Files · Private buckets · 0trust.social CDN

Your files. Your plane. Not someone else's cloud.

Private cloud storage on the mesh: folders, previews, share links, trash, and starred items. Images and video publish to the 0trust.social CDN — content-addressed hot blobs at /c/{id}.

Hostdrive.0trust.cloud·CDN0trust.social/c/{id}·Objectsu-{login}·SSOsocial.0trust.cloud
My files
Starred
Trash
Notes
Projects
README.md12 KB
Roadmap.md4 KB
photo.jpgCDN
clip.mp42.1 MB

Built for real work files

Browse like a desktop library. Sync like a product barge. Keep ownership on 0Trust.

📁

Folders & search

Nested folders, quick search, starred items, and soft-delete trash — hot index in ultimate_db for snappy browsing.

Preview & edit text

Markdown-style previews and in-browser editing. Text is stored as CRDT documents so multi-device edits merge cleanly.

Share links

Issue token links for specific files when you want controlled access without making a whole bucket public.

Private object buckets

Each user gets a private S3-compatible bucket on 0trust.social (u-{login}). Owner-only ACL by default.

Replication & rollover

Drive + social barges snapshot upstream to 0trust.services for same-hostname rollover — no DNS surgery.

🔑

Passkey SSO

Sign in with Social SSO (social.0trust.cloud) or domain identity — the same passkey plane as the rest of 0Trust.

How powerful is this CDN?

Upload a JPEG, PNG, GIF, or MP4 in Drive. Preview is not a same-origin blob — it is live 0trust.social delivery.

Hot content-addressed blobs

Each media upload is hashed and stored on the social hot tier. Same bytes, same id — dedupe free across the mesh.

Public /c/{id} URLs

Previews and share pages load https://0trust.social/c/{id} directly. Range requests for video. Embed-ready CSP.

Attribution chain

Originator + share tokens travel with content so embeds on Williwaw, Bandy, and MotionKB stay verifiable.

Hot → cold lifecycle

Touch keeps media hot; idle content ages into cold archive without breaking the stable /c/{id} path.

S2S from product barges

Drive publishes over trusted mesh headers on loopback — DBSC-bound subject, consumer id drive.

One CDN, every product

The same node serves chat media, CMS assets, and your Drive library. One plane. Zero third-party file hosts.

Security posture

Same controls you already trust on the control plane.

DBSC sessions

Device-bound sessions on protected app routes — not just a cookie.

OIDC client Drive

First-party IdP client with redirect https://drive.0trust.cloud/auth/callback.

Mesh-native storage

Content-addressed blobs, cold archive, and full-barge snapshots when binaries change.

How the stack fits

One product face, two durable layers, one CDN.

drive.0trust.cloud
Product UI · guikit
ultimate_db
Folder index
0trust.social
Objects + CDN /c/{id}
0trust.services
Snapshot standby