← All extensions
Object Storage banner

Object Storage

ivyx✓

Browse your buckets and move files in and out of S3, Azure Blob, Google Cloud, or MinIO

Object Storage

Browse and move data between your workspace and your object storage — AWS S3, Azure Blob Storage, Google Cloud Storage, and MinIO or any S3-compatible endpoint.

What you can do

  • Keep several accounts connected at once, grouped by backend, and drill from a connection down through bucket and prefix to a single object
  • Page through huge buckets safely — objects arrive a page at a time, and nothing here ever walks a whole bucket
  • Download an object into your workspace and have it open in the right place: a .csv in the CSV viewer, a .parquet queryable in DuckDB, an image in the image viewer
  • Upload a workspace file back to a bucket
  • Delete a single object, behind a confirmation

Objects over 100 MB (configurable) are downloaded to the host data directory instead, so they don't pollute your workspace.

Requirements

This extension is the hub: it owns the connections tree, the object list and the transfer panel, but no cloud SDK of its own. Install the provider for each backend you use alongside it:

Backend Provider extension
MinIO / S3-compatible extension-object-storage-minio
AWS S3 extension-object-storage-aws
Azure Blob Storage extension-object-storage-abs
Google Cloud Storage extension-object-storage-gcs

The desktop app is required. Each provider runs a small local helper process to talk to its backend, and the browser edition has neither that process bridge nor a persistent secret store — so connections are desktop-only. The panel says so rather than storing your keys somewhere they would silently vanish.

Credentials

Keys are never written into .punica/object-storage.yaml. They go to the host's OS-keychain-encrypted secret store and appear in the Secrets panel as object-storage.<connection>.<field>, where you can inspect or remove them.

.punica/object-storage.yaml holds only non-secret metadata (label, endpoint, region, account, default bucket). It is git-ignored by default.

Scope

This is a data source, not a storage admin console: no bucket creation, no policies, no lifecycle rules, no IAM. Sign-in is key-based (access keys, connection string or SAS, service-account JSON); SSO / IAM roles / ADC are not supported yet.

See docs/design.md for the hub↔provider contract.

Getting started

Install the provider for your backend, open Object Storage in the activity bar, and press + to add a connection.