You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardexpand all lines: docs/source/guide/storage.md
+24-3
Original file line number
Diff line number
Diff line change
@@ -298,11 +298,28 @@ In Label Studio Enterprise, you can use an IAM role configured with an external
298
298
If you want to use a revocable method to grant Label Studio access to your Amazon S3 bucket, use an IAM role and its temporary security credentials instead of an access key ID and secret. This added layer of security is only available in Label Studio Enterprise. For more details about security in Label Studio and Label Studio Enterprise, see [Secure Label Studio](security.html).
299
299
300
300
#### Set up an IAM role in Amazon AWS
301
+
302
+
!!! note "Notice for Label Studio Cloud users"
303
+
<ul><li><p>On <strong>April 7th 2025</strong>, new storage connections will require an update to the AWS principal in your IAM role policy.</p>
304
+
305
+
<p>You must replace this: <code>"arn:aws:iam::490065312183:user/rw_bucket"</code></p>
<p>Existing S3 IAM role-based-access storages added to Label Studio will continue to work as is without any changes necessary.</p></li>
312
+
313
+
<li><p>On <strong>July 7th 2025</strong>, we will no longer support the legacy IAM user, and all policies should be updated to the new IAM role.</p></li></ul>
314
+
301
315
Set up an IAM role in Amazon AWS to use with Label Studio.
302
316
303
-
1. In the Label Studio UI, open the **Organization** page to get an `External ID` to use for the IAM role creation in Amazon AWS. You must be an administrator to view the Organization page.
304
-
2. Follow the [Amazon AWS documentation to create an IAM role](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-user.html) in your AWS account. <br/>Make sure to require an external ID and do not require multi-factor authentication when you set up the role. Select an existing permissions policy, or create one that allows programmatic access to the bucket.
317
+
1. From Label Studio, go to **Organization** page to retrieve your organization's `External ID`. You must be an Owner or Admin to view the Organization page.
318
+
2. Follow the [Amazon AWS documentation to create an IAM role](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-user.html) in your AWS account.
319
+
320
+
Make sure to require an external ID and do not require multi-factor authentication when you set up the role. Select an existing permissions policy, or create one that allows programmatic access to the bucket.
305
321
3. Create a trust policy using the external ID. Use the following example:
322
+
306
323
```json
307
324
{
308
325
"Version": "2012-10-17",
@@ -311,7 +328,7 @@ Set up an IAM role in Amazon AWS to use with Label Studio.
@@ -326,6 +343,10 @@ Set up an IAM role in Amazon AWS to use with Label Studio.
326
343
]
327
344
}
328
345
```
346
+
347
+
!!! attention
348
+
If your bucket is already connected to a Label Studio project, and that connection was created before April 7, 2025, you will need to add the new role (listed above) along with your old user to continue using your existing project.
349
+
329
350
4. After you create the IAM role, note the Amazon Resource Name (ARN) of the role. You need it to set up the S3 source storage in Label Studio.
330
351
5. Assign role policies to the role to allow it to access your S3 bucket. Replace `<your_bucket_name>` with your S3 bucket name. Use the following role policy for S3 source storage:
0 commit comments