Skip to main content

S3 APIs

Intro​

The Cubbit S3 Gateway supports most of the AWS S3 RESTful APIs used by the AWS SDKs (like aws-sdk-js, aws-sdk-go, etc), by the official AWS Command Line Interface and by all the S3 compatible clients.

This implies that the aforementioned tools can be used with Cubbit simply by configuring them to use the right endpoint, i.e. https://s3.cubbit.eu. For example, in this documentation, you can find instructions on how to setup the AWS CLI.

The following sections describe broadly what features are currently supported and how closely they reflect the original AWS S3 specification. The final section gives a detailed view of what API methods are supported.

Bucket management​

Creating and deleting new buckets is supported, along with listing their content.

Object management​​

Uploading, downloading, copying, and deleting objects are fully supported operations.

Multipart Upload​​

Multipart Uploads are fully supported. More information about the multipart upload can be found here.

Versioning​​

Versioning can be activated on a bucket and can be suspended. All operations related to versioned objects, like creating new versions, listing, or deleting them are supported. More information on bucket versioning can be found here.

Object Lock​

The Object Lock feature is fully supported. The following table summarizes the various lock methods.

Lock typeModeSupport
Legal Hold-Yes
Object RetentionCOMPLIANCEYes
Object RetentionGOVERNANCEYes

ACL​

ACL APIs are supported.

The grantee may be one of the following:

  • a user (by their ID or their email)
  • a predefined group

The supported predefined groups are:

  • AllUsers
  • AuthenticatedUsers

It should also be noted that:

  • read and write operations are not yet supported in a public-read or public-read-write scenario
  • the implementation of these groups might slightly change in the future

The following canned ACLs are allowed:

  • private
  • public-read (with the aforementioned limitations)
  • public-read-write (with the aforementioned limitations)
  • authenticated-read
  • bucket-owner-read
  • bucket-owner-full-control

More information can be found here.

Lifecycle Configuration​​

The Lifecycle Configuration feature is partially supported.

A single configuration rule is allowed. The only configuration rule supported is the NoncurrentVersionExpiration with no filters.

More information can be found here.

Object Tagging​​

We support the core Object Tagging APIs for managing tags on individual S3 objects:

  • PutObjectTagging: Assign or replace the complete tags set on an existing object.
  • GetObjectTagging: Retrieve all tags associated with a specified object.
  • DeleteObjectTagging: Remove all tags from a specified object.

We also preserve tags when copying objects using the CopyObject API.

Unsupported Tagging Features​

Specific tagging capabilities in ancillary APIs are not yet supported:

  • ⚠️ Tagging at Upload Time: You cannot add tags inline during PutObject or CreateMultipartUpload requests.
  • ⚠️ Tag Count in Retrieval: The GetObject response does not include the x-amz-tagging-count header.
  • ⚠️ Tag Overwrite on Copy: You cannot override or replace tags via CopyObject. Only tag preservation is supported.
note

Some legacy buckets created before object tagging was available may not support tagging operations at all. If you happen to encounter errors, please make sure that the target bucket has tagging enabled.

Bucket Tagging​​

Not supported.

Object Lifecycle​​

Not supported.

Request Headers​

The Cubbit S3 Gateway accepts the request headers summarized below. The table lists the significant S3 request headers and whether the gateway evaluates them. A header marked No is accepted without error but is not evaluated: its effect is not applied by the gateway. Authentication and signing headers (such as Authorization and x-amz-date) are handled as part of normal request processing and are not listed. Support for conditional requests is targeted for early 2027; the exact release date is subject to change.

warning

Some of the headers below are used by S3 clients to protect data: conditional writes, checksums, and client-side encryption keys are not enforced yet. Until support is available, do not rely on them to prevent overwrites, to verify integrity, or to encrypt objects with your own key.

FamilyRequest headerApplies toEvaluatedNotes
MetadataContent-TypeCopyObject, CreateMultipartUpload, PutObjectYesStored as object metadata; on CopyObject, only with x-amz-metadata-directive: REPLACE.
MetadataContent-DispositionCopyObject, CreateMultipartUpload, PutObjectYesStored as object metadata; on CopyObject, only with x-amz-metadata-directive: REPLACE.
MetadataContent-EncodingCopyObject, CreateMultipartUpload, PutObjectYesStored as object metadata; on CopyObject, only with x-amz-metadata-directive: REPLACE.
MetadataCache-ControlCopyObject, CreateMultipartUpload, PutObjectYesStored as object metadata; on CopyObject, only with x-amz-metadata-directive: REPLACE.
Metadatax-amz-meta-*CopyObject, CreateMultipartUpload, PutObjectYesStored with the object; a total size limit applies; on CopyObject, only with x-amz-metadata-directive: REPLACE.
MetadataContent-LanguageCopyObject, CreateMultipartUpload, PutObjectNoNot stored with the object.
MetadataExpiresCopyObject, CreateMultipartUpload, PutObjectNoNot stored with the object.
Access Controlx-amz-aclCreateBucket, CopyObject, CreateMultipartUpload, PutBucketAcl, PutObject, PutObjectAclYesValidated; invalid canned ACLs are rejected.
Access Controlx-amz-grant-readCreateBucket, CopyObject, CreateMultipartUpload, PutBucketAcl, PutObject, PutObjectAclYes
Access Controlx-amz-grant-read-acpCreateBucket, CopyObject, CreateMultipartUpload, PutBucketAcl, PutObject, PutObjectAclYes
Access Controlx-amz-grant-writeCreateBucket, PutBucketAcl, PutObjectAclYesIgnored when writing object data (PutObject, CopyObject, CreateMultipartUpload); honored on bucket ACLs. On object ACLs (PutObjectAcl) the grant is stored but never evaluated by object authorization.
Access Controlx-amz-grant-write-acpCreateBucket, CopyObject, CreateMultipartUpload, PutBucketAcl, PutObject, PutObjectAclYes
Access Controlx-amz-grant-full-controlCreateBucket, CopyObject, CreateMultipartUpload, PutBucketAcl, PutObject, PutObjectAclYes
Access Controlx-amz-expected-bucket-ownerMost bucket and object operationsYesA mismatch returns Access Denied.
Access Controlx-amz-source-expected-bucket-ownerCopyObject, UploadPartCopyNoThe source bucket owner is not checked.
Access Controlx-amz-object-ownershipCreateBucketYesValidated; unknown values are rejected.
Object Lockx-amz-object-lock-modeCopyObject, CreateMultipartUpload, PutObjectYesEnforced.
Object Lockx-amz-object-lock-retain-until-dateCopyObject, CreateMultipartUpload, PutObjectYesEnforced.
Object Lockx-amz-object-lock-legal-holdCopyObject, CreateMultipartUpload, PutObjectYesEnforced.
Object Lockx-amz-bypass-governance-retentionDeleteObject, DeleteObjects, PutObjectRetentionYesEnforced.
Object Lockx-amz-bucket-object-lock-enabledCreateBucketYesEnforced.
Object Lockx-amz-bucket-object-lock-tokenPutObjectLockConfigurationNoNot evaluated.
Copyx-amz-copy-sourceCopyObject, UploadPartCopyYesRequired to identify the source object.
Copyx-amz-copy-source-rangeUploadPartCopyYesEnforced.
Copyx-amz-metadata-directiveCopyObjectYesCOPY and REPLACE are honored.
Storagex-amz-storage-classCopyObject, CreateMultipartUpload, PutObjectYesValidated; invalid storage classes are rejected.
MiscRangeGetObject, HeadObjectYesByte-range requests are honored.
Miscx-amz-request-payerMost bucket and object operationsNoNo effect; Requester Pays is not supported.
Miscx-amz-mfaDeleteObject, DeleteObjects, PutBucketVersioningNoNo effect; the bucket's Multi-Factor Authentication (MFA) Delete setting is enabled through the PutBucketVersioning request body and reported by GetBucketVersioning, but it is never enforced on delete operations.
Miscx-amz-website-redirect-locationCopyObject, CreateMultipartUpload, PutObjectNoNot stored.
Miscx-amz-optional-object-attributesListObjectVersions, ListObjects, ListObjectsV2NoNot returned.
ConditionalIf-MatchCompleteMultipartUpload, DeleteObject, DeleteObjects, GetObject, HeadObject, PutObjectNoNot evaluated; no 412 Precondition Failed is returned.
ConditionalIf-None-MatchCompleteMultipartUpload, GetObject, HeadObject, PutObjectNoNot evaluated; no 412 Precondition Failed or 304 Not Modified is returned.
ConditionalIf-Modified-SinceGetObject, HeadObjectNoNot evaluated; no 304 Not Modified is returned.
ConditionalIf-Unmodified-SinceGetObject, HeadObjectNoNot evaluated; no 412 Precondition Failed is returned.
Conditionalx-amz-copy-source-if-matchCopyObject, UploadPartCopyNoNot evaluated; the copy is performed unconditionally.
Conditionalx-amz-copy-source-if-none-matchCopyObject, UploadPartCopyNoNot evaluated; the copy is performed unconditionally.
Conditionalx-amz-copy-source-if-modified-sinceCopyObject, UploadPartCopyNoNot evaluated; the copy is performed unconditionally.
Conditionalx-amz-copy-source-if-unmodified-sinceCopyObject, UploadPartCopyNoNot evaluated; the copy is performed unconditionally.
Server-Side Encryptionx-amz-server-side-encryptionCopyObject, CreateMultipartUpload, PutObjectNoNot applied; objects are stored with the platform's default encryption.
Server-Side Encryptionx-amz-server-side-encryption-aws-kms-key-idCopyObject, CreateMultipartUpload, PutObjectNoNot applied.
Server-Side Encryptionx-amz-server-side-encryption-contextCopyObject, CreateMultipartUpload, PutObjectNoNot applied.
Server-Side Encryptionx-amz-server-side-encryption-bucket-key-enabledCopyObject, CreateMultipartUpload, PutObjectNoNot applied.
Server-Side Encryptionx-amz-server-side-encryption-customer-algorithmCompleteMultipartUpload, CopyObject, CreateMultipartUpload, GetObject, HeadObject, ListParts, PutObject, UploadPart, UploadPartCopyNoThe client-provided key is never used.
Server-Side Encryptionx-amz-server-side-encryption-customer-keyCompleteMultipartUpload, CopyObject, CreateMultipartUpload, GetObject, HeadObject, ListParts, PutObject, UploadPart, UploadPartCopyNoThe client-provided key is never used.
Server-Side Encryptionx-amz-server-side-encryption-customer-key-md5CompleteMultipartUpload, CopyObject, CreateMultipartUpload, GetObject, HeadObject, ListParts, PutObject, UploadPart, UploadPartCopyNoThe client-provided key is never used.
Server-Side Encryptionx-amz-copy-source-server-side-encryption-customer-algorithmCopyObject, UploadPartCopyNoThe source encryption key is never used.
Server-Side Encryptionx-amz-copy-source-server-side-encryption-customer-keyCopyObject, UploadPartCopyNoThe source encryption key is never used.
Server-Side Encryptionx-amz-copy-source-server-side-encryption-customer-key-md5CopyObject, UploadPartCopyNoThe source encryption key is never used.
Checksumsx-amz-checksum-crc32CompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-crc32cCompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-crc64nvmeCompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-sha1CompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-sha256CompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-sha512CompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-md5CompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-xxhash64CompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-xxhash3CompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-xxhash128CompleteMultipartUpload, PutObject, UploadPartNoThe checksum is not verified.
Checksumsx-amz-checksum-algorithmCopyObject, CreateMultipartUploadNoNot applied.
Checksumsx-amz-sdk-checksum-algorithmMost write operations, including DeleteObjects and bucket configuration requestsNoNot applied.
Checksumsx-amz-checksum-modeGetObject, HeadObjectNoChecksums are not included in the response.
Checksumsx-amz-trailerPutObject, UploadPartNoTrailers are discarded.
ChecksumsContent-MD5Most object and bucket operationsNoOnly used as part of the Signature Version 2 (SigV2) signature; it is never verified against the payload.
Object Taggingx-amz-taggingCopyObject, CreateMultipartUpload, PutObjectNoTags are not applied. See Object Tagging.
Object Taggingx-amz-tagging-directiveCopyObjectNoNot applied. See Object Tagging.

API Compatibility Table​

MethodSupportNotes
AbortMultipartUploadYes
CompleteMultipartUploadYes
CopyObjectYes
CreateBucketYes
CreateMultipartUploadYes
DeleteBucketYes
DeleteBucketAnalyticsConfigurationNo
DeleteBucketCorsNo
DeleteBucketEncryptionNo
DeleteBucketIntelligentTieringConfigurationNo
DeleteBucketInventoryConfigurationNo
DeleteBucketLifecycleYes
DeleteBucketMetricsConfigurationNo
DeleteBucketOwnershipControlsYes
DeleteBucketPolicyNo
DeleteBucketReplicationNo
DeleteBucketTaggingNo
DeleteBucketWebsiteNo
DeleteObjectYes
DeleteObjectsYes
DeleteObjectTaggingYesMay not be available for some buckets
DeletePublicAccessBlockNo
GetBucketAccelerateConfigurationNo
GetBucketAclYes
GetBucketAnalyticsConfigurationNo
GetBucketCorsNo
GetBucketEncryptionNo
GetBucketIntelligentTieringConfigurationNo
GetBucketInventoryConfigurationNo
GetBucketLifecycleNo
GetBucketLifecycleConfigurationYesNoncurrentVersionExpiration only
GetBucketLocationYes
GetBucketLoggingNo
GetBucketMetricsConfigurationNo
GetBucketNotificationNo
GetBucketNotificationConfigurationNo
GetBucketOwnershipControlsYes
GetBucketPolicyNo
GetBucketPolicyStatusNo
GetBucketReplicationNo
GetBucketRequestPaymentNo
GetBucketTaggingNo
GetBucketVersioningYes
GetBucketWebsiteNo
GetObjectYes
GetObjectAclYes
GetObjectAttributesNo
GetObjectLegalHoldYes
GetObjectLockConfigurationYes
GetObjectRetentionYes
GetObjectTaggingYesMay not be available for some buckets
GetObjectTorrentNo
GetPublicAccessBlockNo
HeadBucketYes
HeadObjectYes
ListBucketAnalyticsConfigurationsNo
ListBucketIntelligentTieringConfigurationsNo
ListBucketInventoryConfigurationsNo
ListBucketMetricsConfigurationsNo
ListBucketsYes
ListMultipartUploadsYes
ListObjectsYes
ListObjectsV2Yes
ListObjectVersionsYes
ListPartsYes
PutBucketAccelerateConfigurationNo
PutBucketAclYes
PutBucketAnalyticsConfigurationNo
PutBucketCorsNo
PutBucketEncryptionNo
PutBucketIntelligentTieringConfigurationNo
PutBucketInventoryConfigurationNo
PutBucketLifecycleNo
PutBucketLifecycleConfigurationYesNoncurrentVersionExpiration only
PutBucketLoggingNo
PutBucketMetricsConfigurationNo
PutBucketNotificationNo
PutBucketNotificationConfigurationNo
PutBucketOwnershipControlsYes
PutBucketPolicyNo
PutBucketReplicationNo
PutBucketRequestPaymentNo
PutBucketTaggingNo
PutBucketVersioningYes
PutBucketWebsiteNo
PutObjectYes
PutObjectAclYes
PutObjectLegalHoldYes
PutObjectLockConfigurationYes
PutObjectRetentionYes
PutObjectTaggingYesMay not be available for some buckets
PutPublicAccessBlockNo
RestoreObjectNo
SelectObjectContentNo
UploadPartYes
UploadPartCopyYes
WriteGetObjectResponseNo