# Secure Zero Trust Secretless Access to AWS S3

> Octelium documentation. Canonical page: <https://octelium.com/docs/octelium/latest/management/guide/service/http/s3-zero-trust-secretless-access>.

Octelium enables you to seamlessly provide identity-based, secretless secure access to your AWS S3 buckets or any S3 compatible stores. The benefits of using Octelium to access your S3 bucket objects can be summed up as follows:

- You no longer need to have allow public unrestricted anonymous access to your S3 buckets.
- Eliminate the need to manage AWS IAM identities and create, distribute, monitor, rotate and revoke over-privileged, long-lived AWS credentials for your, possibly hundreds or thousands of, human *Users* as well as service accounts and workloads that actually need to access your S3 resources. You can read more about Octelium secretless access capabilities [here](https://octelium.com/docs/octelium/latest/management/core/service/secretless.md).
- You can use Octelium's rich identity-based, context-aware, L7 aware, on a per-request basis, centralized access control via policy-as-code with CEL and OPA to enforce fine-grained access control way beyond of what AWS policies can offer (read more about *Policies* and access control [here](https://octelium.com/docs/octelium/latest/management/core/policy.md)).
- Centralize identity management for all of your human *Users* via Octelium's OpenID Connect and SAML 2.0 *IdentityProviders* (read more [here](https://octelium.com/docs/octelium/latest/management/core/identity-providers.md)) as well as for your workload *Users* via OAuth2 client credentials (read more [here](https://octelium.com/docs/octelium/latest/management/core/credential.md#oauth2-client-credentials)) and bearer access tokens (read more [here](https://octelium.com/docs/octelium/latest/management/core/credential.md#access-tokens)).

Let us assume that we have an S3 bucket with the URL `https://my-bucket-abcdef-123456.s3.eu-central-1.amazonaws.com`. You can now create an IAM user and obtain an access key for that user with a `s3:GetObject` permission to that bucket. Now you can now create a *Secret* for your AWS IAM user secret access key as follows:

```bash
octeliumctl create secret s3-bucket-1
```

Now we create our S3 bucket's *Service* as follows:

```yaml
kind: Service
metadata:
  name: s3
spec:
  mode: HTTP
  isPublic: true
  config:
    upstream:
      url: https://my-bucket-abcdef-123456.s3.eu-central-1.amazonaws.com
    http:
      auth:
        sigv4:
          accessKeyID: ABCDEF...FEDCBA
          secretAccessKey:
            fromSecret: s3-bucket-1
          region: eu-central-1
          service: s3
```

> **Note:**
>
> Note that you have to set the `service` field to `s3` and the `region` field to your S3 bucket region.

Now authorized *Users* can now fetch S3 objects at the public URL `https://s3.<DOMAIN>`. When it comes to access control, Octelium provides a rich layer-7 aware, identity-based, context-aware ABAC access control on a per-request basis where you can control access based on the HTTP request's path, method, body content, etc... using policy-as-code with CEL and Open Policy Agent (OPA) (You can read more in detail about *Policies* and access control [here](https://octelium.com/docs/octelium/latest/management/core/policy.md)). Here is an example:

```yaml
kind: Service
metadata:
  name: s3
spec:
  mode: HTTP
  isPublic: true
  config:
    upstream:
      url: https://my-bucket-abcdef-123456.s3.eu-central-1.amazonaws.com
    http:
      auth:
        sigv4:
          accessKeyID: ABCDEF...FEDCBA
          secretAccessKey:
            fromSecret: s3-bucket-1
          region: eu-central-1
          service: s3
  authorization:
    inlinePolicies:
      - spec:
          rules:
            - effect: ALLOW
              condition:
                all:
                  of:
                    - match: ctx.user.spec.email.endsWith("@example.com")
                    - match: ctx.user.spec.groups.hasAny(["dev", "ops"])
                    - match: ctx.request.http.path.startsWith("/prefix1")
                    - match: [".jpg", ".webp"].exists(x, ctx.request.http.path.endsWith(x))
                    - match: ctx.request.http.method == "GET"
```

Octelium also provides OpenTelemetry-ready, application-layer L7 aware visibility and access logging in real time (see an example for HTTP [here](https://octelium.com/docs/octelium/latest/management/core/service/http.md#visibility)). You can read more about visibility [here](https://octelium.com/docs/octelium/latest/management/core/visibility.md).

This was a very short guide to show you how to use Octelium to deploy, scale, route and provide dynamic zero trust secure access to your workloads. Here are a few more related features that you might be interested in:

- Routing not just by request paths, but also by header keys and values, request body content including JSON (read more [here](https://octelium.com/docs/octelium/latest/management/core/service/http.md#json-request-body)).
- Request/response header manipulation (read more [here](https://octelium.com/docs/octelium/latest/management/core/service/http.md#header-manipulation)).
- Cross-Origin Resource Sharing (CORS) (read more [here](https://octelium.com/docs/octelium/latest/management/core/service/http.md#cross-origin-resource-sharing-cors)).
- gRPC mode (read more [here](https://octelium.com/docs/octelium/latest/management/core/service/http.md#grpc)).
- Secretless access to upstreams and injecting bearer, basic, or custom authentication header credentials (read more [here](https://octelium.com/docs/octelium/latest/management/core/service/http.md#secretless-access)).
- Exposing the API publicly for anonymous access (read more [here](https://octelium.com/docs/octelium/latest/management/core/service/anonymous-access.md)).
- Application layer-aware ABAC access control via policy-as-code using CEL and Open Policy Agent (read more [here](https://octelium.com/docs/octelium/latest/management/core/policy.md)).
- OpenTelemetry-ready, application-layer L7 aware auditing and visibility (read more [here](https://octelium.com/docs/octelium/latest/management/core/visibility.md)).
