Skip to main content

Chipper Access

Before Chipper can read logs from your S3 bucket, you need to create AWS IAM credentials with appropriate permissions. This one-time setup allows Chipper to securely access your log files.


What You'll Need​

  • AWS account with S3 and IAM access
  • An S3 bucket containing your log files
  • Permissions to create IAM users and policies

Step 1: Create an IAM User​

  1. Navigate to IAM Console

    • Log into AWS Console
    • Go to IAM (Identity and Access Management)
  2. Create New User

    • Click "Users" in the left sidebar
    • Click "Create user"
    • Enter a username (e.g., chipper-log-reader)
    • Click Next

Step 2: Set Permissions​

Create a policy for the bucket Chipper will read:

  1. Select Attach policies directly, then Create policy → JSON.
  2. Replace YOUR-BUCKET-NAME in this policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:ListBucket", "s3:GetBucketLocation", "s3:GetBucketNotification"],
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME"
},
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME/*"
}
]
}
  1. Save the policy, attach it to the reader user, and finish creating the user.

s3:GetBucketNotification lets the instant-import wizard verify the notification destination. It does not let Chipper edit the customer's bucket notifications. A storage administrator can further restrict listing and object reads to the intended prefix; ensure the connection check and actual log reads still succeed. SSE-KMS objects also require access to their encryption key.


Step 3: Generate Access Keys​

  1. Open the Created User

    • Click on the username you just created
    • Go to the Security credentials tab
  2. Create Access Key

    • Scroll to Access keys section
    • Click "Create access key"
    • Select "Third-party service" as the use case
    • Click Next → Create access key
  3. Save Your Credentials

    • Copy the Access Key ID (starts with AKIA...)
    • Copy the Secret Access Key (long random string)

    ⚠️ Important: The Secret Access Key is only shown once. Save it securely - you'll need both values for Chipper configuration.


What's Next?​

Now that you have your credentials, you can:


Troubleshooting​

Access Denied Errors​

Symptom: Chipper can't list or read files from your bucket

Solutions:

  • Verify both resource ARNs in your IAM policy match your bucket name exactly:
    • arn:aws:s3:::your-bucket-name (for listing)
    • arn:aws:s3:::your-bucket-name/* (for reading)
  • Check that s3:GetObject AND s3:ListBucket are both allowed
  • Ensure the IAM user has the policy attached

Invalid Credentials​

Symptom: Authentication errors when testing connection

Solutions:

  • Verify you copied the full Access Key ID and Secret Access Key
  • Check for extra spaces or line breaks when pasting
  • Ensure the access key is still active (check IAM console)

Need Help?​

If you encounter issues with AWS access setup, check: