# Snapshot to S3 - no delete permission

**URL:** <https://discuss.elastic.co/t/snapshot-to-s3-no-delete-permission/49493>\
**Category:** Elasticsearch\
**Created:** [May 8, 2016, 7:08pm UTC](https://discuss.elastic.co/t/snapshot-to-s3-no-delete-permission/49493 "2016-05-08T19:08:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sirkubax\_1](https://avatars.discourse-cdn.com/v4/letter/s/9de053/32.png) [@sirkubax\_1](https://discuss.elastic.co/u/sirkubax_1)\
**Post date:** [May 8, 2016, 7:08pm UTC](https://discuss.elastic.co/t/snapshot-to-s3-no-delete-permission/49493/1 "2016-05-08T19:08:09Z")

</div>

I have a goal of creating **'write-once' snapshot** of my current indexes.  
It would be a protection against someone 'accidentally' deleting some of the data.

To achieve that I've created a S3 bucket, but I had to add IAM policy permission:

> ```
> "s3:DeleteObject",
> 
> ```

via

> **[Snapshot module | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-snapshots.html)**

> **[GitHub - elastic/elasticsearch-cloud-aws: AWS Cloud Plugin for Elasticsearch](https://github.com/elastic/elasticsearch-cloud-aws#s3-repository)**
>
> AWS Cloud Plugin for Elasticsearch. Contribute to elastic/elasticsearch-cloud-aws development by creating an account on GitHub.

```
{
    "Statement": [
        {
            "Action": [
                "s3:ListBucket",
                "s3:GetBucketLocation",
                "s3:ListBucketMultipartUploads",
                "s3:ListBucketVersions"
            ],
            "Effect": "Allow",
            "Resource": [
                "arn:aws:s3:::snaps.example.com"
            ]
        },
        {
            "Action": [
                "s3:GetObject",
                "s3:PutObject",
                "s3:DeleteObject",
                "s3:AbortMultipartUpload",
                "s3:ListMultipartUploadParts"
            ],
            "Effect": "Allow",
            "Resource": [
                "arn:aws:s3:::snaps.example.com/*"
            ]
        }
    ],
    "Version": "2012-10-17"
}

```

This is because, registration of the repository:

> curl -XPUT '[http://localhost:9200/\_snapshot/my\_s3\_repository?pretty](http://localhost:9200/_snapshot/my_s3_repository?pretty)' -d {bucket\_settings}

while 'registering the repository', does create, and then **delete** some files in s3 bucket, example:

s3://elb-snapshot/tests-kvpG54MJS0mUqovrwWcIeQ-master  
s3://elb-snapshot/tests-kvpG54MJS0mUqovrwWcIeQ-ibLCaJIoSEuJqM1N5rb3ug

I've checked, that actually, after You register the repository (automatically for every cluster node), You can  
**remove** the IAM policy rule, the line:

> ```
> "s3:DeleteObject",
> 
> ```

and the snapshot would be _still working fine!_

My question is - would it brake at some time? I guess a new node attachment or a cluster restart _might_ like to repeat write/read/delete bucket test...

(What about removing old files?  
I did set up bucket TTL policy to remove files after 365 days  
[Snapshots to s3; file TTL](https://discuss.elastic.co/t/snapshots-to-s3-file-ttl/49492))

---

<div class="post-metadata">

**Author:** ![sirkubax\_1](https://avatars.discourse-cdn.com/v4/letter/s/9de053/32.png) [@sirkubax\_1](https://discuss.elastic.co/u/sirkubax_1)\
**Post date:** [May 9, 2016, 10:15pm UTC](https://discuss.elastic.co/t/snapshot-to-s3-no-delete-permission/49493/2 "2016-05-09T22:15:43Z")

</div>

You can create IAM policy without this Permission, if You add verify=false while registering the bucket

curl -XPUT '[http://localhost:9200/\_snapshot/my\_ttl\_repository?verify=false](http://localhost:9200/_snapshot/my_ttl_repository?verify=false)' -d @configure\_ttl

It won't create\_and\_delete files to check the permissions - so there You go.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:52pm UTC](https://discuss.elastic.co/t/snapshot-to-s3-no-delete-permission/49493/3 "2017-07-05T22:52:55Z")

</div>


