One bucket · one gate · a key per app
One gate in front of the bucket.
Every app that takes uploads writes its own bucket policy, size limits, type checks and sanitising, and nobody decides when anything gets deleted. gatething is one gate: a key per app, the rules in one file, and a sanitize endpoint anything can call.
Act I
Every app, its own bucket rules.
A shop wants customers to upload a photo. Storing a file safely turns out to be five decisions, and every app makes them again.
01 · A bucket
A bucket, and its policies.
Create it, write a CORS policy in JSON, a lifecycle rule, and an access key the app keeps in its environment. For this app only.
02 · The checks
Then the checks, in the app.
A size limit, allowed types, a filename that won't break anything, and metadata stripping you wrote yourself. Is it right? Probably.
03 · The next app
Then again, slightly different.
The booking app copied the handler and changed it. Now one app allows SVG, and an SVG can carry a script.
04 · What's in there?
And the bucket only grows.
Nobody decided how long a file lives, so every file lives forever, and nobody knows which ones are safe to delete.
That was two apps.
- policies by hand
- 2
- rules copied into code
- 3
- holes
- 2
- files with an expiry
- 0
Here's the same upload, through the gate.
Act II
The gatething way.
One bucket, and gatething in front of it. Apps never hold a bucket key; they hold a gate key, and the gate applies their rules.
01 · The rules, once
Every app's rules in one file.
How big, which types, how long it lives and how it's cleaned, per app. Defaults cover what nobody should allow, like SVG.
02 · A key per app
A key that can only reach its own files.
The shop's key writes to the shop's prefix and nowhere else. Revoking it doesn't touch any other app.
03 · Upload through the gate
The app sends the file. The gate does the rest.
Size, type, sanitising and an expiry date are applied on the way in. The app gets back an id and what was cleaned.
04 · Sanitize, without storing
And sanitising on its own.
Anything can send a file or some input to the sanitize endpoint and get the clean version back, stored or not. The rules live in one service instead of in every app.
Act III
What the gate decides.
Storing a file is a handful of decisions. gatething makes them once, writes them down, and applies them to everything that stores a file.
-
1
What gets in
A size limit and a list of types per app, and defaults for what nothing should accept. The check happens at the gate, not in every handler.
-
2
How it's cleaned
Metadata stripped, names normalised, scripts refused. The same policies behind uploads are open on their own at
/api/v1/sanitize. -
3
How long it lives
Every file gets an expiry when it arrives, and the gate deletes it on schedule. The bucket is maintained, not just filled.
| Measure | Per app | gatething |
|---|---|---|
| Bucket keys in apps | one per app | none |
| Size and type limits | copied, then drifted | one file |
| Sanitising | hand-rolled per app | one service, one endpoint |
| Deleting old files | nobody decided | an expiry on every file |
Storing files in more than one app?
Tell me what your apps take in. gatething is where every project here will put its files.