SlideShare a Scribd company logo
4
Most read
8
Most read
12
Most read
Nagesh Ramamoorthy
Agenda
• ICOS Overview
• Storage Classes
• Resiliency Options
• End points
• Access Policies
• Service credentials and HMAC credentials
• Firewalls & Encryption
• Aspera High Speed Transfer
• Lifecycle Rules: Expiration and Archival
• Immutable Object Storage
• IBM Cloud SQL Query
ICOS Overview
• Formerly known as Cleversafe.
• IBM COS supports objects up to 10 TB, and maximum of
100 buckets.
• S3 API support is available in order to provide
compatibility to standalone clients for AWS S3 storage.
• IBM COS is IAM enabled.
• We can enable Activity tracker based API logging for
Each bucket level management and data events
Storage Classes
Four storage Classes:
• Standard :Used for active workloads , no retrieval fee
• Vault: Used for Cold data and retrieval fee applicable
• Cold Vault: Used for cold data , not accessed for more
than 90 days . More retrieval fee applicable
• Flex: Used for dynamic workloads with no predictable
usage patterns
Resiliency Options
Three types of
resiliency/replication
provided:
Cross-Region ( Data replicated across three
regions in a geography)
Regional ( Data is replicated across three
AZs in a region)
Single Datacenter ( Data is replicated across
multiple servers in the same location)
End Points
• ICOS supports private and public end points.
• VPC endpoints can connect to ICOS using a separate direct end points privately .
• There are different end points for Regional , Cross-regional and datacenter
locations.
• Regional End Points for US-South Region example:
Public: s3.us-south.cloud-object-storage.appdomain.cloud
Private: s3.private.us-south.cloud-object-storage.appdomain.cloud
Direct: s3.direct.us-south.cloud-object-storage.appdomain.cloud
Access Policy
• Every user that accesses the IBM® Cloud Object Storage service in your account
must be assigned an access policy with an IAM user role pre-defined ( Platform
management and service access)
• There is no bucket resource level permission option other than through IAM
method.
• Using IAM access policies , permissions can be granted at individual bucket level.
• Public access can be granted by clicking on "access policy" inside bucket
configuration
Service and HMAC credentials
• A service credential provides the necessary information to connect an application to Object Storage
packaged in a JSON document.
• "Service credentials" option under object storage tab allows to create service id and associate privileges
for all the buckets in the storage service along with end point details in a json document.
• When a service credential is created, the underlying Service ID is granted a role on the entire instance
of Object Storage.
• If the intention that the credential be used to grant, access to a subset of buckets and not the entire
instance, this policy needs to be edited.
• HMAC credentials contains an access key and secret access key which is compatible to AWS S3 API.
• HMAC credentials can be generated as part of "service credentials" option
Firewalls and Encryption
• We can set up firewall by allowing certain limited number of IPs to access the
bucket.
• Once the firewall is setup , other IBM coud services can't access the bucket
privately.
• The objects are encrypted by default at rest with automatic provider side Advanced
Encryption Standard (AES) 256-bit encryption and Secure Hash Algorithm (SHA)-
256 hash.
• IBM Cloud Object storage provides option to encrypt through customer provided
keys which is called server side encryption with customer provided keys (SSE-C)
and also through SSE-KP (Server side encryption with IBM Key protect)
Aspera High-Speed Transfer
• Aspera High Speed transfer allows transfers larger than 200 MB through console
using proprietary FASP ( Fast and secure Protocol)
• Aspera High Speed transfer requires either a browser plug-in or a desktop agent
• Aspera High Speed transfer supports Java and Python SDKs
• Aspera High Speed transfer supports windows, Ubuntu Linux and Mac OS agents
Lifecycle Rules: Expiration , Archival
• Expiration rule makes the objects deleted automatically after given number of days from object
creation.
• IBM Cloud object storage archive is a low cost option for data that is rarely accessed.
• You can transition data from any storage class ( Standard , Vault, Cold Vault ,Flex) to Archive.
• For immediate archival , the archival time should be set to 0 days.
• To access the data that is archived , it should be restored by specifying the period of which the
object should be kept in the original class.
• The restoration duration can be up to 12 hours
• Together Expiration and Archive policies , we can set up to 1000 life cycle policies
Immutable Object Storage
• Immutable Object Storage preserves electronic records and maintains data integrity.
• Retention policies ensure that data is stored in a WORM (Write-Once-Read-Many), non-
erasable and non-rewritable manner.
• Retention Policies allows prevention of deletion of object within specified time.
• Retention policies once enabled, can't be disabled
• Retention policy can be set while uploading an object as well but the specified value
should be within minimum and maximum value set at the bucket level.
• The default retention period can be set at the bucket configuration.
• Enabling "Permanent retention" at bucket level ,never allows objects deletion
IBM Cloud SQL
• IBM Cloud SQL is a fully managed service
which allows to run "SELECT" statements
on object storage files of ORC, CSV, JSON
format.
• The query results are stored in a CSV file in
the object storage.
• Actions with Cloud SQL such as CREATE,
DELETE, INSERT, and UPDATE are not
possible.

More Related Content

PPTX
AWS database services
PPTX
AWS Cloud SAA Relational Database presentation
PPTX
EC2 and S3 Level 100
PPTX
AWS network services
PPTX
AWS solution Architect Associate study material
PPTX
Power of OpenStack & Hadoop
PPTX
Amazon Virtual Private Cloud - VPC 1
PPTX
Hybrid cloud sample architectures
AWS database services
AWS Cloud SAA Relational Database presentation
EC2 and S3 Level 100
AWS network services
AWS solution Architect Associate study material
Power of OpenStack & Hadoop
Amazon Virtual Private Cloud - VPC 1
Hybrid cloud sample architectures

Similar to IBM Cloud Object Storage (20)

PPTX
AWS Amazon S3 Mastery Bootcamp
PPTX
Aws Solution Architecture Associate - summary
PPTX
AWS Storage - S3 Fundamentals
PPTX
Module 06_Cloud Backup and Solutions.pptx
PDF
Deep Dive on EC2 and S3
PPTX
Amazon_S3 (Simple storage service)_Presentation.pptx
PDF
Building a Bigdata Architecture on AWS
PDF
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
PPTX
Managing storage on Prem and in Cloud
PPTX
SoftLayer Storage Services Overview
PPTX
Servicios de Almacenamiento en AWS
PPTX
AWS Simple Storage Service (s3)
PPSX
Amazon ec2 s3 dynamo db
PDF
Inter connect2016 yss1841-cloud-storage-options-v4
PDF
AWS Well Architected-Info Session WeCloudData
PPTX
Being Well Architected in the Cloud (Updated)
PPTX
AWS-S3.pptx
PDF
Better, faster, cheaper infrastructure with apache cloud stack and riak cs redux
PDF
Getting started with S3
PPTX
Microsoft Azure Veri Servisleri
AWS Amazon S3 Mastery Bootcamp
Aws Solution Architecture Associate - summary
AWS Storage - S3 Fundamentals
Module 06_Cloud Backup and Solutions.pptx
Deep Dive on EC2 and S3
Amazon_S3 (Simple storage service)_Presentation.pptx
Building a Bigdata Architecture on AWS
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
Managing storage on Prem and in Cloud
SoftLayer Storage Services Overview
Servicios de Almacenamiento en AWS
AWS Simple Storage Service (s3)
Amazon ec2 s3 dynamo db
Inter connect2016 yss1841-cloud-storage-options-v4
AWS Well Architected-Info Session WeCloudData
Being Well Architected in the Cloud (Updated)
AWS-S3.pptx
Better, faster, cheaper infrastructure with apache cloud stack and riak cs redux
Getting started with S3
Microsoft Azure Veri Servisleri
Ad

More from Nagesh Ramamoorthy (12)

PPTX
IBM Cloud PowerVS - AIX and IBM i on Cloud
PPTX
NextGen IBM Cloud Monitoring and Logging
PPTX
IBM Cloud VPC Deep Dive
PPTX
IBM Cloud Direct Link 2.0
PPTX
CIS bench marks for public clouds
PPTX
AWS Security Hub Deep Dive
PPTX
AWS deployment and management Services
PPTX
AWS Storage services
PPTX
AWS compute Services
PPTX
AWS core services
PPTX
AWS Introduction and History
PDF
Cloud computing
IBM Cloud PowerVS - AIX and IBM i on Cloud
NextGen IBM Cloud Monitoring and Logging
IBM Cloud VPC Deep Dive
IBM Cloud Direct Link 2.0
CIS bench marks for public clouds
AWS Security Hub Deep Dive
AWS deployment and management Services
AWS Storage services
AWS compute Services
AWS core services
AWS Introduction and History
Cloud computing
Ad

Recently uploaded (20)

PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Approach and Philosophy of On baking technology
PPTX
Big Data Technologies - Introduction.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Modernizing your data center with Dell and AMD
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
NewMind AI Monthly Chronicles - July 2025
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Empathic Computing: Creating Shared Understanding
PDF
cuic standard and advanced reporting.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
Advanced methodologies resolving dimensionality complications for autism neur...
Approach and Philosophy of On baking technology
Big Data Technologies - Introduction.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Modernizing your data center with Dell and AMD
Network Security Unit 5.pdf for BCA BBA.
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Diabetes mellitus diagnosis method based random forest with bat algorithm
NewMind AI Monthly Chronicles - July 2025
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Reach Out and Touch Someone: Haptics and Empathic Computing
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Empathic Computing: Creating Shared Understanding
cuic standard and advanced reporting.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...

IBM Cloud Object Storage

  • 2. Agenda • ICOS Overview • Storage Classes • Resiliency Options • End points • Access Policies • Service credentials and HMAC credentials • Firewalls & Encryption • Aspera High Speed Transfer • Lifecycle Rules: Expiration and Archival • Immutable Object Storage • IBM Cloud SQL Query
  • 3. ICOS Overview • Formerly known as Cleversafe. • IBM COS supports objects up to 10 TB, and maximum of 100 buckets. • S3 API support is available in order to provide compatibility to standalone clients for AWS S3 storage. • IBM COS is IAM enabled. • We can enable Activity tracker based API logging for Each bucket level management and data events
  • 4. Storage Classes Four storage Classes: • Standard :Used for active workloads , no retrieval fee • Vault: Used for Cold data and retrieval fee applicable • Cold Vault: Used for cold data , not accessed for more than 90 days . More retrieval fee applicable • Flex: Used for dynamic workloads with no predictable usage patterns
  • 5. Resiliency Options Three types of resiliency/replication provided: Cross-Region ( Data replicated across three regions in a geography) Regional ( Data is replicated across three AZs in a region) Single Datacenter ( Data is replicated across multiple servers in the same location)
  • 6. End Points • ICOS supports private and public end points. • VPC endpoints can connect to ICOS using a separate direct end points privately . • There are different end points for Regional , Cross-regional and datacenter locations. • Regional End Points for US-South Region example: Public: s3.us-south.cloud-object-storage.appdomain.cloud Private: s3.private.us-south.cloud-object-storage.appdomain.cloud Direct: s3.direct.us-south.cloud-object-storage.appdomain.cloud
  • 7. Access Policy • Every user that accesses the IBM® Cloud Object Storage service in your account must be assigned an access policy with an IAM user role pre-defined ( Platform management and service access) • There is no bucket resource level permission option other than through IAM method. • Using IAM access policies , permissions can be granted at individual bucket level. • Public access can be granted by clicking on "access policy" inside bucket configuration
  • 8. Service and HMAC credentials • A service credential provides the necessary information to connect an application to Object Storage packaged in a JSON document. • "Service credentials" option under object storage tab allows to create service id and associate privileges for all the buckets in the storage service along with end point details in a json document. • When a service credential is created, the underlying Service ID is granted a role on the entire instance of Object Storage. • If the intention that the credential be used to grant, access to a subset of buckets and not the entire instance, this policy needs to be edited. • HMAC credentials contains an access key and secret access key which is compatible to AWS S3 API. • HMAC credentials can be generated as part of "service credentials" option
  • 9. Firewalls and Encryption • We can set up firewall by allowing certain limited number of IPs to access the bucket. • Once the firewall is setup , other IBM coud services can't access the bucket privately. • The objects are encrypted by default at rest with automatic provider side Advanced Encryption Standard (AES) 256-bit encryption and Secure Hash Algorithm (SHA)- 256 hash. • IBM Cloud Object storage provides option to encrypt through customer provided keys which is called server side encryption with customer provided keys (SSE-C) and also through SSE-KP (Server side encryption with IBM Key protect)
  • 10. Aspera High-Speed Transfer • Aspera High Speed transfer allows transfers larger than 200 MB through console using proprietary FASP ( Fast and secure Protocol) • Aspera High Speed transfer requires either a browser plug-in or a desktop agent • Aspera High Speed transfer supports Java and Python SDKs • Aspera High Speed transfer supports windows, Ubuntu Linux and Mac OS agents
  • 11. Lifecycle Rules: Expiration , Archival • Expiration rule makes the objects deleted automatically after given number of days from object creation. • IBM Cloud object storage archive is a low cost option for data that is rarely accessed. • You can transition data from any storage class ( Standard , Vault, Cold Vault ,Flex) to Archive. • For immediate archival , the archival time should be set to 0 days. • To access the data that is archived , it should be restored by specifying the period of which the object should be kept in the original class. • The restoration duration can be up to 12 hours • Together Expiration and Archive policies , we can set up to 1000 life cycle policies
  • 12. Immutable Object Storage • Immutable Object Storage preserves electronic records and maintains data integrity. • Retention policies ensure that data is stored in a WORM (Write-Once-Read-Many), non- erasable and non-rewritable manner. • Retention Policies allows prevention of deletion of object within specified time. • Retention policies once enabled, can't be disabled • Retention policy can be set while uploading an object as well but the specified value should be within minimum and maximum value set at the bucket level. • The default retention period can be set at the bucket configuration. • Enabling "Permanent retention" at bucket level ,never allows objects deletion
  • 13. IBM Cloud SQL • IBM Cloud SQL is a fully managed service which allows to run "SELECT" statements on object storage files of ORC, CSV, JSON format. • The query results are stored in a CSV file in the object storage. • Actions with Cloud SQL such as CREATE, DELETE, INSERT, and UPDATE are not possible.