<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S3 limited bucket permissions in Get Started Discussions</title>
    <link>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/120490#M10118</link>
    <description>&lt;P&gt;Thanks, but no thanks, spam resides in JUNK folder&lt;/P&gt;</description>
    <pubDate>Thu, 29 May 2025 06:33:15 GMT</pubDate>
    <dc:creator>arnas</dc:creator>
    <dc:date>2025-05-29T06:33:15Z</dc:date>
    <item>
      <title>S3 limited bucket permissions</title>
      <link>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/119926#M10062</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;can I run Databricks on limited/restricted S3 bucket folder, no access to bucket root level as it is restricted per project folder in IAM?&lt;BR /&gt;&lt;BR /&gt;i.e s3://mybucket/myproject_abc/&lt;BR /&gt;&lt;BR /&gt;Now I configured all permissions as per documentation&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/connect/unity-catalog/cloud-storage/storage-credentials" target="_blank"&gt;https://docs.databricks.com/aws/en/connect/unity-catalog/cloud-storage/storage-credentials&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;"Condition": {&lt;BR /&gt;"StringLike": {&lt;BR /&gt;"s3:prefix": "myproject_abc/*"&lt;BR /&gt;}&lt;BR /&gt;},&lt;BR /&gt;"Effect": "Allow",&lt;BR /&gt;"Resource": [&lt;BR /&gt;"arn:aws:s3:::mybucket/myproject_abc/*",&lt;BR /&gt;"arn:aws:s3:::mybucket"&lt;BR /&gt;],&lt;BR /&gt;"Sid": "AllowS3ActionsForProjectABC"&lt;BR /&gt;}&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 22 May 2025 05:37:39 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/119926#M10062</guid>
      <dc:creator>arnas</dc:creator>
      <dc:date>2025-05-22T05:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: S3 limited bucket permissions</title>
      <link>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/119985#M10066</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/165470"&gt;@arnas&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can give Databricks access to just the S3 folder s3://mybucket/myproject_abc/ without exposing the whole bucket.&lt;/P&gt;&lt;P&gt;IAM Policy should include:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Bucket level: Allow s3:ListBucket on arn:aws:s3:::mybucket with a condition for the myproject_abc/ prefix.&lt;/LI&gt;&lt;LI&gt;Object level: Allow s3:GetObject, s3:PutObject, and s3:DeleteObject on arn:aws:s3:::mybucket/myproject_abc/*.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 22 May 2025 15:58:09 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/119985#M10066</guid>
      <dc:creator>SP_6721</dc:creator>
      <dc:date>2025-05-22T15:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: S3 limited bucket permissions</title>
      <link>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/120429#M10112</link>
      <description>&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;aws cli works to list the folder, and I am able to download files from inside the folder&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;aws s3 ls&lt;BR /&gt;aws s3 cp&lt;BR /&gt;&lt;BR /&gt;here is my policy, anything I am missing ?&lt;BR /&gt;&lt;BR /&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Version"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"2012-10-17"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Statement"&lt;/SPAN&gt;&lt;SPAN&gt;: [&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Sid"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"AllowObjectActionsInCustomerPrefix"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Effect"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"Allow"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Action"&lt;/SPAN&gt;&lt;SPAN&gt;: [&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:GetObject"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:PutObject"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:DeleteObject"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:AbortMultipartUpload"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:ListMultipartUploadParts"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;],&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Resource"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"arn:aws:s3:::mybucket/folder/*"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;},&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Sid"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"AllowListBucketInCustomerPrefix"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Effect"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"Allow"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Action"&lt;/SPAN&gt;&lt;SPAN&gt;: [&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:ListBucket"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:GetBucketLocation"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:ListBucketMultipartUploads"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;],&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Resource"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"arn:aws:s3:::mybucket"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Condition"&lt;/SPAN&gt;&lt;SPAN&gt;: {&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"StringLike"&lt;/SPAN&gt;&lt;SPAN&gt;: {&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"s3:prefix"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"folder/*"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;},&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Sid"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"AllowAssumeRole"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Effect"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"Allow"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Action"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"sts:AssumeRole"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Resource"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"arn:aws:iam::MYACCOUNTID:role/mycustomer-databricks-access"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;}&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 May 2025 13:56:14 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/120429#M10112</guid>
      <dc:creator>arnas</dc:creator>
      <dc:date>2025-05-28T13:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: S3 limited bucket permissions</title>
      <link>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/120490#M10118</link>
      <description>&lt;P&gt;Thanks, but no thanks, spam resides in JUNK folder&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 06:33:15 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/s3-limited-bucket-permissions/m-p/120490#M10118</guid>
      <dc:creator>arnas</dc:creator>
      <dc:date>2025-05-29T06:33:15Z</dc:date>
    </item>
  </channel>
</rss>

