<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External volume over S3 Access point in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/external-volume-over-s3-access-point/m-p/92969#M38596</link>
    <description>&lt;P&gt;This look fine to me. I am the owner of the (external) volume and have READ VOLUME privilege on it. (as for the external location I am also its owner and have READ FILES, BROSE, CREATE EXTERNAL TABLE and CREATE EXTERNAL VOLUME)&lt;/P&gt;&lt;P&gt;One additional info I got, it seems to me that&amp;nbsp; Databricks launches&lt;FONT face="courier new,courier"&gt;&amp;nbsp;s3:GetBucketOwnershipControls&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;s3:GetBucketVersioning&lt;/FONT&gt;&amp;nbsp;actions (which in my case are on the bucket possibly denied). If so, why does it do so from the volume, but not from the external location? And is it necessary?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2024 13:21:01 GMT</pubDate>
    <dc:creator>pmarko1711</dc:creator>
    <dc:date>2024-10-07T13:21:01Z</dc:date>
    <item>
      <title>External volume over S3 Access point</title>
      <link>https://community.databricks.com/t5/data-engineering/external-volume-over-s3-access-point/m-p/92603#M38474</link>
      <description>&lt;P&gt;Can anybody confirm if&amp;nbsp; external volumes pointing to S3 access points work in Databricks on AWS?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have S3 bucket, but can only access it via S3 access point. The bucket is KMS encrypted.&lt;/LI&gt;&lt;LI&gt;I created an IAM role that can list and read the S3 access point (and can also use the KMS key, plus it gives read access to the underlying bucket). I double checked that it can browse the S3 access point.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;The IAM role is assumable by Databricks and by itself.&lt;/LI&gt;&lt;LI&gt;I registered a storage credential and defined an external location (using the former)&lt;/LI&gt;&lt;LI&gt;I created an external volume that uses the very same external location, and I have READ VOLUME privilege&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;With that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I can browse the files (of the S3 access point) using the external location; however&lt;/LI&gt;&lt;LI&gt;When I try to browse files via the external volume, I get "&lt;SPAN&gt;Access to the storage bucket is forbidden by AWS." error.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;I would assume that if I can browse the S3 access point via the external location, I would also be able to browse it via the (linked) external volume. What am I doing wrong? Do S3 access points work for external volumes?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 16:17:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/external-volume-over-s3-access-point/m-p/92603#M38474</guid>
      <dc:creator>pmarko1711</dc:creator>
      <dc:date>2024-10-02T16:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: External volume over S3 Access point</title>
      <link>https://community.databricks.com/t5/data-engineering/external-volume-over-s3-access-point/m-p/92965#M38593</link>
      <description>&lt;P&gt;Please check the volume permissions.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 12:45:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/external-volume-over-s3-access-point/m-p/92965#M38593</guid>
      <dc:creator>gchandra</dc:creator>
      <dc:date>2024-10-07T12:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: External volume over S3 Access point</title>
      <link>https://community.databricks.com/t5/data-engineering/external-volume-over-s3-access-point/m-p/92969#M38596</link>
      <description>&lt;P&gt;This look fine to me. I am the owner of the (external) volume and have READ VOLUME privilege on it. (as for the external location I am also its owner and have READ FILES, BROSE, CREATE EXTERNAL TABLE and CREATE EXTERNAL VOLUME)&lt;/P&gt;&lt;P&gt;One additional info I got, it seems to me that&amp;nbsp; Databricks launches&lt;FONT face="courier new,courier"&gt;&amp;nbsp;s3:GetBucketOwnershipControls&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;s3:GetBucketVersioning&lt;/FONT&gt;&amp;nbsp;actions (which in my case are on the bucket possibly denied). If so, why does it do so from the volume, but not from the external location? And is it necessary?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 13:21:01 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/external-volume-over-s3-access-point/m-p/92969#M38596</guid>
      <dc:creator>pmarko1711</dc:creator>
      <dc:date>2024-10-07T13:21:01Z</dc:date>
    </item>
  </channel>
</rss>

