---
title: "STACKIT Object Storage"
description: "S3-compatible, highly available object storage providing unlimited bucket scaling and WORM ransomware protection."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Object Storage", "S3", "Buckets", "Storage", "WORM"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/advisory/assetcontainer/stackit/stackit-service-object-storage/"
source_file: "docs/advisory/assetcontainer/stackit/stackit-service-object-storage.mdx"
---

STACKIT Object Storage provides scalable S3-compliant object storage for unstructured data and backups.

## Service Overview
- **S3 API Compatibility**: Natively compatible with standard S3 SDKs, Veeam Backup, and AWS CLI tools.
- **Object Lock Defense**: Immutability locks protect backup datasets against ransomware deletion or alteration.
- **No Egress Bandwidth Fees**: Pay-as-you-go pricing based purely on stored volume without ingress/egress charges.

## Technical Details
- **Compliance**: 100% GDPR-compliant storage hosted inside German data centers (ISO 27001, BSI C5).
- **Management**: Bucket creation, credential generation, and lifecycle rules controlled via Portal and Terraform.

## Limits and Regions

The values below come from the STACKIT documentation and update themselves.

> From the STACKIT docs: [Limits of Object Storage › General limits](https://docs.stackit.cloud/products/storage/object-storage/reference/limits-object-storage/#general-limits) (Source updated 21.07.2026, copied 05.10.2026)

| Limit | Value | Note |
| --- | --- | --- |
| Max. Object size: | 5 TB | Object Storage Objects can range in size from 1 byte to 5 terabytes. |
| Max. Part Size (multipart upload) | 5 GB | Max size of one part, using multipart upload. |
| Max. number of parts (multipart upload) | 10.000 | Max number of parts, using multipart upload. |
| Max. Bucket size: | no limit | See “**tenant quota”** |
| Max. Versions per Object | 1000 | If object versioning is used this limitation is applied. |
| Tenant Quota | 500 TB | Can be adjusted on request. Contact our Support |
| Max. Objects per Bucket | no limit |  |
| Max. Buckets per STACKIT Project | 1000 | per STACKIT project |
| Credentials Groups | 1000 | per STACKIT project |
| Max. Read/Write Requests per Second | 2500 | per STACKIT project |
| Max. Up-/Download bandwidth | 500 MB/s | per STACKIT project |
| Max. Concurrent Read/Write Requests per Second | 500 | per STACKIT project |
| Bucket Policy size limit | 20,480 Bytes | max. size of a bucket policy |
| Max. Retention for Compliance Lock | 365 days | Max. time that can be set to lock objects |

> From the STACKIT docs: [Architecture of Object Storage › Regions and availability zones](https://docs.stackit.cloud/products/storage/object-storage/basics/architecture/#regions-and-availability-zones) (Source updated 21.07.2026, copied 05.10.2026)

Object Storage is available in dedicated regions. Within each region, your data is automatically replicated across all three **Availability Zones**. This replication happens transparently, you do not need to configure it.

The following diagram shows the structure of Object Storage in an example region (EU01):

Each region has a dedicated **endpoint URL**. You need to use the endpoint of the region where your bucket resides.

| Region | Endpoint URL |
| --- | --- |
| EU01 | `https://object.storage.eu01.onstackit.cloud` |
| EU02 | `https://object.storage.eu02.onstackit.cloud` |

All STACKIT Object Storage endpoints support TLS 1.3 encryption.

Buckets are region-specific. You can not move a bucket between regions after creation.

## Limitations & Constraints
- **Public API Endpoints Only**: Access routes through public regional S3 endpoints (private SNA endpoints in development).

<LinkCard title="STACKIT Object Storage Documentation" href="https://docs.stackit.cloud" />
