Core Concepts
Before working with Object Storage it helps to understand the building blocks: buckets, objects, regions, endpoints, and access via API Credentials.
Buckets
A bucket is a container for objects. Every object you upload lives in exactly one bucket.
- Bucket names are globally unique within IBEE Object Storage.
- A bucket’s location is fixed at creation and cannot be changed — to use a different location, create a new bucket and migrate your objects.
- Use multiple buckets to separate environments, projects, or access boundaries.
Bucket names must be 3 to 63 characters, lowercase, and contain only letters, numbers, and hyphens. They must start and end with a letter or number. See Buckets for the full naming rules and the create flow.
Objects
An object is a single file plus its metadata. Each object has:
- A key — the path-like name within the bucket (
reports/2026-05.pdf). - The object data — up to 5 TiB per object.
- A type (MIME type, e.g.
image/jpeg) and storage class (Standard). - System metadata — size, last-modified, ETag.
There’s no real folder hierarchy — only keys with / separators. The portal renders prefixes as folders. See Objects for upload, download, and management.
Regions
A region is a physical data center where buckets live. Pick the region closest to your users or your compute.
When creating a bucket, keep Automatic location to let the platform pick the best available region, or click Need a specific location? click here to choose a site yourself. Pre-order sites show Talk to Sales instead of a create button. Jurisdiction-based placement (Specify jurisdiction) is coming soon — talk to sales if you need it today. See Buckets → Create a bucket and Regions & Locations.
Endpoints
The endpoint is the HTTPS URL S3-compatible clients connect to. Each workspace has its own S3 endpoint:
Use this with the AWS CLI, AWS SDKs, s3cmd, rclone, or any S3-compatible tool — paired with the Access Key ID and Secret Access Key from an API Credentials.
For browser delivery from a public bucket, use the bucket’s Public Access URL or a Custom Domain instead. See Buckets → Policies and Buckets → Custom Domains.
Access
To reach buckets from S3-compatible tools you create an S3 credential under Organization → API Tokens → S3 Credentials. Each credential belongs to one workspace and gives you:
Permission levels range from Object Read only to Admin Read & Write. Object-level credentials can be limited to specific buckets; Admin credentials always apply to every bucket in the workspace. See API Credentials for the full flow.
Public access and Object Lock
These bucket-level settings control how objects can be read, written, and kept:
- Public Access — when enabled, objects can be served unauthenticated via the bucket’s Public Access URL. Toggled from Settings → General.
- Versioning — keeps previous versions of overwritten or deleted objects. Turned on at bucket creation under Versioning and object lock.
- Object Lock — prevents objects from being deleted or overwritten while a retention period is in effect. Permanent setting that must be enabled at bucket creation under Versioning and object lock (it also turns on versioning). See Objects → Locking.
