Before uploading encrypted files, the first thing to do is to create a bucket. The following examples assume that you have a Cloud VM Set containing four VMs called client-1, finance, database-server, and acl-server.

Let's assume that we want to move encrypted files between these four VMs (in any direction) via S3 buckets. The first thing we must do is to create a bucket. Bucket names have rules as defined by Amazon, which you can find here: Amazon S3 Bucket Restrictions

Now let's create a bucket called hcs-aws-bucket.

# hcs3 create hcs-aws-bucket

The hcs3 command creates a default KeyID that is used to encrypt files when they are uploaded to S3. The name of the default KeyID is derived by prepending the bucket name with the characters hcs3. This is done so that the admin can differentiate between general KeyIDs and KeyIDs that are created for S3 usage.

Tip: You can also create the bucket in the AWS console. For details, see your AWS documentation.

The list of S3 buckets created can be obtained by running the following command:

# hcs3 list
Buckets
---------------------------------------------------
hcs-aws-bucket

The S3 bucket created by hcs3 can be deleted by using the following command:

# hcs3 delete <bucketname>

To remove a bucket, the bucket must first be empty. If not, you will see the following warning:

# hcs3 delete hcs-aws-bucket
Error deleting bucket: The bucket you tried to delete is not empty

If the bucket is empty and you request that the bucket be deleted, we delete both the bucket and the KeyID, so be warned: if you do use that KeyID to encrypt other files, you will no longer be able to decrypt those files. We highly recommend that you do not use S3 KeyIDs for any other purpose than with the S3 bucket for which they were created.