Storage provider
colis with AWS S3
Credentials come from the provider chain, so a Lambda or an ECS task needs no keys at all.
import { createBucket } from '@colis/core'
// Credentials from the AWS provider chain: env, shared config, or the role.
const store = createBucket({
bucket: process.env.S3_BUCKET,
region: 'eu-west-3',
prefix: 'transfers',
maxSize: 4 * 1024 * 1024,
})Why this one
AWS S3
On AWS, colis is the AWS SDK v3 with the transfer rules on top. Omit credentials and the default provider chain applies: environment variables, the shared config file, or the role attached to the instance, task or function.
From the command line
A starter configuration, and what is left to do.
init writes the file with ${VAR} references rather than secrets, so it is meant to be committed; the env file it points at is not.
{
"bucket": "transfers",
"region": "eu-west-3",
"prefix": "transfers",
"expiresIn": "24h"
}Then
- 01Give the machine credentials the usual way: AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY, a profile, or a role.
- 02Add a lifecycle rule on the prefix that expires objects after a day or two.
- 03Run
colis verifier. It performs the operations colis needs and reports what happened.
Worth knowing
Notes on S3.
Virtual-hosted addressing
Without an endpoint, colis leaves path-style addressing off, which is what S3 proper expects. Set forcePathStyle yourself only if a gateway in front demands it.
Large files
Large files go from the browser straight to the bucket, in parts. The bucket needs a CORS rule that allows PUT from your delivery page and exposes ETag; without it, small files still work.
Expiry cleanup
The expiry stops a parcel being handed over; only a lifecycle rule deletes the object. Give the prefix a rule that expires objects after a day or two, and colis verifier turns green.
Other providers
The endpoint is the only difference.
Send it. They sign off. You know.
Your storage, a delivery page under your name, a webhook at every step. Nothing hosted by someone else.