Storage and cloud settings
Govern reusable source connections and storage behavior at workspace scope.
Govern reusable source connections and storage behavior at workspace scope.
Cloud Storage is configured once at workspace scope and then used from Data Space to create a connected cloud folder. Separate connection administration from the folder-level source scope that data operators actually import or synchronize.
Create a dedicated organization-owned cloud identity with the minimum bucket and prefix permissions required.
Record the connection owner, environment, rotation schedule, revocation procedure, and approved secret store.
Confirm the current Unitlab connection mode and downstream source-availability requirements.

Open Workspace Settings › Cloud storage and choose Add cloud storage. Select the provider and enter the display name, bucket, access key ID, secret access key, region, and optional prefix. Credentials in this product capture are intentionally blank.
The current Add Cloud Storage dialog offers:
Amazon S3;
Google Cloud Storage;
Azure Blob Storage;
MinIO;
DigitalOcean Spaces;
Cloudflare R2;
Wasabi;
Backblaze B2;
custom S3-compatible storage.
The exact credential fields vary by provider, but the current configuration model includes a display name, bucket or container, credentials, region where applicable, and an optional prefix or sub-path. A prefix can restrict Unitlab to a controlled part of a larger bucket.
The SDK can list safe storage metadata, browse a prefix, create a cloud-backed Unitlab folder, synchronize it, and import selected files or directory paths into a project. Cloud credentials are not returned by SDK list or browse operations.
Cloud folders are created from New Folder ▾ → Add Cloud Folder:
The user chooses a provider/integration.
The user selects an optional bucket sub-prefix and display name.
Unitlab creates a root folder representing that cloud location.
Opening it registers the first bucket level automatically if it has never been synchronized.
Immediate files appear as normal assets; child prefixes appear as child cloud folders.
The user can run Sync to refresh the current level.
Cloud folders reference customer storage; they do not copy the source bytes into Unitlab storage. Unitlab stores the object reference and a small preview where needed. Cloud folders display a provider badge, Synced state, and provider/resource path. Their contents are read-only mirrors for organization, so drag-move is disabled.
Cloud-folder Sync means “refresh this bucket prefix in Data Assets.” It is not project-to-dataset synchronization. A project receives cloud-backed content only through normal import/upload behavior or by attaching a frozen published dataset version.
Display name
Use a durable source-system and environment name that operators can distinguish.
Prefix
Restrict the connection to the smallest approved sub-path.
Identity
Use a dedicated service identity, not a personal cloud credential.
Lifecycle
Changing or removing a connection can affect ingestion and later source retrieval; reconcile dependencies first.
Secrets
Never place access keys, signed URLs, private bucket paths, or regulated filenames in documentation or logs.
The screenshot shows the field structure only. Never populate or publish a real access key ID, secret access key, private prefix, or signed URL in documentation.
Create the connected cloud folder in Data Space.
Curate the processed content inside that folder.
Review credential ownership and rotation on schedule.
Explore related Unitlab capabilities: enterprise data annotation workflows · Unitlab’s data curation platform