aws.s3control.get_data_access
Example SQL Queries
SELECT * FROMaws.s3control.get_data_accessWHERE"account_id" = 'VALUE'AND "target" = 'VALUE'AND "permission" = 'VALUE';Description
Returns a temporary access credential from S3 Access Grants to the grantee or client application. The temporary credential is an Amazon Web Services STS token that grants them access to the S3 data.
- Permissions
You must have the s3:GetDataAccess permission to use this operation.
- Additional Permissions
The IAM role that S3 Access Grants assumes must have the following permissions specified in the trust policy when registering the location: sts:AssumeRole, for directory users or groups sts:SetContext, and for IAM users or roles sts:SetSourceIdentity.
Table Definition
| Column Name | Column Data Type |
|---|---|
| account_id Required Input Column The ID of the Amazon Web Services account that is making this request. | VARCHAR |
| permission Required Input Column The type of permission granted to your S3 data, which can be set to one of the following values:
| VARCHAR |
| target Required Input Column The S3 URI path of the data to which you are requesting temporary access credentials. If the requesting account has an access grant for this data, S3 Access Grants vends temporary access credentials in the response. | VARCHAR |
| duration_seconds Input Column The session duration, in seconds, of the temporary access credential that S3 Access Grants vends to the grantee or client application. The default value is 1 hour, but the grantee can specify a range from 900 seconds (15 minutes) up to 43200 seconds (12 hours). If the grantee requests a value higher than this maximum, the operation fails. | BIGINT |
| privilege Input Column The scope of the temporary access credential that S3 Access Grants vends to the grantee or client application.
| VARCHAR |
| target_type Input Column The type of Target. The only possible value is Object. Pass this value if the target data that you would like to access is a path to an object. Do not pass this value if the target data is a bucket or a bucket and a prefix. | VARCHAR |
| _aws_profile Input Column The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( |
Show child fields
| |
| credentials The temporary credential token that S3 Access Grants vends. | STRUCT( |
Show child fields
| |
| matched_grant_target The S3 URI path of the data to which you are being granted temporary access credentials. | VARCHAR |