SISuperintelligenceDocs

Search docs

Search every page of the documentation.

Data

Object storage

Private S3 buckets for files your projects store and serve.

Create a bucket

Cloud → Storage → Create bucket, or create it from a project's Storage tab to link it right away. You need resources:write.

  • Name: 3–40 lowercase letters, numbers and dashes.
  • Location: the bucket is created in the region the location resolves to for S3 and stays there.

Buckets are private: all public access is blocked, and objects are encrypted at rest. The bucket name (si-…-<org id>-<name>-<suffix>) is shown under its name in Storage. Each bucket gets one CORS rule, si-cloud-uploads, that lets Cloud upload to it from the browser.

Browse files

A bucket's Files tab browses it one folder at a time (reading needs resources:read, changing resources:write):

  • Upload files, or drop them on the page. Each file can be up to 5 GB; the browser sends it straight to S3 with a link valid for 15 minutes, so uploads don't pass through the platform.
  • New folder creates an empty folder.
  • Select a file to see its size, type, storage class, encryption, headers (Cache-Control, Content-Disposition, Content-Encoding) and metadata, and to download it with a link valid for 5 minutes.
  • Delete files and folders. A folder is deleted with everything in it. With versioning on, previous versions are kept.

The size and file count on the bucket's page are what S3 reports once a day.

Settings

Setting
AccessShows whether the public access block is in place.
VersioningKeep every version of every file. Turning it off suspends it: existing versions are kept, new writes aren't versioned.
CORSYour own CORS rules (up to 20), for browsers that call the bucket directly. Cloud's si-cloud-uploads rule is kept separately and can't be edited.
Expire filesLifecycle rules (up to 50): S3 deletes files under a path (or the whole bucket) a number of days after they're written, and optionally old versions a number of days after they're replaced. Rules set outside Cloud with transitions or filters are marked, since Cloud doesn't show those parts.

Connect

The Connect tab shows the environment variables a linked project gets and code for uploading, downloading, listing and sharing files.

Link a bucket the same way as a database. From the next deployment, the project's server function gets:

VariableValue
SI_BUCKET_<NAME>The bucket name.
SI_BUCKET_<NAME>_REGIONThe bucket's region.

A bucket named uploads becomes SI_BUCKET_UPLOADS.

Use it from your code

npm install @aws-sdk/client-s3 @aws-sdk/s3-request-presigner
lib/files.ts
import { GetObjectCommand, PutObjectCommand, S3Client } from "@aws-sdk/client-s3"
import { getSignedUrl } from "@aws-sdk/s3-request-presigner"

const Bucket = process.env.SI_BUCKET_UPLOADS!
const s3 = new S3Client({ region: process.env.SI_BUCKET_UPLOADS_REGION })

export async function saveFile(key: string, body: Uint8Array, contentType: string) {
  await s3.send(new PutObjectCommand({ Bucket, Key: key, Body: body, ContentType: contentType }))
}

export async function readText(key: string) {
  const res = await s3.send(new GetObjectCommand({ Bucket, Key: key }))
  return res.Body?.transformToString()
}

/** A link a browser can download from for the next 5 minutes. */
export function downloadUrl(key: string) {
  return getSignedUrl(s3, new GetObjectCommand({ Bucket, Key: key }), { expiresIn: 300 })
}

The runtime role allows GetObject, PutObject, DeleteObject and ListBucket on every bucket of the organization. Presigned URLs carry the function's temporary credentials, so they stop working when those expire, even if expiresIn is longer.

Buckets aren't served at a public URL. Serve files through your app, or hand out presigned URLs.

Delete a bucket

Delete every file first, then choose Delete bucket in Settings (needs resources:write). Old versions of deleted files are removed with the bucket; this can't be undone. If the bucket was already deleted outside the platform, Remove from Cloud removes the record.