Serves the `s3` capability socket from pasted coordinates and credentials, so an operator-owned bucket (a migrated Nextcloud corpus, a legacy media bucket, a bucket managed by Terraform or by the provider's console) can be consumed by SHC apps without SHC ever creating, emptying or deleting it. Unlike the bundled `s3` app this ships NO integration job that mutates, NO unintegration job, and NO vapp/vsocket surface — the destructive paths do not exist to be reached. Only a read-only reachability probe (HeadBucket + ListObjectsV2) runs, and it fails the install loudly if the bucket is missing or the credentials are wrong. Presets: Hetzner Object Storage (<loc>.your-objectstorage.com:443), AWS S3, Cloudflare R2, Backblaze B2, Wasabi, Scaleway, DigitalOcean Spaces, self-hosted MinIO/Ceph.