Fuse Over Amazon

Takeshi Nakatani edited this page Jul 8, 2018 · 31 revisions

FUSE-based file system backed by Amazon S3


s3fs-fuse is moved from s3fs on googlecode after v1.74. Please submit usage/support questions to the Issues area instead of as a comment to this Wiki page. Thanks!

What's New

  • v1.84 fixed many bugs etc.
  • v1.83 fixed many bugs etc.
  • v1.82 not fallback to http.
  • v1.81 fixed many bugs etc.
  • v1.80 fixed many bugs etc.
  • v1.79 fixed many bugs etc.
  • v1.78 supported for SSE-C, and fixed some bugs.
  • v1.77 fixed curl ssl problems etc.
  • v1.76 fixed some bugs
  • v1.75 fixed some bugs and for MacOSX build
  • v1.74 initial version in Github, same as in googlecodes v1.74

Older version is in GoogleCodes, please refer to it for the version before v1.74.


s3fs is a FUSE filesystem that allows you to mount an Amazon S3 bucket as a local filesystem. It stores files natively and transparently in S3 (i.e., you can use other programs to access the same files). The maximum size of objects that s3fs can handle depends on Amazon S3. For example, up to 5 GB when using single PUT API. And up to 5 TB is supported when Multipart Upload API is used.

s3fs is stable and is being used in number of production environments, e.g., rsync backup to s3.

Important Note:

Your kernel must support FUSE, kernels earlier than 2.6.18-164 may not have FUSE support (see issue #140). Virtual Private Servers (VPS) may not have FUSE support compiled into their kernels.

To use it:

  1. Get an Amazon S3 account! http://aws.amazon.com/s3/
  2. Download, compile and install, (see Installation Notes or the ReadMe Install Notes)
  3. Specify your Security Credentials (Access Key ID & Secret Access Key) by one of the following methods:
  • using the passwd_file command line option
  • setting the AWSACCESSKEYID and AWSSECRETACCESSKEY environment variables
  • using a .passwd-s3fs file in your home directory
  • using the system-wide /etc/passwd-s3fs file
  1. do this:
/usr/bin/s3fs mybucket /mnt

That's it! the contents of your amazon bucket "mybucket" should now be accessible read/write in /mnt.

The s3fs password file has this format (use this format if you have only one set of credentials):


If have more than one set of credentials, then you can have default credentials as specified above, but this syntax will be recognized as well:


If you want to use IAM account, you can get AccessKey/secretAccessKey pair on AWS S3 console.


The credentials files may not have lax permissions as this creates a security hole. ~/.passwd-s3fs may not have others/group permissions and /etc/passwd-s3fs may not have others permissions. Set permissions on these files accordingly:

% chmod 600 ~/.passwd-s3fs
% sudo chmod 640 /etc/passwd-s3fs

s3fs supports mode (e.g., chmod), mtime (e.g, touch) and uid/gid (chown). s3fs stores the values in x-amz-meta custom meta headers, and uses x-amz-copy-source to efficiently change them.

s3fs has a caching mechanism: You can enable local file caching to minimize downloads, e.g., :

/usr/bin/s3fs mybucket /mnt -ouse_cache=/tmp

Hosting a cvsroot on s3 works! Although you probably don't really want to do it in practice. E.g., cvs -d /s3/cvsroot init. Incredibly, mysqld also works, although I doubt you really wanna do that in practice! =)

s3fs works with rsync! (as of svn 43) as of r152 s3fs uses x-amz-copy-source for efficient update of mode, mtime and uid/gid.

s3fs will retry s3 transactions on certain error conditions. The default retry count is 2, i.e., s3fs will make 2 retries per s3 transaction (for a total of 3 attempts: 1st attempt + 2 retries) before giving up. You can set the retry count by using the "retries" option, e.g., "-oretries=2".


default_acl (default="private")

  • the default canned acl to apply to all written s3 objects, e.g., "private", "public-read".
    empty string means do not send header.
  • see http://aws.amazon.com/documentation/s3/ for the full list of canned acls.

prefix (default="") (coming soon!)

  • a prefix to append to all s3 objects
  • For now, you can specify via s3fs mybucket:/path/prefix/

retries (default="5")

  • number of times to retry a failed s3 transaction

use_cache (default="" which means disabled)

  • local folder to use for local file cache

use_rrs (default="" which means diabled)

  • use Amazon's Reduced Redundancy Storage

use_sse (default is disable)

  • not specify use_sse option
    default is SSE-DISABLE
  • "use_sse" or "use_sse=1"(old type parameter)
    uses Amazon S3-managed encryption keys
  • "use_sse=custom:'filepath'" or "use_sse='filepath'"(old type parameter)
    uses customer-provided encryption keys.
    The custom key file must be 600 permission.
    The file can have some lines, each line is one SSE-C key.
    The first line in file is used as Customer-Provided Encryption Keys for uploading and changing headers etc.
    If there are some keys after first line, those are used downloading object which are encrypted by not first key.
    So that, you can keep all SSE-C keys in file, that is SSE-C key history.
  • "use_sse=custom"
    If you specify "custom"("c") without file path, you need to set custom key by load_sse_c option or AWSSSECKEYS environment.
    (AWSSSECKEYS environment has some SSE-C keys with ":" separator.)
    This option is used to decide the SSE type.
    So that if you do not want to encrypt a object object at uploading, but you need to decrypt encrypted object at downloaing, you can use load_sse_c option instead of this option.
  • "use_sse=kmsid" or "use_sse=kmsid:'kms id'"
    uses the master key which you manage in AWS KMS.
    You can use "k" for short "kmsid".
    If you san specify SSE-KMS type with your 'kms id' in AWS KMS, you can set it after "kmsid:"(or "k:").
    If you specify only "kmsid"("k"), you need to set AWSSSEKMSID environment which value is 'kms id'.
  • notice
    You must be careful about that you can not use the KMS id which is not same EC2 region.

load_sse_c - specify SSE-C keys

  • Specify the custom-provided encription keys file path for decrypting at duwnloading.
    If you use the custom-provided encription key at uploading, you specify with "use_sse=custom".
    The file has many lines, one line means one custom key.
    So that you can keep all SSE-C keys in file, that is SSE-C key history.
    AWSSSECKEYS environment is as same as this file contents.

passwd_file (default="")

  • specify the path to the password file, over-rides looking for the password in in $HOME/.passwd-s3fs and /etc/passwd-s3fs

ahbe_conf (default="" which means disabled)

  • This option specifies the configuration file path which file is the additional HTTP header by file(object) extension.

public_bucket (default="" which means disabled)

  • anonymously mount a public bucket when set to 1, ignores the $HOME/.passwd-s3fs and /etc/passwd-s3fs files.
    S3 does not allow copy object api for anonymous users, then s3fs sets nocopyapi option automatically when public_bucket=1 option is specified.

connect_timeout (default="10" seconds)

  • time to wait for connection before giving up

readwrite_timeout (default="30" seconds)

  • time to wait between read/write activity before giving up

list_object_max_keys (default="1000")

  • specify the maximum number of keys returned by S3 list object API. The default is 1000. you can set this value to 1000 or more.

max_stat_cache_size (default="100,000" entries (about 40MB))

  • maximum number of entries in the stat cache

url (default="https://s3.amazonaws.com")

  • sets the url to use to access Amazon S3. If you want to use HTTP, then you can set "url=http://s3.amazonaws.com".
    If you do not use https, please specify the URL with the url option.

stat_cache_expire (default is no expire)

  • specify expire time(seconds) for entries in the stat cache.

enable_noobj_cache (default is disable)

  • enable cache entries for the object which does not exist.


  • s3fs is always using dns cache, this option make dns cache disable.


  • disable multipart uploads.

multireq_max (default="500")

  • maximum number of parallel request for listing objects.

parallel_count (default="5")

  • number of parallel request for downloading/uploading large objects. s3fs uploads large object(over 20MB) by multipart post request, and sends parallel requests. This option limits parallel request count which s3fs requests at once.

enable_content_md5 (default is disable)

  • verifying uploaded data without multipart by content-md5 header.


ecs ( default is disable )

This option instructs s3fs to query the ECS container credential metadata address instead of the instance metadata address.

iam_role ( default is no role )

  • set the IAM Role that will supply the credentials from the instance meta-data. specify only IAM role name.

ibm_iam_auth ( default is not using IBM IAM authentication )

This option instructs s3fs to use IBM IAM authentication. In this mode, the AWSAccessKey and AWSSecretKey will be used as IBM's Service-Instance-ID and APIKey, respectively.


  • for a distributed object storage which is compatibility S3 API without PUT(copy api). If you set this option, s3fs do not use PUT with "x-amz-copy-source"(copy api).


  • for a distributed object storage which is compatibility S3 API without PUT(copy api). This option is a subset of nocopyapi option.


  • Enable compatibility with S3-like APIs which do not support the virtual-host request style, by using the older path request style.


  • Customize the list of TLS cipher suites
    Expects a colon separated list of cipher suite names.
    A list of available cipher suites, depending on your TLS engine, can be found on the CURL library documentation:


  • complement lack of file/directory mode
    s3fs complements lack of information about file/directory mode if a file or a directory object does not have x-amz-meta-mode header.
    As default, s3fs does not complements stat information for a object, then the object will not be able to be allowed to list/modify.


  • not support compatibility directory types
    As a default, s3fs supports objects of the directory type as much as possible and recognizes them as directories.
    Objects that can be recognized as directory objects are "dir/", "dir", "dir_$folder$", and there is a file object that does not have a directory object but contains that directory path.
    s3fs needs redundant communication to support all these directory types.
    The object as the directory created by s3fs is "dir/".
    By restricting s3fs to recognize only "dir/" as a directory, communication traffic can be reduced.
    This option is used to give this restriction to s3fs.
    However, if there is a directory object other than "dir/" in the bucket, specifying this option is not recommended.
    s3fs may not be able to recognize the object correctly if an object created by s3fs exists in the bucket.
    Please use it when the directory in the bucket is only "dir/" object.


  • create new bucket at starting to run s3fs
    Attempts to create a new bucket immediately after starting s3fs. If new creation is impossible, s3fs ends with error. If you can create a bucket, mount the created bucket and start s3fs normally.
    This option can not be described in fstab. If you specify this option in fstab, the mount fails because s3fs tries to create a bucket each time at mounting. Please use this when starting s3fs on the command line.

dbglevel ( default="crit" )

  • Set the debug message level. set value as crit(critical), err(error), warn(warning), info(information), dbg(debug) to debug level. default debug level is critical. If s3fs run with "-d" option, the debug level is set information. When s3fs catch the signal SIGUSR2, the debug level is bumpup.


  • Put the debug message from libcurl when this option is specified.


If enabled via "use_cache" option, s3fs automatically maintains a local cache of files in the folder specified by use_cache. Whenever s3fs needs to read or write a file on s3 it first downloads the entire file locally to the folder specified by use_cache and operates on it. When fuse release() is called, s3fs will re-upload the file to s3 if it has been changed. s3fs uses md5 checksums to minimize downloads from s3. Note: this is different from the stat cache (see below).

Local file caching works by calculating and comparing md5 checksums (ETag HTTP header).

The folder specified by use_cache is just a local cache. It can be deleted at any time. s3fs re-builds it on demand. Note: this directory grows unbounded and can fill up a file system dependent upon the bucket and reads to that bucket. Take precaution by using a quota system or routinely clearing the cache (or some other method).

s3fs supports chmod (mode) and touch (mtime) by virtue of "x-amz-meta-mode" and "x-amz-meta-mtime" custom meta headers. as of r149 s3fs uses x-amz-copy-source, this means that s3fs no longer needs to operate in a brute-force manner; much faster now (one minor performance-related corner case left to solve... /usr/bin/touch)

The stat cache stores file information in memory and can improve performance. It's default setting is to store 10,000 entries which can account for about 4 MB of memory usage. When the stat cache fills up, entries with a low hit count are deleted first. The size of the stat cache is controllable with an option.

s3fs uses /etc/mime.types to "guess" the "correct" content-type based on file name extension. This means that you can copy a website to s3 and serve it up directly from s3 with correct content-types. Uknown file types are assigned "application/octet-stream".

Important Limitations

Eventual Consistency

Due to S3's "eventual consistency" limitations file creation can and will occasionally fail. Even after a successful create subsequent reads can fail for an indeterminate time, even after one or more successful reads. Create and read enough files and you will eventually encounter this failure. This is not a flaw in s3fs and it is not something a FUSE wrapper like s3fs can work around. The retries option does not address this issue. Your application must either tolerate or compensate for these failures, for example by retrying creates or reads. For more details, see Eventual Consistency

libcurl version

s3fs runs with libcurl, then if you use libcurl with libnss, s3fs requires libcurl after version 7.21.5. If you use lbcurl(with libnss) under version 7.21.5, s3fs leaks memory. You don't mind about libcurl version when libcurl linked OpenSSL library instead of libnss.

Release Notes

Older changes list is in GoogleCodes, please refer to it for the version before r501.



  • server side copies are not possible - due to how FUSE orchestrates the low level instructions, the file must first be downloaded to the client and then uploaded to the new location


  • permissions: using -o allow_other, even though files are owned by root 0755, another use can make changes
  • use default_permissions option?!?
  • better error logging for troubleshooting.
  • need to parse response on, say, 403 and 404 errors, etc... and log 'em!

See Also

Here is a list of other Amazon S3 filesystems:

Other tools that combine with s3fs in useful ways:

  • S3Proxy - allows applications using the S3 API to access other object stores, e.g., EMC Atmos, Microsoft Azure, OpenStack Swift
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.
Press h to open a hovercard with more details.