Private Endpoint for Object Storage
Private Endpoint for Object Storage
Access your OVHcloud Object Storage buckets privately, directly from your Private Network, keeping your data within your vRack Private Network at all times.
Why Private Endpoint?
Customers running workloads on OVHcloud Public Cloud Private Network currently have no native way to reach Object Storage from their Private Network. Private Endpoint will close this gap providing a dedicated, isolated network path between your workloads and your buckets.
Private Endpoint key benefits

Traffic isolation
All S3 traffic stays on the OVHcloud backbone. Data transits through your vRack Private Network interface.

Sized to your workload
Available in multiple bandwidth tiers to match your workload: from development and testing to production pipelines.

Simple, declarative API
One API call describes the endpoint you want. It handles VIP allocation, DNS, and routing for you: no manual plumbing.

Granular access control
Restrict a user to a specific Private Endpoint, not just an IP range.
How it works?
Your workload sits inside a subnet on your Private Network, just like today.
A Private Endpoint is created in that subnet and acts as the private doorway to Object Storage. Your ressource then talks to it directly, and it forwards traffic to Object Storage over OVHcloud's own infrastructure.
From your side, nothing changes about how you use Object Storage: same client, same credentials. You simply point it at the Private Endpoint instead of the public Object Storage endpoint.
Alpha Program
- Availability: access granted on request - Spots are very limited during this phase, more to come during upcoming Beta phase
- Regions: GRA and EU-WEST-PAR
- Associated service: S3-compatible Object Storage only
- Bandwidth tiers: up to 4Gbps at first
- Pricing: Free during alpha and beta
-
Alpha
-
Beta
-
General Availability
FAQ
How do I join the alpha?
Request access via the survey button above. Spots are very limited during this phase. We're working closely with a small number of participants to validate the feature before opening it up further. If you're not selected this round, the following phase of public Beta will offer larger-scale availability!
Which regions are supported?
GRA and EU-WEST-PAR only during the alpha. Other regions will follow in Beta and GA.
Can I manage Private Endpoint from the Console?
Not yet, the beginning of the Alpha is API-only. Control Panel support is planned and will be added soon.
How do I make sure only traffic through my Private Endpoint can reach my bucket?
Attach a user policy with a SourceVpce condition scoped to your endpoint's ID. The getting started guide shared with alpha testers will provide examples.
Can I reach a Private Endpoint from Bare Metal or another Private Network subnet?
Yes, through routing. You can either create one endpoint per subnet, or route to a single endpoint from other subnets/environments via a router.
What happens after the alpha?
We're gathering feedback to shape the beta, expected in approximately one month, followed by broader regional and service coverage toward GA.
Do the General Public Cloud Terms & Conditions (T&Cs) apply during the alpha program?
No, the General Public Cloud T&Cs do not apply during the alpha program.