How to manage CoreWeave AI Object Storage buckets with popular S3 clients.
CoreWeave AI Object Storage stores data as objects consisting of the data itself, its metadata, and a unique identifier. These objects are organized into containers called buckets, which provide a namespace for objects to ensure that object names are unique within a bucket. Additionally, buckets can have specific configurations and policies to manage the data lifecycle and security.You can create and delete buckets programmatically using the S3-compatible Object Storage API or various S3-compatible tools.This guide explains how to manage CoreWeave AI Object Storage buckets with Cloud Console and using popular clients: S3cmd, AWS CLI, Boto3, and s5cmd.
This guide assumes that you have followed the steps in Get started with AI Object Storage. Before you begin, ensure that you have completed the following tasks:
Obtain Access Keys with OpenID Connect (OIDC) Workload Identity Federation for production or a CoreWeave API access token for development and testing.
For the delete and usage-reporting examples, create a bucket to manage.
To use LOTA, clients must point their requests to the LOTA endpoint instead of the primary endpoint. No other changes are required for S3-compatible clients.
Use the LOTA endpoint, http://cwlota.com, when running inside a CoreWeave cluster. The LOTA endpoint routes to the LOTA path for best performance.
Use the primary endpoint, https://cwobject.com, when running outside of a CoreWeave cluster.
You can’t create a bucket without a valid API access key. Anonymous requests are never allowed to create buckets. To obtain an API access key, see How-To: Manage Access Keys.When you create a bucket, you automatically become the bucket owner. The bucket owner has full control over the bucket and its contents.
Bucket names must be globally unique, and adhere to the following rules:
Length: 3 to 63 characters.
Characters: Only lowercase letters (a-z), numbers (0-9), and hyphens (-). No dots, uppercase letters, underscores, spaces, or other special characters.
Start and end: Must begin and end with a letter or number. Cannot start or end with a hyphen (-).
Prohibited patterns: Cannot start with xn--.
Reserved: Must not begin with cw-, vip-, or log-stitcher-ch-. Must not be the exact name int. These are reserved for internal use.
If you try to create a bucket with a name that already exists in another location, or that doesn’t adhere to these rules, you receive an error.
All requests to CoreWeave AI Object Storage endpoints must be in DNS (virtual-hosted) style, where the bucket name is part of the domain name in the URL.
Use http://[BUCKET-NAME].cwlota.comif using the LOTA endpoint.
Use https://[BUCKET-NAME].cwobject.comif using the primary endpoint.
The Buckets section lets you manage your buckets. You can create and delete buckets, and view their total size and the number of objects in them. To browse, upload, download, or delete the objects within a bucket, select the bucket to open it.The Grafana link at the top of the page leads to a Grafana dashboard for all buckets in your organization.For each bucket, the vertical dot menu on the right allows you to view the Grafana dashboard for that bucket, or delete the bucket.
S3cmd, AWS CLI, and Boto3 use the term “region” to define the location of the object storage service. However, at CoreWeave, are larger constructs that are organized into . When configuring your client, use a CoreWeave Availability Zone in place of the traditional AWS “region”.When you create a new bucket, specify the Availability Zone in which the bucket is created.
When creating a bucket with S3cmd, use --bucket-location with the Availability Zone.
When creating a bucket with AWS CLI or Boto3, use LocationConstraint.
s5cmd doesn’t support specifying an Availability Zone at bucket creation. Use the AWS CLI, s3cmd, or Boto3 if you need to create a bucket in a specific Availability Zone.
The following examples show how to manage buckets with the AWS CLI, s3cmd, and Boto3.
The AWS CLI is a command-line tool that manages AWS services. It provides a consistent interface to interact with S3-compatible services, including CoreWeave AI Object Storage. Follow these steps to install and configure the AWS CLI, then use it to create and delete buckets in CoreWeave AI Object Storage.
S3cmd is a command-line tool that manages objects in S3-compatible object storage services. You can use it to create, delete, and manage buckets, as well as upload, download, and manage objects within those buckets. S3cmd is available for Linux and macOS.
Boto3 is the AWS SDK for Python. It lets you interact with AWS services programmatically using Python. Follow these steps to install and configure Boto3, then use it to create and delete buckets in CoreWeave AI Object Storage.
s5cmd is a high-performance, parallel S3 CLI tool. Use the CoreWeave fork of s5cmd, which uses virtual-hosted addressing for AI Object Storage compatibility. Follow these steps to install and configure s5cmd, then use it to create and delete buckets in CoreWeave AI Object Storage. For bulk transfers, see Migrate data to AI Object Storage.
The preferred S3cmd installation method is to download the latest version from GitHub. Alternatively, you can install it with the package manager for your system. For example, macOS can use Homebrew.
macOS Example
brew install s3cmd
Linux distributions can use their native package manager. For example:
Debian example
sudo apt install s3cmd
The version of S3cmd available in these package managers may not be the latest version. If you require the latest version, download it from the S3cmd GitHub repository.
Use the CoreWeave fork of s5cmd with AI Object StorageThe upstream s5cmd uses path-style addressing with custom endpoint URLs. AI Object Storage doesn’t support path-style addressing and requires virtual-hosted style URLs. Use the CoreWeave fork of s5cmd, which is compatible with AI Object Storage and can safely replace any existing s5cmd installation. For setup and usage, see Migrate data to AI Object Storage.
Download the latest release binary for your platform from the CoreWeave s5cmd releases page. After downloading, make the binary executable and move it to a directory in your PATH:
To set up your AWS configuration for CoreWeave AI Object Storage, create a cw profile. We recommend using a separate profile to avoid conflicts with your other AWS profiles and S3-compatible services.
Create a cw profile:
Create a new profile
aws configure --profile cw
When prompted for information, provide the following values:
Set the endpoint URL to the appropriate endpoint for your use case:
Endpoint URL
Description
https://cwobject.com
The primary endpoint for CoreWeave AI Object Storage. Use this when running outside of a CoreWeave cluster.
http://cwlota.com
The LOTA endpoint, which routes to the LOTA cache for best performance. Always use the LOTA endpoint when running inside a CoreWeave cluster.
Set the LOTA endpoint URL
aws configure set endpoint_url http://cwlota.com --profile cw
Set the primary endpoint URL
aws configure set endpoint_url https://cwobject.com --profile cw
Set the default addressing style to virtual. This is required for CoreWeave AI Object Storage, as it uses virtual-hosted style URLs.
Set virtual addressing style
aws configure set s3.addressing_style virtual --profile cw
Pass --profile cw to each AWS CLI command to use these credentials, or run export AWS_PROFILE=cw before running commands.
S3cmd requires your API token, default Region, endpoint and other information to use CoreWeave AI Object Storage. To configure S3cmd, run the following command:
Configure S3cmd
s3cmd --configure
When prompted, provide the following values:
Field
Value
Access Key
The Access Key created by the CoreWeave AI Object Storage API.
Secret Key
The Secret Key created by the CoreWeave AI Object Storage API.
Default Region
The CoreWeave Availability Zone is found in the Availability Zones table.
S3 Endpoint
• cwobject.com is the primary endpoint. • cwlota.com is the LOTA endpoint.
DNS-style template
• %(bucket)s.cwobject.com is the primary template. • %(bucket)s.cwlota.com is the LOTA template.
Path to GPG program
Defaults to /usr/bin/gpg.
Use HTTPS protocol
Boolean value indicating whether you’re using the HTTPS protocol. Defaults to True.
HTTP Proxy server name
Name of HTTP Proxy server.
HTTP Proxy server port
Port number of HTTP Proxy server.
When you use secure HTTPS protocol, all communication with Amazon S3 servers is protected from third-party eavesdropping. This method is slower than plain HTTP,
and can only be proxied with Python 2.7 or newer.On some networks, all internet access must go through an HTTP proxy. Try setting the name and port here if you can’t connect to S3 directly.Leave the remaining fields blank or press Enter to accept the default values. Test and save the configuration when prompted.By default, S3cmd stores its configuration in $HOME/.s3cfg.
Boto3 uses the same configuration files as the AWS CLI. If you have already configured the AWS CLI, you can skip this step. Otherwise, configure Boto3 by following the steps in the AWS CLI Configuration tab within this section.Boto3 can also use a Config object or the environment to override the AWS CLI configuration. See this example for more details.
Use the CoreWeave fork of s5cmd with AI Object StorageThe upstream s5cmd uses path-style addressing with custom endpoint URLs. AI Object Storage doesn’t support path-style addressing and requires virtual-hosted style URLs. Use the CoreWeave fork of s5cmd, which is compatible with AI Object Storage and can safely replace any existing s5cmd installation. For setup and usage, see Migrate data to AI Object Storage.
s5cmd reads credentials from the standard AWS credential chain: environment variables or the shared credentials file used by the AWS CLI. If you’ve already configured the AWS CLI, s5cmd uses the same credentials.
Unlike the AWS CLI, s5cmd doesn’t read endpoint_url from the AWS configuration file. Pass --endpoint-url on every command. Replace [COMMAND] with the s5cmd subcommand you want to run, such as cp or ls:
Use the aws s3api command to create a new bucket. For example:Replace [BUCKET-NAME] with your desired bucket name and [AVAILABILITY-ZONE] with a CoreWeave Availability Zone.
Bucket names must be globally unique and adhere to the following rules:
Length: 3 to 63 characters.
Characters: Only lowercase letters (a-z), numbers (0-9), and hyphens (-). No dots, uppercase letters, underscores, spaces, or other special characters.
Start and end: Must begin and end with a letter or number. Cannot start or end with a hyphen (-).
Prohibited patterns: Cannot start with xn--.
Reserved: Must not begin with cw-, vip-, or log-stitcher-ch-. Must not be the exact name int. CoreWeave reserves these for internal use.
To create a bucket with S3cmd, use the mb (make bucket) command as shown below.Replace [AVAILABILITY-ZONE] with a CoreWeave Availability Zone and [BUCKET-NAME] with a globally-unique name.
Bucket names must be globally unique and adhere to the following rules:
Length: 3 to 63 characters.
Characters: Only lowercase letters (a-z), numbers (0-9), and hyphens (-). No dots, uppercase letters, underscores, spaces, or other special characters.
Start and end: Must begin and end with a letter or number. Cannot start or end with a hyphen (-).
Prohibited patterns: Cannot start with xn--.
Reserved: Must not begin with cw-, vip-, or log-stitcher-ch-. Must not be the exact name int. CoreWeave reserves these for internal use.
Set environment variables for your CoreWeave credentials:
Alternatively, configure your CoreWeave credentials to work with the AWS CLI.We recommend using a separate profile for CoreWeave AI Object Storage to avoid conflicts with your other AWS profiles and S3-compatible services. If you don’t set up this configuration, you might encounter errors when using AI Object Storage. If you have no other AWS profiles, you can use the default profile instead of the cw profile created in the following steps. In that case, omit --profile cw from the commands.
For production workloads, CoreWeave recommends Workload Identity Federation for automated, short-lived credentials instead of static access keys.
Configure CoreWeave credentials with static access keys
Create a cw profile:
Create a new profile
aws configure --profile cw
When prompted, provide the following values:
AWS Access Key ID: The Access Key ID of your CoreWeave AI Object Storage Access Key.
AWS Secret Access Key: The Secret Key of your CoreWeave AI Object Storage Access Key.
Set the default endpoint URL to the appropriate endpoint for your use case:
The primary endpoint, https://cwobject.com, for use outside a CoreWeave cluster.
The LOTA endpoint, http://cwlota.com, for use inside a CoreWeave cluster. The LOTA endpoint routes to the LOTA path for best performance.
Set the primary endpoint for local development
aws configure set endpoint_url https://cwobject.com --profile cw
Set the S3 addressing_style to virtual:
Set virtual addressing style
aws configure set s3.addressing_style virtual --profile cw
To use this profile, pass --profile cw to your AWS CLI commands, or set AWS_PROFILE=cw in your environment.If you set endpoint_url and s3.addressing_style directly in your code (for example, in a Boto3 Config object), you can skip steps 3 and 4. The profile only needs the access key, secret key, and region.
Configure CoreWeave credentials with Workload Identity Federation (OIDC)
If you’ve configured Workload Identity Federation with OIDC, the AWS SDK automatically discovers temporary credentials. Set the following environment variables instead of configuring static access keys.Replace [ORG-ID] with your CoreWeave organization ID, [PATH-TO-JWT-TOKEN-FILE] with the path to your JWT token file, and [AVAILABILITY-ZONE] with your CoreWeave Availability Zone.
Configure WIF OIDC credentials
export AWS_CONTAINER_CREDENTIALS_FULL_URI=https://api.coreweave.com/v1/cwobject/temporary-credentials/oidc/[ORG-ID]export AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE=[PATH-TO-JWT-TOKEN-FILE]aws configure set s3.addressing_style virtualexport AWS_REGION="[AVAILABILITY-ZONE]"export AWS_ENDPOINT_URL_S3="https://cwobject.com"
With WIF configured, your S3-compatible tools and Boto3 code automatically obtain and refresh temporary credentials without passing access keys explicitly.Requires awscli >= 2.33.2 or boto3 >= 1.42.5. See Use Workload Identity Federation with OIDC for the full setup guide.
Use the create_bucket method to create a bucket. Replace [BUCKET-NAME] with your desired bucket name and [AVAILABILITY-ZONE] with a CoreWeave Availability Zone.
Bucket names must be globally unique and adhere to the following rules:
Length: 3 to 63 characters.
Characters: Only lowercase letters (a-z), numbers (0-9), and hyphens (-). No dots, uppercase letters, underscores, spaces, or other special characters.
Start and end: Must begin and end with a letter or number. Cannot start or end with a hyphen (-).
Prohibited patterns: Cannot start with xn--.
Reserved: Must not begin with cw-, vip-, or log-stitcher-ch-. Must not be the exact name int. CoreWeave reserves these for internal use.
Use the CoreWeave fork of s5cmd with AI Object StorageThe upstream s5cmd uses path-style addressing with custom endpoint URLs. AI Object Storage doesn’t support path-style addressing and requires virtual-hosted style URLs. Use the CoreWeave fork of s5cmd, which is compatible with AI Object Storage and can safely replace any existing s5cmd installation. For setup and usage, see Migrate data to AI Object Storage.
To create a bucket with s5cmd, use the mb command. Replace [BUCKET-NAME] with your desired bucket name.
s5cmd mb doesn’t support specifying a LocationConstraint. To create a bucket in a specific Availability Zone, use the AWS CLI, s3cmd, or Boto3.
Bucket naming rules
Bucket names must be globally unique and adhere to the following rules:
Length: 3 to 63 characters.
Characters: Only lowercase letters (a-z), numbers (0-9), and hyphens (-). No dots, uppercase letters, underscores, spaces, or other special characters.
Start and end: Must begin and end with a letter or number. Cannot start or end with a hyphen (-).
Prohibited patterns: Cannot start with xn--.
Reserved: Must not begin with cw-, vip-, or log-stitcher-ch-. Must not be the exact name int. CoreWeave reserves these for internal use.
Only empty buckets can be deleted. Remove all objects, object versions, delete markers, and incomplete multipart uploads before deleting a bucket. See Empty and delete a bucket for the complete cleanup procedure.
AWS CLI
s3cmd
Boto3
s5cmd
To delete a bucket, use the delete-bucket sub-command as shown. Only empty buckets can be deleted. Remove all objects, object versions, and delete markers before deleting a bucket.Replace [BUCKET-NAME] with the name of the bucket to delete.
To delete a bucket with S3cmd, use the rb (remove bucket) command as shown below. Only empty buckets can be deleted. Remove all objects, object versions, and delete markers before deleting a bucket.Replace [BUCKET-NAME] with the name of your bucket.
Remove a bucket with S3cmd
s3cmd rb s3://[BUCKET-NAME]
To delete a bucket with Boto3, use the delete_bucket method. Only empty buckets can be deleted. Remove all objects, object versions, and delete markers before deleting a bucket.
Set environment variables for your CoreWeave credentials:
Alternatively, configure your CoreWeave credentials to work with the AWS CLI.We recommend using a separate profile for CoreWeave AI Object Storage to avoid conflicts with your other AWS profiles and S3-compatible services. If you don’t set up this configuration, you might encounter errors when using AI Object Storage. If you have no other AWS profiles, you can use the default profile instead of the cw profile created in the following steps. In that case, omit --profile cw from the commands.
For production workloads, CoreWeave recommends Workload Identity Federation for automated, short-lived credentials instead of static access keys.
Configure CoreWeave credentials with static access keys
Create a cw profile:
Create a new profile
aws configure --profile cw
When prompted, provide the following values:
AWS Access Key ID: The Access Key ID of your CoreWeave AI Object Storage Access Key.
AWS Secret Access Key: The Secret Key of your CoreWeave AI Object Storage Access Key.
Set the default endpoint URL to the appropriate endpoint for your use case:
The primary endpoint, https://cwobject.com, for use outside a CoreWeave cluster.
The LOTA endpoint, http://cwlota.com, for use inside a CoreWeave cluster. The LOTA endpoint routes to the LOTA path for best performance.
Set the primary endpoint for local development
aws configure set endpoint_url https://cwobject.com --profile cw
Set the S3 addressing_style to virtual:
Set virtual addressing style
aws configure set s3.addressing_style virtual --profile cw
To use this profile, pass --profile cw to your AWS CLI commands, or set AWS_PROFILE=cw in your environment.If you set endpoint_url and s3.addressing_style directly in your code (for example, in a Boto3 Config object), you can skip steps 3 and 4. The profile only needs the access key, secret key, and region.
Configure CoreWeave credentials with Workload Identity Federation (OIDC)
If you’ve configured Workload Identity Federation with OIDC, the AWS SDK automatically discovers temporary credentials. Set the following environment variables instead of configuring static access keys.Replace [ORG-ID] with your CoreWeave organization ID, [PATH-TO-JWT-TOKEN-FILE] with the path to your JWT token file, and [AVAILABILITY-ZONE] with your CoreWeave Availability Zone.
Configure WIF OIDC credentials
export AWS_CONTAINER_CREDENTIALS_FULL_URI=https://api.coreweave.com/v1/cwobject/temporary-credentials/oidc/[ORG-ID]export AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE=[PATH-TO-JWT-TOKEN-FILE]aws configure set s3.addressing_style virtualexport AWS_REGION="[AVAILABILITY-ZONE]"export AWS_ENDPOINT_URL_S3="https://cwobject.com"
With WIF configured, your S3-compatible tools and Boto3 code automatically obtain and refresh temporary credentials without passing access keys explicitly.Requires awscli >= 2.33.2 or boto3 >= 1.42.5. See Use Workload Identity Federation with OIDC for the full setup guide.
Replace [BUCKET-NAME] with the name of the bucket to delete.
Use the CoreWeave fork of s5cmd with AI Object StorageThe upstream s5cmd uses path-style addressing with custom endpoint URLs. AI Object Storage doesn’t support path-style addressing and requires virtual-hosted style URLs. Use the CoreWeave fork of s5cmd, which is compatible with AI Object Storage and can safely replace any existing s5cmd installation. For setup and usage, see Migrate data to AI Object Storage.
To delete a bucket with s5cmd, use the rb (remove bucket) command. Only empty buckets can be deleted. Remove all objects, object versions, and delete markers before deleting a bucket.Replace [BUCKET-NAME] with the name of your bucket.
To report the usage of a bucket, use aws s3 with the ls sub-command. Use the --recursive, --human-readable, and --summarize parameters to view information in an easier-to-understand format.Replace [BUCKET-NAME] with the name of your bucket.
Report bucket usage with AWS CLI
aws s3 ls s3://[BUCKET-NAME] --recursive --human-readable --summarize --profile cw
To report the usage of a bucket, use the du (disk usage) command. Use the --human-readable-sizes parameter to view information in an easier-to-understand format.Replace [BUCKET-NAME] with the name of your bucket.
Report bucket usage with S3cmd
s3cmd du --human-readable-sizes s3://[BUCKET-NAME]
Set environment variables for your CoreWeave credentials:
Alternatively, configure your CoreWeave credentials to work with the AWS CLI.We recommend using a separate profile for CoreWeave AI Object Storage to avoid conflicts with your other AWS profiles and S3-compatible services. If you don’t set up this configuration, you might encounter errors when using AI Object Storage. If you have no other AWS profiles, you can use the default profile instead of the cw profile created in the following steps. In that case, omit --profile cw from the commands.
For production workloads, CoreWeave recommends Workload Identity Federation for automated, short-lived credentials instead of static access keys.
Configure CoreWeave credentials with static access keys
Create a cw profile:
Create a new profile
aws configure --profile cw
When prompted, provide the following values:
AWS Access Key ID: The Access Key ID of your CoreWeave AI Object Storage Access Key.
AWS Secret Access Key: The Secret Key of your CoreWeave AI Object Storage Access Key.
Set the default endpoint URL to the appropriate endpoint for your use case:
The primary endpoint, https://cwobject.com, for use outside a CoreWeave cluster.
The LOTA endpoint, http://cwlota.com, for use inside a CoreWeave cluster. The LOTA endpoint routes to the LOTA path for best performance.
Set the primary endpoint for local development
aws configure set endpoint_url https://cwobject.com --profile cw
Set the S3 addressing_style to virtual:
Set virtual addressing style
aws configure set s3.addressing_style virtual --profile cw
To use this profile, pass --profile cw to your AWS CLI commands, or set AWS_PROFILE=cw in your environment.If you set endpoint_url and s3.addressing_style directly in your code (for example, in a Boto3 Config object), you can skip steps 3 and 4. The profile only needs the access key, secret key, and region.
Configure CoreWeave credentials with Workload Identity Federation (OIDC)
If you’ve configured Workload Identity Federation with OIDC, the AWS SDK automatically discovers temporary credentials. Set the following environment variables instead of configuring static access keys.Replace [ORG-ID] with your CoreWeave organization ID, [PATH-TO-JWT-TOKEN-FILE] with the path to your JWT token file, and [AVAILABILITY-ZONE] with your CoreWeave Availability Zone.
Configure WIF OIDC credentials
export AWS_CONTAINER_CREDENTIALS_FULL_URI=https://api.coreweave.com/v1/cwobject/temporary-credentials/oidc/[ORG-ID]export AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE=[PATH-TO-JWT-TOKEN-FILE]aws configure set s3.addressing_style virtualexport AWS_REGION="[AVAILABILITY-ZONE]"export AWS_ENDPOINT_URL_S3="https://cwobject.com"
With WIF configured, your S3-compatible tools and Boto3 code automatically obtain and refresh temporary credentials without passing access keys explicitly.Requires awscli >= 2.33.2 or boto3 >= 1.42.5. See Use Workload Identity Federation with OIDC for the full setup guide.
Use the list_objects_v2 method to sum the size of all objects in the bucket. Replace [BUCKET-NAME] with the name of your bucket.
Use the CoreWeave fork of s5cmd with AI Object StorageThe upstream s5cmd uses path-style addressing with custom endpoint URLs. AI Object Storage doesn’t support path-style addressing and requires virtual-hosted style URLs. Use the CoreWeave fork of s5cmd, which is compatible with AI Object Storage and can safely replace any existing s5cmd installation. For setup and usage, see Migrate data to AI Object Storage.
To report the usage of a bucket, use the du (disk usage) command with the --humanize parameter.Replace [BUCKET-NAME] with the name of your bucket.
Report bucket usage with s5cmd
s5cmd --endpoint-url https://cwobject.com \ du --humanize 's3://[BUCKET-NAME]/*'