Groups keyboard shortcuts have been updated
Dismiss
See shortcuts

S3 Cross account IAM Roles and Globus

27 views
Skip to first unread message

Ken Carlile

unread,
Oct 23, 2024, 5:11:42 PM10/23/24
to Discuss
Hi all, 

I wanted to check if anyone has had success with using AWS cross account IAM roles with the Globus S3 connector, and if so, how you did it. As I understand it, when using this type of authentication, a user has a set of keys that don't directly grant access to the bucket. Rather, they need to use an IAM role to get to the bucket. Sorry if this is vague, it's kind of new to me. But the upshot is, my user doesn't have a keypair that will directly access the bucket, and that keypair doesn't even really exist. 

I was referred to these docs by our S3 admin: 


Thanks, 
Ken

Brigitte Raumann

unread,
Oct 24, 2024, 7:00:19 PM10/24/24
to Ken Carlile, Discuss
Hi Ken,

Unfortunately, the S3 connector does not currently support access via IAM roles.  We have had users request this feature before, and it is on our backlog.  I'll note your interest on the backlog ticket.

Brigitte
Globbus Product Manager

Ken Carlile

unread,
Oct 25, 2024, 10:05:01 AM10/25/24
to Discuss, brau...@uchicago.edu, Discuss, Ken Carlile
OK, thanks. Our S3 admin thinks he has a workaround for the time being. At least once we resolve the other S3 issue, which we have an open ticket on. 

Brigitte Raumann

unread,
Oct 25, 2024, 10:39:22 AM10/25/24
to Ken Carlile, Discuss
OK, thanks.  Not that this provides support for S3 access using IAM roles, but I did want to flag that we recently released support for multiple S3 keys to allow for cross account access with keys.

Brigitte

Michael Gutteridge

unread,
Oct 25, 2024, 12:13:23 PM10/25/24
to Discuss
Ken- do you think it possible to share your S3 admin's workaround here?  I think we're struggling with similar issues.

Thanks
 - Michael

Ken Carlile

unread,
Oct 29, 2024, 3:20:49 PM10/29/24
to Discuss, m...@fredhutch.org
Hi Michael, 

He said he's using (what is probably Karl's) instructions here: https://globus.stanford.edu/cloud/s3.html

--Ken

Reply all
Reply to author
Forward
0 new messages