Amazon S3 data source requirements

Population Health Analytics can connect to an Amazon S3 bucket as a data source. The required settings must be met by the IAM configuration, bucket structure, and S3 URI.

IAM requirements

This table shows the IAM requirements for an Amazon S3 data source:

Requirement Description
AWS account and Region Create the IAM user in the same AWS account and Region as the S3 bucket.
Required permissions Grant s3:ListBucket and s3:GetObject permissions.
Access credentials Save the file containing the access key and the secret access key. The Secret Access Key is only visible once. If lost, you must create a new access key.

Bucket requirements

This table shows the bucket requirements for Amazon S3 data source:

Requirement Description
File location Store files in a subfolder.
Root folder usage Do not store files directly in the bucket root when you use the sample IAM policy.
GetObject resource ARN Ensure that the resource ARN for s3:GetObject ends with /*.

S3 URI requirements

This table shows the S3 URI requirements for Amazon S3 data source:

Requirement Description
Folder path A folder path must be included in the S3 URI.
Trailing slash The S3 URI must end with a forward slash
Use this format for the S3 URI:
s3://bucket-name/folder/

Do not use the bucket root as the data source location.