Endpoints, ports and addressing styles
Which address and port to connect to, when a bucket can also be reached by its own hostname, and how to sign for each.
In the dashboard
Every Object Storage region has one endpoint, and every endpoint answers on port 7337. Some regions also answer on port 443, and some also let you use a bucket's own hostname. This page says how to tell, and what to sign for each address.
Find your endpoint
Section titled Find your endpointUse the endpoint the dashboard and the API show, and copy it as it is.
- In the dashboard, open Object Storage, open the service, and read the Endpoints card on the Overview tab. It has one row for each region the service uses.
- With the API, read
endpointsin the service summary, andendpointin the answer that creates an access key, in a bucket and in the list of regions.
An endpoint is https://s3.<region>.coritan.com, followed by :7337 unless the region also answers on port 443. A bucket answers only at the endpoint of its own region. Another region's endpoint answers NoSuchBucket for it.
Ports
Section titled Ports| Port | Where it works | What to know |
|---|---|---|
| 7337 | Every region. | The endpoint carries the port, as in https://s3.fra.coritan.com:7337. This port keeps working when a region also offers port 443. |
| 443 | A region whose endpoint the dashboard shows without a port. | The endpoint is https://s3.fra.coritan.com. Port 443 is the HTTPS default, so the endpoint needs no port. |
Sign for the address you connect to. A request signed for s3.fra.coritan.com:7337 is refused with SignatureDoesNotMatch on port 443, and the other way round. S3 clients do this for you, because they sign for the endpoint you give them. A presigned URL works at the address it was made for, so a URL that names :7337 stays on port 7337.
If you cannot reach the endpoint, check the port first:
curl -I https://s3.fra.coritan.com:7337
Any HTTP status in the answer, even 403, means your network reaches us. No answer means a firewall or a proxy blocks the port. When the dashboard shows your region's endpoint without a port, try that endpoint, which needs outgoing port 443 only.
Addressing styles
Section titled Addressing stylesAn address names a bucket in one of two ways.
- Path style
- The bucket is the first part of the path, as in
https://s3.fra.coritan.com:7337/u7-assets/photo.jpg. Every region answers this way, and every example in these guides uses it. - Virtual-hosted style
- The bucket is the first part of the hostname, as in
https://u7-assets.s3.fra.coritan.com:7337/photo.jpg. A region answers this way only when the dashboard offers it: the Connect a client card on the Overview tab then shows an Addressing choice with Path style and Virtual-hosted.
Use virtual-hosted style when a tool or an SDK only builds addresses that way. Otherwise path style is the simpler choice, because it works everywhere.
A bucket whose name has a dot, such as u7-my.assets, stays path style. Its hostname would have two labels in front of the endpoint, and the endpoint's certificate covers one.
Both styles reach the same bucket with the same keys, and a request needs a signature in both. A virtual-hosted request is signed for the bucket's hostname, u7-assets.s3.fra.coritan.com, and a path-style request for the endpoint. Your client does this once you set the style.
A presigned URL for a virtual-hosted address works only at that hostname. Change the bucket in the hostname and the signature no longer matches, so the request answers SignatureDoesNotMatch.
Client settings
Section titled Client settings| Client | Path style | Virtual-hosted style |
|---|---|---|
| AWS CLI | aws configure set default.s3.addressing_style path |
aws configure set default.s3.addressing_style virtual |
| AWS CLI profile | addressing_style = path under s3 = |
addressing_style = virtual under s3 = |
| rclone | force_path_style=true |
force_path_style=false |
| s3cmd | --host-bucket=s3.fra.coritan.com |
--host-bucket=%(bucket)s.s3.fra.coritan.com |
| boto3 | Config(s3={"addressing_style": "path"}) |
Config(s3={"addressing_style": "virtual"}) |
| AWS SDK for JavaScript | forcePathStyle: true |
forcePathStyle: false |
Add the port to the endpoint and to --host-bucket when the region's endpoint has one. The Connect an S3 client guide has a full setup for each tool.
Related
Section titled RelatedAPI operations on this page
| Method | Path | What it does |
|---|---|---|
GET | /api/v1/client/object-storage/{service_id} | One service with its endpoints, its limits and how it is billed |