At a glance
- Availability: Experimental (how to enable).
- Authentication: API key.
- Connection: Credentials come from the variables below.
Credentials
Set these per environment. See Connect an integration.Setup
Step 1: Create an IAM User
- Log in to the AWS Console
- Navigate to IAM (Identity and Access Management)
- Click on Users in the left sidebar
- Click Add users
- Enter a username (e.g.,
veryfront-integration) - Select Access key - Programmatic access
- Click Next: Permissions
Step 2: Attach Permissions
You can either:Option A: Create a Custom Policy (Recommended)
- Click Attach existing policies directly
- Click Create policy
- Choose the JSON tab
- Paste the following policy:
example.json
- Click Review policy
- Name it
VeryfrontAWSIntegration - Click Create policy
- Go back to the user creation tab and refresh the policy list
- Search for and select
VeryfrontAWSIntegration
Option B: Use AWS Managed Policies
Attach these managed policies:AmazonS3ReadOnlyAccessAmazonEC2ReadOnlyAccessAWSLambdaReadOnlyAccess
Step 3: Complete User Creation
- Click Next: Tags (optional)
- Click Next: Review
- Click Create user
-
Important: Save your credentials:
- Access Key ID
- Secret Access Key
Step 4: Configure Environment Variables
- Copy the
.env.examplefile to.env.local - Add your AWS credentials:
.env
- Replace
your_access_key_id_hereandyour_secret_access_key_herewith your actual credentials - Update
AWS_REGIONto your preferred region (e.g.,us-west-2,eu-west-1)
Step 5: Install Dependencies
Run the following command to install required AWS SDK packages:request.sh
Step 6: Test Your Integration
You can test your integration by using any of the available tools:list-s3-buckets- List all your S3 bucketslist-s3-objects- List objects in a specific bucketget-s3-object- Retrieve an object from S3list-ec2-instances- List your EC2 instanceslist-lambda-functions- List your Lambda functions
Security Best Practices
- Never commit your
.env.localfile - It’s already in.gitignore - Use the principle of least privilege - Only grant permissions needed
- Rotate credentials regularly - Update your access keys periodically
- Use different credentials for different environments - Dev, staging, and production
- Consider using AWS IAM Roles - For production environments, use IAM roles with EC2/ECS/Lambda
Troubleshooting
”Access Denied” Errors
- Verify your IAM user has the correct permissions
- Check that the region in your
.env.localmatches where your resources are located
”Invalid Access Key” Errors
- Double-check your
AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEY - Ensure there are no extra spaces or newlines in your credentials
- Verify the IAM user is active and the access key hasn’t been deleted
Region Issues
- Some resources are region-specific (EC2, Lambda)
- S3 bucket listing is global, but object access respects bucket regions
- Update
AWS_REGIONto match where your resources are located