<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic S3 and IAM Roles - Where to apply them? in ArcGIS Enterprise in the cloud Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-in-the-cloud-questions/s3-and-iam-roles-where-to-apply-them/m-p/1273529#M584</link>
    <description>&lt;P&gt;I'm toying with the idea of adding S3 buckets to our Portal setup for things like tile caches, etc. I've read just about every post here on the Community and in the documentation that I can, and I have a pretty clear understanding of &lt;EM&gt;most &lt;/EM&gt;of the process. Creating buckets, IAM roles, etc., that's all fine.&lt;/P&gt;&lt;P&gt;I'm still a bit confused on one thing, though. There are many references to the specific permissions that would need to be granted to an IAM role for these things to work. But &lt;EM&gt;where am I implementing to role itself?&lt;/EM&gt; Is it being assigned to the EC2 instance running the Server? The Portal? Something else?&lt;/P&gt;&lt;P&gt;I don't want to grant access via a long-term key, I'd rather go the IAM route. So, where am I assigning the role?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 13:57:31 GMT</pubDate>
    <dc:creator>jcarlson</dc:creator>
    <dc:date>2023-03-30T13:57:31Z</dc:date>
    <item>
      <title>S3 and IAM Roles - Where to apply them?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-in-the-cloud-questions/s3-and-iam-roles-where-to-apply-them/m-p/1273529#M584</link>
      <description>&lt;P&gt;I'm toying with the idea of adding S3 buckets to our Portal setup for things like tile caches, etc. I've read just about every post here on the Community and in the documentation that I can, and I have a pretty clear understanding of &lt;EM&gt;most &lt;/EM&gt;of the process. Creating buckets, IAM roles, etc., that's all fine.&lt;/P&gt;&lt;P&gt;I'm still a bit confused on one thing, though. There are many references to the specific permissions that would need to be granted to an IAM role for these things to work. But &lt;EM&gt;where am I implementing to role itself?&lt;/EM&gt; Is it being assigned to the EC2 instance running the Server? The Portal? Something else?&lt;/P&gt;&lt;P&gt;I don't want to grant access via a long-term key, I'd rather go the IAM route. So, where am I assigning the role?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 13:57:31 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-in-the-cloud-questions/s3-and-iam-roles-where-to-apply-them/m-p/1273529#M584</guid>
      <dc:creator>jcarlson</dc:creator>
      <dc:date>2023-03-30T13:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: S3 and IAM Roles - Where to apply them?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-in-the-cloud-questions/s3-and-iam-roles-where-to-apply-them/m-p/1274216#M585</link>
      <description>&lt;P&gt;Each deployed EC2 instance has an IAM role associated with it, you can either add additional policies to the existing role or create a new role that has the required permissions and apply it to the EC2 instance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From an ArcGIS Enterprise perspective, the cache directory would be access by the service referencing the cache, so ArcGIS Server would need to have read access (at minimum) to the bucket and write access if you're generating the cache after publishing the service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_switch-role-ec2.html" target="_blank"&gt;https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_switch-role-ec2.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 18:06:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-in-the-cloud-questions/s3-and-iam-roles-where-to-apply-them/m-p/1274216#M585</guid>
      <dc:creator>ChristopherPawlyszyn</dc:creator>
      <dc:date>2023-03-31T18:06:38Z</dc:date>
    </item>
  </channel>
</rss>

