One S3 security layer.Many storage backends.
Use DeltaGlider as the stable S3-compatible entry point across on-prem storage, Hetzner, Wasabi, or another backend. Keep access control, bucket aliases, encryption, replication, audit, and operator workflows in one place.
IAM, OAuth, ABAC, aliases, encryption, quotas, replication, metrics, audit.
Latest 90 days, fast local reads, local key custody.
Older encrypted objects, lower storage cost, S3-compatible backend.
Optional replication target for provider optionality or DR.
One policy surface over many object stores.
Bucket aliasing
Unified Access Control
Cross-cloud replication
Encryption at rest
Lifecycle-style retention
Operational evidence
Keep hot data on-prem. Encrypt and replicate older data out.
On-prem hot tier
Keep the newest objects close to applications. Reads are local; keys and policy stay under your control.
Encrypt + replicate
Schedule replication for older prefixes. DGP writes encrypted objects to the target backend and records run history/failures.
Hetzner archive
Store lower-cost ciphertext in cloud object storage. Apps still talk to the same DGP-controlled S3-compatible entry point.
This is a lifecycle-style placement pattern, not a claim of complete Amazon S3 Lifecycle parity. If you require legal hold, Object Lock, or provider-native lifecycle transitions, keep those backend controls in the architecture.