Skip to main content
For self-hosted storage, follow the Silo guide. This page covers managed providers and the requirements for another S3-compatible service. Start with a private bucket. Both the browser and the API must reach the endpoint, and storage CORS must allow your Kaneo origin. Read Files and uploads for the full upload flow.

AWS S3

Use an existing AWS S3 bucket or create a private bucket for Kaneo. Use a bucket and an IAM user with access to that bucket. Example:
For another AWS region, change both S3_ENDPOINT and S3_REGION.

Using an IAM role instead of an access key

If Kaneo runs on AWS (EC2, ECS, or EKS), you can omit S3_ACCESS_KEY_ID and S3_SECRET_ACCESS_KEY entirely and let Kaneo authenticate with the instance’s IAM role. Leave both unset and the AWS SDK resolves credentials from its default provider chain (instance profile, ECS task role, or EKS IRSA).
Set both keys or neither: configuring only one is rejected. The role must allow s3:PutObject, s3:GetObject, and s3:DeleteObject on the bucket. Recommended S3 CORS policy:
Apply the CORS policy above in the S3 bucket settings, replacing the origin with your public Kaneo URL.

Cloudflare R2

R2 works well because it exposes an S3-compatible API. Use your account endpoint, bucket, and R2 access keys. Example:
Notes:
  • S3_REGION=auto is typical for R2
  • a public bucket is not required for Kaneo’s current private asset flow
  • configure the bucket’s CORS policy for your Kaneo origin, including PUT and Content-Type; the JSON above shows the required shape

Other S3-compatible services

Use the provider’s S3 API endpoint, region, and bucket-scoped credentials. Check whether it requires path-style URLs. Leave S3_PUBLIC_BASE_URL unset for Kaneo’s private attachment flow. The service must support presigned PUT requests with signed Content-Length and Content-Type, object metadata checks, reads, and deletes. An S3-compatible label alone does not prove this upload path works; test a browser upload, reload, and download before using it for team files. Apply changes with docker compose up -d --force-recreate kaneo. See Troubleshooting if uploads fail.