# Can't register snapshot repository to S3

**URL:** <https://discuss.elastic.co/t/cant-register-snapshot-repository-to-s3/195115>\
**Category:** Elasticsearch\
**Created:** [August 13, 2019, 10:14pm UTC](https://discuss.elastic.co/t/cant-register-snapshot-repository-to-s3/195115 "2019-08-13T22:14:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bursade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bursade/32/52225_2.png) [@Bursade](https://discuss.elastic.co/u/Bursade)\
**Post date:** [August 13, 2019, 10:14pm UTC](https://discuss.elastic.co/t/cant-register-snapshot-repository-to-s3/195115/1 "2019-08-13T22:14:41Z")

</div>

Hi all!  
I'm trying to register an S3 bucket as my snapshot repository.  
I'm using Elasticsearch Service, from AWS (which uses version 5.5 of Elasticsearch)  
When I run this script

> ```
> import boto3
> import requests
> from requests_aws4auth import AWS4Auth
> 
> host = '' # include https:// and trailing /
> region = '' # e.g. us-west-1
> service = 'es'
> credentials = boto3.Session().get_credentials()
> awsauth = AWS4Auth(credentials.access_key, credentials.secret_key, region, service, session_token=credentials.token)
> 
> # Register repository
> 
> path = '_snapshot/my-snapshot-repo' # the Elasticsearch API endpoint
> url = host + path
> 
> payload = {
> "type": "s3",
> "settings": {
> "bucket": "s3-bucket-name",
> "region": "us-west-1",
> "role_arn": "arn:aws:iam::123456789012:role/TheSnapshotRole"
> }
> }
> 
> headers = {"Content-Type": "application/json"}
> 
> r = requests.put(url, auth=awsauth, json=payload, headers=headers)
> 
> print(r.status_code)
> print(r.text)
> 
> ```

I get this error:

> {"error":{"root\_cause":[{"type":"a\_w\_s\_security\_token\_service\_exception","reason":"a\_w\_s\_security\_token\_service\_exception: Access denied (Service: AWSSecurityTokenService; Status Code: 403; Error Code: AccessDenied; Request ID: 8df9ffae-be16-11e9-a6c9-5561e849f8ed)"}],"type":"blob\_store\_exception","reason":"failed to check if blob exists","caused\_by":{"type":"a\_w\_s\_security\_token\_service\_exception","reason":"a\_w\_s\_security\_token\_service\_exception: Access denied (Service: AWSSecurityTokenService; Status Code: 403; Error Code: AccessDenied; Request ID: 8df9ffae-be16-11e9-a6c9-5561e849f8ed)"}},"status":500}

I've seen posts with similar errors but none of them have any response.

> [@Can't register snapshot repository in elasticsearch](https://discuss.elastic.co/t/cant-register-snapshot-repository-in-elasticsearch/141131):
>
> I would like to register snapshot repository in elasticsearch to S3 in order to backup my data. However, I got below error message when running my python script. Anyone can help? thanks!! Here is the script: import boto3 import requests from requests\_aws4auth import AWS4Auth host = 'https://vpc-test-eqcwh2i6vu5m6btpqr6kv3ay7i.ap-southeast-1.es.amazonaws.com' # include https:// and trailing / region = 'ap-southeast-1' # e.g. us-west-1 service = 'es' credentials = boto3.Session().get\_credentia…

> [@Can't seem to register a snapshot repository with AWS S3](https://discuss.elastic.co/t/cant-seem-to-register-a-snapshot-repository-with-aws-s3/169026):
>
> I'm running an Elasticsearch V6.3.2 cluster on Kubernetes, and I've installed the repository-s3 plugin. I've added my AWS Access Key and Secret Key to the elasticsearch.keystore. I'm trying to register my snapshot repository with: curl -X PUT -H "Content-Type: application/json" -d '{ "type": "s3", "settings": { "bucket": "efk-snapshots-k8s" } }' "localhost:9200/\_snapshot/snap123" The above request fails with: { "error":{ "root\_cause":[ { "type":"amazo…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 10:14pm UTC](https://discuss.elastic.co/t/cant-register-snapshot-repository-to-s3/195115/2 "2019-09-10T22:14:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
