How to disable download of AWS Athena Query results?

0

How to restrict a user from downloading Athena query results, and prevent them from uploading files directly to the Athena results bucket? User should still be able to run query in Athena and see the results. Will be great if someone can share the terraform code for the same.

dipus
질문됨 7달 전506회 조회
1개 답변
1
수락된 답변

Hello,

You can achieve your use case by restricting the user's "Get and Put" Object permissions for that particular S3 location (query result location) and then to still run queries and to view results via Athena, you can consider using AWS global condition context keys such as "aws:CalledViaLast".

{ "Sid": "BlockAthenaDownloads", "Effect": "Deny", "Action": [ "s3:GetObject", "s3:PutObject" ], "Resource": "arn:aws:s3:::athenaquery_result_loction/prefix/*", "Condition": { "StringNotEquals": { "aws:calledViaLast": [ "athena.amazonaws.com" ] } } }

Please refer to the documentation below to learn more about AWS global condition context keys:

[+] AWS global condition context keys - https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-calledvia

Further, to create policy via terraform please refer to the below link:

[+] https://registry.terraform.io/providers/-/aws/latest/docs/resources/iam_role_policy_attachment

Thank you!

AWS
답변함 7달 전
  • Thank you! It worked...

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인