Files
Files is where organization members keep files that belong to this identity app. Bytes live on the same site MinIO that Buzz already runs. The catalog is a meta.json next to each object. This is not a customer bucket, not an App Data table, and not a chat attachment.
Open it in the console: app.orkestia.dev → the Identity app → Files (Operations, next to Hosting and Chat).
What Files is (and is not)
| Files is | Files is not |
|---|---|
| App-scoped objects on the hosted site's MinIO | storage.* — your own S3 / R2 / GCS bucket |
Managed by org members (apphost.file.*) | data.appdata.document.* — end-user documents wrapping Storage |
| A separate key prefix from chat media | Chat attachments or Buzz /media under conversations/ |
| Bound to this identity app | An org-wide dump across apps |
End-users of the app do not see these files. Staff actors (agt_) cannot start the verbs. Do not mint an end-user principal so a builder can upload a PNG.
Prerequisites
Files reuse Buzz MinIO. There is no separate storage addon in v1.
- The Identity app is live and the site is claimed.
- Buzz is applied so MinIO is running on the site.
- You are signed in as an organization member (Cognito), not as an app end-user.
Empty states on the tab send you to Hosting when there is no site, or when MinIO is not ready.
Open the Files tab
Open the Identity app
In the console, open Identity and the app (or go to /identity/apps/<uuid>).
Click Files
The Files tab sits in Operations, after Hosting and Chat.
Upload, list, download
Any org member can list, upload, and download. Uploads are at most 4 MiB. HTML and obvious executables are blocked.
Delete (owners and admins)
Delete is hidden unless you are an organization owner or admin. The workflow still enforces that on the server (apphost.file.delete).
Each file can carry an optional folder string (a prefix, not a first-class directory). Listing filters by that prefix.
Limits
| Limit | Value |
|---|---|
| Per file | 4 MiB |
| Where it sits | The Buzz MinIO volume (5 Gi / 20 Gi / 50 Gi with the Buzz size) |
| Types | Block text/html and obvious executables; otherwise allow |
| Who | Human org members only. Agents cannot call apphost.file.* |
| End-users | None in v1 |
Upload goes through the AppHost runner. The browser cannot PUT to the ClusterIP MinIO, and there is no public presigned PUT.
Workflows
Featured types (same org token as Hosting). Resolve the live schema from the catalog.
| Type | Who | What |
|---|---|---|
apphost.file.ensure-store | member | Site exists and Buzz MinIO can serve files/ |
apphost.file.list | member | Ready files for this app, optional folder prefix |
apphost.file.get | member | Catalog plus file bytes |
apphost.file.put | member | Upload ≤4 MiB |
apphost.file.rename | member | Display name / folder only |
apphost.file.delete | admin | Delete this file |
apphost.file.purge-site | admin | Delete every files/ object for the app |
Public inputs are UUID-only for the app and the file. You never pass an object key.
apphost.site.delete does not empty files/. Call apphost.file.purge-site when you mean to wipe app files. Removing Buzz does delete the MinIO volume, which also deletes Files.
How it is stored
Two keys per ready file, on bucket buzz-media, not under conversations/:
apps/{identity_app_uuid}/files/{file_uuid}/meta.json
apps/{identity_app_uuid}/files/{file_uuid}/{safe_name}
Chat attachments stay at apps/{identity_app_uuid}/conversations/{conversation_uuid}/{name}. The two prefixes do not collide.
Ask your AI assistant
List apphost.file.* workflow types available to my org and say which ones a member can start and which need an admin.
My identity app has no Files yet. Tell me whether the site is claimed and whether Buzz MinIO is ready, then stop. Do not upload anything.
Upload is the wrong tool — I need objects in my own S3 bucket. Point me at storage.* instead of apphost.file.*.
For AI agents
| Rule | Detail |
|---|---|
| Human-only | Do not start apphost.file.* as a Staff actor. The run refuses unless metadata.actor.kind=user. |
| Not documents | data.appdata.document.* needs an end-user and a Storage connection. That is a different product. |
| Not Storage | storage.* writes the customer's bucket. Native app files never go there. |
| Not chat media | Do not put builder files through apphost.addon.object.put or Buzz /media. |
| Site first | If ensure-store or list fails with no site / MinIO not ready, send the human to Hosting + Buzz. |
| Delete is admin | Members list/put/get/rename. Only owner/admin (or platform staff) delete or purge. |
Related
- Buzz — the MinIO volume Files reuses
- Website and process
- App Data — tables and
document.*, not this tab - Platform services — BYO
storage.* - Chat limits — conversation attachments, not app files
