We will deliver your requested data directly into an Amazon S3 bucket owned by your organization. Please use the steps below to create a private destination bucket and grant our delivery role temporary, write-only access.
Transfer Details:
Our delivery role ARN:
arn:aws:iam::627481450372:role/treez-data-exporter-accessDelivery prefix:
treez-data-export
Three Options:
There are three different ways to create the bucket and apply the necessary permissions:
Manual Creation
1. Create the bucket
In the AWS Management Console, open Amazon S3 and create a general purpose bucket with these settings:
AWS Region: Ask support which region is preferred for your dispensary
Bucket name: Choose a globally unique name. eg:
storename-treez-data-exportObject Ownership: Bucket owner enforced (ACLs disabled)
Block Public Access: Keep all four settings enabled
Default encryption: Server-side encryption with Amazon S3 managed keys (SSE-S3)
Bucket Versioning: Recommended until you have confirmed receipt of the delivery
Important: Do not make the bucket or its objects public. With Bucket owner enforced, your organization owns every object we upload.
2. Add the bucket policy
Open the bucket, select Permissions → Bucket policy, and paste the policy below.
Replace <BUCKET_NAME> with the bucket name you specified in the previous step.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowDeliveryRoleToLocateBucket",
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::627481450372:role/treez-data-exporter-access" },
"Action": "s3:GetBucketLocation",
"Resource": "arn:aws:s3:::<BUCKET_NAME>"
},
{
"Sid": "AllowDeliveryRoleToListDeliveryPrefix",
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::627481450372:role/treez-data-exporter-access" },
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::<BUCKET_NAME>",
"Condition": {
"StringLike": {
"s3:prefix": [
“treez-data-export",
"treez-data-export/*"
]
}
}
},
{
"Sid": "AllowDeliveryRoleToUpload",
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::627481450372:role/treez-data-exporter-access" },
"Action": [
"s3:PutObject",
"s3:AbortMultipartUpload",
"s3:ListMultipartUploadParts"
],
"Resource": "arn:aws:s3:::<BUCKET_NAME>/treez-data-export/*"
},
{
"Sid": "DenyInsecureTransport",
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": [
"arn:aws:s3:::<BUCKET_NAME>",
"arn:aws:s3:::<BUCKET_NAME>/*"
],
"Condition": {
"Bool": { "aws:SecureTransport": "false" }
}
}
]
}
What this allows: Our named role can upload and manage multipart uploads only under the agreed prefix. It cannot read, download, or delete delivered objects.
3. Send us the destination details
Bucket name: The name of the new S3 bucket
Region: Confirmation of which region the bucket was created in
Bucket policy: Confirmation that the policy has been saved
Please do not send AWS access keys, passwords, or other credentials. We will authenticate using our own AWS role.
We will perform a small test upload first. After you confirm the test, we will deliver the full dataset.
4. Remove our access after delivery
After you verify the delivery, remove the three AllowDeliveryRole… statements from the bucket policy.
Keep the DenyInsecureTransport statement and Block Public Access settings in place. You can then apply your normal retention, lifecycle, and access policies.
Alternative: Command Line Creation
Alternatively, you can create bucket and apply the policy using the AWS CLI.
Be sure to specify the bucket name.
Please reach out to support to confirm which AWS region to specify.
#!/usr/bin/env bash
BUCKET_NAME="your-bucket-name"
REGION="us-west-2"
# 1. Create the bucket
aws s3api create-bucket \
--bucket "$BUCKET_NAME" \
--region "$REGION" \
--create-bucket-configuration LocationConstraint="$REGION"
# 2. Block all public access
aws s3api put-public-access-block \
--bucket "$BUCKET_NAME" \
--public-access-block-configuration \
"BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true"
# 3. Apply the bucket policy
aws s3api put-bucket-policy \
--bucket "$BUCKET_NAME" \
--policy "{
\"Version\": \"2012-10-17\",
\"Statement\": [
{
\"Sid\": \"AllowCrossAccountDataExporter\",
\"Effect\": \"Allow\",
\"Principal\": {
\"AWS\": \"arn:aws:iam::627481450372:role/treez-data-exporter-access\"
},
\"Action\": [
\"s3:GetObject\",
\"s3:AbortMultipartUpload\",
\"s3:ListMultipartUploadParts\",
\"s3:PutObject\",
\"s3:DeleteObject\"
],
\"Resource\": \"arn:aws:s3:::$BUCKET_NAME/treez-data-export/*\"
},
{
\"Sid\": \"DenyInsecureTransport\",
\"Effect\": \"Deny\",
\"Principal\": \"*\",
\"Action\": \"s3:*\",
\"Resource\": [
\"arn:aws:s3:::$BUCKET_NAME\",
\"arn:aws:s3:::$BUCKET_NAME/*\"
],
\"Condition\": {
\"Bool\": {
\"aws:SecureTransport\": \"false\"
}
}
}
]
}"
Alternative: Cloud Formation Template
Be sure to specify the bucket name.
Please reach out to support to confirm which AWS region to specify.
AWSTemplateFormatVersion: "2010-09-09"
Description: Private S3 bucket with cross-account data exporter access and enforced HTTPS
Parameters:
BucketName:
Type: String
Description: Name of the S3 bucket to create
Resources:
DataBucket:
Type: AWS::S3::Bucket
Properties:
BucketName: !Ref BucketName
AccessControl: Private
PublicAccessBlockConfiguration:
BlockPublicAcls: true
IgnorePublicAcls: true
BlockPublicPolicy: true
RestrictPublicBuckets: true
BucketEncryption:
ServerSideEncryptionConfiguration:
- ServerSideEncryptionByDefault:
SSEAlgorithm: AES256
DataBucketPolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref DataBucket
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: AllowCrossAccountDataExporter
Effect: Allow
Principal:
AWS: arn:aws:iam::627481450372:role/treez-data-exporter-access
Action:
- s3:GetObject
- s3:PutObject
- s3:DeleteObject
Resource: !Sub "arn:aws:s3:::${BucketName}/treez-data-export/*"
- Sid: DenyInsecureTransport
Effect: Deny
Principal: "*"
Action: "s3:*"
Resource:
- !Sub "arn:aws:s3:::${BucketName}"
- !Sub "arn:aws:s3:::${BucketName}/*"
Condition:
Bool:
aws:SecureTransport: "false"
Outputs:
BucketName:
Value: !Ref DataBucket
Description: Name of the created S3 bucket
BucketArn:
Value: !GetAtt DataBucket.Arn
Description: ARN of the created S3 bucket
Deploy With:
aws cloudformation deploy \
--template-file bucket.yaml \
--stack-name my-data-export-bucket \
--parameter-overrides BucketName=your-bucket-name