EC2 and ECS: connecting your compute service to an S3 bucket on the canvas ALWAYS generates a scoped s3:GetObject/PutObject/ListBucket policy at export time — regardless of which way you drew the edge, whether the role is auto-created, connected directly to the Task Definition, or connected to the Service, and whether the canvas was drawn by hand, loaded from a saved project or starter template, or imported from CloudFormation/Terraform/draw.io. For ECS specifically, connect the bucket to the SERVICE node — the Task Definition node has no S3 connection rule of its own, so a bucket connected only there gets neither a grant nor a warning. You should not see this warning for an ECS Service or an EC2 instance; if you do, it is a real bug — report it. Lambda is the one exception: Lambda↔S3 can mean two different things (S3 triggering the Lambda vs. the Lambda reading/writing the bucket), so the grant is generated only once you tell CloudStack Canvas which one you mean — see "Make the choice on the canvas" below. The manual policy in this guide is for the rare case none of that applies (e.g. you deleted the auto-generated policy resource by hand after exporting) — you should not normally need it.
Paste into this field
IAM Role → permissions policy (or draw the edge on the canvas)Output looks like
Canvas edge: EC2 → S3 (auto-generates an s3:GetObject/PutObject policy)Click the edge label between the Lambda and the bucket and choose "Read/Write Access" in the chooser. (Drawing the edge FROM the Lambda TO the bucket already defaults to this — the choice only matters if you drew it the other way, S3 → Lambda, which defaults to "S3 triggers this Lambda" instead.) Re-open Export and the warning is gone; no manual IAM editing needed.
Click "Add permissions" → "Create inline policy" → the JSON tab. Paste the policy below, replacing my-bucket with your bucket name. The two resource ARNs are required: the bucket itself (for ListBucket) and its objects (for Get/Put).
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": ["s3:GetObject", "s3:PutObject", "s3:ListBucket"],
"Resource": [
"arn:aws:s3:::my-bucket",
"arn:aws:s3:::my-bucket/*"
]
}]
}Name it something like AllowS3Access and click "Create policy". The role now has the permissions; no value needs pasting back into CloudStack Canvas.
Once you have the value, go back to CloudStack Canvas and paste it into the highlighted field.
CloudStack Canvas · Validation Guide