Close|CloudStack Canvas · How-To Guide
How-To Fix

Grant a Compute Service Access to an S3 Bucket

EC2 and ECS: connecting your compute service to an S3 bucket on the canvas ALWAYS generates a scoped s3:GetObject/PutObject/ListBucket policy at export time — regardless of which way you drew the edge, whether the role is auto-created, connected directly to the Task Definition, or connected to the Service, and whether the canvas was drawn by hand, loaded from a saved project or starter template, or imported from CloudFormation/Terraform/draw.io. For ECS specifically, connect the bucket to the SERVICE node — the Task Definition node has no S3 connection rule of its own, so a bucket connected only there gets neither a grant nor a warning. You should not see this warning for an ECS Service or an EC2 instance; if you do, it is a real bug — report it. Lambda is the one exception: Lambda↔S3 can mean two different things (S3 triggering the Lambda vs. the Lambda reading/writing the bucket), so the grant is generated only once you tell CloudStack Canvas which one you mean — see "Make the choice on the canvas" below. The manual policy in this guide is for the rare case none of that applies (e.g. you deleted the auto-generated policy resource by hand after exporting) — you should not normally need it.

Paste into this field

IAM Role → permissions policy (or draw the edge on the canvas)

Output looks like

Canvas edge: EC2 → S3 (auto-generates an s3:GetObject/PutObject policy)

1Make the choice on the canvas (Lambda only)

Click the edge label between the Lambda and the bucket and choose "Read/Write Access" in the chooser. (Drawing the edge FROM the Lambda TO the bucket already defaults to this — the choice only matters if you drew it the other way, S3 → Lambda, which defaults to "S3 triggers this Lambda" instead.) Re-open Export and the warning is gone; no manual IAM editing needed.

3Manual policy (only if the above does not apply to your case)

Click "Add permissions" → "Create inline policy" → the JSON tab. Paste the policy below, replacing my-bucket with your bucket name. The two resource ARNs are required: the bucket itself (for ListBucket) and its objects (for Get/Put).

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": ["s3:GetObject", "s3:PutObject", "s3:ListBucket"],
    "Resource": [
      "arn:aws:s3:::my-bucket",
      "arn:aws:s3:::my-bucket/*"
    ]
  }]
}

6Save the policy

Name it something like AllowS3Access and click "Create policy". The role now has the permissions; no value needs pasting back into CloudStack Canvas.

Once you have the value, go back to CloudStack Canvas and paste it into the highlighted field.

CloudStack Canvas · Validation Guide

Grant a Compute Service Access to an S3 Bucket — CloudStack Canvas