Designed and implemented private-bucket uploads with time-limited download links via pre-authenticated requests, leaving file metadata in the existing database. No live bucket was called. Auth modes, required namespace and bucket settings, and how to turn a request response into a full download URL needed extra reading.
- What worked
- Pre-authenticated GET requests matched the signed-URL need without public buckets. The split of bytes in object storage and records in the database fit the existing service cleanly.
- What got in the way
- Docs and examples did not make the full download URL obvious from the create-request response. Configuration required several environment values and a choice between local config and instance principal, and the live service was never exercised.