Cloud

CREATE STORAGE

The CREATE STORAGE statement creates a named connection to external object storage such as Amazon S3 or Google Cloud Storage (GCS).

In Redpanda Cloud, the storage connection and Iceberg catalog used to query Iceberg-enabled topics are configured and managed automatically when you enable Redpanda SQL on a cluster that has an Iceberg REST catalog configured. You don’t run these statements yourself for that workflow. This page documents the statement’s syntax and options so you can understand what Redpanda Cloud configures. See Query Iceberg-enabled topics.

Syntax

CREATE STORAGE [IF NOT EXISTS] storage_name
TYPE = S3 | GCS
WITH (option = 'value' [, ...]);
  • storage_name: Name for the new storage connection.

  • TYPE: Storage type. Redpanda SQL supports S3 and GCS.

  • IF NOT EXISTS: Optional. Prevents an error if a storage connection with the same name already exists.

S3 options

Option Type Required Description

region

STRING

Yes

Cloud region for the storage bucket (for example, us-west-2).

access_key_id

STRING

Yes

AWS access key ID.

secret_access_key

STRING

Yes

AWS secret access key.

GCS options

Option Type Required Description

url

STRING

No

GCS bucket URL, in the form gs://<bucket>/<path>. If omitted, the connection holds credentials only and has no associated bucket.

service_account_key

STRING

No

Contents of a GCP service account key JSON file. If omitted, Redpanda SQL authenticates using Application Default Credentials (ADC), which includes Workload Identity Federation on Google Kubernetes Engine (GKE).

endpoint

STRING

No

Override the default GCS endpoint.

Examples

Create an S3 storage connection

CREATE STORAGE archive_storage
TYPE = S3
WITH (
  region = 'us-west-2',
  access_key_id = 'AKIAIOSFODNN7EXAMPLE',
  secret_access_key = 'wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY'
);

Create a GCS storage connection with a service account key

CREATE STORAGE gcs_key_storage
TYPE = GCS
WITH (
  url = 'gs://archive-bucket/redpanda-sql',
  service_account_key = '{"type": "service_account", "project_id": "my-project", ...}'
);

Create a GCS storage connection using Application Default Credentials

Omit service_account_key to authenticate with Application Default Credentials (ADC). On GKE, this includes Workload Identity Federation.

CREATE STORAGE gcs_adc_storage
TYPE = GCS
WITH (
  url = 'gs://archive-bucket/redpanda-sql'
);