S3-Compatible Gateway

One API.
Every backend.

Warp Storage Engine speaks the S3 protocol and stores wherever you want — AWS S3, Azure Blob, or plain disk. Point your S3 clients at it. Done.

Get started → Quick start
docker run
$ docker run -p 8080:8080 \
  -e STORAGE_PROVIDER=s3 \\\ # s3 | azure | local
  -e S3_ENDPOINT=https://s3.amazonaws.com \
  -e AUTH_TYPE=awsv4 \
  -e AUTH_IDENTITY=proxy-key \
  -e AUTH_CREDENTIAL=proxy-secret
 
$ aws s3 ls --endpoint-url http://localhost:8080
10-40x
Faster with caching layer
<10ms
Request latency
3
Storage backends
~0
Client changes needed
Core capabilities

The S3 API your clients expect.
Backends you actually have.

Full object-store semantics over any provider — buckets, multipart uploads, pre-signed URLs, range requests — with auth, caching and observability built in.

Compatibility

S3 API Complete

Bucket and object operations, multipart uploads, metadata and ACLs, range requests, and pre-signed URLs — verified against standard S3 clients.

Performance

Intelligent Caching

Metadata and small-object caching layer delivering a 10–40x boost on hot paths, plus zero-copy streaming and connection pooling with HTTP/2.

Auth

SigV2 / SigV4

AWS Signature V2 and V4 with fast-path validation and built-in signature caching. Basic auth and anonymous access modes also available.

Access

Per-Bucket ACLs

Fine-grained access control per bucket and key prefix. TLS termination support for secure deployments out of the box.

Resilience

Backpressure Built In

Rate limiting, backpressure handling, graceful shutdown, and health check endpoints. Built for traffic, not just demos.

Operations

Prometheus Native

Prometheus metrics, structured logging with configurable levels, and health probes — drop it into Kubernetes and scrape away.

Storage backends

Swap storage, not code.

One environment variable switches the provider. Your clients never notice.

01 STORAGE_PROVIDER=s3 AWS S3
02 MinIO · Ceph · S3-compatible compatible
03 STORAGE_PROVIDER=azure Azure Blob
04 SAS token support azure
05 STORAGE_PROVIDER=local filesystem
06 Zero-copy streaming, any backend fast path

Azure without rewriting clients.

Point any AWS SDK, CLI, or S3 tool at Warp and back it with Azure Blob Storage — account key or SAS token auth, containers mapped to buckets.

Local disk for dev, S3 for prod.

Same API in every environment. Develop against the filesystem backend, ship against S3 or Azure — the endpoint contract doesn't change.

Tuned for the platform.

Linux TCP stack optimizations, configurable worker pools, and concurrent operation handling squeeze the most out of the host.

  • Multipart upload
  • Pre-signed URLs
  • Range requests
  • HTTP/2 pooling
  • SigV4 fast path
  • TLS/SSL
Workflow

Up in four steps.

From container pull to first object stored.

Run the gateway

Pull the image from GHCR and run it with your provider config — S3, Azure, or local. One port, one process.

Point auth at it

Set AUTH_TYPE to SigV4 or basic. Clients keep their existing access/secret keys — Warp validates them.

Use any S3 client

AWS CLI, SDKs, rclone, MinIO client — override the endpoint URL and operate normally, including multipart and presigned URLs.

Ship to production

Deploy via Docker Compose or the Helm chart. Enable TLS, wire Prometheus metrics, set rate limits — done.

Ready to serve?

One binary. Every backend. S3 all the way down.

View on GitHub → Read the docs