Documentation

Learn how to architect your data pipeline in minutes.

Amazon S3 Setup Guide

Create a dedicated IAM policy, assign it to a restricted user, and generate access keys for Rilavek.

Zero Read Access by Design

Newly created AWS IAM users start with zero permissions. To connect AWS S3 with Rilavek, you will create a write-focused policy scoped exclusively to your target bucket. Rilavek never needs to read your files back or touch any other AWS services.

1. The Rilavek IAM Policy

Copy the JSON policy below and replace YOUR-BUCKET-NAME with your actual S3 bucket name. On AWS, s3:PutObject implicitly covers multipart upload operations.

rilavek-s3-policy.json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "RilavekBucketLevel",
      "Effect": "Allow",
      "Action": [
        "s3:ListBucket"
      ],
      "Resource": "arn:aws:s3:::YOUR-BUCKET-NAME"
    },
    {
      "Sid": "RilavekObjectLevel",
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:AbortMultipartUpload",
        "s3:ListMultipartUploadParts"
      ],
      "Resource": "arn:aws:s3:::YOUR-BUCKET-NAME/*"
    }
  ]
}

2. AWS Console Walkthrough

Perform these steps inside the AWS Management Console to set up your credentials.

1

Create the Policy

  1. Open the AWS IAM Console.
  2. In the left sidebar, click Policies, then choose Create policy.
  3. Click the JSON tab in the policy editor.
  4. Paste the JSON policy from above, replacing YOUR-BUCKET-NAME with your bucket name in both statement resources.
  5. Click Next.
  6. Name your policy RilavekS3IngestPolicy and click Create policy.
2

Create an IAM User & Attach Policy

  1. In the IAM sidebar, click Users, then choose Create user.
  2. Set a descriptive username such as rilavek-uploader and click Next. (Leave AWS Management Console access unchecked).
  3. Under Permissions options, select Attach policies directly.
  4. In the search box, type RilavekS3IngestPolicy, check the box next to it, and click Next.
  5. Review your user configuration and click Create user.
3

Generate Access Key and Secret

  1. From the Users table, click on your newly created user name (rilavek-uploader).
  2. Select the Security credentials tab.
  3. Scroll to the Access keys section and click Create access key.
  4. Select Other (or "Application running outside AWS") as the use case, check the confirmation box, and click Next.
  5. Click Create access key.
  6. Click Download .csv file or copy the Access Key ID and Secret Access Key to a safe place. Keep in mind AWS will not show the secret key again once you close this window.

3. Connecting to Rilavek

With your credentials ready, open your Rilavek console and configure your destination:

1. Go to Data Stores > New Data Store and pick Amazon S3.

2. Enter a friendly name (such as Primary S3 Bucket).

3. Paste your Access Key ID and Secret Access Key.

4. Enter your exact Bucket Name and select the corresponding Region.

5. Click Save Data Store. Rilavek immediately verifies the connection with an automated write check.

Need general permissions context? Read the S3 Permissions OverviewOfficial AWS Access Keys Documentation