Manage AWS S3 assets¶
Operations on S3 assets (connections, buckets, objects).
In general, these should be:
- Created in top-down order (connection, then bucket, then object)
- Deleted in bottom-up order (objects, then buckets, then connections)1
erDiagram
Connection ||--o{ S3Bucket : contains
S3Bucket ||--o{ S3Object : contains
Asset structure¶
Connection¶
An AWS S3 connection requires a name
and qualifiedName
. For creation, specific settings are also required to distinguish it as an AWS S3 connection rather than another type of connection. In addition, at least one of adminRoles
, adminGroups
, or adminUsers
must be provided.
Create an S3 connection | |
---|---|
1 2 3 4 5 6 7 8 9 10 |
|
- Retrieve the GUID for the admin role, to use later for defining the roles that can administer the connection.
- Build up the minimum request to create a connection.
- Provide a human-readable name for your connection, such as
production
ordevelopment
. - Set the type of connection to S3.
- List the workspace roles that should be able to administer the connection (or null if none). All users with that workspace role (current and future) will be administrators of the connection. Note that the values here need to be the GUID(s) of the workspace role(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided. - List the group names that can administer this connection (or null if none). All users within that group (current and future) will be administrators of the connection. Note that the values here are the name(s) of the group(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided. - List the user names that can administer this connection (or null if none). Note that the values here are the username(s) of the user(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided. - Actually call Atlan to create the connection. Because this operation will persist the asset in Atlan, you must provide it an
AtlanClient
through which to connect to the tenant. - Retrieve the qualifiedName for use in subsequent creation calls. (You'd probably want to do some null checking first.)
Create an S3 connection | |
---|---|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 |
|
- Retrieve the GUID for the admin role, to use later for defining the roles that can administer the connection.
- Build up the minimum request to create a connection.
- Provide a human-readable name for your connection, such as
production
ordevelopment
. - Set the type of connection to S3.
- List the workspace roles that should be able to administer the connection (if any, defaults to
None
). All users with that workspace role (current and future) will be administrators of the connection. Note that the values here need to be the GUID(s) of the workspace role(s). At least one ofadmin_roles
,admin_groups
, oradmin_users
must be provided. - List the group names that can administer this connection (if any, defaults to
None
). All users within that group (current and future) will be administrators of the connection. Note that the values here are the name(s) of the group(s). At least one ofadmin_roles
,admin_groups
, oradmin_users
must be provided. - List the user names that can administer this connection (if any, defaults to
None
). Note that the values here are the username(s) of the user(s). At least one ofadmin_roles
,admin_groups
, oradmin_users
must be provided. - Actually call Atlan to create the connection.
- Retrieve the qualified_name for use in subsequent creation calls. (You'd probably want to do some other checks first.)
Create an S3 connection | |
---|---|
1 2 3 4 5 6 7 8 9 10 |
|
- Retrieve the GUID for the admin role, to use later for defining the roles that can administer the connection.
- Build up the minimum request to create a connection.
- Provide a human-readable name for your connection, such as
production
ordevelopment
. - Set the type of connection to S3.
- List the workspace roles that should be able to administer the connection (or null if none). All users with that workspace role (current and future) will be administrators of the connection. Note that the values here need to be the GUID(s) of the workspace role(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided. - List the group names that can administer this connection (or null if none). All users within that group (current and future) will be administrators of the connection. Note that the values here are the name(s) of the group(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided. - List the user names that can administer this connection (or null if none). Note that the values here are the username(s) of the user(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided. - Actually call Atlan to create the connection. Because this operation will persist the asset in Atlan, you must provide it an
AtlanClient
through which to connect to the tenant. - Retrieve the qualifiedName for use in subsequent creation calls. (You'd probably want to do some null checking first.)
POST /api/meta/entity/bulk | |
---|---|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 |
|
- The
typeName
must be exactlyConnection
. - Human-readable name for your connection, such as
production
ordevelopment
. - The
connectorName
must be exactlys3
. - The
qualifiedName
should follow the pattern:default/s3/<epoch>
, where<epoch>
is the time in milliseconds at which the connection is being created. - The
category
must beObjectStore
. - List any workspace roles that can administer this connection. All users with that workspace role (current and future) will be administrators of the connection. Note that the values here need to be the GUID(s) of the workspace role(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided. - List any groups that can administer this connection. All users within that group (current and future) will be administrators of the connection. Note that the values here are the name(s) of the group(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided. - List any users that can administer this connection. Note that the values here are the username(s) of the user(s). At least one of
adminRoles
,adminGroups
, oradminUsers
must be provided.
Access policies
Atlan creates the policies that grant access to a connection, including the ability to retrieve the connection and to create assets within it, asynchronously. It can take several seconds (even up to approximately 30 seconds) before these are in place after creating the connection.
You may therefore need to wait before you'll be able to create the assets below within the connection.
To confirm access, retrieve the connection after it has been created. The SDKs' retry loops will automatically retry until the connection can be successfully retrieved. At that point, your API token has permission to create the other assets.
Note: if you are reusing an existing connection rather than creating one via your API token, you must give your API token a persona that has access to that connection. Otherwise all attempts to create, read, update, or delete assets within that connection will fail due to a lack of permissions.
S3Bucket¶
An AWS S3 bucket requires both a name
and a qualifiedName
. During creation, you also need to specify the connectionQualifiedName
of the connection associated with the bucket, and optionally provide a unique awsArn
.
Create an S3 bucket | |
---|---|
11 12 13 14 15 16 17 18 |
|
- Build up the minimum request to create a bucket.
- Provide a human-readable name for your bucket.
- Provide the
qualifiedName
of the connection for this bucket. - (Optional) If
awsArn
is provided, it will be used to construct thequalifiedName
for the bucket; otherwise, thename
of the bucket will be used. - (Optional) To ensure the UI displays the correct count of
S3Object
's, set thes3ObjectCount
directly on theS3Bucket
instance. - Actually call Atlan to create the bucket. Because this operation will persist the asset in Atlan, you must provide it an
AtlanClient
through which to connect to the tenant. - Retrieve the created bucket for use in subsequent creation calls. (You'd probably want to do some null checking first.)
Create an S3 bucket | |
---|---|
16 17 18 19 20 21 22 23 |
|
- Build up the minimum request to create a bucket.
- Provide a human-readable name for your bucket.
- Provide the
qualified_name
of the connection for this bucket. - (Optional) If
aws_arn
is provided, it will be used to construct thequalified_name
for the bucket; otherwise, thename
of the bucket will be used. - (Optional) To ensure the UI displays the correct count of
S3Object
's, set thes3_object_count
directly on theS3Bucket
instance. - Actually call Atlan to create the bucket.
- Retrieve the
qualified_name
for use in subsequent creation calls. (You'd probably want to do some checks first.)
Create an S3 bucket | |
---|---|
11 12 13 14 15 16 17 18 |
|
- Build up the minimum request to create a bucket.
- Provide a human-readable name for your bucket.
- Provide the
qualifiedName
of the connection for this bucket. - (Optional) If
awsArn
is provided, it will be used to construct thequalifiedName
for the bucket; otherwise, thename
of the bucket will be used. - (Optional) To ensure the UI displays the correct count of
S3Object
's, set thes3ObjectCount
directly on theS3Bucket
instance. - Actually call Atlan to create the bucket. Because this operation will persist the asset in Atlan, you must provide it an
AtlanClient
through which to connect to the tenant. - Retrieve the created bucket for use in subsequent creation calls. (You'd probably want to do some null checking first.)
POST /api/meta/entity/bulk | |
---|---|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 |
|
- The
typeName
must be exactlyS3Bucket
. - Human-readable name for your bucket.
- The
awsArn
should be the unique ARN from AWS for this bucket. - The
qualifiedName
should follow the pattern:default/s3/<epoch>/<awsArn>
, wheredefault/s3/<epoch>
is the qualifiedName of the connection for this bucket and<awsArn>
is the unique ARN for this bucket. - The
connectionQualifiedName
must be the exact qualifiedName of the connection for this bucket. - The
connectorName
must be exactlys3
.
S3Object¶
An AWS S3 object requires a name
and a qualifiedName
. For creation, you also need to specify the connectionQualifiedName
of the connection for the object, and a unique awsArn
or prefix
. You should also specify the bucket
the object is in, along with its s3BucketName
and s3BucketQualifiedName
.
By AWS ARN¶
Create an S3 object using AWS ARN:
Create an S3 object using AWS ARN | |
---|---|
18 19 20 21 22 23 |
|
- Build up the minimum request to create an object.
- Provide a human-readable name for your object.
- Provide the bucket in which this object should be created.
- Provide the unique ARN from AWS for this object.
- Actually call Atlan to create the object. Because this operation will persist the asset in Atlan, you must provide it an
AtlanClient
through which to connect to the tenant.
Create an S3 object using AWS ARN | |
---|---|
23 24 25 26 27 28 29 30 |
|
- Build up the minimum request to create an object.
- Provide a human-readable name for your object.
- Provide the
qualified_name
of the connection for this object. - Provide the unique ARN from AWS for this object.
- Provide the
name
of the bucket this object should be created within. - Provide the
qualified_name
of the bucket this object should be created within. - Actually call Atlan to create the object.
Create an S3 object using AWS ARN | |
---|---|
18 19 20 21 22 23 |
|
- Build up the minimum request to create an object.
- Provide a human-readable name for your object.
- Provide the bucket in which this object should be created.
- Provide the unique ARN from AWS for this object.
- Actually call Atlan to create the object. Because this operation will persist the asset in Atlan, you must provide it an
AtlanClient
through which to connect to the tenant.
POST /api/meta/entity/bulk | |
---|---|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 |
|
- The
typeName
must be exactlyS3Object
. - Human-readable name for your object.
- The
awsArn
should be the unique ARN from AWS for this object. - The
qualifiedName
should follow the pattern:default/s3/<epoch>/<awsArn>
, wheredefault/s3/<epoch>
is thequalifiedName
of the connection for this object and<awsArn>
is the unique ARN for this object. - The
connectionQualifiedName
must be the exact qualifiedName of the connection for this object. - The
connectorName
must be exactlys3
. - The bucket in which this object exists is embedded in the
bucket
attribute. - The
typeName
for this embedded reference must beS3Bucket
. - To complete the reference, you must include a
uniqueAttributes
object with the qualifiedName of the bucket. Note: the bucket must already exist in Atlan before creating the object. - The
s3BucketName
should be the human-readable name of the bucket. - The
s3BucketQualifiedName
should be the qualifiedName of the bucket.
By prefix¶
Create an S3 object using prefix:
Create an S3 object using prefix | |
---|---|
18 19 20 21 22 23 |
|
- Build up the minimum request to create an object.
- Provide a human-readable name for your object.
- Provide the bucket in which this object should be created.
- Provide the folder path where the object is located within the bucket.
- Actually call Atlan to create the object. Because this operation will persist the asset in Atlan, you must provide it an
AtlanClient
through which to connect to the tenant.
Create an S3 object using prefix | |
---|---|
23 24 25 26 27 28 29 30 |
|
- Build up the minimum request to create an object.
- Provide a human-readable name for your object.
- Provide the
qualified_name
of the connection for this object. - Provide the folder path where the object is located within the bucket.
- Provide the
name
of the bucket this object should be created within. - Provide the
qualified_name
of the bucket this object should be created within. - Actually call Atlan to create the object.
Create an S3 object using prefix | |
---|---|
18 19 20 21 22 23 |
|
- Build up the minimum request to create an object.
- Provide a human-readable name for your object.
- Provide the bucket in which this object should be created.
- Provide the folder path where the object is located within the bucket.
- Actually call Atlan to create the object. Because this operation will persist the asset in Atlan, you must provide it an
AtlanClient
through which to connect to the tenant.
POST /api/meta/entity/bulk | |
---|---|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 |
|
- The
typeName
must be exactlyS3Object
. - Human-readable name for your object.
- Provide the folder path where the object is located within the bucket.
- The
qualifiedName
should follow the pattern:default/s3/<prefix>/<name>
, wheredefault/s3/<epoch>
is thequalifiedName
of the connection for this object, and<prefix>/<name>
is the folder path where this object is located within the bucket. - The
connectionQualifiedName
must be the exact qualifiedName of the connection for this object. - The
connectorName
must be exactlys3
. - The bucket in which this object exists is embedded in the
bucket
attribute. - The
typeName
for this embedded reference must beS3Bucket
. - To complete the reference, you must include a
uniqueAttributes
object with the qualifiedName of the bucket. Note: the bucket must already exist in Atlan before creating the object. - The
s3BucketName
should be the human-readable name of the bucket. - The
s3BucketQualifiedName
should be the qualifiedName of the bucket.
Available relationships¶
Every level of the object store structure is an Asset
, and can therefore be related to the following other assets.
erDiagram
Asset }o--o{ AtlasGlossaryTerm : meanings
Asset ||--o{ Link : links
Asset ||--o| Readme : readme
Asset }o--o{ Process : inputToProcesses
Asset }o--o{ Process : outputFromProcesses
AtlasGlossaryTerm¶
A glossary term provides meaning to an asset. The link terms to assets snippet provides more detail on setting this relationship.
Link¶
A link provides additional context to an asset, by providing a URL to additional information.
Readme¶
A README provides rich documentation for an asset. The add asset READMEs snippet provides more detail on setting this relationship.
Process¶
A process provides lineage information for an asset. An asset can be both an input and an output for one or more processes. The lineage snippets provide more detail on creating and working with lineage.
-
Although if you want to delete everything in a connection, your better avenue is the packaged connection delete utility in the UI. ↩