• Home

    Automating file uploads via AWS S3

    How to automate file uploads to Pugpig using AWS S3, including role assumption, customer configuration, and changes when importers or infrastructure change.

    Written by Nicholas Helke

    Updated at July 28th, 2026

    • Pugpig Bolt

      • Pugpig Site

        • Pugpig Archive

          • Working with Pugpig

            • Pugpig Consulting

              Table of Contents

              How it works Setting up S3 uploads Changing payloads Security Never share role credentials or session tokens

              Where supported by your chosen importer, file uploads to Pugpig can be automated using AWS S3. This is a good option if you or your uploading partner already operate within AWS, as it makes use of AWS's native security model and avoids the need to manage SFTP keys.

              How it works

              We create a dedicated IAM role in our AWS account for each of your environments, typically stage and prod. Each role has a trust policy that allows specific AWS principals on your side to assume it. Once assumed, your systems can upload files directly to our S3 bucket using standard AWS SDKs or CLI tooling. No passwords or SSH keys are required.

              Setting up S3 uploads

              To set up S3 uploads for your environments, we will need to know from you:

              • The AWS principal ARN or ARNs on your side that should be trusted by our role. This could be an IAM role, IAM user, AWS service identity, or AWS organisation. If you have separate principals for stage and prod, please provide both.
              • What sort of payload you will be uploading, so we can ensure files are routed correctly.

              To begin uploading, we will provide you with:

              • The IAM role ARN or ARNs to assume, typically one per environment.
              • The S3 bucket name and key prefix to upload into.
              • The AWS region in which the bucket is hosted.

              Your systems should assume the appropriate role using sts:AssumeRole and use the resulting temporary credentials to perform S3 PutObject operations.

              Changing payloads

              Please give us advance warning of any changes you make to the type of payload you send us, as this may require changes on our side. We may, for instance, need to issue new role or roles, bucket or buckets, and/or use a different region, to ensure the new type of files are routed correctly. We would typically work with you to coordinate such switchovers.

              We may also make changes to roles, buckets, or regions for operational reasons on our side. If we do so for operational reasons, this will be a configuration change for you rather than an operational change. We will let you know which configuration values need to be updated.

              Security

              This process is designed to work without any long-lived AWS access keys. If your tooling requires a static access key rather than role assumption, please discuss this with us before proceeding. We recommend finding an alternative approach, as static keys are harder to rotate and carry a greater security risk.

              Never share role credentials or session tokens

              Temporary credentials obtained by assuming our role should only be used by your authorised systems. Do not share them with third parties or commit them to source control.

               
              aws s3 file upload automation custom importer

              Was this article helpful?

              Yes
              No
              Give feedback about this article

              Related Articles

              • Google Material 3 in Pugpig Bolt
              • Leaderboard Banner
              pugpig logo white
              Navigation
              • Products
              • Customers
              • News
              • Podcast
              Contact
              • Contact us
              • LinkedIn
              • Twitter
              Technical Support
              • Status Page
              • Documentation
              • Customer Support
              Corporate
              • Company
              • Jobs
              • Privacy Policy

              © Kaldor Ltd. 2022

              Powered by Pugpig


              Knowledge Base Software powered by Helpjuice

              Expand