Skip to content

← Documentation

Storage guide

Arkame backups go to a bucket of yours, at the provider you choose — the data never passes through us. This guide takes you from a new account at the provider to a key ready for Arkame, in about 15 minutes.

What every bucket needs

At any provider, three things:

  • Private. No public access to the bucket.
  • Versioning and Object Lock, with a default retention in Compliance mode (30 days is a good start). It's what lets you go back in time and what stops anyone holding the key from deleting or overwriting the backups — ransomware included.
  • A key just for Arkame, with access to that bucket only. You don't type it in the panel: the agent installer asks for it on the server itself, and it stays there.

Not sure which to pick? Compare the costs. For most people, Backblaze B2 is the cheapest option with Object Lock and no minimum charge per file.

Backblaze B2 (recommended)

No minimum charge per file, and Object Lock. Steps:

  1. Create the account. At sign-up you pick the data region (US West, US East, EU Central or Canada East) — it applies to the whole account and can't be changed later.
  2. Create the bucket as private and turn on Object Lock. Note the Endpoint shown on the bucket, like s3.us-west-004.backblazeb2.com.
  3. Set the bucket's default Object Lock retention to Compliance mode, for example 30 days. Backblaze keeps all file versions by default.
  4. Create an application key (Application Keys → Add a New Application Key): under Allow Access to Bucket(s), choose only your bucket; under Type of Access, Read and Write. The keyID is the access key and the applicationKey is the secret — it's shown only once, save it right away.

In Arkame (Storage → New storage), fill in:

Provider
Backblaze B2
Bucket name
the name you gave it
Endpoint
https://s3.us-west-004.backblazeb2.com
Region
can be left blank — Arkame reads it from the endpoint

Use a key restricted to the bucket, never the account's master application key.

Wasabi

No egress fees, with Object Lock. Steps:

  1. Create the account.
  2. Create the bucket with a name and region. Under Properties, turn on Bucket Versioning and Object Lock. At Wasabi, Object Lock can only be turned on when creating the bucket.
  3. In the bucket settings, set the default Object Lock retention to Compliance mode, for example 30 days.
  4. Create a user just for Arkame and a policy that limits it to the bucket — Wasabi accepts the same access policy below. Generate that user's access key and save the secret key, which is shown only once.

In Arkame (Storage → New storage), fill in:

Provider
Wasabi
Bucket name
the name you gave it
Endpoint
https://s3.us-east-1.wasabisys.com
Region
can be left blank — Arkame reads it from the endpoint

Wasabi charges each file for at least 90 days, even if it's deleted earlier. The endpoint depends on the region (s3.us-east-1.wasabisys.com, s3.eu-central-1.wasabisys.com…); Wasabi has no South America region.

AWS S3

Regions everywhere and the AWS ecosystem; pricier storage and egress. Steps:

  1. Create the AWS account.
  2. Create the bucket: pick the region (São Paulo is sa-east-1), keep Block all public access on, enable Bucket Versioning and, in the advanced settings, enable Object Lock.
  3. On the bucket, under Properties → Object Lock, turn on the default retention in Compliance mode, for example 30 days.
  4. Create an IAM user just for Arkame, without console access, and attach the access policy below.
  5. On that user, create an access key (Security credentials → Create access key). Save the Access key ID and the Secret access key — the secret is shown only once.

In Arkame (Storage → New storage), fill in:

Provider
AWS S3
Bucket name
the name you gave it
Region
sa-east-1
Endpoint
not needed

On AWS, Arkame needs only the region, not an endpoint. Restoring downloads data from the bucket, and AWS charges for egress.

Access policy (AWS and Wasabi)

Replace YOUR-BUCKET with your bucket name. It gives the key only what the agent uses: list the bucket and its versions, read the versioning, Object Lock and lifecycle settings, read and write files, delete old versions and request rehydration of cold-storage files. It can't create or delete buckets, or change settings.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket",
        "s3:ListBucketVersions",
        "s3:ListBucketMultipartUploads",
        "s3:GetBucketLocation",
        "s3:GetBucketVersioning",
        "s3:GetBucketObjectLockConfiguration",
        "s3:GetLifecycleConfiguration"
      ],
      "Resource": "arn:aws:s3:::YOUR-BUCKET"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:GetObjectVersion",
        "s3:PutObject",
        "s3:DeleteObjectVersion",
        "s3:RestoreObject",
        "s3:AbortMultipartUpload",
        "s3:ListMultipartUploadParts"
      ],
      "Resource": "arn:aws:s3:::YOUR-BUCKET/*"
    }
  ]
}

s3:DeleteObjectVersion is what Arkame's retention cleanup uses to delete old versions — and only in a bucket without Object Lock. With Object Lock, Arkame deletes nothing, and old versions expire through a lifecycle rule on the bucket, after each one's deadline; then the permission can be removed from the key.

Other providers

Oracle Cloud (OCI), Google Cloud Storage and MinIO also work through the S3 API, but versioning and retention work differently there — see the notes in Documentation → storage. Cloudflare R2 isn't accepted for new storage: it has no versioning through the S3 API.

Bucket ready?

In the panel, under Storage → New storage, fill in your provider's fields. The key is asked for later, by the installer, on the server itself — it never passes through Arkame.

Add the storage →
Storage guide · Arkame