Private Endpoint for Object Storage


New

Private Endpoint for Object Storage

Access your OVHcloud Object Storage buckets privately, directly from your Private Network, keeping your data within your vRack Private Network at all times.

BGP

Why Private Endpoint?

Customers running workloads on OVHcloud Public Cloud Private Network currently have no native way to reach Object Storage from their Private Network. Private Endpoint will close this gap providing a dedicated, isolated network path between your workloads and your buckets.

Private Endpoint key benefits

connectivity2x

Traffic isolation

All S3 traffic stays on the OVHcloud backbone. Data transits through your vRack Private Network interface.

scaleup

Sized to your workload

Available in multiple bandwidth tiers to match your workload: from development and testing to production pipelines.

simple

Simple, declarative API

One API call describes the endpoint you want. It handles VIP allocation, DNS, and routing for you: no manual plumbing.

People Admin Icon

Granular access control

Restrict a user to a specific Private Endpoint, not just an IP range.

 

How it works?

Your workload sits inside a subnet on your Private Network, just like today.

A Private Endpoint is created in that subnet and acts as the private doorway to Object Storage. Your ressource then talks to it directly, and it forwards traffic to Object Storage over OVHcloud's own infrastructure.

From your side, nothing changes about how you use Object Storage: same client, same credentials. You simply point it at the Private Endpoint instead of the public Object Storage endpoint.

Private Endpoint Example

Alpha Program

  • Availability: access granted on request - Spots are very limited during this phase, more to come during upcoming Beta phase
  • Regions: GRA and EU-WEST-PAR
  • Associated service: S3-compatible Object Storage only
  • Bandwidth tiers: up to 4Gbps at first 
  • Pricing: Free during alpha and beta

 

 

  • Alpha
  • Beta
  • General Availability

FAQ

How do I join the alpha?

Request access via the survey button above. Spots are very limited during this phase. We're working closely with a small number of participants to validate the feature before opening it up further. If you're not selected this round, the following phase of public Beta will offer larger-scale availability!

Which regions are supported?

GRA and EU-WEST-PAR only during the alpha. Other regions will follow in Beta and GA.

Can I manage Private Endpoint from the Console?

Not yet, the beginning of the Alpha is API-only. Control Panel support is planned and will be added soon.

How do I make sure only traffic through my Private Endpoint can reach my bucket?

Attach a user policy with a SourceVpce condition scoped to your endpoint's ID. The getting started guide shared with alpha testers will provide examples.

Can I reach a Private Endpoint from Bare Metal or another Private Network subnet?

Yes, through routing. You can either create one endpoint per subnet, or route to a single endpoint from other subnets/environments via a router.

What happens after the alpha?

We're gathering feedback to shape the beta, expected in approximately one month, followed by broader regional and service coverage toward GA.

Do the General Public Cloud Terms & Conditions (T&Cs) apply during the alpha program?

No, the General Public Cloud T&Cs do not apply during the alpha program.