Skip to main content
This tutorial walks you through creating an AWS IAM role and chaining it to Anaconda Platform so your flows and workstations can access AWS services with the permissions you define.
Creating a resource integration requires an administrator role. If you do not have administrator access, ask your administrator to create the integration before you begin.
By the end of this tutorial, you will have:
  • An IAM role with the permissions your workloads need
  • The role registered as a platform integration
  • Verified access to AWS services from a workstation or flow

Create an IAM role

  1. In the AWS IAM console, create a new role.
  2. In Anaconda Platform, select Integrations in the left-hand navigation, then click AWS in the Add an Integration section.
  3. Copy the trust policy statement shown in the integration panel and add it to your role’s trust policy in AWS.
  4. Tag your role in AWS with the key and value shown in the integration panel:
    • Key: outerbounds.com/accessible-by-deployment
    • Value: the value shown in the panel
  5. Attach the AWS managed policies or custom policies your workloads need (Example: AmazonS3ReadOnlyAccess, AWSAthenaFullAccess).
  6. Copy the role’s ARN. You need it for the next step.
  7. In the integration panel, enter a name, a description, and the role ARN, then click Add.
After the integration is created, the How to use tab shows a code snippet with the exact role_arn value for your flows.

Test S3 access

To use your role with S3, pass the role ARN when creating the S3 client:

Test other AWS services

For other AWS services, use get_aws_client with your role ARN:
This pattern works in workstation notebooks and in Metaflow tasks.

Next steps

To build on this tutorial:
  • Add additional AWS service permissions to the role as needed.
  • Use the role in your Metaflow flows to access AWS services.
  • For security guidance, see AWS IAM best practices.