[object Object] Icon

Learn how to create, start, manage and modify Encodings

[object Object] Icon

Learn how to create, start, manage and modify Players

[object Object] Icon

Learn how to create, start, manage and modify Analyticss

Docs Home
User shortcuts for search
Focus by pressing f
Hide results by pressing Esc
Navigate via   keys

Mon Sep 02 2019

How to create an S3 role-based output on Bitmovin for Analytics exports

OverviewLink Icon

S3 role-based Inputs resp. S3 role-based Outputs are an alternative way of our services to access your AWS (Amazon Web Services) S3 bucket to be used as an Input (Encoding) and/or Output (Encoding/Analytics).

Instead of you providing your AWS Access/Secret key pair to our Encoding or Analytics service, we provide you with an AWS IAM (Identity and Access Management) user name, which you can grant specific access rights in your account so it can access your desired S3 bucket.

To do that, you are asked to create an IAM role in your AWS account, and attach an IAM policy to it. This policy states which of your buckets can be accessed by our user, and which permissions are granted to it.

Create an IAM Role in your AWS accountLink Icon

In order to continue, you will have to create a Role in your AWS account.

  1. Login to your AWS account.
  2. Click on "Services" near the top left.
  3. Look for "Security, Identity & Compliance" and click on "IAM". You are now in the Identity and Access Management (IAM) page of your account.
  4. On the left pane, click on "Access Management" -> "Roles".
  5. Click on "Create Role". The Create Role page appears.
  6. The page shows you four boxes of which you can select one for a type of trusted entity. Click on the "Another AWS account" box.
  7. In the field "Account ID", enter 630681592166.
  8. Next to "Option", check the "Require external ID" checkbox. A box opens asking you to enter an External ID.
  9. Freely choose an external ID and write it down for later use. In this example, we will use myextid123 as the external ID. (Note: The external ID can be anything, but setting it to a a randomly generated UUID for better security and uniqueness is a good way to go).
  10. Click on "Next: Permissions"
  11. Assign a policy to the role by selecting it in the policy list. (Note: The pre-defined AmazonS3FullAccess policy is known to be suitable but since it provides unrestricted access to your bucket, you might need to create a custom policy with fine-tuned access rights.)
  12. Click on "Next: Tags". The Add Tags page appears, on which you optionally can assign tags to the role.
  13. Click "Next: Review". The Review page appears. Give the new role a name, e.g. "Bitmovin".
  14. Click "Create Role". You are now back in the Identity and Access Management(IAM)-Roles page, and the system tells you "The role Bitmovin has been created". You also see the new role in the list of roles in your account.

If you want to learn more about Roles in AWS, please see their documentation.

(Java) S3 role-based Output for Analytics ExampleLink Icon

This example uses our latest Open API client for Java, which is available on Github.

Create a new S3 role-based Output

1bitmovinApi = BitmovinApi.builder().withApiKey("YOUR_BITMOVIN_API_KEY").build();
3List<AclEntry> s3RoleBasedAclPermissions = new ArrayList<>();
4AclEntry aclEntry = new AclEntry();
8S3RoleBasedOutput s3RoleBasedOutput = new S3RoleBasedOutput();
14s3RoleBasedOutput = bitmovinApi.analytics.outputs.s3RoleBased.create(s3RoleBasedOutput);

Use an existing S3 role-based Output

1bitmovinApi = BitmovinApi.builder().withApiKey("YOUR_BITMOVIN_API_KEY").build();
3S3RoleBasedOutput s3RoleBasedOutput = bitmovinApi.analytics.outputs.s3RoleBased.get("YOUR_S3_ROLE_BASED_OUTPUT_ID");

(CURL) S3 role-based Output for Analytics ExampleLink Icon

Create a new S3 role-based Output

API reference: create a role-based S3 Output:

1curl -X POST \
2 https://api.bitmovin.com/v1/analytics/outputs/s3-role-based \
3 -H 'Content-Type: application/json' \
4 -H 'x-api-key: YOUR_BITMOVIN_API_KEY' \
5 -d '{
6 "bucketName": "<BUCKET_NAME>",
7 "roleArn": "<AWS_ARN_ROLE>",
8 "externalId": "<AWS_ROLE_EXT_ID>",
9 "acl": [
10 {
11 "permission": "PRIVATE"
12 }
13 ]

Get a existing S3 role-based Output

API reference: get a S3 role-based Output

1curl https://api.bitmovin.com/v1/analytics/outputs/s3-role-based/YOUR_S3_ROLE_BASED_OUTPUT_ID \
2 -H 'Content-Type: application/json' \
3 -H 'x-api-key: YOUR_BITMOVIN_API_KEY'

What's next?Link Icon

Now that you have an S3 role-based Output for Bitmovin Analytics available, you can export your Bitmovin analytics Data to it :)

Give us feedback