Skip to main content

Connect S3 to other products

For your information

You can connect S3 to other products over a private network only in specific pools: in the ru-3 and ru-7 pools, you can connect to servers in Russia; in the uz-2 pool, you can connect to servers in Uzbekistan.

To connect S3 to other products via a private network, a global router is used.

  1. If you don't have a global router yet, create a router.
  2. Connect the subnet of another product to the global router.
  3. Create an interconnect subnet to connect S3 to the global router.
  4. Configure a static route to S3 on servers in another product.
  5. Configure access to the private S3 endpoint on servers in another product.

1. Create a Global Router

  1. In the Control panel, in the top menu, click Products and select Global Router.
  2. Click Create router. A limit of five global routers is set for each account.
  3. Enter the router name.
  4. Click Create.
  5. If the router was created with the status ERROR or is stuck in one of the statuses, submit a ticket.

2. Connect the other product's subnet to the Global Router

You can connect a new network to the router or an existing network if it is not already connected to any of the account's global routers.

  1. In the control panel, on the top menu, click Products and select Global Router.

  2. Open the router page → Networks tab.

  3. Click Create network.

  4. Enter a network name. It will only be used in the control panel.

  5. Select the Servers and Equipment service.

  6. Select a location for the network.

  7. Select or enter a VLAN.

  8. If you want to create a network to an internal segment (Q-in-Q), specify its tag — a number from 2 to 4094. If a network already exists for the VLAN, you must specify the Q-in-Q segment of this VLAN.

  9. Enter a subnet name. It will only be used in the control panel.

  10. Enter the CIDR — the IP address and mask of the private subnet. You can enter a new subnet or an existing private server subnet if it has not yet been added to any of the global routers in the account. The subnet must meet the following conditions:

    • belong to the RFC 1918 private address range: 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16;
    • have a size of at least /29, as three addresses will be occupied by Servercore network equipment;
    • do not overlap with other subnets added to this router — there must be no identical IP addresses within subnets on the same router;
    • if a Managed Kubernetes cluster on cloud servers is to be connected to the global router network, the subnet must not overlap with the ranges 10.10.0.0/16, 10.96.0.0/12, 10.250.0.0/16 and 10.251.0.0/24. If a cluster on dedicated servers is to be connected to the network — with the ranges 10.10.0.0/16, 10.222.0.0/16, 10.250.0.0/16, 10.251.0.0/24 and 172.250.0.0/14. These subnets are used for internal Managed Kubernetes addressing; using them may lead to network conflicts in the global router.
  11. Enter the gateway IP or leave the first address from the subnet, which is assigned by default. Do not assign this address to your devices to avoid network disruption.

  12. Enter the service IPs or leave the last addresses from the subnet, which are assigned by default. Do not assign these addresses to your devices to avoid network disruption.

  13. Click Create network.

  14. Optional: check the network topology on the global router. In the control panel, on the top menu, click Products → Global Router → router page → Network map.

  15. If you specified a Q-in-Q tag in step 8, you must enable Q-in-Q technology on the switch port and configure the network interface for the private network you specified in step 10. For more information, see the Configure Q-in-Q subsection of the Q-in-Q guide.

3. Create an interconnect subnet and endpoint to connect S3 to the global router

  1. Create a ticket. In the ticket, specify:

    • Global Router ID; you can find it in the Control Panel: in the top menu, click Products → Servercore Global Router → router page → copy the ID under the router name;
    • the desired CIDR for a subnet of at least /28, which will be used as the connection subnet from the Global Router to S3. The subnet must belong to the private address range per RFC 1918: 10.0.0.0/8, 172.16.0.0/12`` or 192.168.0.0/16. The subnet must not overlap with other subnets added to this router—subnets on the same router must not contain duplicate IP addresses;
    • an endpoint is a single private IP address to which traffic to S3 will be sent. This IP address must not be part of the selected interconnect subnet.
  2. Wait for a response from a Servercore specialist confirming that connectivity between S3 and the global router has been set up. The created interconnect subnet will not be displayed in the global router in the Control Panel. If you need to change the addressing of the subnet or S3 endpoint, submit a ticket.

4. Add static routes to S3

On each server you connect to S3, you need to configure a static route to the S3 endpoint via the global router.

If you are using the Global Router as the default gateway on your servers, you do not need to add routes.

  1. Connect to the server.

  2. Open the network configuration file:

    vi /etc/netplan/01-netcfg.yaml
  3. At the end of the block for the required network interface, add a route:

    routes:
    - to: <endpoint_ip_address>/32
    via: <gateway>

    Specify:

  4. Save the file.

  5. Check the settings:

    sudo netplan try
  6. Apply the changes:

    netplan apply

5. Configure access to the private S3 endpoint on servers in another product

By default, requests to S3 are sent via a public domain. If a request arrives at a private IP address, the response will return a certificate mismatch error.

To avoid the error, map the endpoint that you specified in the ticket when creating a private network and endpoint in step 3 to the S3 API domain in the desired pool (ru-3, ru-7, or uz-2).

The configuration depends on whether you have your own DNS recursor in your infrastructure.

Add A records on the recursor:

storage.selcloud.ru. IN A <endpoint_ip_address>
<s3_domain>. IN A <endpoint_ip_address>

Specify: