# Configure blob storage

Archives from GitLab need to be temporarily stored so GitHub can read them.

For most customers, we recommend storing archives with GitHub-owned blob storage. This is the simplest path and does not require any extra configuration.

However, you may want to configure storage with an external provider if you have firewall requirements or need to retain archives after the migration is complete.

## Choosing where to stage archives

The GL2GH extension exports each GitLab project to an archive, then uploads the archive to blob storage that GitHub can read from. You choose the storage backend when you run a migration.

| Storage option                          | How to select it                                                                                                                                        | Notes                                                                                                                             |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| GitHub-owned blob storage (recommended) | `--use-github-storage`                                                                                                                                  | No setup required. GitHub deletes the archive automatically after a successful migration, or seven days after a failed migration. |
| AWS S3                                  | `--aws-bucket-name` (with the `AWS_REGION`, `AWS_ACCESS_KEY_ID`, and `AWS_SECRET_ACCESS_KEY` environment variables, and optionally `AWS_SESSION_TOKEN`) | You own the bucket and its lifecycle. GitHub does not delete archives from your storage.                                          |
| Azure Blob Storage                      | `AZURE_STORAGE_CONNECTION_STRING` environment variable (for a single `migrate-repo` command, you can instead use `--azure-storage-connection-string`)   | Only storage-account access-key connection strings are supported (not SAS). GitHub does not delete archives from your storage.    |

## Configuring blob storage

If you are using GitHub-owned blob storage, you do not need to configure anything. You will use the `--use-github-storage` flag to select this method with the CLI. However, you may want to set the `GITHUB_OWNED_STORAGE_MULTIPART_MEBIBYTES` variable (default 100 MiB, minimum 5 MiB) to a lower number if you have a slow or proxied connection.

If you are using external blob storage, you will need to set this up.

### Setting up an AWS S3 storage bucket

En AWS, configura un cubo S3. Para más información, consulta [Creación de un cubo](https://docs.aws.amazon.com/AmazonS3/latest/userguide/create-bucket-overview.html) en la documentación de AWS.

También necesitará una clave de acceso de AWS y una clave secreta con los siguientes permisos:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "s3:PutObject",
                "s3:GetObject",
                "s3:ListBucketMultipartUploads",
                "s3:AbortMultipartUpload",
                "s3:ListBucket",
                "s3:DeleteObject",
                "s3:ListMultipartUploadParts"
            ],
            "Resource": [
                "arn:aws:s3:::github-migration-bucket",
                "arn:aws:s3:::github-migration-bucket/*"
            ]
        }
    ]
}
```

> \[!NOTE]
> GitHub Enterprise Importer no elimina el archivo de AWS una vez que finaliza la migración. Para reducir los costos de almacenamiento, se recomienda configurar la eliminación automática del archivo después de un período de tiempo. Para más información, consulta [Establecimiento de la configuración del ciclo de vida en un cubo](https://docs.aws.amazon.com/AmazonS3/latest/userguide/how-to-set-lifecycle-configuration-intro.html) en la documentación de AWS.

Cuando estés listo para ejecutar la migración, deberás proporcionar tus credenciales de AWS a GitHub CLI: región, clave de acceso, clave secreta y token de sesión (si es necesario). Puedes pasarlas como argumentos o establecer variables de entorno denominadas `AWS_REGION`, `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY` y `AWS_SESSION_TOKEN`.

También deberás pasar el nombre del cubo S3 con el argumento `--aws-bucket-name`.

### Setting up an Azure Blob Storage storage account

En Azure, crea una cuenta de almacenamiento y anota la cadena de conexión. Para más información, consulta [Administración de las claves de acceso de la cuenta de almacenamiento](https://learn.microsoft.com/en-gb/azure/storage/common/storage-account-keys-manage?tabs=azure-portal#regenerate-access-keys) en Microsoft Docs.

> \[!NOTE]
> GitHub Enterprise Importer no elimina el archivo de Azure Blob Storage una vez que finaliza la migración. Para reducir los costos de almacenamiento, se recomienda configurar la eliminación automática del archivo después de un período de tiempo. Para más información, consulta [Optimización de los costes mediante la administración automática del ciclo de vida de los datos](https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-overview) en Microsoft Docs.

Cuando estés listo para ejecutar la migración, puedes pasar la cadena de conexión a la GitHub CLI como argumento, o bien pasarla mediante una variable de entorno denominada `AZURE_STORAGE_CONNECTION_STRING`.

### Allowing network access

If you have configured firewall rules on your storage account, ensure you have allowed access to the IP ranges for your migration destination. See [Manage access for a migration from GitLab to GitHub](/es/migrations/using-github-enterprise-importer/migrate-from-gitlab/manage-access#configure-ip-allow-lists-on-github).