Keeping objects secure

Introducción a AWS Boto en Python

Maksim Pecherskiy

Data engineer

Why care about permissions?

df = pd.read_csv('https://gid-staging.potholes.csv')

Permissions overview

Introducción a AWS Boto en Python

Why care about permissions?

Permission Allowed!

# Generate the boto3 client for interacting with S3
s3 = boto3.client('s3', region_name='us-east-1', 
                         aws_access_key_id=AWS_KEY_ID, 
                         aws_secret_access_key=AWS_SECRET)

# Use client to download a file s3.download_file( Filename='potholes.csv', Bucket='gid-requests', Key='potholes.csv')
Introducción a AWS Boto en Python

AWS Permissions Systems

IAM

Bucket Policy

ACL

Presigned URL

Introducción a AWS Boto en Python

AWS Permissions Systems

IAM

Bucket Policy

ACL

Presigned URL

Introducción a AWS Boto en Python

ACLs

ACL

Introducción a AWS Boto en Python

ACLs

Upload File

s3.upload_file(
  Filename='potholes.csv', Bucket='gid-requests', Key='potholes.csv')

Set ACL to 'public-read'

s3.put_object_acl(
  Bucket='gid-requests', Key='potholes.csv', ACL='public-read')
Introducción a AWS Boto en Python

Setting ACLs on upload

Upload file with 'public-read' ACL

s3.upload_file(
  Bucket='gid-requests', 
  Filename='potholes.csv', 
  Key='potholes.csv', 
  ExtraArgs={'ACL':'public-read'})
Introducción a AWS Boto en Python

Accessing public objects

S3 Object URL Template

https://{bucket}.{key}

URL for Key='2019/potholes.csv'

https://gid-requests.2019/potholes.csv
Introducción a AWS Boto en Python

Generating public object URL

Generate Object URL String

url = "https://{}.{}".format(
  "gid-requests", 
  "2019/potholes.csv")

'https://gid-requests.2019/potholes.csv'

# Read the URL into Pandas
df = pd.read_csv(url)
Introducción a AWS Boto en Python

How access is decided

Access hierarchy

Introducción a AWS Boto en Python

How access is decided

Access Hierarchy

Introducción a AWS Boto en Python

Review

IAM

Bucket Policy

ACL

Presigned URL

Introducción a AWS Boto en Python

Review

Set ACL to 'public-read'

s3.put_object_acl(
  Bucket='gid-requests', Key='potholes.csv', ACL='public-read')

Set ACL to 'private'

s3.put_object_acl(
  Bucket='gid-requests', Key='potholes.csv', ACL='private')
Introducción a AWS Boto en Python

Review

Upload file with 'public-read' ACL

s3.upload_file(
  Bucket='gid-requests', 
  Filename='potholes.csv', 
  Key='potholes2.csv', 
  ExtraArgs={'ACL':'public-read'})
Introducción a AWS Boto en Python

Review

Generate Object URL String

url = "https://{}.{}".format(
  "gid-requests", 
  "2019/potholes.csv")

'https://gid-requests.2019/potholes.csv'

# Read the URL into Pandas
df = pd.read_csv(url)
Introducción a AWS Boto en Python

Let's practice!

Introducción a AWS Boto en Python

Preparing Video For Download...