Storage

Google Cloud Storage

Store watermarked files in your own Google Cloud Storage bucket. Grant Etchv access without a private key (recommended) or with a service account key.

Connect with keyless Workload Identity Federation or a service account JSON key. Federation lets Etchv sign in to Google Cloud with its AWS identity, so no private key is shared. Keyless access uses short-lived tokens. It works even when your organization blocks service account keys.

Grant access to your bucket

Create a service account used only for Etchv. On the bucket, grant it a custom role with storage.objects.create and storage.objects.get. Limit the role to your prefix and the small test file (probe) Etchv uses to check the connection. See Google’s permission reference.

  1. Enable the IAM, IAM Service Account Credentials and Security Token Service APIs.
  2. Create a dedicated workload identity pool with an AWS provider.
  3. In Dashboard storage, choose Google Cloud Storage → Keyless, or send this to POST /storage/destinations with a storage:write owner/admin key:
JSON
{
  "name": "Production GCS",
  "provider": "gcs",
  "bucket": "YOUR_BUCKET",
  "prefix": "etchv",
  "visibility": "private",
  "gcs_auth": "workload_identity",
  "gcs_workload_identity_provider": "projects/123456789/locations/global/workloadIdentityPools/etchv-pool/providers/aws-etchv",
  "gcs_service_account": "etchv-storage@your-project.iam.gserviceaccount.com"
}

Use the project number in the provider resource. Save the returned aws_principal_arn and gcs_subject. The subject is unique to your Etchv organization and is the same for all its destinations.

Trust the exact Etchv identity

For returned role arn:aws:iam::AWS_ACCOUNT_ID:role/ROLE_NAME, configure:

SettingValue
AWS accountAWS_ACCOUNT_ID
Attribute mappinggoogle.subject = assertion.arn.extract('assumed-role/ROLE_NAME/{session}')
Attribute conditionassertion.arn.startsWith('arn:aws:sts::AWS_ACCOUNT_ID:assumed-role/ROLE_NAME/etchv-')
AWS account
Value
AWS_ACCOUNT_ID
Attribute mapping
Value
google.subject = assertion.arn.extract('assumed-role/ROLE_NAME/{session}')
Attribute condition
Value
assertion.arn.startsWith('arn:aws:sts::AWS_ACCOUNT_ID:assumed-role/ROLE_NAME/etchv-')

Grant Workload Identity User (roles/iam.workloadIdentityUser) on the service account to this exact principal, using the returned subject:

Text
principal://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/subject/GCS_SUBJECT

Click Test connection or call POST /storage/destinations/{id}/verify. The probe checks write and read access. IAM changes can take a few minutes to apply, so wait and try again if needed. A destination that is not verified cannot receive new requests. See Google’s AWS federation guide.

Store outputs

Pass the destination ID in your embedding request. SDK storage options work unchanged.

VisibilityReturned location
Privategs://bucket/key
Already publicURI plus https://storage.googleapis.com/bucket/key
Private
Returned location
gs://bucket/key
Already public
Returned location
URI plus https://storage.googleapis.com/bucket/key

Etchv does not change IAM or ACLs. Generation preconditions prevent overwrites: Etchv writes only when no object with that name exists yet. Your bucket controls how long files are kept. Deleting an Etchv record does not delete its file in your bucket.

Optional: service account JSON keys

Choose Service account JSON key, or use these request fields instead of the federation fields:

FieldValue
gcs_auth"service_account_key"
credentialsFull service account JSON encoded as a string
gcs_auth
Value
"service_account_key"
credentials
Value
Full service account JSON encoded as a string

The key must use https://oauth2.googleapis.com/token. Etchv encrypts credentials and never returns them. A general Google API key will not work.

Rotate credentials or change authentication mode

Replace credentials with PATCH /storage/destinations/{id}, then verify before revoking the old key. Keyless destinations do not accept credential uploads. You can't change the authentication mode or provider details later. To change them, create a new destination.

View source on GitHub

Your privacy, your choice

We use essential cookies to keep Etchv working. Optional analytics helps us improve the site. Analytics is on by default; you can turn it off in preferences. PostHog loads only if you accept all. Privacy policy

ETCHV

Privacy preferences

Choose what you allow on this browser. Analytics is enabled by default. You can turn it off, and change your choice at any time.

Essential

Always active

Supports secure sign-in, account sessions, site security, and remembering your privacy choice. These are needed for Etchv to work.

Analytics

Helps us understand visits and improve the website using page-view and device statistics, which do not use cookies. PostHog also measures visits and campaigns and may set cookies; it loads only after you save a choice with analytics on. Turning this off stops future analytics events.

We do not load advertising scripts. Meeting calendars load only when you open them. These preferences do not change your account, watermarking requests, or asset storage.

Your choice is remembered for 180 days on this browser. Privacy policy