Skip to content

Commit

Permalink
improv: adjust list formating
Browse files Browse the repository at this point in the history
  • Loading branch information
zaiste committed Oct 23, 2014
1 parent bdeda09 commit 1856c3e
Showing 1 changed file with 28 additions and 32 deletions.
60 changes: 28 additions & 32 deletions content/blog/2014-10_AWS_buckets_migration.md
Expand Up @@ -10,44 +10,40 @@ tags:
---

Recently we needed to migrate data between two Amazon S3 buckets on different accounts. Situation seemed simple but while diving into topic we didn't find good documentation how to accomplish this. We tried few solutions but result one was that we had migrated data between buckets without proper rights on files so we couldn't do much with migrated data.

Solution is to add proper policies on destination bucket and use `sync` on source bucket via AWS CLI. Here's how we did it in 2 steps:

1. Create policy on destination bucket.
Source bucket user needs to have access to destination bucket. You need to know source bucket account ID and source bucket user name (for user name you may use `root` if you don't want to use specific user).


```
{
"Id": "Policy1357935677554",
"Statement":
[
{
"Sid": "Stmt1357935647218",
"Action": "s3:*",
"Effect": "Allow",
"Resource":
[
"arn:aws:s3:::destination-bucket-here",
"arn:aws:s3:::destination-bucket-here/*"
],
"Principal":

{
"Id": "Policy1357935677554",
"Statement":
[
{
"AWS": "arn:aws:iam::account-number-here:user-name-here"
"Sid": "Stmt1357935647218",
"Action": "s3:*",
"Effect": "Allow",
"Resource":
[
"arn:aws:s3:::destination-bucket-here",
"arn:aws:s3:::destination-bucket-here/*"
],
"Principal":
{
"AWS": "arn:aws:iam::account-number-here:user-name-here"
}
}
}
]
}
```
2. Synchronise buckets via AWS CLI
Make sure you have AWS CLI installed and set up with source bucket user credentials. Then you're ready to use `sync`.
]
}

2. Synchronise buckets via AWS CLI Make sure you have AWS CLI installed and set up with source bucket user credentials. Then you're ready to use `sync`.
> A sync command makes it easy to synchronise the contents of a local folder with a copy in a S3 bucket.
In our case we'll synchronise two S3 buckets on different accounts with acl set to public-read.
In our case we'll synchronise two S3 buckets on different accounts with acl set to public-read.

> Amazon S3 Access Control Lists (ACLs) enable you to manage access to buckets and objects. Each bucket and object has an ACL attached to it as a subresource. It defines which AWS accounts or groups are granted access and the type of access. When a request is received against a resource, Amazon S3 checks the corresponding ACL to verify the requester has the necessary access permissions.
```
aws s3 sync s3://source-bucket-name s3://destination-bucket-name --acl public-read
```
aws s3 sync s3://source-bucket-name s3://destination-bucket-name --acl public-read

In case you may need different parameters have a look at [sync](http://docs.aws.amazon.com/cli/latest/reference/s3/sync.html) in AWS reference.

0 comments on commit 1856c3e

Please sign in to comment.