Saltar al contenido
Olimpia
Esc
↑↓navegar↵abrir⌘Jvista previa
En esta página

Credenciales y SDKs

Las variables de cada bucket y cómo usarlas con el AWS SDK de JavaScript, boto3, Go, la AWS CLI y rclone.

Cada bucket tiene sus credenciales en Credenciales. Son estas cinco variables:

AWS_ENDPOINT_URL_S3=https://t3.storage.dev
AWS_REGION=auto
AWS_ACCESS_KEY_ID=tid_...
AWS_SECRET_ACCESS_KEY=tsec_...
BUCKET_NAME=olimpia-...

Los SDKs de AWS leen AWS_ENDPOINT_URL_S3, AWS_REGION y las keys solos, así que no hace falta configurar nada en el código. BUCKET_NAME es el nombre real del bucket en el almacenamiento, distinto del nombre que ves en la consola.

Ejemplos

import { GetObjectCommand, PutObjectCommand, S3Client } from "@aws-sdk/client-s3";
import { getSignedUrl } from "@aws-sdk/s3-request-presigner";

const s3 = new S3Client({});
const Bucket = process.env.BUCKET_NAME;

await s3.send(new PutObjectCommand({ Bucket, Key: "avatars/ana.png", Body: archivo }));

const url = await getSignedUrl(s3, new GetObjectCommand({ Bucket, Key: "avatars/ana.png" }), {
  expiresIn: 3600,
});
import os
import boto3

s3 = boto3.client("s3")
bucket = os.environ["BUCKET_NAME"]

s3.upload_file("informe.pdf", bucket, "informes/2026-10.pdf")
url = s3.generate_presigned_url("get_object", Params={"Bucket": bucket, "Key": "informes/2026-10.pdf"}, ExpiresIn=3600)
cfg, _ := config.LoadDefaultConfig(ctx)
client := s3.NewFromConfig(cfg)

_, err := client.PutObject(ctx, &s3.PutObjectInput{
    Bucket: aws.String(os.Getenv("BUCKET_NAME")),
    Key:    aws.String("datos/export.csv"),
    Body:   archivo,
})
aws s3 cp ./foto.jpg "s3://$BUCKET_NAME/fotos/foto.jpg"
aws s3 ls "s3://$BUCKET_NAME/fotos/"
[olimpia]
type = s3
provider = Other
endpoint = https://t3.storage.dev
region = auto
access_key_id = tid_...
secret_access_key = tsec_...

Subidas desde el navegador

No pongas las keys en el frontend. Generá una URL firmada en tu backend y que el navegador suba directo con ella:

import { PutObjectCommand } from "@aws-sdk/client-s3";
import { getSignedUrl } from "@aws-sdk/s3-request-presigner";

const url = await getSignedUrl(
  s3,
  new PutObjectCommand({ Bucket: process.env.BUCKET_NAME, Key: `uploads/${id}`, ContentType: tipo }),
  { expiresIn: 600 },
);

Alcance de la key

La key de cada bucket solo puede operar sobre ese bucket. Si se filtra, no sirve para leer ni escribir en tus otros buckets.

Para cambiarla, abrí Credenciales y rotá la key: se genera una nueva y la anterior deja de valer. Actualizá las variables en tus apps y desplegá.

¿Te ha resultado útil esta página?