Object Storage
Object storage is one of the most fundamental storage services in cloud computing. It stores data in a flat key-value structure, offering high availability, high scalability, and low cost. The AWS S3 protocol has become the de facto standard for object storage, and nearly all cloud providers (Alibaba Cloud OSS, Tencent Cloud COS, Huawei Cloud OBS) offer S3-compatible interfaces.
Object Storage Core Concepts
Section titled “Object Storage Core Concepts”| Concept | Description |
|---|---|
| Bucket | A container for objects with a globally unique name |
| Object | The basic unit of storage, containing data and metadata |
| Key | The unique identifier of an object within a bucket, similar to a file path |
| Region | The geographic region where the bucket is located |
| ACL | Access Control List |
| Presigned URL | A signed temporary access link |
Using the AWS CLI for Object Storage
Section titled “Using the AWS CLI for Object Storage”Installing the AWS CLI
Section titled “Installing the AWS CLI”# Method 1: Install via pipsudo dnf install -y python3 python3-pippip3 install --user awscli
# Method 2: Install via the official packagecurl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"sudo dnf install -y unzipunzip awscliv2.zipsudo ./aws/install
# Verify installationaws --versionConfiguring Credentials
Section titled “Configuring Credentials”# Interactive configurationaws configure# AWS Access Key ID: YOUR_ACCESS_KEY# AWS Secret Access Key: YOUR_SECRET_KEY# Default region name: ap-northeast-1# Default output format: json
# Configuration files are located atcat ~/.aws/credentialscat ~/.aws/config
# Use Named Profiles to manage multiple accountsaws configure --profile aliyun-ossFor S3-compatible services (such as Alibaba Cloud OSS), you need to specify the endpoint:
# Alibaba Cloud OSSaws configure set default.s3.endpoint_url https://oss-cn-hangzhou.aliyuncs.com
# Or specify it with each commandaws s3 ls --endpoint-url https://oss-cn-hangzhou.aliyuncs.comBucket Operations
Section titled “Bucket Operations”# Create a bucketaws s3 mb s3://my-backup-bucket
# List all bucketsaws s3 ls
# List bucket contentsaws s3 ls s3://my-backup-bucket/aws s3 ls s3://my-backup-bucket/logs/ --recursive
# View bucket size statisticsaws s3 ls s3://my-backup-bucket --recursive --summarize --human-readable
# Delete an empty bucketaws s3 rb s3://my-backup-bucket
# Delete a bucket and all its contentsaws s3 rb s3://my-backup-bucket --forceUploading and Downloading Files
Section titled “Uploading and Downloading Files”# Upload a single fileaws s3 cp /var/log/messages s3://my-backup-bucket/logs/messages
# Download a single fileaws s3 cp s3://my-backup-bucket/logs/messages /tmp/messages
# Upload an entire directoryaws s3 cp /var/www/html/ s3://my-backup-bucket/website/ --recursive
# Download an entire directoryaws s3 cp s3://my-backup-bucket/website/ /var/www/html/ --recursive
# Use exclude and include filtersaws s3 cp /var/log/ s3://my-backup-bucket/logs/ \ --recursive \ --exclude "*" \ --include "*.log"File Synchronization
Section titled “File Synchronization”s3 sync only transfers changed files, similar to rsync:
# Sync a local directory to S3aws s3 sync /var/www/html/ s3://my-backup-bucket/website/
# Sync from S3 to localaws s3 sync s3://my-backup-bucket/website/ /var/www/html/
# Sync and delete extra files at the destinationaws s3 sync /var/www/html/ s3://my-backup-bucket/website/ --delete
# Exclude specific filesaws s3 sync /data/ s3://my-backup-bucket/data/ \ --exclude "*.tmp" \ --exclude ".git/*"
# Dry run (no actual transfers)aws s3 sync /data/ s3://my-backup-bucket/data/ --dryrunOther Operations
Section titled “Other Operations”# Move a fileaws s3 mv s3://my-bucket/old-path/file.txt s3://my-bucket/new-path/file.txt
# Delete a fileaws s3 rm s3://my-backup-bucket/logs/old.log
# Delete recursivelyaws s3 rm s3://my-backup-bucket/logs/ --recursive
# Generate a presigned URL (valid for 3600 seconds)aws s3 presign s3://my-backup-bucket/files/report.pdf --expires-in 3600
# Set object ACLaws s3api put-object-acl \ --bucket my-backup-bucket \ --key public/image.png \ --acl public-readMinIO Self-Hosted Object Storage
Section titled “MinIO Self-Hosted Object Storage”MinIO is a high-performance S3-compatible object storage server, ideal for private cloud and on-premises environments.
Installing the MinIO Server
Section titled “Installing the MinIO Server”# Download the MinIO binarywget https://dl.min.io/server/minio/release/linux-amd64/miniochmod +x miniosudo mv minio /usr/local/bin/
# Create the data directorysudo mkdir -p /data/minio
# Create a MinIO system usersudo useradd -r -s /sbin/nologin minio-usersudo chown minio-user:minio-user /data/minioConfiguring MinIO Environment Variables
Section titled “Configuring MinIO Environment Variables”sudo cat > /etc/default/minio << 'EOF'# MinIO data directoryMINIO_VOLUMES="/data/minio"
# Admin credentialsMINIO_ROOT_USER=minioadminMINIO_ROOT_PASSWORD=ChangeThisStrongPassword123
# Listen addressMINIO_OPTS="--console-address :9001"EOFCreating a Systemd Service
Section titled “Creating a Systemd Service”sudo cat > /etc/systemd/system/minio.service << 'EOF'[Unit]Description=MinIO Object StorageDocumentation=https://min.io/minio/linux/index.htmlAfter=network-online.targetWants=network-online.target
[Service]User=minio-userGroup=minio-userEnvironmentFile=/etc/default/minioExecStart=/usr/local/bin/minio server $MINIO_VOLUMES $MINIO_OPTSRestart=alwaysRestartSec=10LimitNOFILE=65536
[Install]WantedBy=multi-user.targetEOF
# Start MinIOsudo systemctl daemon-reloadsudo systemctl enable --now minio
# Check statussudo systemctl status minioConfiguring the Firewall
Section titled “Configuring the Firewall”# Open the MinIO API port (9000) and console port (9001)sudo firewall-cmd --permanent --add-port=9000/tcpsudo firewall-cmd --permanent --add-port=9001/tcpsudo firewall-cmd --reloadMinIO console access URL: http://your-server-ip:9001
Installing the MinIO Client
Section titled “Installing the MinIO Client”# Download the mc clientwget https://dl.min.io/client/mc/release/linux-amd64/mcchmod +x mcsudo mv mc /usr/local/bin/
# Configure connection to local MinIOmc alias set local http://localhost:9000 minioadmin ChangeThisStrongPassword123
# You can also configure connections to other S3-compatible servicesmc alias set myaws https://s3.amazonaws.com YOUR_ACCESS_KEY YOUR_SECRET_KEYmc alias set aliyun https://oss-cn-hangzhou.aliyuncs.com YOUR_ACCESS_KEY YOUR_SECRET_KEY
# Verify connectionmc admin info localUsing the MinIO Client
Section titled “Using the MinIO Client”# Create bucketsmc mb local/my-bucketmc mb local/backups
# List bucketsmc ls local
# Upload filesmc cp /etc/hosts local/my-bucket/hostsmc cp --recursive /var/log/ local/backups/logs/
# Download filesmc cp local/my-bucket/hosts /tmp/hosts-backup
# Sync directoriesmc mirror /var/www/html/ local/my-bucket/website/
# Continuous watch and syncmc mirror --watch /var/www/html/ local/my-bucket/website/
# View object informationmc stat local/my-bucket/hosts
# Set bucket policymc anonymous set download local/my-bucket/public/
# Manage usersmc admin user add local newuser newpassword123mc admin policy attach local readwrite --user newuser
# View service informationmc admin info localMinIO Multi-Disk Deployment (Erasure Coding)
Section titled “MinIO Multi-Disk Deployment (Erasure Coding)”# In production, use multiple disks for erasure code protection# At least 4 disks are requiredsudo mkdir -p /data/minio-disk{1..4}sudo chown minio-user:minio-user /data/minio-disk{1..4}
# Modify environment variablessudo sed -i 's|MINIO_VOLUMES=.*|MINIO_VOLUMES="/data/minio-disk{1...4}"|' /etc/default/minio
# Restart the servicesudo systemctl restart miniorclone Multi-Cloud Storage Management
Section titled “rclone Multi-Cloud Storage Management”rclone is called “rsync for cloud storage” and supports over 70 storage backends.
Installing rclone
Section titled “Installing rclone”# Method 1: Official installation scriptcurl https://rclone.org/install.sh | sudo bash
# Method 2: Manual installationRCLONE_VERSION="1.67.0"wget https://downloads.rclone.org/v${RCLONE_VERSION}/rclone-v${RCLONE_VERSION}-linux-amd64.rpmsudo dnf install -y ./rclone-v${RCLONE_VERSION}-linux-amd64.rpm
# Verifyrclone versionConfiguring Storage Backends
Section titled “Configuring Storage Backends”# Interactive configurationrclone config
# Configuration file locationcat ~/.config/rclone/rclone.confYou can also edit the configuration file directly:
cat > ~/.config/rclone/rclone.conf << 'EOF'[aws-s3]type = s3provider = AWSaccess_key_id = YOUR_AWS_ACCESS_KEYsecret_access_key = YOUR_AWS_SECRET_KEYregion = ap-northeast-1
[aliyun-oss]type = s3provider = Alibabaaccess_key_id = YOUR_ALICLOUD_ACCESS_KEYsecret_access_key = YOUR_ALICLOUD_SECRET_KEYendpoint = oss-cn-hangzhou.aliyuncs.com
[tencent-cos]type = s3provider = TencentCOSaccess_key_id = YOUR_TENCENT_SECRET_IDsecret_access_key = YOUR_TENCENT_SECRET_KEYendpoint = cos.ap-guangzhou.myqcloud.com
[local-minio]type = s3provider = Minioaccess_key_id = minioadminsecret_access_key = ChangeThisStrongPassword123endpoint = http://localhost:9000EOFrclone Basic Operations
Section titled “rclone Basic Operations”# List all configured remotesrclone listremotes
# List bucketsrclone lsd aws-s3:
# List files in a bucketrclone ls aws-s3:my-bucket/rclone lsl aws-s3:my-bucket/ # Including time and size
# Copy a filerclone copy /var/log/messages aws-s3:my-bucket/logs/
# Copy a directoryrclone copy /var/www/html/ aws-s3:my-bucket/website/ --progress
# Sync (mirror, deletes extra files at destination)rclone sync /var/www/html/ aws-s3:my-bucket/website/ --progress
# Move filesrclone move /tmp/uploads/ aws-s3:my-bucket/uploads/
# Deleterclone delete aws-s3:my-bucket/old-logs/rclone purge aws-s3:my-bucket/temp-bucket/ # Delete path and all contentsCross-Cloud Transfers
Section titled “Cross-Cloud Transfers”# Copy from AWS S3 to Alibaba Cloud OSSrclone copy aws-s3:source-bucket/data/ aliyun-oss:dest-bucket/data/ --progress
# Sync from Alibaba Cloud OSS to local MinIOrclone sync aliyun-oss:my-bucket/ local-minio:backup-bucket/ --progress
# Compare differences between two remotesrclone check aws-s3:my-bucket/ aliyun-oss:my-bucket/rclone Advanced Features
Section titled “rclone Advanced Features”# Bandwidth limitingrclone copy /data/ aws-s3:my-bucket/ --bwlimit 10M
# Encrypted storage (create an encrypted remote)rclone config# Select the "crypt" type and specify the underlying remote
# Mount as a local filesystemsudo dnf install -y fuse3rclone mount aws-s3:my-bucket /mnt/s3 --daemon --allow-other --vfs-cache-mode full
# Run the mount as a servicecat > ~/.config/systemd/user/rclone-mount.service << 'UNIT'[Unit]Description=rclone S3 mountAfter=network-online.target
[Service]ExecStart=/usr/bin/rclone mount aws-s3:my-bucket /mnt/s3 --allow-other --vfs-cache-mode fullExecStop=/bin/fusermount -uz /mnt/s3Restart=on-failure
[Install]WantedBy=default.targetUNIT
systemctl --user enable --now rclone-mount
# View remote space usagerclone about aws-s3:Backing Up to Object Storage
Section titled “Backing Up to Object Storage”Database Backup Script
Section titled “Database Backup Script”#!/bin/bash# MySQL/MariaDB backup to object storage
set -euo pipefail
# ConfigurationBACKUP_DIR="/tmp/db-backup"BUCKET="s3://my-backup-bucket/database"DB_NAME="myapp"DATE=$(date +%Y%m%d-%H%M%S)RETENTION_DAYS=30
# Create temporary directorymkdir -p "${BACKUP_DIR}"
# Perform backupecho "[$(date)] Starting backup of database ${DB_NAME}..."mysqldump --single-transaction \ --routines \ --triggers \ --databases "${DB_NAME}" | \ gzip > "${BACKUP_DIR}/${DB_NAME}-${DATE}.sql.gz"
# Upload to object storageecho "[$(date)] Uploading backup to object storage..."aws s3 cp "${BACKUP_DIR}/${DB_NAME}-${DATE}.sql.gz" \ "${BUCKET}/${DB_NAME}-${DATE}.sql.gz"
# Clean up local temporary filesrm -f "${BACKUP_DIR}/${DB_NAME}-${DATE}.sql.gz"
# Clean up expired remote backupsecho "[$(date)] Cleaning up backups older than ${RETENTION_DAYS} days..."CUTOFF_DATE=$(date -d "-${RETENTION_DAYS} days" +%Y%m%d)aws s3 ls "${BUCKET}/" | while read -r line; do FILE_DATE=$(echo "$line" | grep -oP '\d{8}' | head -1) FILE_NAME=$(echo "$line" | awk '{print $NF}') if [[ -n "${FILE_DATE}" && "${FILE_DATE}" < "${CUTOFF_DATE}" ]]; then echo " Deleting expired backup: ${FILE_NAME}" aws s3 rm "${BUCKET}/${FILE_NAME}" fidone
echo "[$(date)] Backup complete"Incremental System File Backup
Section titled “Incremental System File Backup”#!/bin/bash# Incremental backup to object storage using rclone
set -euo pipefail
REMOTE="aliyun-oss"BUCKET="server-backups"HOSTNAME=$(hostname)LOG_FILE="/var/log/backup-files.log"
echo "[$(date)] Starting file backup..." >> "${LOG_FILE}"
# Sync configuration filesrclone sync /etc/ "${REMOTE}:${BUCKET}/${HOSTNAME}/etc/" \ --exclude "shadow" \ --exclude "gshadow" \ --log-file="${LOG_FILE}" \ --log-level INFO
# Sync website datarclone sync /var/www/ "${REMOTE}:${BUCKET}/${HOSTNAME}/www/" \ --log-file="${LOG_FILE}" \ --log-level INFO
# Sync user datarclone sync /home/ "${REMOTE}:${BUCKET}/${HOSTNAME}/home/" \ --exclude ".cache/**" \ --exclude ".local/share/Trash/**" \ --log-file="${LOG_FILE}" \ --log-level INFO
echo "[$(date)] Backup complete" >> "${LOG_FILE}"Setting Up Scheduled Backups
Section titled “Setting Up Scheduled Backups”# Set up daily database backupsudo chmod +x /usr/local/bin/backup-db.shsudo cat > /etc/cron.d/db-backup << 'EOF'# Run database backup daily at 2 AM0 2 * * * root /usr/local/bin/backup-db.sh >> /var/log/backup-db.log 2>&1EOF
# Set up daily incremental file backupsudo chmod +x /usr/local/bin/backup-files.shsudo cat > /etc/cron.d/file-backup << 'EOF'# Run file backup daily at 3 AM0 3 * * * root /usr/local/bin/backup-files.shEOFUsing Lifecycle Policies for Automatic Cleanup
Section titled “Using Lifecycle Policies for Automatic Cleanup”For AWS S3 or compatible services, you can configure lifecycle policies to automatically clean up old backups:
# Create a lifecycle rule configurationcat > /tmp/lifecycle.json << 'EOF'{ "Rules": [ { "ID": "DeleteOldBackups", "Status": "Enabled", "Filter": { "Prefix": "database/" }, "Expiration": { "Days": 30 } }, { "ID": "ArchiveOldFiles", "Status": "Enabled", "Filter": { "Prefix": "files/" }, "Transitions": [ { "Days": 90, "StorageClass": "GLACIER" } ], "Expiration": { "Days": 365 } } ]}EOF
# Apply the lifecycle policyaws s3api put-bucket-lifecycle-configuration \ --bucket my-backup-bucket \ --lifecycle-configuration file:///tmp/lifecycle.jsonObject storage is the foundational storage solution for the cloud era. Once you master the AWS CLI, MinIO, and rclone, you can flexibly manage data across public cloud, private cloud, and hybrid cloud environments, and build reliable backup strategies.