Skip to content

S3 Log Uploads

When a game server container stops, the Gameye agent can automatically upload its collected logs to an S3-compatible storage bucket. This gives you durable, queryable access to logs for every session — useful for post-match debugging, compliance, and analytics.

At the end of every session, the agent gzip-compresses the container’s log output and uploads it to your bucket via multipart upload. The upload happens after the server process exits and before the container is removed, so no intervention is required on your part.

Log files are stored at:

{container-name}/logs/logs.txt

The file is gzip-compressed on upload.

Any S3-compatible object storage works:

  • AWS S3
  • Cloudflare R2
  • MinIO
  • Backblaze B2
  • Any other S3-compatible service

Log uploads are configured per application. You need:

  1. An S3-compatible bucket accessible from Gameye’s network
  2. An access key and secret stored as a Gameye secret
  3. The bucket name and region set on your application

Use the private API to register your S3 credentials. These are encrypted at rest with AES-256-GCM and never returned after creation.

POST /v2/secrets/s3
Authorization: Bearer YOUR_TOKEN
{
"name": "my-log-bucket-creds",
"organization": "your-org-name",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"secretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
}

To delete credentials later:

DELETE /v2/secrets/s3/{organization}/{name}
Authorization: Bearer YOUR_TOKEN

When creating or editing an application, set the three S3 fields:

FieldDescription
s3BucketNameName of your S3-compatible bucket
s3RegionRegion where the bucket lives (e.g. us-east-1, auto for R2)
s3CredentialsIdThe name you chose when creating the secret

These can be set via the Admin Panel or via PUT /application/{name}.

R2 uses auto as the region and requires an account-specific endpoint. Set s3Region to auto and ensure your access key has Object Read & Write permissions on the bucket.

Gameye only needs s3:PutObject and s3:HeadObject on the target bucket. A minimal IAM policy:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:PutObject", "s3:HeadObject"],
"Resource": "arn:aws:s3:::your-bucket-name/*"
}
]
}

No logs appear in my bucket after a session ends.

  • Confirm s3BucketName, s3Region, and s3CredentialsId are all set on the application.
  • Verify the credentials have s3:PutObject and s3:HeadObject permissions on the bucket.
  • Check that the bucket exists and is in the region you specified.

Logs appear but the file is empty.

The container may have exited before writing any output to stdout/stderr. Check whether your game server binary writes to standard streams, or whether it redirects output to a file inside the container.

I see a duplicate file in my bucket.

This should not happen in normal operation — the agent checks for an existing object before uploading. If you do see duplicates, contact Gameye support with the container name and session ID.