TLTan LeBackend & automation · CalgaryLet’s talk
← All posts

AWS API Gateway as an S3 proxy: IAM role and path parameters

Notes on exposing an S3 bucket as a REST API with API Gateway: the IAM role, its trust relationship, and folder/item path parameters.

From the archive · a 2021 working note, kept for reference.

Guides I followed:

IAM role

Edit the trust relationship

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "s3.amazonaws.com"
      },
      "Action": "sts:AssumeRole"
    },
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "apigateway.amazonaws.com"
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

API Gateway

Next, go to API Gateway and create a REST API. Create the {folder} and {item} resources, then create a GET method:

Here tanldttestingapigateway is the S3 bucket name.

On /{folder}/{item} → GET → Method Execution, add the URL path parameters.

Test

Create the folder Test1 and upload a text file for testing.

First published on tanldt.blogspot.com on May 25, 2021.