DroplineDownload

Amazon S3

Engine: S3-compatible (AWS SigV4) · Preset: Amazon S3

Configuration

Settings → Hosts → + → Amazon S3.

Field Value
Endpoint leave empty — Dropline then uses https://s3.<region>.amazonaws.com
Region The bucket's region, exactly: us-east-1, eu-central-1, ap-northeast-1
Bucket The bucket name alone, e.g. my-assets
Access Key ID AKIA… from the IAM user
Secret Access Key The matching secret — goes to the keychain
Public base URL Optional. Your CloudFront domain, if you have one
Object key template images/{{date}}/{{uuid}}.{{ext}}

The region must match the bucket. AWS validates the region inside the signature, so a mismatch fails with SignatureDoesNotMatch rather than a redirect. Find it in the S3 console's bucket list.

Create the bucket

  1. S3 console → Create bucket, pick a name and a region.
  2. Under Block Public Access, uncheck Block all public access if you want bare links to work in a browser. Leave it on if you will serve exclusively through CloudFront with an origin access control.
  3. Create it.

A minimal IAM user

Give Dropline a key that can put objects and do nothing else. In IAM → Users → Create user, no console access, then attach an inline policy:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DroplineUpload",
      "Effect": "Allow",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::my-assets/images/*"
    }
  ]
}

Then Security credentials → Create access key → Application running outside AWS. The secret is shown once.

Note the Resource is scoped to the same prefix as the key template. If you change one, change the other.

Make objects readable

For a bare https://…amazonaws.com/… link to work, the object must be publicly readable. The usual way is a bucket policy:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "PublicReadImages",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-assets/images/*"
    }
  ]
}

This grants read to the world for that prefix only — writing still requires the IAM key.

With Public base URL empty, Dropline returns the path-style URL it uploaded to:

text
https://s3.eu-central-1.amazonaws.com/my-assets/images/2026/08/19/a1f3….png

That works, but it is long, it names your bucket and it is not cached. Put CloudFront in front and set the public base URL to the distribution's domain:

text
https://cdn.example.com

The link then becomes:

text
https://cdn.example.com/images/2026/08/19/a1f3….png

Dropline joins the base and the key with a single / and does nothing else, so if your distribution serves the bucket under a sub-path, include it in the base.

CORS

Only needed if a browser will fetch these files with JavaScript — a plain <img> tag does not need CORS. If you do:

json
[
  {
    "AllowedHeaders": ["*"],
    "AllowedMethods": ["GET"],
    "AllowedOrigins": ["https://example.com"],
    "MaxAgeSeconds": 3600
  }
]

Dropline itself is a native app and is not subject to CORS at all.

Verify

Click Test Upload. On success, open the returned URL in a browser — that proves both the write path and the read path. A success followed by a 404 in the browser means the object is not public, or the base URL is wrong; see Troubleshooting.

Common problems

Symptom Cause
SignatureDoesNotMatch Region does not match the bucket, or the secret has stray whitespace
HTTP 403 with no signature complaint The IAM policy does not allow s3:PutObject on that prefix
HTTP 404 Bucket name misspelled, or it lives in another region
Upload works, link 404s Block Public Access still on, or no bucket policy
On this page