# Conectar armazenamento em nuvem Conecte AWS S3, Microsoft Azure, Google Cloud Storage, Alibaba Cloud OSS ou Tencent Cloud COS para distribuir mídia criptografada. This setup guide is currently available in English. ## 1. Choose your storage[#](#create-bucket) Use managed **1AICLOUD**, or connect **AWS S3, Microsoft Azure Blob Storage, Google Cloud Storage, Alibaba Cloud OSS, or Tencent Cloud COS**. Create a dedicated bucket or container for encrypted media and intended public assets. Keep original videos and private documents in separate storage. These connectors require verification with your own account, permissions, region and delivery settings before production use. A successful connection check verifies listing only; complete the upload and playback checks below. | Provider | Connection fields | Access method | | --- | --- | --- | | AWS S3 | Bucket, region, Access key ID, Secret access key | Amazon S3 API. See the [illustrated S3 and CloudFront guide](https://docs.drm-x.com/storage/amazon-s3). | | Microsoft Azure Blob Storage | Container, storage account name, storage account key | Native Blob API with short-lived, HTTPS, single-blob upload SAS. Public Azure cloud only. | | Google Cloud Storage | Bucket, service account HMAC access ID and HMAC secret | XML API at `https://storage.googleapis.com`. A service account JSON key is not an HMAC credential. | | Alibaba Cloud OSS | Bucket, region such as `cn-hangzhou`, RAM AccessKey ID and AccessKey secret | S3-compatible API at `https://oss-cn-hangzhou.aliyuncs.com`. Alibaba Cloud may need to enable S3-compatible authentication for your account. | | Tencent Cloud COS | Full bucket name including APPID, region such as `ap-guangzhou`, CAM SecretId and SecretKey | S3-compatible API at `https://cos.ap-guangzhou.myqcloud.com`. | DRM-X derives the new providers' API endpoints from the account or region. Your cloud provider bills storage, requests, delivery and any applicable bandwidth separately. Compare your actual usage and provider pricing with the available 1AICLOUD plans. ## 2. Configure credentials[#](#create-credentials) Grant only the list, read, write, copy and delete permissions needed for your delivery bucket. Google uses service-account HMAC credentials from Cloud Storage Settings → Interoperability. Alibaba uses RAM credentials; Tencent uses CAM credentials. Store credentials only in Console → Cloud Storage → Connect storage. DRM-X encrypts saved credentials and does not return the secret after saving. Leave both credential fields blank when editing to retain them; supply both to rotate them. For Azure, use a dedicated storage account with Shared Key access enabled. An account key can access the whole storage account, so isolate delivery data from private data. Microsoft Entra authentication, user-delegation SAS and sovereign-cloud endpoints are not included in this connector. ## 3. Configure public HTTPS delivery[#](#public-delivery) Choose a public delivery URL or CDN origin for encrypted media. For AWS, use a private S3 bucket with CloudFront Origin Access Control. For Azure, use your configured HTTPS CDN or a container with intentional public blob access. A direct Blob URL includes both the account and container, such as `https://ACCOUNT.blob.core.windows.net/CONTAINER/protected`. For Google, Alibaba and Tencent, configure an HTTPS delivery domain or CDN that maps to the bucket. Do not use a cloud-console URL, private API-only endpoint, expiring signed URL or credential-bearing URL as the public prefix. Public object access exposes the encrypted bytes; DRM license authorization controls decryption. Configure GET/HEAD CORS on the final delivery host, including CDN responses. ## 4. Allow browser uploads and playback[#](#configure-cors) Create an upload CORS rule allowing `PUT` only from `https://6.drm-x.com`. Allow `Content-Type` and the provider-specific headers below. Use the provider's own CORS configuration format; Azure and Google do not accept an S3 CORS JSON document. | Provider | Additional upload headers to allow | | --- | --- | | AWS S3, Google Cloud Storage, Tencent Cloud COS | `x-amz-meta-drmx-sha256` | | Alibaba Cloud OSS | `x-amz-meta-drmx-sha256`, `x-oss-s3-compat` | | Microsoft Azure Blob Storage | `x-ms-blob-type`, `x-ms-meta-drmx_sha256` | Add a separate playback rule for `GET` and `HEAD`, allow the `Range` request header, and expose `ETag`, `Content-Length`, `Content-Range` and `Accept-Ranges`. Use `*` for public encrypted media read origins, or list your exact player origins. Media requests must omit cross-origin cookies. CORS is browser configuration, not access authorization. ## 5. Connect and map paths[#](#connect-drmx) Open [Cloud Storage](https://6.drm-x.com/console/cloud-storage), select **Connect storage**, choose your provider and enter its fields. Set an optional protected-content base path and a matching public URL prefix. For example, base path `protected` and public prefix `https://media.example.com/protected` map an object `movie/manifest.mpd` to key `protected/movie/manifest.mpd`. With a direct Azure URL, also include the container in the public prefix. Select **Save and verify**. Select the connection as your default if the Packager should publish there. Existing saved storage connections remain available. Their provider identity, credentials, default selection and published URLs are preserved. They can still be edited, verified and used for uploads. ## 6. Verify with your account[#](#test-upload) - Verify listing in Console, then upload a small encrypted sample. Verify the byte size and public Preview URL. - Test public GET and HEAD, then `Range: bytes=0-15`. Confirm the expected bytes, HTTP 206 and Content-Range. - Test a folder, a filename with spaces and non-ASCII characters, rename, credential rotation, and deletion of disposable test objects. Verify denied permissions fail without exposing secrets. - Publish a complete encrypted package with Desktop Packager or the CLI. Confirm Published status, then play by Content ID in the intended browsers/devices and test seeking. - Keep provider, region, results and timestamps as verification evidence. Do not record account secrets or signed upload URLs. Single-request browser uploads are limited to 5 GiB, or 5,000 MiB for Azure. Use segmented Packager output for large videos. Retention, soft-delete, snapshots and versioning may retain provider-side data or block deletion. Current-object deletion is not proof that every retained version has been erased. ## 7. Troubleshooting[#](#troubleshooting) If listing works but upload fails, check PUT CORS, every signed request header, write permission and clock/expiry. If upload works but the public URL fails, compare bucket/container, base path, CDN origin mapping and case-sensitive filename. If a URL works directly but playback reports Failed to fetch, check GET/HEAD CORS and CDN caches. If Alibaba rejects S3 authentication, confirm the compatibility mode with Alibaba Cloud support. ## Official references[#](#references) - [AWS S3](https://docs.aws.amazon.com/AmazonS3/latest/userguide/Welcome.html) - [Azure Blob Storage API](https://learn.microsoft.com/en-us/rest/api/storageservices/blob-service-rest-api) - [Google Cloud Storage interoperability](https://docs.cloud.google.com/storage/docs/aws-simple-migration) - [Alibaba Cloud OSS interoperability](https://www.alibabacloud.com/help/en/oss/developer-reference/migrate-data-from-amazon-s3-to-oss) - [Tencent Cloud COS interoperability](https://www.tencentcloud.com/document/product/436/32537)