Amazon S3
Use a dedicated IAM user (or role keys) with access limited to one bucket prefix. In ConstellaWP, choose provider Amazon S3.
Prerequisites
Section titled “Prerequisites”- An AWS account
- Permission to create S3 buckets and IAM users
- ConstellaWP role owner or admin
-
In the AWS console, open S3 and create a bucket. Block public access. Note the AWS Region (for example
eu-west-1).Amazon S3: create bucket and note the regionsrc/assets/storage/amazon-s3/create-bucket.pngAmazon S3: create bucket and note the region -
Open IAM → Users and create a user for ConstellaWP. Attach a policy that allows
s3:PutObject,s3:GetObject,s3:DeleteObject, ands3:ListBucketon this bucket (optionally limited to your path prefix). Create an access key and copy Access key ID and Secret access key.Amazon S3: create IAM user and access keyssrc/assets/storage/amazon-s3/create-iam-user.pngAmazon S3: create IAM user and access keys -
In ConstellaWP, go to Storage → Add Destination:
- Provider: Amazon S3
- Fill the fields from the table below
- Save, then Test connection
Field mapping
Section titled “Field mapping”| ConstellaWP field | Where to find it in AWS |
|---|---|
| Bucket | S3 bucket name |
| Region | Bucket region, for example us-east-1 |
| Access Key ID | IAM access key ID |
| Secret Access Key | IAM secret access key (shown once) |
| Path prefix | Chosen by you; default backups |
ConstellaWP uses the AWS SDK default endpoint for the region (no custom endpoint field for S3).
Example IAM policy
Section titled “Example IAM policy”Scope this to your bucket and prefix:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["s3:ListBucket"], "Resource": "arn:aws:s3:::YOUR_BUCKET", "Condition": { "StringLike": { "s3:prefix": ["backups/*"] } } }, { "Effect": "Allow", "Action": ["s3:GetObject", "s3:PutObject", "s3:DeleteObject"], "Resource": "arn:aws:s3:::YOUR_BUCKET/backups/*" } ]}Common errors
Section titled “Common errors”| Error | Likely cause |
|---|---|
| AccessDenied on test | Policy missing PutObject or DeleteObject (test writes then deletes a probe object) |
| PermanentRedirect / wrong region | Region does not match the bucket |
| InvalidAccessKeyId | Typo in Access Key ID, or the key was deleted |
| SignatureDoesNotMatch | Secret Access Key copied with a trailing space, or swapped with the key ID |
| KMS AccessDenied | Bucket default encryption uses a KMS key the IAM user cannot use — grant kms:Decrypt / kms:GenerateDataKey, or use SSE-S3 |