Remote S3 bucket

Keep older call recordings in your own S3-compatible storage and let CommPeak Dialer play them from there when they are no longer in CommPeak storage.

CommPeak Dialer stores every new call recording in CommPeak storage for the retention period you chose. With Remote S3 Storage, you connect a bucket that you own as a second, read-only location. When someone opens a recording that is no longer in CommPeak storage, the Dialer looks for it in your bucket and plays it from there. Playback, download, public recording links, and Speech to Text keep working for those recordings.

This article explains which storage you can use, how to prepare the bucket and the credentials, how to copy the recordings into it, and how to connect and test it in the Dialer.

In this article:

📘

NOTE

CommPeak only reads from your bucket. The Dialer never uploads, changes, or deletes anything there. New recordings are always saved to CommPeak storage, and your retention period, billing, and encryption settings are not affected. See Call Recording: Billing, Storage, and Compliance.

How It Works

  1. A user opens, downloads, or transcribes a recording.
  2. The Dialer looks for the file in CommPeak storage first. If it is there, nothing else happens.
  3. If the file is not in CommPeak storage and Remote S3 Storage is enabled, the Dialer looks for the same file in your bucket, downloads it, and serves it.
  4. If the file is in neither place, the recording is shown as unavailable.

Only the S3 API is supported. Storage that is reachable only through another protocol (FTP, SFTP, WebDAV, a file share, Google Drive, Dropbox, and similar) cannot be connected. The endpoint must use HTTPS.

Preparing Your Bucket

To prepare your bucket:

  1. Create a bucket (or choose an existing one) in your storage provider. Keep the bucket private.
  2. Create credentials that the Dialer will use. They need read-only access to the bucket:
    • permission to read files (in S3 terms, s3:GetObject) — required;
    • permission to list the bucket (s3:ListBucket) — recommended, used by the connection test.
      No write or delete permission is needed, and we recommend not granting any. See Setting the required permissions below for ready-to-use examples.
  3. Copy the access key and the secret key. Most providers show the secret only once.

Setting the Required Permissions

The Dialer needs two permissions on your bucket, both read-only:

PermissionS3 nameNeeded for
Read filess3:GetObjectPlaying, downloading, and transcribing recordings. Required.
List filess3:ListBucketThe connection test: it lists the first files under your path prefix and reads one of them to prove the setup. Recommended. Playback works without it.

Nothing else is needed: no write, delete, ACL, or "list all buckets" permission.

Amazon S3

Attach one of the following policies to the IAM user whose access key you enter in the Dialer. Replace my-bucket with your bucket name.

Recommended: read and list. Lets the Dialer play recordings and lets the connection test show your files and prove the read permission.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ReadRecordings",
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-bucket/*"
    },
    {
      "Sid": "ListBucket",
      "Effect": "Allow",
      "Action": "s3:ListBucket",
      "Resource": "arn:aws:s3:::my-bucket"
    }
  ]
}

Minimal: read only. Enough for playback. The connection test then reports that listing is not permitted and skips the file check.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ReadRecordings",
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-bucket/*"
    }
  ]
}

Optional: limit both permissions to one folder. If your recordings sit under a folder such as archive/, narrow the policy to it and enter archive/ as the Path prefix in the Dialer. For listing, the folder is a condition on the request, not part of the bucket resource.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ReadRecordingsInFolder",
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-bucket/archive/*"
    },
    {
      "Sid": "ListFolderOnly",
      "Effect": "Allow",
      "Action": "s3:ListBucket",
      "Resource": "arn:aws:s3:::my-bucket",
      "Condition": {
        "StringLike": {
          "s3:prefix": ["archive/*", "archive"]
        }
      }
    }
  ]
}

Points that often make a policy fail silently:

  • s3:GetObject applies to the objects, so its resource ends with /*. s3:ListBucket applies to the bucket itself, so its resource has no /*. Swapping them is the most common mistake.
  • s3:GetObject already covers reading file details such as size and date. There is no separate permission for that.
  • The Dialer does not need s3:ListAllMyBuckets. Every request names your bucket.
  • If your bucket uses SSE-KMS encryption, the IAM user also needs kms:Decrypt on that key. The default SSE-S3 encryption needs nothing extra.
  • If your bucket has versioning enabled, nothing extra is needed. The Dialer reads the current version of each file.

Other Providers

ProviderHow to grant the same permissions
Backblaze B2Create an Application Key with Read Only access, limited to your bucket. If you also set a file name prefix on the key, enter that folder as the Path prefix in the Dialer.
Wasabi, IDrive e2Use the same policy documents as for Amazon S3 (the arn:aws:s3::: syntax is accepted).
Cloudflare R2Create an API token with the Object Read only permission for the bucket.
DigitalOcean SpacesCreate a Spaces access key with Read access to the bucket.
MinIO, CephCreate a user and attach the Amazon S3 policy above (both accept the same document), or map a read-only role to the bucket in the server configuration.

Whatever the provider, the connection test in the Dialer tells you if a permission is missing.

Copying Recordings Into Your Bucket

The Dialer finds a recording by its date and file name, so the files in your bucket must keep the same folder structure and file names they have in CommPeak storage.

In CommPeak storage, recordings are organized by year, month, day, and hour (UTC), inside a recordings folder:

recordings/2025/11/11/02/<file name>.flac

In your bucket, the same recording must be at:

<path prefix>2025/11/11/02/<file name>.flac
  • Path prefix is everything in front of the year folder. It can be empty (year folders at the bucket root) or any folder path you like, for example dialer-recordings/ or useast/company-name/. You enter the same prefix in the Dialer settings.
  • Keep the file names exactly as exported, including the .gpg ending on encrypted recordings. Do not rename, convert, or re-encode the files.
  • The recordings folder itself is not part of the layout in your bucket. Copy what is inside it.

Example. If your path prefix is archive/, these files are found by the Dialer:

File in CommPeak storageFile in your bucket
recordings/2025/11/11/02/3f2a…c9d1.flacarchive/2025/11/11/02/3f2a…c9d1.flac
recordings/2025/06/07/13/3f2a…c9d1_ivr.flac (IVR part)archive/2025/06/07/13/3f2a…c9d1_ivr.flac

To copy the recordings:

  1. Download them from CommPeak storage with a Recording Access Account and an S3 client or the AWS CLI, as described in the Recording Access Accounts guide. For example, the following command downloads the whole recordings folder to a local folder and keeps the year, month, day, and hour structure:

    aws s3 sync s3://<commpeak bucket>/recordings/ /home/local_directory/ --endpoint-url https://recordings.commpeak.com --profile "<your profile>" --page-size 100
  2. Upload the local folder to your bucket with your provider's tool or the AWS CLI, under your path prefix. For example, with a path prefix of archive/:

    aws s3 sync /home/local_directory/ s3://<your bucket>/archive/ --endpoint-url <your endpoint URL> --profile "<your other profile>"

After the upload, a recording that was at recordings/2025/11/11/02/

❗️

IMPORTANT

Copy the recordings before their retention period ends. Once CommPeak deletes a recording at the end of its retention period, it cannot be recovered, and your bucket only serves the files you copied into it.

Connecting the Bucket in the Dialer

Users whose role includes the Recordings Storage permission can manage this section. If you don't see it, ask your administrator or contact our support team.

To connect your bucket:

  1. Go to Settings > General Settings and open the Recordings Storage Settings section.
  2. Under Remote S3 Storage, fill in the fields described below.
  3. Click Test connection and make sure all three checks pass (see Testing the connection).
  4. Turn on Enable remote bucket and click Save at the bottom of the page.

ParameterDescription
Enable remote bucketWhen on, the Dialer looks in your bucket for recordings missing from CommPeak storage. When off, your details are kept but the bucket is never used.
Endpoint URLThe S3 address of your storage, starting with https://. Leave it empty for Amazon S3 (the address is derived from the region). Examples: https://s3.us-west-001.backblazeb2.com, https://s3.eu-central-1.wasabisys.com, https://minio.example.com:9000.
RegionThe region of your bucket as your provider names it, for example us-east-1 (Amazon S3) or us-west-001 (Backblaze B2). Leave it empty if your provider has no regions.
BucketThe bucket name.
Access keyThe access key ID (on Backblaze B2, the keyID).
Secret access keyThe secret that belongs to the access key. It is stored encrypted and never shown again. Leave the field empty to keep the saved secret when you change other settings; to change the endpoint, bucket, or region, enter the secret again.
Path prefixEverything in front of the year folder in your bucket, for example archive/. Leave it empty if the year folders are at the bucket root. See Copying recordings into your bucket.
Path-style addressingLeave it on for most providers (Backblaze B2, MinIO, Ceph, and other self-hosted storage). Amazon S3 accepts both settings.

Testing the Connection

Test connection feature, runs three checks in a row and shows the result of each one. You can run it before saving, so a wrong secret or prefix never gets stored.

CheckWhat it verifies
  1. Endpoint reachable
The Dialer can reach your endpoint and bucket from every CommPeak IP address. One line is shown per IP, so you can see if only one address is blocked by your allow-list or firewall.
  1. Credentials and listing
The access key and secret are valid, listing the bucket is allowed, and files exist under the path prefix. The first five files found are shown so you can confirm the folder structure.
  1. Reading a file
The first file from the list can be read, which proves the read permission.

If a check does not pass, the message tells you what to fix:

MessageWhat to do
endpoint must start with https://Enter the endpoint with https://. Plain http:// endpoints are not supported.
endpoint must point to a public addressThe endpoint is a private or reserved network address. Enter the public address or host name of your storage.
endpoint is not a public address (internal or reserved networks…)The endpoint host name resolves to a private or reserved network address. Enter a host name that points to your storage on the public internet.
the endpoint host name could not be resolvedThe host name in the endpoint URL does not exist. Check it for typos and compare it with the endpoint your provider shows for your bucket.
cannot reach … : the connection timed outNothing answered on that address and port. Check the endpoint URL (including the port), and make sure the CommPeak IP address shown on that line is allowed by your bucket policy, IP allow-list, or firewall.
cannot reach … : the connection was refusedThe address answered but nothing is listening on that port. Check the port in the endpoint URL.
cannot reach … : the TLS handshake failedThe endpoint did not present a valid HTTPS certificate, or it does not support HTTPS on that port. Use the HTTPS endpoint your provider publishes.
cannot reach … : the connection was dropped / the connection failedThe connection was interrupted. Try again; if it persists, check the endpoint URL and your firewall or allow-list for the CommPeak IP address shown on that line.
bucket "…" does not exist on …Check the bucket name.
bucket is in another regionThe endpoint or the region does not match the bucket. For providers with regional endpoints, use the endpoint of the region where the bucket was created, and enter that region.
reached … but access was denied (IP allow-list or credentials)The endpoint answered but refused the request. Check that the CommPeak IP addresses are allowed and that the key is valid; the next step gives the exact reason.
access key or secret is wrongEnter the access key and the secret again. Most providers show the secret only once when the key is created.
listing is not permitted for this key — that can be fineYour key can't list the bucket, which is normal for a read-only key. Nothing to fix for playback. If you want the test to show your files and prove the read permission, grant list permission on the bucket (see Setting the required permissions), or, on providers that limit keys to a folder, enter that folder as the Path prefix.
no files found under … — check the path prefixThe path prefix doesn't match where the year folders are. Check the folder structure in your bucket and adjust the prefix; leave it empty if the year folders are at the bucket root.
listing works but s3:GetObject is not granted on …Your credentials can list files but can't read them. Grant read permission on the files (see Setting the required permissions).
no file to fetch (nothing was listed)Step 3 has nothing to read because step 2 listed no files. Fix step 2 first.
Other error codes, for example InternalError (HTTP 500)Your storage provider returned an error. Try again later; if it persists, check the provider's status page or contact our support team with the code shown.
🚧

NOTE

If your bucket becomes unreachable later, recordings that exist only there are shown as unavailable until the bucket is reachable again. Recordings in CommPeak storage are not affected.

Knowledge Base Resources

Explore these related guides for more information:

Getting Help

Submit a support ticket or contact your account manager for more information.


Did this page help you?