All pages
Connecting clouds
Artifacts creates buckets in your AWS account, GCP project or Azure subscription and signs URLs for them, without any long-lived cloud key from you.
Federation
The app is an OpenID Connect identity provider. It publishes
/.well-known/openid-configuration and its keys at /.well-known/jwks.json,
and signs short JWTs whose subject is one connection, org_…:c…. Your cloud
trusts that issuer for that one subject and swaps the JWT for its own
short-lived credentials.
Nothing you give us can be lifted and used elsewhere. Revoking is deleting the role, the workload identity pool or the federated credential on your side.
Connect
- Connections → Connect AWS, GCP or Azure, and name the connection.
- The app shows a setup script with your connection's subject, the issuer and the audience filled in. Run it in your account with the cloud's CLI, as an administrator.
- The script's last line prints the identifiers it created,
key=valuepairs. Paste that line back into the app, or fill in the fields. - The app exchanges a token to check the connection works, and marks it active. A connection whose trust was removed shows as broken, with the error.
Then create locations in that cloud: pick the connection and a region, and the app creates the bucket.
| Cloud | The script creates | It grants | The app signs with |
|---|---|---|---|
| AWS | An IAM OIDC provider for the issuer and a role trusting the subject, max session 12 h | Create o41art-* buckets and set their lifecycle; object and multipart operations in them |
Temporary keys from AssumeRoleWithWebIdentity, cached until shortly before they expire |
| GCP | A workload identity pool and provider for the issuer, a service account the subject may impersonate | Create buckets; storage admin on o41art-* buckets only; sign as the service account |
The service account through IAM signBlob, with the federated token: V4 URLs on the XML API, no key ever made |
| Azure | An app registration with a federated credential for the issuer and subject | Storage Account Contributor and Storage Blob Data Contributor on a resource group you name | A user delegation key per storage account, refreshed daily; user delegation SAS |
The identifiers
| Cloud | Pasted back |
|---|---|
| AWS | roleArn |
| GCP | projectId, projectNumber, poolId, providerId, serviceAccountEmail |
| Azure | tenantId, clientId, subscriptionId, resourceGroup |
Created buckets
- Named
o41art-<random>; on Azure a storage accounto41art<random>with a containerartifacts. - Private, with a lifecycle rule that aborts unfinished multipart uploads after 2 days. Azure drops uncommitted blocks after 7 days by itself.
- The app never deletes a bucket. A location is retired instead: no new writes go to it and its versions stay readable.
- A created location whose bucket or first test write fails stays
unfinished: it takes no writes and can be removed (
locations rm); the bucket, if one was made, stays in your account.
A tenant who cannot set up federation on AWS or GCP adds the bucket as an S3 endpoint with a key instead. Azure Blob has no S3 API, so Azure is federation only.