New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update docs to describe how s3:// URLS does in fact support endpoint, region, and profile for upload #2456
Conversation
86f7f69
to
388bef5
Compare
… region, and profile for upload
388bef5
to
51cbeec
Compare
Also, this one should definitely be backported :) |
"Sid": "AlowDirectReads", | ||
"Action": [ | ||
"s3:GetObject", | ||
"s3:GetBucketLocation" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
GetBucketLocation
is no longer needed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed!
<example><title>Uploading with non-default credential profile for Amazon S3</title> | ||
<para><command>nix copy --to ssh://machine nixpkgs.hello s3://example-bucket?profile=cache-upload</command></para> | ||
<para>Your account will need the following IAM policy to | ||
upload to the cache:</para> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It's a bit strong to say that it needs this IAM policy. Rather the user needs certain rights which may be accomplished via this policy.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed!
Improvements to #2319 after realizing I was wrong. cc @copumpkin
I've tested all these with AWS S3 (copy-pasted these exact policies) and also DigitalOcean Spaces.
Rendered: https://screenshotscdn.firefoxusercontent.com/images/aa56ce00-b8a9-4616-b701-8ff50c0fc651.png