Skip to content

Spaces buckets, and the keys that reach them

DigitalOcean Spaces is an S3-compatible object storage service for storing and serving large amounts of data, billed as one subscription across all of a team's buckets. Duskwatch is an independent iPhone app for DigitalOcean, in development; it lists your Spaces buckets, shows which access keys can reach each one, checks the CDN and its certificate, and shows what Spaces costs this month, without ever reading your files.

Updated

Buckets at a glance

DigitalOcean's main API has no endpoint that lists buckets, so the app gathers them from three places it can read: your projects, your CDN endpoints, and the buckets named in your access keys. Each bucket gets a screen with the DigitalOcean status for Spaces in its region, its CDN, this month's cost and the keys that can reach it.

The region is known only for buckets with a CDN endpoint, and the screen says so rather than guessing. Size, files and bucket settings need the S3 API, which the app does not use; the bucket screen points you to DigitalOcean for those.

Full-access and limited keys

Access keys are where a Spaces leak usually starts: a full-access key copied into a CI job or a laptop years ago reaches every bucket in the team. The bucket screen lists the keys limited to it, each with its permission and age, such as "Read · 6 mo old", and counts the team's full-access keys below them. When the team has full-access keys, the app adds a finding: "1 full-access key can reach every bucket", with the hint to prefer keys limited to the buckets they need. Secrets are never shown; DigitalOcean only returns a secret when the key is created.

Spaces key permissions and how the app shows them
PermissionWhat it reachesHow the app shows it
Full accessAll buckets, including creating and configuring themCounted below the list, plus a finding for the team
Limited: readOnly the buckets chosen for itRead, with its age
Limited: read and writeOnly the buckets chosen for it, with read, write and deleteRead and write, with its age
No key limited to the bucketOnly full-access keys, if any, can reach it"No key limited to this bucket"
  • Full-access keys allow all supported S3 APIs on all buckets, including bucket creation and configuration and listing every bucket. Limited keys grant Read or Read/Write/Delete on specific buckets, and the secret appears only once.

    DigitalOcean docs: manage Spaces access (external link), verified

  • In the API, key permissions are read, readwrite or fullaccess. A fullaccess permission cannot be mixed with bucket-scoped ones and takes priority, and the secret key is returned only in the creation response.

    DigitalOcean API reference: Spaces keys (external link), verified

The CDN and its certificate

For a bucket behind the Spaces CDN, the screen shows the edge host, the custom domain, the cache time and the certificate with its expiry. Two cache times get a finding: "CDN caches for only 1 minute", which sends most requests back to the bucket, and "CDN caches for 7 days", where updated files can take up to a week to show unless you purge the cache in DigitalOcean. A certificate on the custom domain that ends soon or failed shows here and on its own certificate screen.

Findings on a bucket, with synthetic names

Certificate for static.example.com expires in 9 d · The CDN custom domain stops serving HTTPS without it

CDN caches for 7 days · Updated files can take up to a week to show

This month's Spaces cost

The cost section reads the month's invoice preview and shows the Spaces line for all buckets, plus this bucket's share when DigitalOcean breaks it out. When the month's Spaces charges pass the base subscription, a finding notes that storage or transfer beyond the included allowance is billed per GiB. If there is no Spaces line yet, the screen says "No Spaces charges yet".

  • The Spaces subscription includes 250 GiB of storage across all buckets and 1,024 GiB of outbound transfer; more is billed per GiB. Billing begins with your first bucket and ends when you destroy all of them.

    DigitalOcean docs: Spaces pricing (external link), verified

What Duskwatch doesn't do here

  • No browsing, uploading, downloading or deleting files.
  • No bucket size, object counts or bucket settings, which need the S3 API.
  • No creating or revoking access keys, and never a secret key.
  • No CDN cache purge.
  • No push for Spaces: these are findings in the app.

Questions

  • Can one Spaces key reach every bucket?

    Yes, a full-access key reaches all buckets in the team. Duskwatch counts them and flags "1 full-access key can reach every bucket".

  • Can I browse files in a bucket?

    No. The app never uses the S3 API, so it does not list, open or change files; open the bucket in DigitalOcean for that.

  • Does it show the CDN certificate's expiry?

    Yes. The CDN section shows the custom domain's certificate and when it ends, and flags it when it ends within 14 days or has failed.

  • Does it show my secret keys?

    No. It shows key names, permissions and ages; DigitalOcean returns a secret only when a key is created.

  • Will I get a push about Spaces?

    No. Spaces problems are findings on the bucket screen. A DigitalOcean incident in your regions still sends its own push if you turn alerts on.

Duskwatch is in development. Join the waitlist to hear when it's on the App Store.

We'll email you once when Duskwatch is on the App Store. One-click unsubscribe. How we handle your data

Basic monitoring is free; alerts, most actions and advanced features are part of Duskwatch Pro.