Amazon S3
Receive Amazon S3 object events in Tessel through EventBridge, as typed events. Use them to process uploaded files, then read, write or copy objects with a scoped IAM role.
Warehouse
Category
Events
Sync mode
p95 750 ms
Latency
7 min
Setup time
What it can do
- Object createdEvent
- Object deletedEvent
- Object restoredEvent
- Get an objectRead
- List objectsRead
- Put an objectWrite
- Copy an objectWrite
- Create a presigned URLRead
Overview
The Amazon S3 connector listens for object events from the buckets you choose and reads or writes objects with an IAM role in your account. Each event carries the bucket, key, size and ETag, and every file Tessel touches is listed in the trace of the run.
Teams use it to parse vendor CSVs as they land and load them into Snowflake, to copy signed contracts from Google Drive into an archive bucket and to post a Slack message when a nightly export is missing.
Supported setups
General purpose buckets in any AWS region
SSE-S3 and SSE-KMS encrypted objects, with
kms:Decrypton the rolePrefix and suffix filters per trigger, such as
invoices/and.csv
How event delivery works
You turn on EventBridge notifications for the bucket, and a rule forwards matching events to Tessel's endpoint in your workspace region. Tessel checks each event against the schema and starts the workflow, then assumes your role to read the object.
Large files
Objects over 100 MB are read in ranges and written with multipart upload, so a step never holds a whole file in memory. Writes use the run and step as part of the key, so a retry overwrites rather than duplicates.
Permissions needed
Create an IAM role that trusts Tessel's AWS account with your external ID. It needs read access to the buckets your triggers watch. Write access is only required on prefixes you write to.
s3:GetObjectands3:ListBucketon watched bucketss3:PutObjectonly on prefixes a workflow writes tosts:AssumeRoletrust withsts:ExternalIdset to your workspace ID
Five steps. About seven minutes.
Most of the time goes into the CloudFormation stack. Tessel assumes the role before you move on.
- Deploy the CloudFormation stack that creates the IAM roleAWS3 min
- Turn on EventBridge notifications for the bucketAWS1 min
- Paste the role ARN and pick buckets and prefixesTessel2 min
- Confirm the external ID matches the trust policyTessel1 min
- Upload a test file and watch the event arriveVerify750 ms
Your buckets, in a workflow today.
Connect Amazon S3 on the free plan. Up to three builders and 10,000 runs a month, no card required.