Create an S3 action
Create an S3 action when you want Events & Actions to write matching PubNub events into an Amazon S3 bucket you control. You configure the action itself in the Admin Portal, but S3 requires an AWS bucket and an IAM role that trusts PubNub's AWS account before you can save it.
If you already have a bucket and an IAM role configured for PubNub, skip to Configure the S3 action.
Create a bucket
- Open the Amazon S3 console and go to Buckets.
- Click Create bucket, enter a name, and choose a region.
- Configure any other bucket settings your organization requires.
- Click Create bucket.
- Note the bucket name and region. You need both to configure the action.
Create an IAM role
Events & Actions writes to your bucket by assuming an IAM role that you create, so the role must trust PubNub's AWS account and grant write access to the bucket.
-
Open AWS Identity and Access Management and go to Roles.
-
Click Create role and name the role.
-
Select AWS account as the trusted entity type, choose Another AWS account, and enter
535363102202as the account ID. This is PubNub's AWS account, and trusting it lets PubNub assume the role to write to your bucket. -
Under Options, select Require external ID, then paste your app's subscribe key from the keyset's page in the Admin Portal into External ID. AWS recommends this option, and it stops anyone who learns the role ARN from assuming it without also knowing your subscribe key. Continue to the next step.
The resulting trust policy looks like this:
show all 17 lines1{
2 "Version": "2012-10-17",
3 "Statement": [
4 {
5 "Effect": "Allow",
6 "Principal": {
7 "AWS": "arn:aws:iam::535363102202:root"
8 },
9 "Action": "sts:AssumeRole",
10 "Condition": {
11 "StringEquals": {
12 "sts:ExternalId": "<your subscribe key>"
13 }
14 }
15 } -
Create a permissions policy that grants
s3:PutObjecton the objects in your bucket. Click Create policy, switch to the JSON tab, and paste the policy below. Replace<bucket-name>with your bucket's name.1{
2 "Version": "2012-10-17",
3 "Statement": [
4 {
5 "Action": ["s3:PutObject"],
6 "Effect": "Allow",
7 "Resource": "arn:aws:s3:::<bucket-name>/*"
8 }
9 ]
10}The
Resourcemust be an object ARN, which ends in/*.s3:PutObjectapplies to objects, so a policy that names only the bucket ARN (arn:aws:s3:::<bucket-name>) doesn't allow any upload, and the action fails to write. If you set an Object key prefix on the action, you can restrict the policy to that prefix, for examplearn:aws:s3:::<bucket-name>/pubnub-events/*. If your organization adds bucket-level actions such ass3:ListBucket, put them in a separate statement whoseResourceis the bucket ARN without/*.Use the ARN reference guide if you need help formatting the ARN.
-
Finish the policy wizard, attach the new policy to the role, and click Next.
-
Name the role and click Create role.
-
Note the role's ARN. You need it to configure the action.
Use Terraform instead of the console
Apply this equivalent Terraform configuration to create the same bucket, IAM role, and policy.
1resource "random_string" "random" {
2 length = 8
3 upper = false
4 special = false
5}
6resource "aws_s3_bucket" "pubnub_s3" {
7 bucket = "pubnub-s3-example-${random_string.random.result}"
8 tags = {
9 PubNub = "Example"
10 }
11}
12data "aws_iam_policy_document" "pubnub_s3_role" {
13 statement {
14 actions = ["sts:AssumeRole"]
15 principals {
show all 49 linesConfigure the S3 action
- In Events & Actions in the Admin Portal, select your app and keyset, then click + Add Action.
- Click Amazon S3 to select the action type.
- Paste the bucket name and role ARN you noted earlier into Bucket Name and Role ARN.
- Choose the Region that matches your bucket.
- If you want to organize objects like folders inside the bucket, add an Object key prefix.
- If you expect a high volume of events, enable Batching to combine multiple events into a single upload instead of writing one object per event. See Available actions for the batch size and time bounds, and Events & Actions quotas for the bounds on your tier. If you turn on batching, the object may not appear in the bucket until the batch's time bound elapses, so account for that delay when you test.
- If you want failed uploads retried automatically, enable and configure AWS S3 retry. See Available actions for the retry policy and backoff formula.
- Next to Actions, click Add event listener and pair the action with an existing event listener, or create one.
- Click Save changes.
An Events & Actions Amazon S3 batch larger than 5 MB uses an Amazon S3 multipart upload, which splits the batch into parts automatically.
Publish a message that matches the paired listener's filter to confirm the action writes an object to your bucket.
You can export logs from your Functions using an S3 action configured the same way.
Related tasks
- Configure Events & Actions. Create the event listener that triggers this action.
- Available actions. Look up the retry, envelope, and batching settings shared by every action type.
- Create a Kafka action. Forward matching events to an Apache Kafka topic instead of S3.
- Events & Actions. Understand event listeners, filters, and the concepts behind Events & Actions.