Skip to content
Coritan Docs

Endpoints, ports and addressing styles

Which address and port to connect to, when a bucket can also be reached by its own hostname, and how to sign for each.

View as Markdown

Every Object Storage region has one endpoint, and every endpoint answers on port 7337. Some regions also answer on port 443, and some also let you use a bucket's own hostname. This page says how to tell, and what to sign for each address.

Use the endpoint the dashboard and the API show, and copy it as it is.

  • In the dashboard, open Object Storage, open the service, and read the Endpoints card on the Overview tab. It has one row for each region the service uses.
  • With the API, read endpoints in the service summary, and endpoint in the answer that creates an access key, in a bucket and in the list of regions.

An endpoint is https://s3.<region>.coritan.com, followed by :7337 unless the region also answers on port 443. A bucket answers only at the endpoint of its own region. Another region's endpoint answers NoSuchBucket for it.

Port Where it works What to know
7337 Every region. The endpoint carries the port, as in https://s3.fra.coritan.com:7337. This port keeps working when a region also offers port 443.
443 A region whose endpoint the dashboard shows without a port. The endpoint is https://s3.fra.coritan.com. Port 443 is the HTTPS default, so the endpoint needs no port.

Sign for the address you connect to. A request signed for s3.fra.coritan.com:7337 is refused with SignatureDoesNotMatch on port 443, and the other way round. S3 clients do this for you, because they sign for the endpoint you give them. A presigned URL works at the address it was made for, so a URL that names :7337 stays on port 7337.

If you cannot reach the endpoint, check the port first:

Shell
curl -I https://s3.fra.coritan.com:7337

Any HTTP status in the answer, even 403, means your network reaches us. No answer means a firewall or a proxy blocks the port. When the dashboard shows your region's endpoint without a port, try that endpoint, which needs outgoing port 443 only.

An address names a bucket in one of two ways.

Path style
The bucket is the first part of the path, as in https://s3.fra.coritan.com:7337/u7-assets/photo.jpg. Every region answers this way, and every example in these guides uses it.
Virtual-hosted style
The bucket is the first part of the hostname, as in https://u7-assets.s3.fra.coritan.com:7337/photo.jpg. A region answers this way only when the dashboard offers it: the Connect a client card on the Overview tab then shows an Addressing choice with Path style and Virtual-hosted.

Use virtual-hosted style when a tool or an SDK only builds addresses that way. Otherwise path style is the simpler choice, because it works everywhere.

A bucket whose name has a dot, such as u7-my.assets, stays path style. Its hostname would have two labels in front of the endpoint, and the endpoint's certificate covers one.

Both styles reach the same bucket with the same keys, and a request needs a signature in both. A virtual-hosted request is signed for the bucket's hostname, u7-assets.s3.fra.coritan.com, and a path-style request for the endpoint. Your client does this once you set the style.

A presigned URL for a virtual-hosted address works only at that hostname. Change the bucket in the hostname and the signature no longer matches, so the request answers SignatureDoesNotMatch.

Client Path style Virtual-hosted style
AWS CLI aws configure set default.s3.addressing_style path aws configure set default.s3.addressing_style virtual
AWS CLI profile addressing_style = path under s3 = addressing_style = virtual under s3 =
rclone force_path_style=true force_path_style=false
s3cmd --host-bucket=s3.fra.coritan.com --host-bucket=%(bucket)s.s3.fra.coritan.com
boto3 Config(s3={"addressing_style": "path"}) Config(s3={"addressing_style": "virtual"})
AWS SDK for JavaScript forcePathStyle: true forcePathStyle: false

Add the port to the endpoint and to --host-bucket when the region's endpoint has one. The Connect an S3 client guide has a full setup for each tool.

API operations on this page

MethodPathWhat it does
GET/api/v1/client/object-storage/{service_id}One service with its endpoints, its limits and how it is billed