Hi Tom,
In the last year we started using S3 more for transfer sources and AIP storage. Our Archivematica is hosted on a local VM, not in AWS, so the details might be slightly different. We’re using standard storage class while we settle into S3 and work out some of
the rough spots with how Archivematica interacts with objects in S3. I shared your questions with our admin and they shared these words of wisdom:
"I’m not totally sure that
I understand the “ is it possible to pull the S3 credentials via an attached instance role?” question. It sounds like
their instance running the Archivematica software will live in AWS (as an EC2 instance). If that’s the case, and I understand their question, then, yes, it is straightforward to assign an IAM Policy to the EC2 Instance Role that will grant that EC2 instance
access to the S3 bucket and the objects in the bucket. That said, I have no idea if the Archivematica software will respect that — I don’t quite know how an S3 target is defined in the Archivematica Storage Service. It might not be possible to configure and
S3 bucket for Archivematica without specifying and IAM User key/secret pair…”
Take care,
Charlie Hosale
Digital Preservation Coordinator
MIT Libraries
| Scholarly Communications & Collections Strategy
cho...@mit.edu