Minimum IAM Requirements
We recommend using predefined roles for services rather than creating custom IAM policies, but if you want to create custom policies, use the roles described in the following table. Note that the specific policies required by the Amazon S3 driver are subject to change in future releases.
Amazon S3 requires at a minimum the following permissions:
| IAM Role | Description | |
| Tables: Buckets | ||
| SELECT | ListAllMyBuckets | |
| INSERT | CreateBucket | |
| DELETE | GetBucketLocation and DeleteBucket | |
| Objects | ||
| SELECT | GetBucketLocation and ListBucket | |
| Views (All views require GetBucketLocation in addition to the permission listed below) | ||
| BucketACLs | GetBucketAcl | |
| BucketAnalytics | GetAnalyticsConfiguration | |
| BucketCORS | GetBucketCORS | |
| BucketInventory | GetInventoryConfiguration | |
| BucketLifecycle | GetLifecycleConfiguration | |
| BucketReplication | GetReplicationConfiguration | |
| ObjectACLs | GetObjectAcl | |
| PublicAccessBlock | GetBucketPublicAccessBlock | |
| Stored Procedures (All procedures require GetBucketLocation in addition to the permission listed below) | ||
| CopyObject | GetObject at the source bucket and PutObject at the destination bucket | |
| MoveObject | GetObject and DeleteObject at the source bucket and PutObject at the destination bucket | |
| DownloadObjects | GetObject | |
| UploadObject | PutObject, and PutObjectAcl when you set an ACL on the upload | |
| CreateBucket | CreateBucket | |
| DeleteBucket | DeleteBucket | |
| DeleteObject | DeleteObject | |
| PutBucketAcl | PutBucketAcl | |
| PutObjectAcl | PutObjectAcl | |
| GetCallerIdentity | sts:GetCallerIdentity | |
| GeneratePresignedURL | None. The procedure signs the URL locally; the holder of the URL must have the permission for the operation the URL authorizes. |
JSON Example
A JSON version of a minimum permissions policy for full driver functionality is shown in the following code:{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"s3:GetBucketPublicAccessBlock",
"s3:GetLifecycleConfiguration",
"s3:GetInventoryConfiguration",
"s3:CreateBucket",
"s3:ListBucket",
"s3:GetReplicationConfiguration",
"s3:PutObject",
"s3:PutObjectAcl",
"s3:GetObjectAcl",
"s3:PutBucketAcl",
"s3:GetBucketAcl",
"s3:GetObject",
"s3:ListAllMyBuckets",
"s3:GetBucketCORS",
"s3:GetAnalyticsConfiguration",
"s3:DeleteObject",
"s3:GetBucketLocation",
"s3:DeleteBucket",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}
In the above example, "Resource" is set to * to allow access to all buckets, but you can limit access to only one specific bucket.