data_access
Creates, updates, deletes, gets or lists a data_access resource.
Overview
| Name | data_access |
| Type | Resource |
| Id | aws.s3control.data_access |
Fields
The following fields are returned by SELECT queries:
- get_data_access
| Name | Datatype | Description |
|---|---|---|
credentials | string | The temporary credential token that S3 Access Grants vends. |
grantee | string | The user, group, or role that was granted access to the S3 location scope. For directory identities, this API also returns the grants of the IAM role used for the identity-aware request. For more information on identity-aware sessions, see Granting permissions to use identity-aware console sessions. |
matched_grant_target | string | The S3 URI path of the data to which you are being granted temporary access credentials. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get_data_access | select | x-amz-account-id, target, permission, region | durationSeconds, privilege, targetType, auditContext | Returns a temporary access credential from S3 Access Grants to the grantee or client application. The temporary credential is an Amazon Web Services STS token that grants them access to the S3 data. Permissions You must have the s3:GetDataAccess permission to use this operation. Additional Permissions The IAM role that S3 Access Grants assumes must have the following permissions specified in the trust policy when registering the location: sts:AssumeRole, for directory users or groups sts:SetContext, and for IAM users or roles sts:SetSourceIdentity. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
permission | string | The type of permission granted to your S3 data, which can be set to one of the following values: READ – Grant read-only access to the S3 data. WRITE – Grant write-only access to the S3 data. READWRITE – Grant both read and write access to the S3 data. |
region | string | AWS region (default: us-east-1) |
target | string | The S3 URI path of the data to which you are requesting temporary access credentials. If the requesting account has an access grant for this data, S3 Access Grants vends temporary access credentials in the response. |
x-amz-account-id | string | The Amazon Web Services account ID of the S3 Access Grants instance. |
auditContext | string | The context to identify the job or query associated with the credential request. This information will be displayed in CloudTrail log in your account. |
durationSeconds | integer | The session duration, in seconds, of the temporary access credential that S3 Access Grants vends to the grantee or client application. The default value is 1 hour, but the grantee can specify a range from 900 seconds (15 minutes) up to 43200 seconds (12 hours). If the grantee requests a value higher than this maximum, the operation fails. |
privilege | string | The scope of the temporary access credential that S3 Access Grants vends to the grantee or client application. Default – The scope of the returned temporary access token is the scope of the grant that is closest to the target scope. Minimal – The scope of the returned temporary access token is the same as the requested target scope as long as the requested scope is the same as or a subset of the grant scope. |
targetType | string | The type of Target. The only possible value is Object. Pass this value if the target data that you would like to access is a path to an object. Do not pass this value if the target data is a bucket or a bucket and a prefix. |
SELECT examples
- get_data_access
Returns a temporary access credential from S3 Access Grants to the grantee or client application. The temporary credential is an Amazon Web Services STS token that grants them access to the S3 data. Permissions You must have the s3:GetDataAccess permission to use this operation. Additional Permissions The IAM role that S3 Access Grants assumes must have the following permissions specified in the trust policy when registering the location: sts:AssumeRole, for directory users or groups sts:SetContext, and for IAM users or roles sts:SetSourceIdentity.
SELECT
credentials,
grantee,
matched_grant_target
FROM aws.s3control.data_access
WHERE `x-amz-account-id` = '{{ x-amz-account-id }}' -- required
AND target = '{{ target }}' -- required
AND permission = '{{ permission }}' -- required
AND region = '{{ region }}' -- required
AND durationSeconds = '{{ durationSeconds }}'
AND privilege = '{{ privilege }}'
AND targetType = '{{ targetType }}'
AND auditContext = '{{ auditContext }}'
;