Is your feature request related to a problem? Please describe.
While working on an AWS project using this stack, we realised that we have to use boto3 for various things like accessing the SecretsManager and objects in s3 when the environment exchanges credentials using IAM policies (where the application itself does not need the keys to access the bucket).
It would be nice to provide a boto3 wrapped up to work with this stack.
Describe the solution you'd like
A set of wrapper methods on the s3_file_metadata table that allow us to work with IAM managed s3 buckets. These can be specifically be prefixed with aws_ to indicate that they work in an AWS managed environment only.
Secondly consider best practices around working with multiple buckets, in our use case we use a bucket to provide media files (accessed via a CDN) and the the other has user generated content which are only to be accessed via signed urls.
As for documentation it will be helpful to provide assumptions and samples.
Describe alternatives you've considered
NA
Additional context
See aws-eks-cluster for a terraform deployed AWS environment which is setup in the way described above.
Is your feature request related to a problem? Please describe. While working on an
AWS
project using this stack, we realised that we have to useboto3
for various things like accessing theSecretsManager
and objects ins3
when the environment exchanges credentials usingIAM
policies (where the application itself does not need the keys to access the bucket).It would be nice to provide a
boto3
wrapped up to work with this stack.Describe the solution you'd like A set of wrapper methods on the
s3_file_metadata
table that allow us to work withIAM
manageds3
buckets. These can be specifically be prefixed withaws_
to indicate that they work in an AWS managed environment only.Secondly consider best practices around working with multiple buckets, in our use case we use a bucket to provide
media
files (accessed via a CDN) and the the other has user generated content which are only to be accessed via signed urls.As for documentation it will be helpful to provide assumptions and samples.
Describe alternatives you've considered NA
Additional context See aws-eks-cluster for a
terraform
deployed AWS environment which is setup in the way described above.