Skip to content

Amazon S3

Use a dedicated IAM user (or role keys) with access limited to one bucket prefix. In ConstellaWP, choose provider Amazon S3.

  • An AWS account
  • Permission to create S3 buckets and IAM users
  • ConstellaWP role owner or admin
  1. In the AWS console, open S3 and create a bucket. Block public access. Note the AWS Region (for example eu-west-1).

    Amazon S3: create bucket and note the region
  2. Open IAM → Users and create a user for ConstellaWP. Attach a policy that allows s3:PutObject, s3:GetObject, s3:DeleteObject, and s3:ListBucket on this bucket (optionally limited to your path prefix). Create an access key and copy Access key ID and Secret access key.

    Amazon S3: create IAM user and access keys
  3. In ConstellaWP, go to Storage → Add Destination:

    • Provider: Amazon S3
    • Fill the fields from the table below
    • Save, then Test connection
ConstellaWP field Where to find it in AWS
Bucket S3 bucket name
Region Bucket region, for example us-east-1
Access Key ID IAM access key ID
Secret Access Key IAM secret access key (shown once)
Path prefix Chosen by you; default backups

ConstellaWP uses the AWS SDK default endpoint for the region (no custom endpoint field for S3).

Scope this to your bucket and prefix:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:ListBucket"],
"Resource": "arn:aws:s3:::YOUR_BUCKET",
"Condition": {
"StringLike": { "s3:prefix": ["backups/*"] }
}
},
{
"Effect": "Allow",
"Action": ["s3:GetObject", "s3:PutObject", "s3:DeleteObject"],
"Resource": "arn:aws:s3:::YOUR_BUCKET/backups/*"
}
]
}
Error Likely cause
AccessDenied on test Policy missing PutObject or DeleteObject (test writes then deletes a probe object)
PermanentRedirect / wrong region Region does not match the bucket
InvalidAccessKeyId Typo in Access Key ID, or the key was deleted
SignatureDoesNotMatch Secret Access Key copied with a trailing space, or swapped with the key ID
KMS AccessDenied Bucket default encryption uses a KMS key the IAM user cannot use — grant kms:Decrypt / kms:GenerateDataKey, or use SSE-S3