Configuring private communication with Amazon S3 using the Amazon S3 V2 Connector

Configuring private communication with Amazon S3 using the Amazon S3 V2 Connector

Configure the interface endpoint on the AWS console

Configure the interface endpoint on the AWS console

On the AWS console, select a service of the interface type, select the VPC, the private subnet, the security group, and add the policy for the interface endpoint.
Perform the following steps on the AWS console to configure an interface endpoint:
  1. Log in to the
    AWS Console
    , and navigate to the region where you want to create endpoints.
  2. On the
    Search
    tab, search for VPC.
    The VPC dashboard appears.
  3. Click
    Endpoints
    .
  4. Click
    Create endpoint
    .
    The
    Create endpoint page
    appears.
  5. Enter a name for the S3 interface endpoint.
  6. Select
    AWS services
    as the service category.
  7. In
    Services
    , search for S3, and select a service of the interface type.
    To configure the STS VPC endpoint, search for the STS service. To configure the KMS VPC endpoint, search for the KMS service.
    The following image shows the S3 service:
    Select as S3 service of the interface type.
  8. From the list, select the VPC where you want to create the endpoint.
  9. Click
    Additional settings
    , and clear the
    Enable DNS name
    check box.
  10. Select the private subnet that you created.
  11. Select the security group.
  12. Select
    Custom
    or
    Full access
    policy based on your requirement, and paste the policy in the text box.
    For the minimal Amazon IAM policy, see the Amazon S3 V2 Connector guide.
  13. Click
    Create endpoint
    .
    The interface endpoint is created.
  14. Go back to the
    Endpoints
    page to view the details of the interface endpoint.
  15. Copy the DNS name of the interface endpoint.
    You need to enter the DNS name in the
    Endpoint DNS Name for Amazon S3
    connection property in Cloud Data Integration in the following format:
    bucket.<DNS name of the interface endpoint>
    The following image shows the DNS name of the interface endpoint:
    The DNS name of the interface endpoint.
    If you configure the STS VPC interface endpoint, you need to enter the DNS name in the
    Endpoint DNS Name for AWS STS service
    connection property in Cloud Data Integration.
    The following image shows the DNS name of the STS VPC interface endpoint: The DNS name of the STS VPC interface endpoint.
    If you configure the KMS VPC interface endpoint, you need to enter the DNS name in the
    Endpoint DNS Name for AWS KMS service
    connection property in Cloud Data Integration.
    The following image shows the DNS name of the KMS VPC interface endpoint: The DNS name of the KMS VPC interface endpoint.

0 COMMENTS

We’d like to hear from you!