How to store Reg-suit screenshots in Amazon S3
Configure Reg-suit’s S3 publisher for CI, organize snapshot artifacts, and choose permissions and encryption without exposing visual-diff reports.
Reg-suit stores and retrieves visual-regression snapshot images in Amazon S3 through the reg-publish-s3-plugin. Create an S3 bucket, grant the CI identity access, install and prepare the plugin, then configure its required bucketName. Choose a path prefix, encryption, custom domain, and access policy to match how reports should be organized and who should see them.
Review the plugin version before copying configuration or IAM permissions: defaults and required actions can change. In particular, the plugin README documents a public-read ACL default. That can expose report artifacts if enabled, so make visibility an explicit decision. The plugin README documents its options and permission list; AWS explains S3 Block Public Access and the controls for preventing public access.
What you need
- A Reg-suit project and an installed
reg-publish-s3-pluginversion. - An S3 bucket in the AWS account and region you intend to use.
- A CI role or credentials that can perform the operations required by your plugin version and bucket settings.
- A decision about whether reports should be private to authorized AWS identities or available through a deliberately public report setup.
This walkthrough does not assume a particular Reg-suit version or claim that an example IAM policy has been validated against your account. Check the version-specific README and AWS policies before using the setup in a production workflow.
1. Create the bucket and grant CI access
Create an S3 bucket for the visual-regression artifacts. Configure your CI environment to obtain AWS credentials using its supported role or credential mechanism. Prefer an identity scoped to the intended bucket and, where practical, the path prefix used for this project’s reports.
AWS describes S3 resources as private by default and supports access control through policies. Keep public access blocked unless public report access is an intentional requirement. If the plugin attempts to set an ACL, check whether ACLs are enabled and compatible with the bucket’s ownership configuration. See AWS access management and S3 Object Ownership.
2. Install and prepare the S3 publisher
From the project directory, install the plugin and run Reg-suit’s preparation command as shown in the plugin README:
npm install reg-publish-s3-plugin --save-dev
npx reg-suit prepare -p publish-s3
Confirm these commands against the package documentation for the version you install. The prepare command configures the publisher for the Reg-suit project; complete any prompts with the bucket and access choices appropriate to your setup.
3. Configure the bucket and optional settings
Set bucketName to the bucket holding snapshot images. The README documents these options; exact defaults and behavior are version-sensitive.
| Option | Use | Decision to make |
|---|---|---|
bucketName |
Required S3 bucket for publishing and fetching snapshot images. | Use the bucket assigned to this project’s report artifacts. |
pathPrefix |
Places report objects under a key prefix. | Choose a stable prefix to separate projects or organize artifacts. |
acl |
Sets an object ACL; the README documents public-read as the default. |
Do not leave public access as an unexamined default. Verify ACL and bucket ownership behavior. |
enableACL |
Controls ACL behavior; the README documents a default of true. |
Check compatibility with the bucket’s Object Ownership settings and your version. |
sse |
Configures server-side encryption. | Choose the encryption mode required by your organization and bucket. |
sseKMSKeyId |
Supplies the KMS key ID for the documented KMS encryption option. | Ensure the CI role, bucket policy, and KMS key policy permit the required operations. |
customDomain |
Uses a custom host for report URLs. | Set it only after the domain is configured to serve the bucket’s report content. |
sdkOptions |
Passes options to the AWS SDK. | Use only settings supported by the plugin version and SDK it uses. |
Use the plugin’s generated configuration format and property placement for your installed version. The README’s examples illustrate reports under a prefix and support a custom domain; do not assume a configuration snippet from a different release has identical defaults.
4. Scope the CI permissions
The plugin README lists these IAM actions under its role policy guidance:
s3:DeleteObject
s3:GetObject
s3:GetObjectAcl
s3:PutObject
s3:PutObjectAcl
s3:ListBucket
Treat this as the plugin’s documented action list, not a guaranteed minimum for every version or bucket configuration. Review the installed version, the operations your workflow runs, ACL behavior, bucket ownership settings, and encryption requirements. Scope object actions to the intended bucket and prefix where possible; s3:ListBucket applies to the bucket resource. AWS explains resource-level policy structure in its S3 policy overview.
If using KMS, S3 permissions alone may not be sufficient: the CI identity and key policy must also allow the relevant KMS use. Confirm the required key permissions with your AWS administrator and the encryption configuration you selected.
5. Publish and verify from CI
- Run the same Reg-suit publish workflow in CI that will be used for normal builds.
- Confirm the expected snapshot objects appear in the configured bucket and prefix.
- Run a workflow that fetches the prior snapshot data so both publish and retrieval paths are exercised.
- Open a report URL using the intended viewer identity, then confirm that an unauthorized identity cannot access private artifacts.
- Review CI logs and S3 policy behavior for denied actions; grant only the missing access that the workflow requires.
These checks are recommended because the plugin both publishes and fetches images and AWS access depends on the bucket and identity policies. They are not a claim that a particular policy or project was tested for this article.
Security and visibility choices
Visual-regression artifacts can contain page content captured from your application. Decide whether that content may be public before enabling public ACLs or hosting report URLs on a public domain. A safer default for sensitive reports is to keep the bucket private and make report access available only through approved identities or a controlled hosting arrangement.
Because the plugin README describes public-read as its ACL default and enableACL as enabled by default, check the effective configuration rather than relying on assumptions. AWS recommends using policies to grant access to intended principals and provides Block Public Access controls to help prevent unintended public exposure.
Encryption, prefixes, and custom domains
Server-side encryption
Use sse or sseKMSKeyId when your storage requirements call for the documented encryption options. KMS adds policy dependencies: verify access for the CI role and the KMS key, as well as any bucket policy conditions. Validate a real publish and fetch cycle after changing encryption settings.
Path organization
A pathPrefix can keep report objects grouped under a project-specific or otherwise meaningful key path. Align the prefix with your IAM resource scope so the CI role does not need broad access to unrelated objects.
Custom domain
Use customDomain only when the domain is already configured to serve the relevant bucket content. A custom hostname does not by itself make access private; the bucket, hosting layer, and report links must all follow the intended access policy.
Performance, reliability, and cost considerations
- Performance: The research sources do not provide a benchmark or latency comparison. Bucket region, CI location, artifact volume, and report access patterns can affect the workflow; choose a region consistent with your deployment and measure your own pipeline.
- Reliability: The workflow depends on CI credentials, S3 permissions, and any KMS policy. Validate both publish and fetch behavior in the actual CI identity, and inspect failures in CI and AWS logs.
- Storage and request costs: S3 storage and requests may have costs under your AWS account. The research does not establish a cost estimate for a Reg-suit workload. Check current AWS pricing for your region, retention, object volume, and request pattern.
- Retention: Decide how long historical report artifacts need to remain available. Any lifecycle or cleanup policy should preserve the snapshots required for comparisons and avoid deleting data still referenced by reports.
- Security: Public access can make report artifacts visible outside the development team. Confirm effective ACLs, bucket policies, identity policies, and any custom hosting configuration.
Troubleshooting
| Symptom | Likely cause | What to check |
|---|---|---|
| Access denied while publishing | The CI identity lacks an action required by the plugin, or a bucket policy denies it. | Compare the error and workflow operation with the installed plugin’s IAM list; check identity and bucket policies and scope. |
| Access denied while fetching snapshots | Read permissions are missing, or the report is being accessed with an identity that cannot read the object. | Check s3:GetObject, bucket policy conditions, and how report viewers authenticate. |
| ACL operation fails | ACLs may be disabled or the bucket’s Object Ownership settings may not permit the plugin’s ACL behavior. | Review enableACL, acl, bucket ownership configuration, and the installed plugin version. |
| Objects appear in the wrong location | The configured bucket or pathPrefix differs from the path being inspected. |
Check the effective plugin configuration and object key prefix. |
| KMS-encrypted write or read fails | The CI role, bucket policy, or KMS key policy does not authorize the operation. | Review all three policies and verify the configured key ID and encryption option. |
| Custom report URL does not resolve | The hostname is not configured to serve the bucket path, or the URL path does not match the prefix. | Verify domain and hosting configuration and compare the resulting report path to the stored object key. |
| Works locally but fails in CI | Local credentials differ from the CI role, or CI uses different environment/configuration values. | Inspect the role assumed by CI and compare its effective configuration without printing secret credentials. |
Or skip the browser setup
If your goal is to capture a website for a report or workflow, ScreenshotNeo is a website screenshot API and MCP server. Its API returns an image or PDF with one GET request. It is separate from Reg-suit’s S3 publisher: use Reg-suit’s plugin when you need Reg-suit to publish and fetch visual-regression snapshots in your own bucket.
For a quick website capture, use cURL, or see the ScreenshotNeo API documentation for configuration:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', res);
- Cookie banners are accepted and removed before capture, along with known consent platforms, newsletter popups, and chat widgets; each cleanup step can be turned off.
- Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed; response headers say the page verdict and whether the shot was billed.
- An MCP server provides
take_screenshot,get_page_info, andcapture_pdftools for AI agents and MCP clients. - The Free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000. Every feature is on every plan.
Create a free ScreenshotNeo account to get 1,000 screenshots a month with no card.
FAQ
Does Reg-suit store the full report in S3?
The S3 publisher is documented as publishing and fetching snapshot images. Check your Reg-suit setup and report configuration to determine where the rest of the report is served.
Should I use a public bucket so teammates can view reports?
Only if public access is an intentional choice for the captured content. Otherwise, keep artifacts private and provide access through an approved identity or controlled report-hosting setup.
Can I use a KMS key with the plugin?
The README documents sse and sseKMSKeyId. The relevant CI, bucket, and KMS key policies must all allow the configured operations.
Where do I find the exact options for my release?
Inspect the README and package documentation corresponding to the installed reg-publish-s3-plugin version; the cited repository’s master branch may evolve.


