BucketDeskOpen BucketDesk
BUCKETDESK JOURNAL

Build a better file experience without hiding the tradeoffs.

Practical product and engineering guidance for teams working with business files in object storage.

LATEST WRITING

Useful answers before product claims.

Architecture6 min read

Your S3 Files Stay in Your AWS Account: How BucketDesk Uses CloudFormation for Secure Access

How customer-controlled CloudFormation stacks, scoped IAM roles, and temporary credentials connect BucketDesk to S3—and where optional processing creates temporary copies.

Read article
Security9 min read

Secure AWS Access Without Sharing Access Keys: How BucketDesk Uses IAM Roles and External IDs

How customer-owned IAM roles, temporary STS credentials and connection-specific External IDs protect cross-account access in BucketDesk.

Read article
Engineering6 min read

Inside BucketDesk: the AWS architecture behind your file workspace

How Laravel, Fargate, PostgreSQL and temporary AWS access turn an S3 bucket into a file workspace, without building a second search index.

Read article
Product decisions6 min read

When Storage Browser for Amazon S3 is the better choice

Choose the AWS component when the job is direct S3 file management. Choose a workspace when people need to understand and safely process what the objects contain.

Read article
Operations5 min read

Where the productivity gain actually comes from

The value is not a prettier bucket listing. It is fewer handoffs between finding an object, opening it, understanding it and completing the next safe action.

Read article
Engineering8 min read

A cost conscious technical stack for an S3 file workspace

Start with a modular application, browser native previews and one isolated worker. Add managed media and search infrastructure only after demand justifies them.

Read article
Product architecture7 min read

Automation, agents and the approval boundary

Agents should understand content and propose decisions. Deterministic workflow policy should control what can happen to customer files.

Read article
Security6 min read

Connect customer AWS accounts without collecting access keys

Use customer IAM roles, an external ID and temporary STS credentials so every workspace receives bounded, expiring access.

Read article

Editorial standard

We do not invent benchmarks, customers or compliance claims. Technical articles link to primary documentation and distinguish shipped behavior from product direction.