Skip to main content

Service accounts

What is a service account?​

A service account is an IAM user that belongs to a project and is used by an application or a service instead of a person: a backup job, a sync client, a script, or any other tool that connects to Cubbit over the S3 API. Service accounts authenticate with an access key and secret key, so they do not need to sign in to the Cubbit Console.

Using a dedicated service account for each application keeps credentials separate from personal accounts: you can assign only the permissions the application needs, and rotate or revoke its access keys without affecting other users.

Create a service account​

To create a service account, invite a user to the project from the DS3 Console:

  1. Sign in to the Cubbit web console (https://console.cubbit.eu, or https://console.[your-tenant].cubbit.eu for a custom tenant) and select the project you want to work on.
  2. Open Project -> IAM -> Users.
  3. Select Invite user.
  4. Enter a username that identifies the application, for example backup-veeam.
  5. Enter an email address you control. Prefer an address that is already verified with Cubbit: the email of the account you are currently signed in with, or another mailbox that already belongs to a Cubbit account.
  6. Optionally select the policies or groups to assign.
  7. Select Invite user to submit the form.

If you use an address that is new to Cubbit, the invited user receives an email with instructions to access the account, and the access must be completed within 7 days. Otherwise the account is automatically deleted. See Accounts not accessed within 7 days are deleted.

Assign policies​

  1. Open Project -> IAM -> Users and select the service account.
  2. Attach the policies the application needs, or add the user to a group.

Every project includes the preset policies Member, Admin, and ReadOnly; you can also create custom policies that grant only the actions the application needs. See Permissions & Policies for the available actions, the policy syntax, and examples.

Create access keys​

Access keys are bound to a specific IAM user. To generate a pair for the service account:

  1. Open Project -> IAM -> Users and select the service account.
  2. Select Manage access keys, or open Access keys from the row menu in the Users list.
  3. Select Generate new client API key.
  4. Download the CSV file and keep it safe, then use Show to reveal the secret key.
  5. Copy the access key and the secret key into the settings of the application.

Configure the client with the Cubbit S3 endpoint (https://s3.cubbit.eu, or https://s3.[your-tenant].cubbit.eu for a custom tenant) and the region eu-west-1. For a step-by-step example, see the Quickstart.

Accounts not accessed within 7 days are deleted​

warning

An account that is invited to a project but is not accessed within 7 days is automatically deleted. If the account is used by an application, any access keys created for it stop working, and the application can no longer connect.

To avoid interruptions:

  • Use an email address you control and monitor it, so the invitation does not go unnoticed.
  • Complete the access and verification flow as soon as the invitation arrives.
  • If a service account is deleted, create a new one and generate new access keys, then update the application configuration.