# Amazon\_s3\_exception: Access Denied Service: Amazon S3; Status Code: 403;

**URL:** <https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267>\
**Category:** Elasticsearch\
**Created:** [December 1, 2020, 7:32pm UTC](https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267 "2020-12-01T19:32:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 1, 2020, 7:32pm UTC](https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267/1 "2020-12-01T19:32:28Z")

</div>

I have a 3 node ec2 dev cluster. I'm trying to setup a snapshot repository for elasticsearch to s3 but I'm getting the following error. AWS command line works for me but setting up through elasticsearch is not. any ideas?

```auto
# aws s3 ls s3://d-elasticsearch-snapshots/d-aw2-bdelksa1/
2020-11-25 17:59:58 0 
2020-11-30 17:21:41 5 blah.out

# curl -XPUT "elastic: *****@d-aw2-bdelksa1-1.***** :9200/_snapshot/d-aw2-bdelksa1-repo?pretty" -H 'Content-Type: application/json' -d'
> {
> "type": "s3",
> "settings": {
> "bucket": "d-elasticsearch-snapshots",
> "client": "default",
> "base_path": "d-aw2-bdelksa1",
> "canned_acl": "private",
> "storage_class": "standard",
> "role_arn": "arn:aws:iam::695893684697:role/ ***** -IFX-PowerUser-CrossAccountRole-695893684697",
> "server_side_encryption": true
> }
> }'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "repository_verification_exception",
        "reason" : "[d-aw2-bdelksa1-repo] path [d-aw2-bdelksa1] is not accessible on master node"
      }
    ],
    "type" : "repository_verification_exception",
    "reason" : "[d-aw2-bdelksa1-repo] path [d-aw2-bdelksa1] is not accessible on master node",
    "caused_by" : {
      "type" : "i_o_exception",
      "reason" : "Unable to upload object [d-aw2-bdelksa1/tests-zWEQ0252SU6cPOCWUrdgPw/master.dat] using a single upload",
      "caused_by" : {
        "type" : "amazon_s3_exception",
        "reason" : "amazon_s3_exception: Access Denied (Service: Amazon S3; Status Code: 403; Error Code: AccessDenied; Request ID: 1KFJDR4V1GBN8 ***; S3 Extended Request ID: QImJhz*** /TD9Hm99xh4wVfZYJfABYrxtOaGuolDB6HGwjm7tCBTD7ZQEN0XpUZxFI5ygi ***** )"
      }
    }
  },
  "status" : 500
}

```

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 1, 2020, 7:33pm UTC](https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267/2 "2020-12-01T19:33:44Z")

</div>

I've also set my credentials with ...

```auto
/usr/share/elasticsearch/bin/elasticsearch-keystore add s3.client.default.access_key
/usr/share/elasticsearch/bin/elasticsearch-keystore add s3.client.default.secret_key

```

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 7, 2020, 10:31pm UTC](https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267/3 "2020-12-07T22:31:10Z")

</div>

any help would be appreciated. i've worked with my aws admin and he is stating that privileges are fine. i'm able to use aws cli to send files there and list but when trying to setup through elastic, getting the Access Denied error.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 10, 2020, 10:49pm UTC](https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267/4 "2020-12-10T22:49:10Z")

</div>

any help?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 10, 2020, 11:00pm UTC](https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267/5 "2020-12-10T23:00:05Z")

</div>

> [@kyle\_che](#):
>
> ```plaintext
> > "role_arn": "arn:aws:iam::695893684697:role/ ***** -IFX-PowerUser-CrossAccountRole-695893684697",
> 
> ```

This isn't a valid [repository setting](https://www.elastic.co/guide/en/elasticsearch/plugins/7.9/repository-s3-repository.html) so you should remove it. If you want to access S3 using a role, use [`aws sts assume-role`](https://docs.aws.amazon.com/cli/latest/reference/sts/assume-role.html) (or equivalent) to obtain temporary credentials and then put those credentials, including the session token, in the keystore instead of your main account credentials.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 18, 2020, 8:11pm UTC](https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267/6 "2020-12-18T20:11:30Z")

</div>

i ended up having a roll tied to my user that has access to the s3 bucket. i also see that whenever you make changes to keystore for s3, you have to run the below to reload them. i ended up deleting the entries i put in and reloading to get it to work.

```auto
curl -X POST "localhost:9200/_nodes/reload_secure_settings?pretty"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2021, 8:11pm UTC](https://discuss.elastic.co/t/amazon-s3-exception-access-denied-service-amazon-s3-status-code-403/257267/7 "2021-01-15T20:11:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
