Creating a resource integration requires an administrator role. If you do not have administrator access, ask your administrator to create the integration before you begin.
- An IAM role with the permissions your workloads need
- The role registered as a platform integration
- Verified access to AWS services from a workstation or flow
Create an IAM role
- In the AWS IAM console, create a new role.
- In Anaconda Platform, select Integrations in the left-hand navigation, then click AWS in the Add an Integration section.
- Copy the trust policy statement shown in the integration panel and add it to your role’s trust policy in AWS.
-
Tag your role in AWS with the key and value shown in the integration panel:
- Key:
outerbounds.com/accessible-by-deployment - Value: the value shown in the panel
- Key:
-
Attach the AWS managed policies or custom policies your workloads need (Example:
AmazonS3ReadOnlyAccess,AWSAthenaFullAccess). - Copy the role’s ARN. You need it for the next step.
- In the integration panel, enter a name, a description, and the role ARN, then click Add.
role_arn value for your flows.
Test S3 access
To use your role with S3, pass the role ARN when creating the S3 client:Test other AWS services
For other AWS services, useget_aws_client with your role ARN:
Next steps
To build on this tutorial:- Add additional AWS service permissions to the role as needed.
- Use the role in your Metaflow flows to access AWS services.
- For security guidance, see AWS IAM best practices.