AWS S3
Use an existing AWS S3 bucket or create a private bucket for Kaneo. Use a bucket and an IAM user with access to that bucket. Example:S3_ENDPOINT and S3_REGION.
Using an IAM role instead of an access key
If Kaneo runs on AWS (EC2, ECS, or EKS), you can omitS3_ACCESS_KEY_ID and
S3_SECRET_ACCESS_KEY entirely and let Kaneo authenticate with the instance’s
IAM role. Leave both unset and the AWS SDK resolves credentials from its default
provider chain (instance profile, ECS task role, or EKS IRSA).
s3:PutObject, s3:GetObject, and s3:DeleteObject on the bucket.
Recommended S3 CORS policy:
Cloudflare R2
R2 works well because it exposes an S3-compatible API. Use your account endpoint, bucket, and R2 access keys. Example:S3_REGION=autois typical for R2- a public bucket is not required for Kaneo’s current private asset flow
- configure the bucket’s CORS policy for your Kaneo origin, including PUT and Content-Type; the JSON above shows the required shape
Other S3-compatible services
Use the provider’s S3 API endpoint, region, and bucket-scoped credentials. Check whether it requires path-style URLs. LeaveS3_PUBLIC_BASE_URL unset for Kaneo’s private attachment flow.
The service must support presigned PUT requests with signed Content-Length and Content-Type, object metadata checks, reads, and deletes. An S3-compatible label alone does not prove this upload path works; test a browser upload, reload, and download before using it for team files.
Apply changes with docker compose up -d --force-recreate kaneo. See Troubleshooting if uploads fail.