Theme
Storage backends
Every virtual file system points at exactly one of these.
Disk
A path on the machine the Connector runs on, or a network share it can reach.
| Field | Notes |
|---|---|
| Filesystem path | POSIX such as /srv/data, Windows such as C:\Data, or UNC such as \\server\share |
Things to check:
- The Connector's service account must be able to read and write that path. On Linux that is the service user; on Windows it is the service's logon account.
- A UNC path needs credentials the service account already holds. The Connector does not prompt for network share credentials.
- In Docker, the path must be inside the container, so mount it in first. See Run in Docker.
This is the only backend where a network hiccup between the Connector and the storage is invisible to you: a local disk either works or the machine has bigger problems.
S3
An Amazon S3 bucket, or any S3 compatible store such as MinIO, Wasabi or Cloudflare R2.
| Field | Notes |
|---|---|
| Bucket name | The bucket, without a scheme or a path |
| Path inside | Optional. Confines this virtual file system to a prefix within the bucket |
| Region | The bucket's region |
| Endpoint | Leave blank for Amazon S3. Set it for an S3 compatible store |
| Use path style addressing | Off for Amazon S3. On for most self hosted stores (MinIO, RustFS, Ceph, SeaweedFS, Garage): the bucket name goes in the request path. Off puts the bucket name in front of the endpoint host, which only works where a DNS name exists for every bucket |
| Skip TLS certificate verification | Off. Turn it on only against a test store with a self signed certificate: the traffic to the storage is then open to interception |
| Access key ID | |
| Access secret | Stored encrypted, never shown again |
| Upload concurrency, Download concurrency | Parts of one file transferred at the same time, 1 to 16. Blank means 3 |
Things to check:
- If the connection test says a host such as
mybucket.minio.example.comcould not be resolved, the store expects path style addressing: turn the toggle on. The Connector says so in the test result. - Give the access key only the permissions this virtual file system needs, scoped to this bucket and, if you set one, this prefix.
- S3 compatible stores differ from each other in real ways, not just in the endpoint. Test a listing, an upload, a download and a delete before you hand the storage to users.
- A bucket has no directories. The Connector presents prefixes as folders, which is what your users expect, but an empty folder is not a thing that exists in S3.
Azure
An Azure Blob Storage container.
| Field | Notes |
|---|---|
| Account name | The storage account |
| Container name | |
| Path inside | Optional prefix within the container |
| Endpoint | Optional. The blob service domain the account name is prefixed to. Blank means blob.core.windows.net; a sovereign cloud names its own, for example blob.core.usgovcloudapi.net |
| Skip TLS certificate verification | Off. As for S3 |
| Authentication method | Account key, or SAS token |
| Account key or SAS token | Stored encrypted, never shown again |
| Upload concurrency, Download concurrency | As for S3 |
A SAS token is the better choice when you can use one: it can be scoped to the container and given an expiry. Remember that it does expire, and that transfers stop when it does.
Google Cloud Storage
A GCS bucket.
| Field | Notes |
|---|---|
| Bucket name | |
| Path inside | Optional prefix within the bucket |
| Service account credentials (JSON) | Paste the service account key JSON. Stored encrypted, never shown again |
| Upload concurrency, Download concurrency | As for S3 |
Create a service account with access to that one bucket rather than reusing a broad one.
SFTP
Another SFTP server, which the Connector connects to as a client.
| Field | Notes |
|---|---|
| Host | |
| Port | 22 unless the remote server says otherwise |
| Username | |
| Remote path | The starting directory on the remote server. Blank means the server root |
| Host key fingerprint | Optional, and you should set it. SHA256:... as ssh-keygen -l prints it, or the MD5 colon hex form. The connection is refused if the server presents a different key |
| Password | |
| Private key | PEM content. An alternative or a complement to the password |
| Private key passphrase | Only if the private key is encrypted. Stored encrypted, never shown again |
| Max reconnect retries, Retry interval | How often an operation interrupted by a connection failure is retried, and the seconds between attempts. Blank means 3 and 1 |
Without a fingerprint the server is not verified
An empty Host key fingerprint makes the Connector trust whatever host key the server presents, so anyone who can answer at that address can impersonate it. On the server, ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub prints the value to paste.
At rest encryption is not available for this type
The remote server owns that storage, so the Connector cannot control how it is written to disk.
Use this for bridging an existing SFTP server into your namespace, not as a general storage layer. Every operation crosses two hops, and the remote server's own permissions apply on top of yours.
Choosing between them
| If your files are | Use |
|---|---|
| On the machine, or on a NAS it mounts | Disk |
| In an S3 bucket, or an S3 compatible store | S3 |
| In Azure Blob Storage | Azure |
| In Google Cloud Storage | Google Cloud Storage |
| On an SFTP server you are keeping | SFTP |
Put the Connector close to the storage in every case. The Connector to storage link carries every byte, and it is the one you control.
Credentials
Every secret on this page is encrypted at rest on the Connector, under a machine local key, and is never returned by any interface. Replacing a secret means typing the new one; there is no way to read the old one back.
Give each virtual file system its own credential, scoped to its own bucket, container or path. A credential shared across virtual file systems is a credential whose blast radius you cannot reason about.