Spaces buckets, and the keys that reach them
DigitalOcean Spaces is an S3-compatible object storage service for storing and serving large amounts of data, billed as one subscription across all of a team's buckets. Duskwatch is an independent iPhone app for DigitalOcean, in development; it lists your Spaces buckets, shows which access keys can reach each one, checks the CDN and its certificate, and shows what Spaces costs this month, without ever reading your files.
Updated
Buckets at a glance
DigitalOcean's main API has no endpoint that lists buckets, so the app gathers them from three places it can read: your projects, your CDN endpoints, and the buckets named in your access keys. Each bucket gets a screen with the DigitalOcean status for Spaces in its region, its CDN, this month's cost and the keys that can reach it.
The region is known only for buckets with a CDN endpoint, and the screen says so rather than guessing. Size, files and bucket settings need the S3 API, which the app does not use; the bucket screen points you to DigitalOcean for those.
Spaces is an S3-compatible service for storing and serving large amounts of data.
Full-access and limited keys
Access keys are where a Spaces leak usually starts: a full-access key copied into a CI job or a laptop years ago reaches every bucket in the team. The bucket screen lists the keys limited to it, each with its permission and age, such as "Read · 6 mo old", and counts the team's full-access keys below them. When the team has full-access keys, the app adds a finding: "1 full-access key can reach every bucket", with the hint to prefer keys limited to the buckets they need. Secrets are never shown; DigitalOcean only returns a secret when the key is created.
| Permission | What it reaches | How the app shows it |
|---|---|---|
| Full access | All buckets, including creating and configuring them | Counted below the list, plus a finding for the team |
| Limited: read | Only the buckets chosen for it | Read, with its age |
| Limited: read and write | Only the buckets chosen for it, with read, write and delete | Read and write, with its age |
| No key limited to the bucket | Only full-access keys, if any, can reach it | "No key limited to this bucket" |
Full-access keys allow all supported S3 APIs on all buckets, including bucket creation and configuration and listing every bucket. Limited keys grant Read or Read/Write/Delete on specific buckets, and the secret appears only once.
DigitalOcean docs: manage Spaces access (external link), verified
In the API, key permissions are read, readwrite or fullaccess. A fullaccess permission cannot be mixed with bucket-scoped ones and takes priority, and the secret key is returned only in the creation response.
DigitalOcean API reference: Spaces keys (external link), verified
The CDN and its certificate
For a bucket behind the Spaces CDN, the screen shows the edge host, the custom domain, the cache time and the certificate with its expiry. Two cache times get a finding: "CDN caches for only 1 minute", which sends most requests back to the bucket, and "CDN caches for 7 days", where updated files can take up to a week to show unless you purge the cache in DigitalOcean. A certificate on the custom domain that ends soon or failed shows here and on its own certificate screen.
Certificate for static.example.com expires in 9 d · The CDN custom domain stops serving HTTPS without it
CDN caches for 7 days · Updated files can take up to a week to show
The Spaces CDN edge cache time is one hour by default and can be changed at any time; purging clears files from all edge caches so the next request fetches a fresh copy.
DigitalOcean docs: manage the Spaces CDN cache (external link), verified
A custom subdomain on the Spaces CDN must have an SSL certificate: a managed Let's Encrypt one when DigitalOcean hosts the DNS, or one you upload.
DigitalOcean docs: enable the Spaces CDN (external link), verified
This month's Spaces cost
The cost section reads the month's invoice preview and shows the Spaces line for all buckets, plus this bucket's share when DigitalOcean breaks it out. When the month's Spaces charges pass the base subscription, a finding notes that storage or transfer beyond the included allowance is billed per GiB. If there is no Spaces line yet, the screen says "No Spaces charges yet".
The Spaces subscription includes 250 GiB of storage across all buckets and 1,024 GiB of outbound transfer; more is billed per GiB. Billing begins with your first bucket and ends when you destroy all of them.
What Duskwatch doesn't do here
- No browsing, uploading, downloading or deleting files.
- No bucket size, object counts or bucket settings, which need the S3 API.
- No creating or revoking access keys, and never a secret key.
- No CDN cache purge.
- No push for Spaces: these are findings in the app.
Questions
Can one Spaces key reach every bucket?
Yes, a full-access key reaches all buckets in the team. Duskwatch counts them and flags "1 full-access key can reach every bucket".
Can I browse files in a bucket?
No. The app never uses the S3 API, so it does not list, open or change files; open the bucket in DigitalOcean for that.
Does it show the CDN certificate's expiry?
Yes. The CDN section shows the custom domain's certificate and when it ends, and flags it when it ends within 14 days or has failed.
Does it show my secret keys?
No. It shows key names, permissions and ages; DigitalOcean returns a secret only when a key is created.
Will I get a push about Spaces?
No. Spaces problems are findings on the bucket screen. A DigitalOcean incident in your regions still sends its own push if you turn alerts on.