li&gt;When all domains are selected, the sharing scope is Domain sharing - all. All users in the system can use the project resource.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="set-readwrite-permissions"&gt;Set read/write permissions&lt;/h2&gt;
&lt;p&gt;This feature sets the read/write permissions of a bucket.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Tencent Cloud buckets do not support public read/write;&lt;/li&gt;
&lt;li&gt;Azure buckets do not support authenticated-user read or public read/write;&lt;/li&gt;
&lt;li&gt;AWS buckets do not support authenticated-user read, this-account write with public read, or public read/write;&lt;/li&gt;
&lt;li&gt;Alibaba Cloud and Ceph buckets do not support authenticated-user read;&lt;/li&gt;
&lt;li&gt;Buckets in Alibaba Finance Cloud private network regions do not support setting read/write permissions.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the bucket, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set read/write permissions&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the set access permissions dialog box appears.&lt;/li&gt;
&lt;li&gt;Set read/write permissions: Includes this-account read/write, this-account public read, and public read/write.
&lt;ul&gt;
&lt;li&gt;This-account read/write: Only the user can read and write data in the specified bucket.&lt;/li&gt;
&lt;li&gt;Authenticated-user read: Authenticated users can read data in the bucket; only the user can perform write operations.&lt;/li&gt;
&lt;li&gt;This-account write with public read: Any user can read data in the bucket, but writing data to the bucket requires authentication.&lt;/li&gt;
&lt;li&gt;Public read/write: Any user can read and write data in the bucket without authentication. This permission has extremely high security risk. To protect your data, select it with caution.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="change-project"&gt;Change project&lt;/h2&gt;
&lt;p&gt;This feature changes the project that a bucket belongs to. Only users in the project can use the bucket to store files.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Change project for one bucket&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the bucket, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Change project&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; from the drop-down menu, and the change project dialog box appears.&lt;/li&gt;
&lt;li&gt;Select the domain and project, then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Change project in batch&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the bucket list, select one or more buckets, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Batch actions&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Change project&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the change project dialog box appears.&lt;/li&gt;
&lt;li&gt;Select the domain and project, then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="delete-a-bucket"&gt;Delete a bucket&lt;/h2&gt;
&lt;p&gt;This feature deletes a bucket. A bucket can be deleted only when it contains no files.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;p&gt;Buckets in Alibaba Finance Cloud private network regions do not support setting read/write permissions.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Delete one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the bucket, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Delete multiple&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the bucket list, select one or more buckets, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Batch actions&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="view-bucket-details"&gt;View bucket details&lt;/h2&gt;
&lt;p&gt;This feature views detailed information about a bucket.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;Details&amp;rdquo; tab to open the bucket details page.&lt;/li&gt;
&lt;li&gt;View the following information
&lt;ul&gt;
&lt;li&gt;Basic information: Includes the bucket&amp;rsquo;s cloud ID, ID, name, status, domain, project, sharing scope, platform, region, location (used to check whether an Alibaba Finance Cloud bucket is in a private network region), storage type, availability zone, cloud account, creation time, update time, notes, and more.&lt;/li&gt;
&lt;li&gt;Access domain: After a bucket is created, the corresponding access domain and S3 gateway are generated. Users can manage buckets uniformly through the S3 gateway.&lt;/li&gt;
&lt;li&gt;CDN acceleration domain: Displays the CDN acceleration domain set for the bucket.&lt;/li&gt;
&lt;li&gt;Static website: Displays the access link and related information for the bucket static website.&lt;/li&gt;
&lt;li&gt;Usage statistics: Statistics on capacity used by the bucket, including storage usage and file count.&lt;/li&gt;
&lt;li&gt;Usage limits: Capacity limits set for the bucket, including storage capacity limit and file count limit.&lt;/li&gt;
&lt;li&gt;Access permissions: Set the bucket access permissions, including this-account read/write, this-account public read, and public read/write. This-account information can be obtained from the bucket backend access information.
&lt;ul&gt;
&lt;li&gt;This-account read/write: Only the user can read and write data in the specified bucket.&lt;/li&gt;
&lt;li&gt;Authenticated-user read: Authenticated users can read data in the bucket; only the user can perform write operations.&lt;/li&gt;
&lt;li&gt;This-account public read: Any user can read data in the bucket, but writing data to the bucket requires authentication.&lt;/li&gt;
&lt;li&gt;Public read/write: Any user can read and write data in the bucket without authentication. This permission has extremely high security risk. To protect your data, select it with caution.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Hotlink protection: Displays whether hotlink protection is set for the bucket.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-static-website"&gt;Set static website&lt;/h3&gt;
&lt;p&gt;Object storage supports hosting static websites on a bucket. Users need to upload static website configuration files to the bucket, set file access permissions, and use Set static website to configure the index page, error page, and related information. After configuration, users can access the static website through the access domain. On success, they are redirected to the index page; on error, they are redirected to the error page.&lt;/p&gt;
&lt;p&gt;A static website consists entirely of static content, including client-side scripts such as JavaScript. Object storage does not support content that requires server-side processing, such as PHP, JSP, or ASP.NET.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;p&gt;Currently supported on Tencent Cloud only.&lt;/p&gt;
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;Details&amp;rdquo; tab to open the bucket details page.&lt;/li&gt;
&lt;li&gt;In the Static website section, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set static website&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to the right of the access address, and the set static website dialog box appears.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Status: Select whether to enable static website hosting. The following parameters can be configured only after it is enabled.&lt;/li&gt;
&lt;li&gt;Index document: The index document is the home page of the static website. When users access the static website, this page is accessed by default. In most cases, the index document is index.html.&lt;/li&gt;
&lt;li&gt;Error document: When users encounter an error accessing the static website, a 404 error code and the specified error document information are returned. In most cases, the error document is error.html.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-hotlink-protection"&gt;Set hotlink protection&lt;/h3&gt;
&lt;p&gt;To prevent data in a bucket from being hotlinked and causing unnecessary losses, object storage supports hotlink protection.&lt;/p&gt;
&lt;p&gt;The HTTP protocol supports obtaining the source page of the target page through the Referer header field. Hotlink protection checks whether the Referer field in the request matches the configured whitelist or blacklist. If it matches the whitelist, access is allowed; otherwise, access is blocked.&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Currently supported on Tencent Cloud only.&lt;/li&gt;
&lt;li&gt;If a request to a Tencent Cloud bucket includes a signature (whether in the URL or Header), hotlink protection verification is not performed.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;Details&amp;rdquo; tab to open the bucket details page.&lt;/li&gt;
&lt;li&gt;In the Hotlink protection section, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the set hotlink protection dialog box appears.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Empty Referer: Whether to allow HTTP or HTTPS requests whose header includes an empty Referer (no Referer field or an empty Referer field) to access object storage resources.&lt;/li&gt;
&lt;li&gt;Whitelist Referer: Allow domains in the whitelist to access the default access address of the bucket.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;,&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="file-management"&gt;File management&lt;/h2&gt;
&lt;p&gt;This feature manages files and folders.&lt;/p&gt;
&lt;div class="alert alert-warning" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Caution&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Files in buckets under AWS China cloud accounts on the cloud management platform cannot be downloaded through the UI or URL sharing, regardless of the permissions set.&lt;/li&gt;
&lt;li&gt;Buckets in Alibaba Finance Cloud private network regions do not support file management and related operations.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;h3 id="upload-files"&gt;Upload files&lt;/h3&gt;
&lt;p&gt;This feature uploads files to a specified bucket. Up to 4 files can be uploaded at the same time. Note that files with the same name overwrite previously uploaded files.&lt;/p&gt;
&lt;div class="alert alert-warning" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Caution&lt;/div&gt;
&lt;p&gt;After importing Azure cloud account resources, Azure buckets do not support uploading files in the root directory. Upload files in folders under the root directory.&lt;/p&gt;
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Upload files&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, and the upload files dialog box appears.&lt;/li&gt;
&lt;li&gt;Drag files directly into the dashed box or click the &amp;ldquo;Upload directly&amp;rdquo; hyperlink to select files, then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to upload the files.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="download-files"&gt;Download files&lt;/h3&gt;
&lt;p&gt;This feature lets users download files to the local machine.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Download&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the file. The browser downloads or opens the file.&lt;/li&gt;
&lt;li&gt;If the browser supports opening the downloaded file format, it opens the file instead of downloading it. Save the file as a local file from the browser.&lt;/li&gt;
&lt;li&gt;If the browser does not support opening the downloaded file format, it downloads the file directly.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="delete-files"&gt;Delete files&lt;/h3&gt;
&lt;p&gt;Supports deleting one or multiple files.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Delete one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the file, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Delete multiple&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the file list, select one or more files (or folders), click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="generate-url"&gt;Generate URL&lt;/h3&gt;
&lt;p&gt;This feature generates a temporary URL for a file for sharing.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the file, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Generate URL&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the generate URL dialog box appears.&lt;/li&gt;
&lt;li&gt;Set the connection validity period (other users can access the file via the URL within the validity period) to generate a temporary URL. Click &amp;ldquo;Copy file URL&amp;rdquo; to copy the file URL to the clipboard so users can paste and share it.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Close&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to close the dialog box.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-readwrite-permissions-1"&gt;Set read/write permissions&lt;/h3&gt;
&lt;p&gt;This feature sets the read/write permissions of a file (or folder). If not set, the file&amp;rsquo;s read/write permissions default to the same as the bucket.&lt;/p&gt;
&lt;div class="alert alert-warning" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Caution&lt;/div&gt;
&lt;p&gt;Files in Azure buckets do not support setting read/write permissions. File read/write permissions are the same as the bucket.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Set read/write permissions for one file&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the file, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set read/write permissions&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the set access permissions dialog box appears.&lt;/li&gt;
&lt;li&gt;Set read/write permissions: Includes this-account read/write, this-account public read, and public read/write.
&lt;ul&gt;
&lt;li&gt;This-account read/write: Only the user can read and write data in the specified bucket.&lt;/li&gt;
&lt;li&gt;This-account public read: Any user can read data in the bucket, but writing data to the bucket requires authentication.&lt;/li&gt;
&lt;li&gt;Public read/write: Any user can read and write data in the bucket without authentication. This permission has extremely high security risk. To protect your data, select it with caution.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Set read/write permissions in batch&lt;/strong&gt;&lt;/p&gt;
&lt;div class="alert alert-primary" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Note&lt;/div&gt;
&lt;p&gt;When you set read/write permissions for a folder in a bucket, files in the folder inherit the folder permissions.&lt;/p&gt;
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;In the file list, select one or more files (or folders), click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set read/write permissions&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the set access permissions dialog box appears.&lt;/li&gt;
&lt;li&gt;Set read/write permissions: Includes this-account read/write, this-account public read, and public read/write.
&lt;ul&gt;
&lt;li&gt;This-account read/write: Only the user can read and write data in the specified bucket.&lt;/li&gt;
&lt;li&gt;This-account public read: Any user can read data in the bucket, but writing data to the bucket requires authentication.&lt;/li&gt;
&lt;li&gt;Public read/write: Any user can read and write data in the bucket without authentication. This permission has extremely high security risk. To protect your data, select it with caution.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-http-headers"&gt;Set HTTP headers&lt;/h3&gt;
&lt;p&gt;This feature sets the HTTP headers of a file. If the HTTP header encoding does not match the file&amp;rsquo;s own encoding, the file may display garbled characters when opened in a browser. Users can change the default HTTP header encoding with this feature.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Set HTTP headers for one file&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the file, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set HTTP headers&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the set HTTP headers dialog box appears.&lt;/li&gt;
&lt;li&gt;Set the following parameters:
&lt;ul&gt;
&lt;li&gt;Content-Type: File type, such as image/png, &amp;ldquo;text/html; charset=UTF-8&amp;rdquo;, and so on.&lt;/li&gt;
&lt;li&gt;Content-Encoding: Encoding method, such as gzip, compress, identity, and so on.&lt;/li&gt;
&lt;li&gt;Content-Language: Language, such as de-DE, en-CA, and so on.&lt;/li&gt;
&lt;li&gt;Content-Disposition: Content presentation method. inline means the content can be displayed in the browser together with the page (such as images); attachment means the content is for download.&lt;/li&gt;
&lt;li&gt;Cache-Control: Cache control, such as no-cache, no-store, and so on.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Set HTTP headers in batch&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;In the file list, select one or more files, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;More&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Set HTTP headers&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the set HTTP headers dialog box appears.&lt;/li&gt;
&lt;li&gt;Set the following parameters:
&lt;ul&gt;
&lt;li&gt;Content-Type: File type, such as image/png, &amp;ldquo;text/html; charset=UTF-8&amp;rdquo;, and so on.&lt;/li&gt;
&lt;li&gt;Content-Encoding: Encoding method, such as gzip, compress, identity, and so on.&lt;/li&gt;
&lt;li&gt;Content-Language: Language, such as de-DE, en-CA, and so on.&lt;/li&gt;
&lt;li&gt;Content-Disposition: Content presentation method. inline means the content can be displayed in the browser together with the page (such as images); attachment means the content is for download.&lt;/li&gt;
&lt;li&gt;Cache-Control: Cache control, such as no-cache, no-store, and so on.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="folder-management"&gt;Folder management&lt;/h3&gt;
&lt;p&gt;Folders are mainly used to manage and categorize files. Folders support all file operations such as upload, download, and sharing. Folders support nesting, that is, creating folders inside folders.&lt;/p&gt;
&lt;h4 id="create-a-folder"&gt;Create a folder&lt;/h4&gt;
&lt;p&gt;This feature creates a folder for managing files.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Create folder&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, and the create folder dialog box appears.&lt;/li&gt;
&lt;li&gt;Set the folder name, then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h4 id="delete-a-folder"&gt;Delete a folder&lt;/h4&gt;
&lt;p&gt;This feature deletes a folder. Supports deleting one or multiple folders.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Delete one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the folder, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Delete multiple&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;In the file list, select one or more folders, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="cors-rules"&gt;CORS rules&lt;/h2&gt;
&lt;p&gt;In typical web requests, the same-origin policy restricts interaction between different origins (same protocol, same domain name or IP, and same port are considered one origin). Cross-Origin Resource Sharing (CORS) adds the Origin field in HTTP headers to allow servers to declare which origins are permitted by the browser to access which resources, enabling resource interaction across origins.&lt;/p&gt;
&lt;h3 id="create-a-cors-rule"&gt;Create a CORS rule&lt;/h3&gt;
&lt;p&gt;This feature creates a CORS access rule.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;CORS&amp;rdquo; tab to open the CORS page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Create&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the create CORS rule dialog box appears.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Origin: Origins allowed for cross-origin requests. Multiple origins can be specified; enter one per line.&lt;/li&gt;
&lt;li&gt;Allowed methods: Supports GET, PUT, POST, DELETE, and HEAD.&lt;/li&gt;
&lt;li&gt;Allowed headers: Which custom request headers are allowed for access.&lt;/li&gt;
&lt;li&gt;Exposed headers: Extra headers in the CORS response that provide additional information to the client.&lt;/li&gt;
&lt;li&gt;Cache time: Validity period of the request result.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="modify-a-cors-rule"&gt;Modify a CORS rule&lt;/h3&gt;
&lt;p&gt;This feature modifies a CORS access rule.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;CORS&amp;rdquo; tab to open the CORS page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Modify&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the CORS rule, and the modify CORS rule dialog box appears.&lt;/li&gt;
&lt;li&gt;You can modify the following parameters:
&lt;ul&gt;
&lt;li&gt;Origin: Origins allowed for cross-origin requests. Multiple origins can be specified; enter one per line.&lt;/li&gt;
&lt;li&gt;Allowed methods: Supports GET, PUT, POST, DELETE, and HEAD.&lt;/li&gt;
&lt;li&gt;Allowed headers: Which custom request headers are allowed for access.&lt;/li&gt;
&lt;li&gt;Exposed headers: Extra headers in the CORS response that provide additional information to the client.&lt;/li&gt;
&lt;li&gt;Cache time: Validity period of the request result.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="delete-a-cors-rule"&gt;Delete a CORS rule&lt;/h3&gt;
&lt;p&gt;This feature deletes a CORS access rule.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Delete one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;CORS&amp;rdquo; tab to open the CORS page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the CORS rule, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Delete multiple&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;CORS&amp;rdquo; tab to open the CORS page.&lt;/li&gt;
&lt;li&gt;In the list, select one or more CORS rules, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="authorization-policies"&gt;Authorization policies&lt;/h2&gt;
&lt;p&gt;This feature controls permissions for public cloud root accounts and sub-accounts to access buckets and objects.&lt;/p&gt;
&lt;h3 id="create-an-authorization-policy"&gt;Create an authorization policy&lt;/h3&gt;
&lt;p&gt;This feature creates an authorization policy. An authorization policy defines the specified operation permissions of a specified user on a specified resource.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;Authorization policies&amp;rdquo; tab to open the authorization policies page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Create&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;, and the create authorization policy dialog box appears.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Policy effect: Currently only Allow is supported.&lt;/li&gt;
&lt;li&gt;User: Users allowed to access resources in the authorization policy. Currently supports setting the root account and sub-accounts of the current account. When setting the root account, enter the corresponding root account ID.&lt;/li&gt;
&lt;li&gt;Resource: Resources the user can access. Can be set to the entire bucket or specified resources under the bucket.&lt;/li&gt;
&lt;li&gt;Resource path: When the resource is &amp;ldquo;Entire bucket&amp;rdquo;, the resource path cannot be set. When the resource is &amp;ldquo;Specified resources&amp;rdquo;, set the specific resource paths. Multiple resource paths can be set.&lt;/li&gt;
&lt;li&gt;Actions: Set the user&amp;rsquo;s operation permissions on the resource, including read-only, read/write, full control, and more.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="delete-an-authorization-policy"&gt;Delete an authorization policy&lt;/h3&gt;
&lt;p&gt;This feature deletes an authorization policy.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Delete one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;Authorization policies&amp;rdquo; tab to open the authorization policies page.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the authorization policy, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Delete multiple&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;Authorization policies&amp;rdquo; tab to open the authorization policies page.&lt;/li&gt;
&lt;li&gt;In the list, select one or more authorization policies, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Delete&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list, and an operation confirmation dialog box appears.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to complete the operation&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="view-bucket-monitoring"&gt;View bucket monitoring&lt;/h2&gt;
&lt;p&gt;This feature views monitoring information for a bucket. Currently only Alibaba Cloud and Huawei Cloud bucket monitoring is supported.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;Monitoring&amp;rdquo; tab to open the monitoring page.&lt;/li&gt;
&lt;li&gt;View the number of GET requests for the bucket and the average first-byte latency of GET requests.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="view-bucket-operation-logs"&gt;View bucket operation logs&lt;/h2&gt;
&lt;p&gt;This feature views log information for operations performed on a bucket.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the bucket name to open the file list page.&lt;/li&gt;
&lt;li&gt;Click the &amp;ldquo;Operation Logs&amp;rdquo; tab to open the operation logs page.
&lt;ul&gt;
&lt;li&gt;Load more logs: The list displays 20 operation log entries by default. To view more, click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Load more&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to retrieve more log information.&lt;/li&gt;
&lt;li&gt;View log details: Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;View&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; in the Actions column of the operation log to view log details. You can copy the detail content.&lt;/li&gt;
&lt;li&gt;View logs for a specific time range: To view operation logs for a time range, set the start and end dates in the upper right of the list to query logs for that range.&lt;/li&gt;
&lt;li&gt;Export logs: Currently only logs displayed on the current page can be exported. Click the &lt;img src="/docs/en/docs/web_ui/images/system/download.png" alt=""&gt; icon in the upper right, set the export data columns in the export data dialog box, then click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;OK&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; to export the logs.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="view-bucket-multi-level-organization-structure"&gt;View bucket multi-level organization structure&lt;/h2&gt;
&lt;p&gt;This feature filters and displays bucket resources across multiple levels using project tags.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Buckets page, click the icon to the left of the search box to expand hierarchical projects.&lt;/li&gt;
&lt;li&gt;Click the settings icon in the upper right to open the configure hierarchy page.&lt;/li&gt;
&lt;li&gt;Click &amp;ldquo;Add level&amp;rdquo; to add multiple levels. After selecting a project tag for each level, click &amp;ldquo;OK&amp;rdquo;.&lt;/li&gt;
&lt;li&gt;For how to create project tags, see &lt;a href="../../../../auth-security/authentication/authentication-system/project"&gt;Projects&lt;/a&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-manage-files-in-a-bucket-through-the-s3-gateway"&gt;How to manage files in a bucket through the S3 gateway?&lt;/h2&gt;
&lt;p&gt;The S3 gateway (S3gateway) is a unified object storage gateway that provides standard S3 APIs. The gateway backend connects to object storage on the cloud management platform. Users can access the S3 gateway through standard S3 clients and SDKs for unified access to multi-cloud object storage.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Obtain the S3 gateway address of the bucket.&lt;/p&gt;
&lt;p&gt;In the OneCloud console, on the details page of the specified bucket, find the URL that describes s3gateway under Access domain. The host address of that URL is the S3 gateway access address.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/storage/s3gateway.png" alt=""&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Create an AccessKey/AccessKey Secret in the OneCloud console.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;In the personal information area of the OneCloud console, click the &lt;img src="/docs/en/docs/web_ui/images/intro/userinfo1.png" alt=""&gt; icon in the upper right, select &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Access credentials&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; from the drop-down menu, and open the AccessKey management page.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/storage/AccessKey.png" alt=""&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Create&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt; above the list to create an AccessKey and AccessKey Secret. View and copy the AccessKey and AccessKey Secret information. You can save the AccessKey locally.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/storage/AK_AS.png" alt=""&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enter the gateway address and AccessKey ID and AccessKey Secret in the standard S3 client Cyberduck.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;First download the Cyberduck client from the official website &lt;a href="https://cyberduck.io/" target="_blank" rel="noopener noreferrer"&gt;https://cyberduck.io/&lt;/a&gt; and install it.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After installation, open the Cyberduck client and click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Open Connection&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;. Configure the following parameters.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Select the connection type &amp;ldquo;Amazon S3&amp;rdquo;.&lt;/li&gt;
&lt;li&gt;Set the server address to the S3 gateway address.&lt;/li&gt;
&lt;li&gt;Set Access Key ID to the AccessKey ID.&lt;/li&gt;
&lt;li&gt;Set Secret Access Key to the AccessKey Secret.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;&lt;strong&gt;&lt;em&gt;&amp;ldquo;Connect&amp;rdquo;&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;img src="/docs/en/docs/web_ui/images/storage/s3connection.png" alt=""&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;div class="alert alert-warning" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Caution&lt;/div&gt;
&lt;p&gt;Because s3gateway uses a self-signed certificate, an insecure certificate prompt appears. Select &amp;ldquo;Continue&amp;rdquo; and &amp;ldquo;Always Trust&amp;rdquo;.&lt;/p&gt;
&lt;/div&gt;
&lt;pre&gt;&lt;code&gt; ![](/docs/en/docs/web_ui/images/storage/certificate.png)
![](/docs/en/docs/web_ui/images/storage/validcert1.png)
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start="4"&gt;
&lt;li&gt;Manage S3 file directories through the Cyberduck client, and conveniently upload, download, move, copy, and delete files.&lt;/li&gt;
&lt;/ol&gt;</description></item></channel></rss>