SaigonTech Vault
Loại: knowledge-doc 2026-09-29 active #wiki-import

Steps to obtain an S3 access credentials

1. Create a Policy

Ex name: s3-BUCKET-NAME-access

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "s3:PutObject",
                "s3:GetObject",
                "s3:ListBucket",
                "s3:DeleteObject" <-- Need to confirm here
            ],
            "Resource": [
                "arn:aws:s3:::{{BUKET_NAME}}",
                "arn:aws:s3:::{{BUKET_NAME}}/*"
            ]
        }
    ]
}

2. Create an user

  • Do not provide user access to AWS Management Console
  • Permissions: Choose only one policy (Step 1 Policy "s3-BUCKET-NAME-access")

3. Create Access keys

  • Access to user detail
  • Create and download the credentials (csv file)

**Note: when create an access key

It's okay to use an access key for this use case, but follow the best practices:
Never store your access key in plain text, in a code repository, or in code.
Disable or delete access keys when no longer needed.
Enable least-privilege permissions.
Rotate access keys regularly.

For more details about managing access keys, see the best practices for managing AWS access keys.