Steps to obtain an S3 access credentials
1. Create a Policy
Ex name: s3-BUCKET-NAME-access
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:ListBucket",
"s3:DeleteObject" <-- Need to confirm here
],
"Resource": [
"arn:aws:s3:::{{BUKET_NAME}}",
"arn:aws:s3:::{{BUKET_NAME}}/*"
]
}
]
}
2. Create an user
- Do not provide user access to AWS Management Console
- Permissions: Choose only one policy (Step 1 Policy "s3-BUCKET-NAME-access")
3. Create Access keys
- Access to user detail
- Create and download the credentials (csv file)
**Note: when create an access key
It's okay to use an access key for this use case, but follow the best practices:
Never store your access key in plain text, in a code repository, or in code.
Disable or delete access keys when no longer needed.
Enable least-privilege permissions.
Rotate access keys regularly.
For more details about managing access keys, see the best practices for managing AWS access keys.