# Assume Role snapshot S3

**URL:** <https://discuss.elastic.co/t/assume-role-snapshot-s3/373848>\
**Category:** Elasticsearch\
**Tags:** snapshot-and-restore\
**Created:** [January 29, 2025, 4:23pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848 "2025-01-29T16:23:26Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![suarna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suarna/32/141026_2.png) [@suarna](https://discuss.elastic.co/u/suarna)\
**Post date:** [January 29, 2025, 4:23pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/1 "2025-01-29T16:23:27Z")

</div>

Hi everybody,

How is it going?

Let's see if someone can help me with this. Sorry if the question is trivial (I am new in using elasticsearch)

I have a question regarding the use of the s3 repository plugin in order to automate de snapshot process of our elasticsearch cluster, specifically we are using the plugin version 7.17.6 along with a self-managed elasticsearch version 7.17.6 running on-premises.

We are trying to register an s3 repository

```auto
PUT _snapshot/s3_repository_example
{
    "type" : "s3",
    "settings" : {
      "client": "default",
      "bucket" : "bucket-name",
      "base_path": "snapshot",
      "storage_class" : "standard_ia",
      "endpoint": "https://s3.eu-south-2.amazonaws.com",
      "proxy.host": "proxy.example.local",
      "proxy.port": "4444",
      "region": "eu-south-2"
    }
}

```

and we are getting the following error.

```auto
 "caused_by" : {
      "type" : "i_o_exception",
      "reason" : "Unable to upload object [snapshot/tests-aMqZ1xIiST2J32WPngfCyg/master.dat] using a single upload",
      "caused_by" : {
        "type" : "amazon_s3_exception",
        "reason" : "Access Denied (Service: Amazon S3; Status Code: 403; Error Code: AccessDenied; Request ID: XXXXXXXXXXXX; S3 Extended Request ID: XXXXXXXXXXXXX)"
      }

```

Point that we have added the access\_key and the secret\_key to the the keystore in all nodes and restarted all of them but the problem persists.

I suspect that this behaviour might be caused by the fact that the credentials which we are using are linked to an IAM role and in order to grant the access to the bucket we need to provide the role to get the authorization.

Is there a way to assume an IAM role the same way as it is done in plugins like the input s3 plugin in logstash? or Is there any other way to do that?

```auto
s3 {
                id => "example-id"
                access_key_id => "acces-key"
                secret_access_key => "secret-key"
                role_session_name => "role-name"
                role_arn => "arn:aws:iam::XXXXXXXXXXXX:role/role-name"
                region => "region"
                bucket => "bucket-name"
                interval => 300
                additional_settings => {
                        force_path_style => true
                        follow_redirects => false
                }

```

I'll appreciate your help because we are stuck due to this issue.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [January 29, 2025, 6:27pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/2 "2025-01-29T18:27:27Z")

</div>

> [@suarna](#):
>
> Is there a way to assume an IAM role

Not directly within the S3 plugin. You would need to call the `AssumeRole` API yourself, extract the `AccessKeyId`, `SecretAccessKey` and `SessionToken` values from the response, insert them into the Elasticsearch keystore, and then call the [reload secure settings API](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-nodes-reload-secure-settings.html).

---

<div class="post-metadata">

**Author:** ![suarna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suarna/32/141026_2.png) [@suarna](https://discuss.elastic.co/u/suarna)\
**Post date:** [January 30, 2025, 12:06pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/3 "2025-01-30T12:06:48Z")

</div>

Many thanks for the quick response.

I will check it

---

<div class="post-metadata">

**Author:** ![suarna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suarna/32/141026_2.png) [@suarna](https://discuss.elastic.co/u/suarna)\
**Post date:** [January 30, 2025, 4:03pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/4 "2025-01-30T16:03:53Z")

</div>

Ok,

It works like a charm. The problem now is that the connection, obviously, deads when de sessiontoken dead.

Is there any way to refresh the keystore contents using the API or other method in order to automate the token refreshal process centraly?

Thanks again¡

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [January 30, 2025, 4:35pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/5 "2025-01-30T16:35:54Z")

</div>

Yes you'll need to look at the `Expiration` field in the response to the `AssumeRole` API and repeat the process some time before the credentials expire. And repeat for the next key and so on...

I believe the credentials normally expire after 12h (if obtained with long-term credentials) so an hourly rotation would be more than adequate.

---

<div class="post-metadata">

**Author:** ![suarna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suarna/32/141026_2.png) [@suarna](https://discuss.elastic.co/u/suarna)\
**Post date:** [January 30, 2025, 4:44pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/6 "2025-01-30T16:44:51Z")

</div>

Thst´s correct David,

But, actually I refer to the elasticsearch REST API, I was wondering if there is a way to refresh the elasticsearch keystore remotely without needing to perform the task manually in each node.

Thanks¡¡

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [January 30, 2025, 4:46pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/7 "2025-01-30T16:46:28Z")

</div>

I see, no, that's not possible. ES is not itself permitted to write to its own keystore for security reasons. You need to do this with some external process having sufficient privileges.

---

<div class="post-metadata">

**Author:** ![suarna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suarna/32/141026_2.png) [@suarna](https://discuss.elastic.co/u/suarna)\
**Post date:** [January 30, 2025, 4:47pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/8 "2025-01-30T16:47:30Z")

</div>

Ok,

I see, We will find a way to do that

thanks¡

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2025, 4:47pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848/9 "2025-02-27T16:47:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
