Atlan identity details
The Atlan-side values an Amazon S3 role setup needs, what each is for, and how to get them in a single support ticket.
The Atlan-side values an Amazon S3 role setup needs, what each is for, and how to get them in a single support ticket.
The Amazon S3 second doors - bucket policies, KMS key policies, and how to scope Atlan's access down to a single prefix.
Pick the identity Atlan uses to read your Amazon S3 metadata - a cross-account IAM role it borrows, or an IAM user whose keys you hand over.
Configure and run the S3 crawler to catalog your Amazon S3 buckets and objects in Atlan.
Learn how Atlan reads Amazon S3 - IAM roles, trust policies, External IDs, and the four AWS doors every crawl must pass through.
Create AWS IAM permissions and credentials for Atlan to access and catalog your S3 buckets and objects.
Create Inventory report for Amazon S3 in case of inventory based ingestion through the crawler.
The production-recommended way to connect Atlan to Amazon S3 - Atlan temporarily assumes a role in your AWS account, with no secret created or exchanged.
The fully self-serve way to connect Atlan to Amazon S3 - create an IAM user, attach the permission policy, and paste its keys into Atlan.
Amazon S3 special cases - multi-million-object buckets, multiple AWS accounts, Atlan-hosted bucket flows, External ID limitations, and the region field.
Symptom-first troubleshooting for Amazon S3 connectivity - ListAllMyBuckets 403s, the empty-AKID trap, AssumeRole denials, explicit denies, KMS, region mismatches, and inventory issues.
Complete reference for the S3 assets and properties that Atlan crawls and maps during S3 cataloging.