> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Amazon Simple Storage Service (S3)

> Connect Amazon S3 to Iru Compliance with a cross-account IAM role to collect bucket inventory, encryption, public-access blocks, and policy metadata.

### About Amazon Simple Storage Service (S3)

The **Amazon S3** connector inventories **bucket configuration**: policies, encryption, versioning, logging, notifications, public-access blocks, and related settings without reading **object payloads**. Iru assumes an **IAM role** you create in your account (`sts:AssumeRole` with an **external ID**). This keeps evidence focused on **how buckets are configured**, not on stored file contents.

### How It Works

Iru runs in its own AWS account. To inventory **S3** bucket configuration (not object payloads by default), you create an **IAM role** whose **trust policy** references Iru’s AWS principal and **mandates** the **External ID** from the wizard, and whose **permissions policy** grants only the **metadata** reads your team approves. Prefer the **inline policy** below instead of **`AmazonS3ReadOnlyAccess`** alone. The managed policy includes **`s3:GetObject`**, which many teams disallow for metadata-only integrations. Paste the role’s **ARN** back into Iru.

| Detail             | Value                  |
| ------------------ | ---------------------- |
| **Category**       | Object storage         |
| **Authentication** | Cross-account IAM role |

References: [S3 user guide](https://docs.aws.amazon.com/AmazonS3/latest/userguide/), [Access management](https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-management.html).

### Prerequisites

* IAM rights to **create roles** and attach inline policies.
* The live **principal** + **external ID** pair from **your** connector - not necessarily the sample IDs printed in older screenshots.

### Connect Amazon S3 to Iru

<Tabs>
  <Tab title="Iru Compliance">
    <Note>
      Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below.
    </Note>

    #### Get the trust policy from Iru

    <Steps>
      <Step title="Open Sources">
        In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**.

        <Frame>
          <img src="https://mintcdn.com/iru/7HsGH7lnQ8GpVmI0/assets/media/images/iru-navigation-compliance-sources.png?fit=max&auto=format&n=7HsGH7lnQ8GpVmI0&q=85&s=595982441fd777b333b3ecfea24adc24" alt="Left navigation: Compliance expanded, Sources selected" width="424" height="1056" data-path="assets/media/images/iru-navigation-compliance-sources.png" />
        </Frame>
      </Step>

      <Step title="Turn on AWS S3">
        Find **AWS S3** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open.
      </Step>

      <Step title="Copy the trust policy JSON">
        The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly.

        ```json copy=false lines theme={null}
        {
          "Version": "2012-10-17",
          "Statement": [
            {
              "Effect": "Allow",
              "Principal": {
                "AWS": "arn:aws:iam::753695775620:role/IruConnect"
              },
              "Condition": {
                "StringEquals": {
                  "sts:ExternalId": "YOUR_EXTERNAL_ID"
                }
              },
              "Action": "sts:AssumeRole"
            }
          ]
        }
        ```
      </Step>

      <Step title="Switch to AWS to create the role">
        Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws).
      </Step>
    </Steps>

    #### Submit the role ARN in Iru

    <Note>
      Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role.
    </Note>

    <Steps>
      <Step title="Paste the IAM Role ARN">
        Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it.
      </Step>

      <Step title="Finish the connection">
        Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**.
      </Step>

      <Step title="Confirm the source is Active">
        Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS S3** card is **Active**.
      </Step>
    </Steps>
  </Tab>

  <Tab title="AWS">
    <Note>
      Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**.
    </Note>

    #### Create the IAM role in AWS

    <Steps>
      <Step title="Start the Create role workflow">
        Open **IAM** → **Roles** → **Create role**.
      </Step>

      <Step title="Configure trusted entity">
        Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the value from Iru.
      </Step>

      <Step title="Skip broad managed policy (optional)">
        Advance past the managed policy picker **without** attaching **`AmazonS3ReadOnlyAccess`** if you plan to use the metadata-only inline policy in the next step.
      </Step>

      <Step title="Create the metadata-only inline policy">
        Create the role with a placeholder name if required, then open the role → **Permissions** → **Create inline policy** → JSON editor. Paste:

        ```json lines theme={null}
        {
          "Version": "2012-10-17",
          "Statement": [
            {
              "Effect": "Allow",
              "Action": [
                "s3:ListAllMyBuckets",
                "s3:GetBucketLocation",
                "s3:GetBucketPolicy",
                "s3:GetBucketPolicyStatus",
                "s3:GetBucketAcl",
                "s3:GetBucketVersioning",
                "s3:GetBucketTagging",
                "s3:GetBucketLogging",
                "s3:GetBucketNotification",
                "s3:GetBucketPublicAccessBlock",
                "s3:GetEncryptionConfiguration",
                "s3:GetLifecycleConfiguration",
                "s3:GetReplicationConfiguration",
                "s3:GetBucketCORS",
                "s3:GetBucketWebsite",
                "s3:GetBucketObjectLockConfiguration"
              ],
              "Resource": "*"
            }
          ]
        }
        ```

        Save the inline policy.

        <Note>
          This policy intentionally **excludes** `s3:GetObject` and related object-read APIs so Iru cannot pull object bodies - only bucket-level metadata.
        </Note>
      </Step>

      <Step title="Copy the role ARN">
        Copy the role **ARN** from the role summary page. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru).
      </Step>

      <Step title="Verify the trust relationship">
        Open **Trust relationships** and confirm the JSON matches the wizard - external ID typos are the usual cause of **`AssumeRole`** failures.
      </Step>
    </Steps>

    <Note>
      Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)).
    </Note>
  </Tab>
</Tabs>

### Troubleshooting

<AccordionGroup>
  <Accordion title="Nothing opens when you turn the source on">
    Check **pop-up blocker** settings for the Iru site and try again.
  </Accordion>

  <Accordion title="AssumeRole denied">
    External ID mismatch - re-copy from Iru without stray spaces.
  </Accordion>

  <Accordion title="Missing bucket policy rows">
    Bucket resource policies can deny cross-account reads even when IAM allows them.
  </Accordion>

  <Accordion title="Encryption settings absent">
    Confirm `s3:GetEncryptionConfiguration` stayed in the inline policy.
  </Accordion>
</AccordionGroup>

### Considerations

<CardGroup cols={2}>
  <Card title="Buckets are regional, but ListAllMyBuckets is…" icon="circle-info">
    Buckets are **regional**, but `ListAllMyBuckets` is global - expect multi-Region follow-up calls during inventory.
  </Card>

  <Card title="Explicit Deny statements in bucket policies block…" icon="shield">
    Explicit **Deny** statements in bucket policies block reads regardless of IAM allows - document expectations with auditors.
  </Card>
</CardGroup>

### Related Articles

<CardGroup cols={2}>
  <Card title="Sources Management" icon="plug" href="/en/compliance/sources-management">
    Browse and manage every Compliance source.
  </Card>

  <Card title="Getting Started With Compliance" icon="rocket" href="/en/compliance/getting-started-with-compliance">
    Frameworks, actions, and **Artifacts**.
  </Card>

  <Card title="Iru Overview" icon="layer-group" href="/en/iru/platform-overview/iru-overview">
    How Endpoint, Compliance, and Identity fit together.
  </Card>

  <Card title="Artifacts Management" icon="folder-open" href="/en/compliance/artifacts-management">
    Upload, review, and organize evidence from sources and actions.
  </Card>
</CardGroup>
