Skip to content
  • There are no suggestions because the search field is empty.

How to integrate BinariiDSM with Impossible Cloud Storage

This guide explains how to prepare your storage account, create a secure service user, and add Impossible Cloud Storage as a storage endpoint in BinariiDSM.

BinariiDSM (Data Security Management) is a secure file management and virtual data room solution by Binarii Labs. It encrypts, fragments, and distributes data across user-controlled storage endpoints, ensuring no complete file is held in a single location. Impossible Cloud Storage is supported as a native cloud location in BinariiDSM. Once configured, it appears in the cloud location overview and BinariiDSM will automatically distribute uploaded files across all configured storage endpoints, including Impossible Cloud. 

Prerequisites

  • An Impossible Cloud Storage Account.
  • BinariiDSM installed and accessible.

Step 1: Create the bucket(s)

BinariiDSM is designed around three storage endpoint locations. Three endpoints are the standard setup and are all that's required for DSM's redundancy and availability model. Decide how many of them Impossible Cloud Storage will provide:

  • One endpoint: Impossible Cloud Storage is one of three locations, alongside two other providers. Create one bucket.
  • All three endpoints: Impossible Cloud Storage provides the full endpoint set. Create three buckets, each in a different region, so that the fragments of a file are stored in separate locations.

To create a bucket:

  1. Log in to the Impossible Cloud Storage Console and navigate to Buckets.
  2. Click Add Bucket.
  3. Enter a bucket name, for example my-dsm-bucket-1. See What are the rules for naming buckets?
  4. Select the region for the bucket. The region cannot be changed after the bucket is created.
  5. Leave Versioning and Object Lock disabled.
  6. Click Add.

If you are creating three buckets, repeat these steps and select a different region each time. Example layout:

Bucket Region Location
my-dsm-bucket-1 eu-central-2 Europe (Frankfurt)
my-dsm-bucket-2 eu-west-1 Europe (Amsterdam)
my-dsm-bucket-3 eu-north-1 Europe (Copenhagen)

For the full list of regions, see Storage Console URLs and API Endpoints. Choose regions that match your data residency requirements, since each region stores data in a different country.

Bucket versioning and Object Lock are not officially supported by BinariiDSM, since DSM manages its own versioning and deletion logic at the application level. 

Step 2: Create a secure service user

BinariiDSM should connect with a dedicated IAM user that has programmatic access only and permissions limited to the DSM buckets. Do not use root user credentials.

  1. In the Impossible Cloud Storage Console, navigate to Users and click Add user.
  2. Enter a descriptive username, for example binarii-dsm@example.com.
  3. Uncheck Enable Console Access. The user then has programmatic access only and cannot log in to the console.
  4. Select the new user from the user list and open the Inline Policies tab.
  5. Click Create New Policy, enter a name such as binarii-dsm-access, and paste the policy below into the JSON editor. Replace the bucket names with your own. If you use a single bucket, remove the two extra entries from each Resource list.
  6. Open the Access Keys tab and click Add access key. Copy the access key and secret key, or download them as CSV, and store them securely. The secret key is only shown once.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "BinariiDSMBucketAccess",
"Effect": "Allow",
"Action": [
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::my-dsm-bucket-1",
"arn:aws:s3:::my-dsm-bucket-2",
"arn:aws:s3:::my-dsm-bucket-3"
]
},
{
"Sid": "BinariiDSMObjectAccess",
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject",
"s3:AbortMultipartUpload"
],
"Resource": [
"arn:aws:s3:::my-dsm-bucket-1/*",
"arn:aws:s3:::my-dsm-bucket-2/*",
"arn:aws:s3:::my-dsm-bucket-3/*"
]
}
]
}

Step 3: Add Impossible Cloud as a Cloud Location in BinariiDSM

Each bucket is added as a separate Cloud Location. If you created three buckets in Step 1, complete this step three times, once per bucket.

Open BinariiDSM and navigate to Settings. Click Manage Storage Endpoints.

In the Add Location dialog:

  1. Under Public Clouds, select Impossible Cloud from the dropdown.
  2. Enter your bucket name in the Bucket Name field.
  3. Enter the service user's credentials from Step 2 in the Access Key ID and Secret Access Key fields.
  4. Select the region your bucket was created in from the Region dropdown.
  5. Click Add.

When adding three buckets, use the same access key for each location, but make sure the Bucket Name and Region match each bucket.

Step 4: Verify the Cloud Locations

After clicking Add, the new location appears in the cloud location overview. BinariiDSM includes it as one of the endpoints across which uploaded files are automatically distributed.

If you created three buckets, check that all three locations are listed in the overview, each with its own bucket and region.