Orkestia
Blog
App Host

Files

Org members store files that belong to the identity app on the site MinIO — the Files tab, not Storage and not App Data documents.

Files is where organization members keep files that belong to this identity app. Bytes live on the same site MinIO that Buzz already runs. The catalog is a meta.json next to each object. This is not a customer bucket, not an App Data table, and not a chat attachment.

Open it in the console: app.orkestia.dev → the Identity app → Files (Operations, next to Hosting and Chat).

What Files is (and is not)

Files isFiles is not
App-scoped objects on the hosted site's MinIOstorage.* — your own S3 / R2 / GCS bucket
Managed by org members (apphost.file.*)data.appdata.document.* — end-user documents wrapping Storage
A separate key prefix from chat mediaChat attachments or Buzz /media under conversations/
Bound to this identity appAn org-wide dump across apps

End-users of the app do not see these files. Staff actors (agt_) cannot start the verbs. Do not mint an end-user principal so a builder can upload a PNG.

Prerequisites

Files reuse Buzz MinIO. There is no separate storage addon in v1.

  1. The Identity app is live and the site is claimed.
  2. Buzz is applied so MinIO is running on the site.
  3. You are signed in as an organization member (Cognito), not as an app end-user.

Empty states on the tab send you to Hosting when there is no site, or when MinIO is not ready.

Open the Files tab

Open the Identity app

In the console, open Identity and the app (or go to /identity/apps/<uuid>).

Click Files

The Files tab sits in Operations, after Hosting and Chat.

Upload, list, download

Any org member can list, upload, and download. Uploads are at most 4 MiB. HTML and obvious executables are blocked.

Delete (owners and admins)

Delete is hidden unless you are an organization owner or admin. The workflow still enforces that on the server (apphost.file.delete).

Each file can carry an optional folder string (a prefix, not a first-class directory). Listing filters by that prefix.

Limits

LimitValue
Per file4 MiB
Where it sitsThe Buzz MinIO volume (5 Gi / 20 Gi / 50 Gi with the Buzz size)
TypesBlock text/html and obvious executables; otherwise allow
WhoHuman org members only. Agents cannot call apphost.file.*
End-usersNone in v1

Upload goes through the AppHost runner. The browser cannot PUT to the ClusterIP MinIO, and there is no public presigned PUT.

Workflows

Featured types (same org token as Hosting). Resolve the live schema from the catalog.

TypeWhoWhat
apphost.file.ensure-storememberSite exists and Buzz MinIO can serve files/
apphost.file.listmemberReady files for this app, optional folder prefix
apphost.file.getmemberCatalog plus file bytes
apphost.file.putmemberUpload ≤4 MiB
apphost.file.renamememberDisplay name / folder only
apphost.file.deleteadminDelete this file
apphost.file.purge-siteadminDelete every files/ object for the app

Public inputs are UUID-only for the app and the file. You never pass an object key.

apphost.site.delete does not empty files/. Call apphost.file.purge-site when you mean to wipe app files. Removing Buzz does delete the MinIO volume, which also deletes Files.

How it is stored

Two keys per ready file, on bucket buzz-media, not under conversations/:

apps/{identity_app_uuid}/files/{file_uuid}/meta.json
apps/{identity_app_uuid}/files/{file_uuid}/{safe_name}

Chat attachments stay at apps/{identity_app_uuid}/conversations/{conversation_uuid}/{name}. The two prefixes do not collide.

Ask your AI assistant

prompts
List apphost.file.* workflow types available to my org and say which ones a member can start and which need an admin.

My identity app has no Files yet. Tell me whether the site is claimed and whether Buzz MinIO is ready, then stop. Do not upload anything.

Upload is the wrong tool — I need objects in my own S3 bucket. Point me at storage.* instead of apphost.file.*.

For AI agents

RuleDetail
Human-onlyDo not start apphost.file.* as a Staff actor. The run refuses unless metadata.actor.kind=user.
Not documentsdata.appdata.document.* needs an end-user and a Storage connection. That is a different product.
Not Storagestorage.* writes the customer's bucket. Native app files never go there.
Not chat mediaDo not put builder files through apphost.addon.object.put or Buzz /media.
Site firstIf ensure-store or list fails with no site / MinIO not ready, send the human to Hosting + Buzz.
Delete is adminMembers list/put/get/rename. Only owner/admin (or platform staff) delete or purge.