Skip to content

Repository files navigation

rc - Rust S3 CLI Client

CILicenseCrates.ioDocs.rs

A S3-compatible command-line client written in Rust.

Migrating from MinIO mc? See the mc compatibility and server-blocker matrix.

Features

  • 🚀 High Performance - Written in Rust with async concurrent operations
  • 🔧 S3 Compatible - Data operations support RustFS, MinIO, AWS S3, and other S3-compatible services
  • 📦 Cross-Platform - Supports Linux, macOS, and Windows
  • 🎨 Friendly Output - Human-readable and JSON format output
  • 🔒 Secure - Secure credential storage, no sensitive data in logs

Installation

Binary Download

Download the appropriate binary for your platform from the Releases page. On Linux, use the default linux-amd64 / linux-arm64 artifacts for maximum compatibility (musl static build). If you specifically need glibc-linked builds, use linux-amd64-gnu / linux-arm64-gnu.

Homebrew (macOS/Linux)

brew install rustfs/tap/rc

Scoop (Windows)

scoop bucket add rustfs https://github.com/rustfs/scoop-bucket
scoop install rustfs/rc

Cargo

cargo install rustfs-cli

Docker

# Show help
docker run --rm rustfs/rc:latest --help
# Run a command with a local RustFS instance
docker run --rm --network host rustfs/rc:latest \
aliassetlocal http://localhost:9000 accesskey secretkey

Build from Source

git clone https://github.com/rustfs/cli.git
cd cli
cargo build --release

Quick Start

Configure Aliases

# Add local S3 service
rc aliassetlocal http://localhost:9000 accesskey secretkey
# Add AWS S3
rc aliasset s3 https://s3.amazonaws.com AKIAIOSFODNN7EXAMPLE wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
# List all aliases
rc alias list

Basic Operations

# List buckets
rc ls local/
# Create bucket
rc mb local/my-bucket
# Upload file
rc cp ./file.txt local/my-bucket/
# Download file
rc cp local/my-bucket/file.txt ./
# View object info
rc stat local/my-bucket/file.txt
# Delete object
rc rm local/my-bucket/file.txt
# Delete bucket
rc rb local/my-bucket

Advanced Operations

# Recursively copy directory
rc cp -r ./local-dir/ local/bucket/remote-dir/
# Mirror between the local filesystem and RustFS
rc mirror ./local-dir/ local/bucket/backup/
# Find objects
rc find local/bucket --name "*.txt" --newer 1d
# List anonymous access rules
rc anonymous list local/bucket
# Set anonymous access level
rc anonymous set public local/bucket/public
# Generate download link
rc share download local/bucket/file.txt --expire 24h
# View directory tree
rc tree local/bucket -L 3

Bulk copies accept one or more sources followed by a directory or remote-prefix target:

rc cp ./january.csv ./february.csv local/reports/ --concurrency 8 --summary
rc cp -r ./reports/ local/archive/ --include '*.csv' --exclude 'private-*' --newer-than 7d
rc cp -r ./reports/ local/archive/ --rate-limit 10MiB/s --retry-attempts 5 --continue-on-error

Direction-safe mc compatibility commands reuse the same copy planner:

rc get local/reports/report.json ./report.json
rc put ./report.json local/reports/

When include rules are present, a path must match at least one of them. Exclude rules are applied after include rules and always win, regardless of flag order. Age filters compare source metadata in UTC: newer/older boundaries are strict, while --rewind includes the specified boundary. Rate, concurrency, and retry settings are shared across the full command. Any failed item leaves the aggregate command exit code non-zero even when --continue-on-error is used. An empty selection succeeds by default; pass --fail-empty when automation should receive a not-found exit code.

Admin Operations (IAM)

# List users
rc admin user list local/
# Add a new user
rc admin user add local/ newuser secretpassword
# Create a policy
rc admin policy create local/ readonly --file policy.json
# Attach policy to user
rc admin policy attach local/ readonly --user newuser
# Detach multiple policies from a user
rc admin policy detach local/ readonly diagnostics --user newuser
# Create a service account (access_key + secret_key)
rc admin service-account create local/ AKIAIOSFODNN7EXAMPLE wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
# Create a service account with a policy file
rc admin service-account create local/ SAKEY123 SASECRET123 --policy ./service-account-policy.json
# Create a service account with inline policy JSON
rc admin service-account create local/ SAKEY123 SASECRET123 --policy-json '{"Version":"2012-10-17","Statement":[]}'# Update selected fields on an existing service account
rc admin service-account update local/ SAKEY123 --policy ./service-account-policy.json --description "Automation access"# Inspect any access key and resolve whether it belongs to a user, service account, or STS credential
rc admin access-key info local/ AKIAIOSFODNN7EXAMPLE
rc admin access-key info local/ AKIAIOSFODNN7EXAMPLE --json
# Manage bucket event notifications
rc event add local/my-bucket arn:aws:sns:us-east-1:123456789012:topic --event 's3:ObjectCreated:*'
rc event list local/my-bucket
rc event remove local/my-bucket arn:aws:sns:us-east-1:123456789012:topic
# Manage bucket CORS configuration
rc bucket cors list local/my-bucket
rc bucket cors get local/my-bucket
rc bucket cors set local/my-bucket cors.xml
cat cors.xml | rc bucket cors set local/my-bucket -
rc bucket cors set local/my-bucket --file cors.json
rc cors remove local/my-bucket

Lifecycle (ILM) Operations

# Add lifecycle rule: expire objects after 30 days with prefix filter
rc ilm rule add local/my-bucket --expiry-days 30 --prefix "logs/"# Add lifecycle rule: transition to remote tier after 90 days
rc ilm rule add local/my-bucket --transition-days 90 --storage-class WARM
# List lifecycle rules
rc ilm rule list local/my-bucket
# Edit an existing rule
rc ilm rule edit local/my-bucket --id rule-abc123 --expiry-days 60
# Remove a specific rule or all rules
rc ilm rule remove local/my-bucket --id rule-abc123
rc ilm rule remove local/my-bucket --all
# Export/import lifecycle configuration (JSON)
rc ilm rule export local/my-bucket > lifecycle.json
rc ilm rule import local/my-bucket lifecycle.json
# Manage remote storage tiers
rc ilm tier add rustfs WARM local --endpoint http://remote:9000 --access-key ak --secret-key sk --bucket warm-bucket
rc ilm tier list local
rc ilm tier info WARM local
rc ilm tier remove WARM local --force
# Restore a transitioned (archived) object
rc ilm restore local/my-bucket/archived-file.dat --days 7

Bucket Replication

# Replication requires versioning on both source and destination buckets
rc version enable local/my-bucket
rc version enable remote/target-bucket
# Configure a remote alias with the destination RustFS endpoint URL.# rc normalizes the remote target endpoint to the host:port form expected by# the RustFS admin API when creating replication targets.
rc aliasset remote http://remote:9000 ACCESS_KEY SECRET_KEY
# Add a replication rule
rc replicate add local/my-bucket \
--remote-bucket remote/target-bucket \
--priority 1 \
--replicate delete,delete-marker,existing-objects
# Allow self-signed or otherwise untrusted target certificates for this# replication target only.
rc replicate add local/my-bucket \
--remote-bucket remote/target-bucket \
--replicate delete,delete-marker,existing-objects \
--insecure
# Upload a local PEM CA bundle so RustFS can trust a private CA when it# connects to the remote replication target.
rc replicate add local/my-bucket \
--remote-bucket remote/target-bucket \
--replicate delete,delete-marker,existing-objects \
--ca-cert ./private-ca.pem
# List replication rules
rc replicate list local/my-bucket
# View replication status/metrics
rc replicate status local/my-bucket
# Update a replication rule
rc replicate update local/my-bucket --id rule-1 --priority 2
# Remove replication rules
rc replicate remove local/my-bucket --id rule-1
rc replicate remove local/my-bucket --all
# Export/import replication configuration (JSON)
rc replicate export local/my-bucket > replication.json
rc replicate import local/my-bucket replication.json

Admin Operations (Cluster)

# Cluster information
rc admin info cluster local
rc admin info server local
rc admin info disk local --offline
# Aggregate background heal status
rc admin heal status local# Root recursive manual heal
rc admin heal start local --scan-mode deep
rc admin heal status local --client-token <TOKEN_FROM_START>
rc admin heal stop local --client-token <TOKEN_FROM_START># Bucket manual heal
rc admin heal start local --bucket mybucket --scan-mode deep
rc admin heal status local --bucket mybucket --client-token <TOKEN_FROM_START>
rc admin heal stop local --bucket mybucket --client-token <TOKEN_FROM_START># Global force stop
rc admin heal stop local# Pool expansion and decommission workflows
rc admin pool list local
rc admin pool status local 1 --by-id
rc admin expand start local
rc admin expand status local
rc admin expand stop local
rc admin decommission start local'/data/pool1/disk{1...4}'
rc admin decommission status local'/data/pool1/disk{1...4}'
rc admin decommission cancel local 1 --by-id
rc admin decommission clear local 1 --by-id
# Rebalance data after adding server pools
rc admin rebalance start local
rc admin rebalance status local
rc admin rebalance stop local# Site replication across clusters (peer sites given as alias names)
rc admin replicate add site1 site2
rc admin replicate info site1
rc admin replicate status site1
rc admin replicate remove site1 --all
# Service control (restart/stop perform a graceful shutdown;# a process manager such as systemd relaunches after restart)
rc admin service restart local
rc admin service stop local# JSON output
rc admin info cluster local --json
rc admin heal status local --json
rc admin rebalance status local --json

Operational Health and Usage

# Public liveness and dependency-readiness probes
rc ping local
rc ready local --timeout 2
# Prefer the RustFS background-scanner snapshot
rc du local# Explicitly permit a portable paginated S3 fallback
rc du local/photos/2026/ --fallback --versions
rc du local/photos --fallback --incomplete

rc du never starts the potentially expensive client scan after an unsupported or unauthorized admin request unless --fallback is present. See the operational utilities reference for count, staleness, and partial-result semantics.

Command Overview

For full command documentation, see the rc command reference.

CommandDescription
aliasManage storage service aliases
adminManage IAM users, policies, groups, service accounts, and cluster operations
lsList buckets or objects
mbMake bucket
rbRemove bucket
cpCopy objects
mvMove objects
rmRemove objects
catDisplay object contents
headDisplay first N lines of object
statDisplay object metadata
findFind objects
anonymousManage anonymous access to buckets and objects
diffCompare two locations
mirrorMirror local and S3-compatible directory trees
treeTree view display
shareGenerate presigned URLs
eventManage bucket event notifications
corsManage bucket CORS configuration
pipeUpload from stdin
versionManage bucket versioning
tagManage bucket and object tags
quotaManage bucket quota
ilmManage lifecycle rules, storage tiers, and object restore
replicateManage bucket replication
watchStream live RustFS object notifications
completionsGenerate shell completion scripts
pingCheck service liveness and round-trip latency
readyCheck service dependency readiness
duReport server-snapshot or explicitly permitted client-scan usage

Admin Subcommands

CommandDescription
admin userManage IAM users (add, remove, list, info, enable, disable)
admin policyManage IAM policies and inspect entity mappings (create, remove, list, info, attach, detach, entities)
admin groupManage IAM groups (add, remove, list, info, enable, disable, add-members, rm-members)
admin service-accountManage service accounts (create, update, remove, list, info)
admin access-keyInspect access key identity and metadata (info)
admin infoDisplay cluster information (cluster, server, disk)
admin healManage cluster healing operations (status, start, stop)
admin poolList pools and inspect expansion/decommission status
admin expandManage post-expansion data rebalancing (start, status, stop)
admin decommissionManage server pool decommissioning (start, status, cancel, clear)
admin rebalanceManage post-expansion rebalancing (start, status, stop)

ILM Subcommands

CommandDescription
ilm rule addAdd a lifecycle rule to a bucket
ilm rule editEdit an existing lifecycle rule
ilm rule listList lifecycle rules on a bucket
ilm rule removeRemove lifecycle rules from a bucket
ilm rule exportExport lifecycle configuration as JSON
ilm rule importImport lifecycle configuration from JSON
ilm tier addAdd a remote storage tier
ilm tier editEdit tier credentials
ilm tier listList all configured storage tiers
ilm tier infoShow details for a specific tier
ilm tier removeRemove a storage tier
ilm restoreRestore a transitioned (archived) object

Replicate Subcommands

CommandDescription
replicate addAdd a new replication rule
replicate updateUpdate an existing replication rule
replicate listList replication rules for a bucket
replicate statusShow replication status and metrics
replicate removeRemove replication rules
replicate exportExport replication configuration as JSON
replicate importImport replication configuration from JSON

Output Format

Human-Readable (default)

rc ls local/bucket
[2024-01-15 10:30:00] 0B dir/
[2024-01-15 10:30:00] 1.2MiB file.txt

JSON Format

The versioned schemas and migration guidance are documented in the JSON output contracts. Existing command output remains on its documented v1 or v2 contract; new command families adopt v3 explicitly.

rc ls local/bucket --json
{
"items": [
{
"key": "dir/",
"is_dir": true
},
{
"key": "file.txt",
"size_bytes": 1258291,
"size_human": "1.2 MiB",
"is_dir": false
}
],
"truncated": false
}

Shell Completion

Generate and install shell completion scripts:

Bash

rc completions bash >~/.bash_completion.d/rc
# Or add to .bashrc:# source <(rc completions bash)

Zsh

rc completions zsh >~/.zfunc/_rc
# Ensure ~/.zfunc is in your fpath (add to .zshrc):# fpath=(~/.zfunc $fpath)# autoload -Uz compinit && compinit

Fish

rc completions fish >~/.config/fish/completions/rc.fish

PowerShell

rc completions powershell >>$PROFILE

Configuration

Configuration file is located at ~/.config/rc/config.toml:

schema_version = 1
[defaults]
output = "human"color = "auto"progress = true
[[aliases]]
name = "local"endpoint = "http://localhost:9000"access_key = "accesskey"secret_key = "secretkey"region = "us-east-1"

Exit Codes

CodeDescription
0Success
1General error
2Usage/path error
3Network error (retryable)
4Authentication/permission error
5Resource not found
6Conflict/precondition failed
7Feature not supported
130Interrupted (Ctrl+C)

Compatibility

Supported Backends

These tiers describe S3-compatible data operations. The rc admin commands use the RustFS Admin API and do not support MinIO Admin API endpoints.

BackendTierDescription
RustFSTier 1S3 and Admin APIs supported
MinIOTier 2S3 operations supported
AWS S3Tier 3Best effort S3 support
Other S3-compatibleBest EffortNo compatibility guarantee

Minimum Rust Version

  • Rust 1.92 or higher (Edition 2024)

Development

Build

cargo build --workspace

Test

# Unit tests
cargo test --workspace
# Integration tests (requires S3-compatible backend)
docker compose -f docker/docker-compose.yml up -d
cargo test --workspace --features integration
docker compose -f docker/docker-compose.yml down

Lint

cargo fmt --all --check
cargo clippy --workspace -- -D warnings

Contributing

Contributions are welcome! Please read AGENTS.md for development guidelines.

License

This project is dual-licensed under MIT or Apache-2.0. See LICENSE-MIT and LICENSE-APACHE.

Acknowledgments

About

A S3-compatible command-line client written in Rust.

Topics

Resources

Stars

123 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages