在AWS Glue作业写入S3时,能否指定SSE:KMS密钥ID加密数据?
AWS Glue S3 Write with SSE-KMS Encryption
Question 1: Can I specify an SSE:KMS key ID when writing to S3 in an AWS Glue job?
Yes, you absolutely can. AWS Glue fully supports server-side encryption with KMS keys when writing data to S3, letting you take control of how your stored objects are encrypted.
Question 2: Can I add a KMS key to the auto-generated Glue script for Parquet writes?
Definitely. The default script from the Glue job wizard doesn’t include this setting, but it’s easy to extend the connection_options parameter to add your KMS key details.
Here’s how to modify your existing code to enable SSE-KMS encryption:
datasink4 = glueContext.write_dynamic_frame.from_options( frame=dropnullfields3, connection_type="s3", connection_options={ "path": "s3://my-s3-bucket/datafile.parquet", "sseType": "sse-kms", "sseKmsKeyId": "arn:aws:kms:us-east-1:123456789012:key/your-kms-key-id" }, format="parquet", transformation_ctx="datasink4", )
sseType: Set this tosse-kmsto specify you want to use KMS-managed encryption.sseKmsKeyId: You can provide either the full ARN of your KMS key, or just the key ID itself (if the key is in the same AWS region and account as your Glue job).
Just remember to ensure your Glue job’s IAM role has the necessary permissions for the KMS key—specifically kms:GenerateDataKey and kms:Decrypt permissions.
内容的提问来源于stack exchange,提问作者Stephen Paulger
相关产品推荐
相关产品推荐

