How to obtain S3 keys for standalone S3 object storage through My DataLake Services

This guide explains how to generate and manage S3 access and secret keys for the standalone S3 object storage service through My DataLake Services. The service is separate from Islet/OpenStack and provides a shared DEDL storage pool in which users can create and manage private S3 buckets. It exposes an S3-compatible API, so you can access it with the same S3 tools and clients commonly used with OpenStack Object Storage, although the two storage services remain separate.

S3-compatible object storage is accessed over HTTPS through an S3 API. Authentication requires an access key and a secret key. This article shows how to obtain, refresh, and delete these credentials in My DataLake Services.

What we are going to cover

Prerequisites

No. 1 Account

You must create a profile in My DataLake Services: How to create a profile on My DataLake Services.

No. 2 Administrative privileges within a project

You must be an administrator of a project in My DataLake Services or receive administrative privileges from the project owner.

To learn how to create a project, see How to create a project on My DataLake Services.

Alternatively, you can join an existing project and ask its administrator to grant you administrative privileges.

Available S3 keys in My DataLake Services

My DataLake Services can provide credentials for more than one S3-compatible service. eodata is used to access Earth observation datasets, while s3-object-storage provides standalone S3 object storage for user-created private buckets. The standalone S3 service is independent of Islet/OpenStack and uses a shared DEDL storage pool.

You can use either service separately or both at the same time. This article covers only s3-object-storage.

Types of S3 data in My DataLake Services

Type

Description

Security

EODATA

Earth Observation satellite data collections.

First downloaded, then processed.

Public datasets, shared access.

OpenStack Object Storage

Object storage provided as part of

an Islet/OpenStack environment.

Access and sharing follow the rules of

the relevant OpenStack project.

Standalone S3 object storage

Private S3 buckets created in a shared

DEDL storage pool that is separate

from Islet/OpenStack.

Credentials are assigned per user, and

access is controlled through the generated

S3 key pair.

Get access and quota for standalone S3 object storage

If this is your first time requesting access and quota roles for standalone S3 object storage, the page initially looks similar to the following:

../../_images/new-s3cmd-download-12-v3-vv.png

Each available site has its own role for standalone S3 object storage, as shown in the red rectangle. In this example, use s3-object-storage-central and click Request access in the relevant row.

Access roles

For s3-object-storage, there is only one access role:

s3-object-storage-access

Access to standalone S3 object storage.

Although only one access role is available, you must still select it by clicking the circle under Select role.

Enter a justification in the mandatory Description of planned activities field.

../../_images/new-s3cmd-download-26.png

Quota roles

Then select among three quota roles – low, medium and high:

../../_images/new-s3cmd-download-27-v45.png
s3-object-storage-low

Low quota for standalone S3 object storage. Maximum 216 buckets and 432,000 bucket objects, maximum user quota 115.96 GB.

s3-object-storage-medium

Medium quota for standalone S3 object storage. Maximum 540 buckets and 1,080,000 bucket objects, maximum user quota 289.91 GB.

s3-object-storage-high

High quota for standalone S3 object storage. Maximum 900 buckets and 1,800,000 bucket objects, maximum user quota 483.18 GB.

Select the required quota and explain the planned use of the storage in the mandatory Description of planned activities field. Click Request role to submit the request and display it under Role requests.

../../_images/new-s3cmd-download-28.png

You can initiate role requests for other services, such as hda and hook. Once submitted, each request appears under Role requests with the status PENDING until the operator reviews it.

The operator’s decision, explanation, and the resulting email notification are described in the following section.

Operator review and decision

Your request remains PENDING until it is reviewed by the operator. The operator can make one of the following decisions:

Approved

The requested role is granted and becomes available under Active roles. The operator’s comment explains the approval or provides any additional information relevant to the granted access.

Rejected

The requested role is not granted. The operator’s comment explains why the request was rejected, for example because the selected role is not suitable, the justification is insufficient, or the requested quota cannot be granted.

Returned for improvement

The role is not granted immediately. The operator returns the request so that you can correct, clarify, or restructure it. The operator’s comment explains what must be changed before the request can be submitted again.

The operator must provide a comment for every decision. After the request is approved, rejected, or returned for improvement, My DataLake Services sends an email notification to the user. The email contains the request details, its resulting status, and the operator’s comment.

The following example shows an email sent after a role request was approved. The message contains the request details and the comment entered by the operator:

../../_images/role-request-approved-email.png

Email notification containing the operator’s decision and comment.

You can also open Role requests and click Details to review the decision and the operator’s comment in the portal.

Once approved, the role appears under Active roles.

../../_images/s3cmd-download-42.png

You now have an active role for standalone S3 object storage:

../../_images/s3cmd-download-43.png

List active roles

With option Access -> Active roles from the left side menu, you can see the existing active roles. The following example shows active roles for eodata, hda, and s3-object-storage:

../../_images/new-s3cmd-download-64.png

List role requests

The Role requests option shows both pending requests and the history of requests already processed by the operator. For every processed request, click Details to review its status and the operator’s comment. The same decision and comment are also sent to you by email.

The following example shows access and quota roles approved by the operator for eodata and s3-object-storage:

../../_images/new-s3cmd-download-62.png

Click Details to review the complete request, its resulting status, and the comment provided by the operator. The following example shows the details of the s3-object-storage-central-low role:

../../_images/new-s3cmd-download-63.png

Get S3 keys for standalone S3 object storage

Obtaining credentials consists of two stages. First, create the standalone S3 object storage account. Then generate a separate S3 key pair for each site, brand, or bridge that you want to access.

Create the standalone S3 account

Open Object storage -> Account & keys from the menu on the left.

../../_images/s3cmd-for-eodata-8.png

Click Generate account to create your standalone S3 object storage account.

../../_images/s3cmd-for-eodata-13.png

Confirm the operation and wait until the account has the status ACTIVE. Account creation is performed only once and does not yet generate any S3 credentials.

Generate S3 keys for a site

After the account becomes active, click Generate key.

In the dialog window, select the site, brand, or bridge for which you want to generate the credentials:

../../_images/generate-object-storage-key-select-site.png

Selecting the site for which the S3 key pair will be generated.

Confirm the selection. My DataLake Services generates an access key and secret key pair dedicated to the selected site.

../../_images/s3cmd-for-eodata-10_v2.png

The access key remains visible in the portal, but the secret key is displayed only once. Copy the secret key immediately and store it securely.

Repeat the process for every additional site that you want to use. You can keep several active key pairs under the same account, but each pair is tied to the site selected when it was generated. For example, credentials generated for eumetsat must be used with the EUMETSAT standalone S3 endpoint and cannot be used with the central or leonardo endpoint.

The Keys table lists all generated key pairs together with their associated sites:

../../_images/multiple-site-object-storage-keys.png

Separate active S3 key pairs for the central, eumetsat, and leonardo sites.

Manage the standalone S3 account and keys

Delete account

Click on Delete account in the Account & keys menu. There are two cases to consider:

One or more buckets still exist in standalone S3 object storage

The account cannot be deleted while it still contains buckets:

../../_images/unable_to_delete_the_account.png

To delete the account, open Object storage -> Usage and delete all existing buckets one by one. For each bucket, open the three-dot menu and select Delete bucket.

There are no buckets in standalone S3 object storage

You will be asked to confirm the deletion:

../../_images/s3cmd-download-57.png

Once confirmed, the account will be deleted and you will be given the option to create a new one:

../../_images/new-s3cmd-download-60.png

Deleting the account also removes every S3 key pair generated under it, regardless of the site with which each pair is associated. If you later create a new account, you must generate new credentials separately for every site that you want to access.

Refresh secret key

Each row in the Keys table represents the key pair for one site. To replace a secret key, find the relevant site and click Refresh in its row. You may want to refresh a secret key if you suspect that it has been exposed or compromised.

../../_images/new-s3cmd-download-59.png

My DataLake Services generates a new secret key while keeping the existing access key and its associated site unchanged.

../../_images/new-pair-of-s3-object-storage-keys.png

The previous secret key for that site stops working, while key pairs generated for other sites remain unaffected. Update every S3 client, configuration file, script, or application that uses the previous secret key.

Delete an S3 key pair

You can delete the key pair for an individual site without deleting the standalone S3 account or key pairs generated for other sites.

In Object storage -> Account & keys, find the row for the relevant site and click Delete:

../../_images/new-s3cmd-download-56.png

Confirm the operation:

../../_images/new-s3cmd-download-57.png

After deletion, you can no longer authenticate to the standalone S3 service at that site until you generate another key pair for it. The account and credentials associated with all other sites remain active.

Review standalone S3 storage usage

Open Object storage -> Usage to review the resources consumed in standalone S3 object storage. When no buckets have been created yet, the page may look as follows:

../../_images/s3cmd-download-41-v2.png

Important

My DataLake Services does not provide an interface for creating buckets, uploading or downloading files, browsing objects, or performing other operations directly on the S3 storage.

To work with the storage, use the credentials generated in this article with an external S3-compatible client or library, such as Cyberduck, s3cmd, boto3, the AWS CLI, or another application that supports the S3 API. My DataLake Services is used to manage access, quotas, accounts, keys, and usage information.

The following screenshots from a graphical S3 client illustrate how buckets and their contents may appear after they have been created with an external S3-compatible tool.

Assume that you have created two buckets named bucket and replace-with-a-unique-test-bucket-name. They appear in the graphical S3 client as follows:

../../_images/two_buckets_show_from_cyberduck.png

Two buckets displayed in a graphical S3 client.

The bucket named bucket contains a folder-like entry named incoming, under which seven images have been uploaded:

../../_images/bucket_with_subfolder_with_images.png

Seven images displayed under the incoming folder-like entry.

You can review the same resources under Object storage -> Usage:

../../_images/object_storage_usage_real_state.png

Buckets listed in the standalone S3 object storage usage view.

The total number of buckets is displayed under Total usage -> Number of buckets. In this example, the value is 2, and the Buckets section lists bucket and replace-with-a-unique-test-bucket-name.

To manage an individual bucket, open the three-dot menu at the right side of its row:

../../_images/bucket_row_three_dot_menu.png

Three-dot menu for an individual bucket.

Refresh usage

Retrieves the latest usage information for the bucket, including the number of objects and the amount of storage consumed.

S3 object storage does not contain directories in the same sense as a desktop file system. Graphical S3 clients commonly display object-name prefixes as folders. In this example, the portal reports eight objects: the seven images and the object representing the incoming folder-like entry.

Delete bucket

Deletes the selected bucket and its contents. In this example, the first bucket contains eight objects consuming 15.48 MB.

Select Delete bucket, then confirm the operation:

../../_images/are_you_sure_you_want_to_delete_bucket.png

Confirmation before deleting the bucket.

While the operation is in progress, the bucket has the status DELETING:

../../_images/deleting_the_bucket.png

Bucket deletion in progress.

After deletion finishes, the bucket row disappears and the values under Total usage are updated:

../../_images/stats_change_after_bucket_deletion.png

Updated usage information after bucket deletion.

How to change roles

The standalone s3-object-storage service has only one access role, so that role cannot be changed. However, you can request a change from your current quota role to either of the other available quota roles.

For example, assume that you initially selected s3-object-storage-low and now see the following entry under Active roles:

../../_images/change-object-storage-role--1.png

To request s3-object-storage-medium or s3-object-storage-high, open Role requests and click Edit access in the s3-object-storage row:

../../_images/change-object-storage-role--2.png

The remaining quota roles are displayed:

../../_images/change-object-storage-role--3.png

Because you already have the low quota, you can request either the medium or high quota.

Select the required quota and explain why you need the change in Description of planned activities. After completing the mandatory field, click Request role.

A confirmation message appears in the lower-right corner of the browser window:

../../_images/stack-jupyter-role--10.png

The new quota-change request appears under Role requests with the status PENDING. It remains in this state until the operator approves it, rejects it, or returns it for improvement:

../../_images/change-object-storage-role--4.png

Two options are available for the pending request:

Details

Opens the request and displays its current status and submitted information.

Delete

Withdraws the request before the operator reviews it.

You can cancel the operation or confirm that the request should be deleted:

../../_images/stack-jupyter-role--5.png

After confirmation, a message appears in the lower-right corner of the browser window:

../../_images/change-object-storage-role--5.png

The request will be displayed with the status REJECTED. However, this does not mean that the operator rejected it. When you click Details, the reason is shown as deleted directly, indicating that the request was withdrawn by the user before operator review.

../../_images/change-object-storage-role--6.png

If you do not delete the request, it remains PENDING until the operator reviews it. The operator can approve the quota change, reject it, or return the request so that you can improve or restructure the justification.

For every outcome, the operator provides a comment explaining the decision. The comment is shown under Details, and My DataLake Services also sends you an email containing the request details, its resulting status, and the operator’s comment.

If the request is approved, its status changes to APPROVED:

../../_images/change-object-storage-role--7.png

Click Active roles to verify that the quota has changed to medium:

../../_images/change-object-storage-role--8.png

If the request is rejected, open Details to read why the operator did not approve it. The same explanation is included in the email notification.

If the request is returned for improvement, open Details and read the operator’s instructions. Correct or expand the request as indicated, then submit it again for review. The email notification also contains the operator’s explanation of what should be changed.

What to do next

If you want to stop being an owner of a My DataLake Services account, see How to delete account on My DataLake Services.

See status page for Destination Earth Data Lake object storage S3 keys.

To work with standalone S3 object storage through a graphical interface on Windows or macOS, see Using Cyberduck with S3-compatible object storage on Destination Earth.

To access the service from Linux or through scripts and command-line workflows, install and configure s3cmd as described in How to install s3cmd on Linux.