AWS Cross-Account PUT
If your infrastructure is hosted on AWS, please adopt this solution.
How to use Cross-Account PUT, detailed documentation is here.
1. Overview
To ensure seamless and secure data delivery between Klavi and partners, we utilize the AWS Cross-Account S3 PUT method. In this architecture, Klavi (the Source Account) pushes files directly into an S3 bucket managed within the partner's AWS environment (the Destination Account).
Key Benefits:
- Data Sovereignty: Data is stored directly in your infrastructure.
- Security: Leverages AWS Identity and Access Management (IAM) without the need for exchanging long-term access keys.
- Automation: Supports automated workflows with native AWS scaling.
2. Partner Configuration Requirements
As the data recipient, the partner must configure their AWS environment to permit Klavi’s IAM role to write objects to the designated bucket.
2.1 Create an S3 Bucket
Create a dedicated S3 bucket for receiving Klavi data.
- Recommended naming: klavi-data-transfer-<partner-name>
- Region: Any supported AWS Region (please specify your choice).
2.2 Configure Bucket Policy
To allow Klavi to upload files, you must attach a Resource-based Policy to your bucket. This policy grants Klavi’s IAM Role the s3:PutObject and s3:PutObjectAcl permissions.
Replace <Your-Bucket-Name> with your actual bucket name and use the Klavi IAM Role ARN provided by our integration team.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowKlaviCrossAccountPut",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::KLAVI_ACCOUNT_ID:role/KlaviDataExporterRole"
},
"Action": [
"s3:PutObject",
"s3:PutObjectAcl"
],
"Resource": "arn:aws:s3:::<Your-Bucket-Name>/*",
"Condition": {
"StringEquals": {
"s3:x-amz-acl": "bucket-owner-full-control"
}
}
}
]
}2.3 Set S3 Object Ownership
To ensure your account gains full ownership of the files uploaded by Klavi, you must enable S3 Object Ownership:
- Go to the Permissions tab of your bucket.
- Under Object Ownership, select Bucket owner preferred.
- Note: This ensures that when Klavi uploads with the bucket-owner-full-control ACL, the object ownership is automatically transferred to your account.
3. Information Exchange Checklist
To complete the integration, the following technical details must be exchanged via secure channels.
3.1 From Partner to Klavi
Please provide these details to Klavi’s support team:
Parameter | Description | Example |
|---|---|---|
AWS Region | The region where your bucket is hosted. | us-east-1 |
S3 Bucket Name | The exact name of the destination bucket. | klavi-delivery-acme-prod |
S3 Prefix (Optional) | A specific folder path within the bucket. | /daily-sync/ |
KMS Key ARN (Optional) | Required if using a Customer Managed Key for encryption. | arn:aws:kms:region:acct:key/id |
3.2 From Klavi to Partner
Klavi will provide the following identity information for your Policy configuration:
Parameter | Description |
|---|---|
Klavi AWS Account ID | Klavi’s unique AWS identifier. |
Klavi IAM Role ARN | The identity that will perform the PutObject operations. |
4. Klavi Operational Workflow
Once the partner provides the bucket details and applies the policy, Klavi will:
- Provision IAM Permissions: Grant our internal export service the rights to access your external bucket.
- Configure Delivery Pipeline: Set up the daily automated transfer job.
- Connectivity Validation: Perform a test upload file to verify permissions and encryption settings.
5. Security & Compliance
- Encryption in Transit: All data is transferred over HTTPS using TLS 1.2+.
- Encryption at Rest: We support SSE-S3 and SSE-KMS (AWS Key Management Service).
- Least Privilege: Our IAM roles are strictly scoped to PutObject actions only; Klavi cannot list or delete other files in your bucket.
Support: For technical assistance during setup, please contact our support team at [email protected].