Amazon S3 Setup Guide
Create a dedicated IAM policy, assign it to a restricted user, and generate access keys for Rilavek.
Zero Read Access by Design
Newly created AWS IAM users start with zero permissions. To connect AWS S3 with Rilavek, you will create a write-focused policy scoped exclusively to your target bucket. Rilavek never needs to read your files back or touch any other AWS services.
1. The Rilavek IAM Policy
Copy the JSON policy below and replace YOUR-BUCKET-NAME with your actual S3 bucket name. On AWS, s3:PutObject implicitly covers multipart upload operations.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "RilavekBucketLevel",
"Effect": "Allow",
"Action": [
"s3:ListBucket"
],
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME"
},
{
"Sid": "RilavekObjectLevel",
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:AbortMultipartUpload",
"s3:ListMultipartUploadParts"
],
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME/*"
}
]
}2. AWS Console Walkthrough
Perform these steps inside the AWS Management Console to set up your credentials.
Create the Policy
- Open the AWS IAM Console.
- In the left sidebar, click Policies, then choose Create policy.
- Click the JSON tab in the policy editor.
- Paste the JSON policy from above, replacing
YOUR-BUCKET-NAMEwith your bucket name in both statement resources. - Click Next.
- Name your policy
RilavekS3IngestPolicyand click Create policy.
Create an IAM User & Attach Policy
- In the IAM sidebar, click Users, then choose Create user.
- Set a descriptive username such as
rilavek-uploaderand click Next. (Leave AWS Management Console access unchecked). - Under Permissions options, select Attach policies directly.
- In the search box, type
RilavekS3IngestPolicy, check the box next to it, and click Next. - Review your user configuration and click Create user.
Generate Access Key and Secret
- From the Users table, click on your newly created user name (
rilavek-uploader). - Select the Security credentials tab.
- Scroll to the Access keys section and click Create access key.
- Select Other (or "Application running outside AWS") as the use case, check the confirmation box, and click Next.
- Click Create access key.
- Click Download .csv file or copy the Access Key ID and Secret Access Key to a safe place. Keep in mind AWS will not show the secret key again once you close this window.
3. Connecting to Rilavek
With your credentials ready, open your Rilavek console and configure your destination:
1. Go to Data Stores > New Data Store and pick Amazon S3.
2. Enter a friendly name (such as Primary S3 Bucket).
3. Paste your Access Key ID and Secret Access Key.
4. Enter your exact Bucket Name and select the corresponding Region.
5. Click Save Data Store. Rilavek immediately verifies the connection with an automated write check.