roboto.domain.orgs.s3_integration
Module Contents
RegisterS3IntegrationRequest
Bases: pydantic.BaseModel
Request payload to integrate an S3 bucket with Roboto.
Parameters
data AnyAttributes
RegisterS3IntegrationRequest.org_id
Organization ID to associate with this S3 integration.
RegisterS3IntegrationRequest.readonly
Whether Roboto should have read-only access to the bucket.
RegisterS3IntegrationRequest.transfer_accelerated
Whether to enable S3 Transfer Acceleration for faster uploads.
RegisterS3IntegrationResponse
Bases: pydantic.BaseModel
Response payload containing S3 integration setup instructions.
Parameters
data AnyAttributes
RegisterS3IntegrationResponse.iam_role_name
Name of the IAM role to create for Roboto access.
RegisterS3IntegrationResponse.iam_role_policy
IAM policy document to attach to the role.
RegisterS3IntegrationResponse.iam_role_trust_relationship
IAM trust policy document for the role.
RegisterS3IntegrationResponse.s3_bucket_cors_policy
CORS policy to apply to the S3 bucket.
S3BucketHealthCheck
Bases: pydantic.BaseModel
Summary of the most recent health check against an S3 bucket integration.
Carries only a machine-readable classification and curated, non-sensitive copy: no identifiers (bucket name, role ARN, account ID), no secrets, and no raw AWS error text. The identifiers a reader needs live on the enclosing S3BucketIntegrationRecord.
Parameters
data AnyAttributes
S3BucketHealthCheck.aws_error_code
AWS error code that drove the classification (e.g. AccessDenied), if any — a fixed token, never AWS’s free-text message.
S3BucketHealthCheck.probes
Outcome per probe name (assume_role, list, put, …), each one of ok / denied / error / skipped.
S3BucketHealthCheck.reason_code
Machine-readable result classification — a fixed token, e.g. ok or permission_denied.
S3BucketIntegrationRecord
Bases: pydantic.BaseModel
Record representing an S3 bucket integration with a Roboto organization.
Parameters
data AnyAttributes
S3BucketIntegrationRecord.created
Timestamp when the integration was created.
S3BucketIntegrationRecord.last_health_check
Summary of the most recent health check, or None if the integration has never been checked.
S3BucketIntegrationRecord.modified
Timestamp when the integration was last modified.
S3BucketIntegrationRecord.status
Integration status: one of ‘unverified’, ‘healthy’, ‘unhealthy’, ‘unknown’.
S3BucketIntegrationRecord.status_last_updated
Timestamp when status was last written, i.e. when the most recent health check ran.
S3IntegrationService
Service for integrating S3 buckets with Roboto organizations.
This service handles the setup of cross-account IAM roles and S3 bucket policies to allow Roboto to access customer S3 buckets for data storage and processing.
Parameters
roboto_client roboto.sts_client Optional[Any]s3_client Optional[Any]iam_client Optional[Any]S3IntegrationService.register_bucket()
Register an S3 bucket for use with a Roboto organization.
This method sets up the necessary IAM roles and S3 bucket policies to allow Roboto to access the specified S3 bucket. The caller must have appropriate AWS credentials with permissions to create IAM roles and modify S3 bucket policies.
Parameters
org_id strOrganization ID to associate with this S3 integration.
account_id strAWS account ID that owns the S3 bucket.
bucket_name strName of the S3 bucket to integrate.
transfer_accelerated boolWhether to enable S3 Transfer Acceleration.
readonly boolWhether Roboto should have read-only access to the bucket.
Raises
AWS credentials are invalid or account ID mismatch.
ValueErrorThe specified bucket does not exist or is not owned by the account.
botocore.exceptions.ClientErrorAWS API errors during setup.
Usage
Register a bucket for read-write access:
from roboto.domain.orgs import S3IntegrationService
from roboto import RobotoClient
service = S3IntegrationService(RobotoClient())
service.register_bucket(org_id="org_12345", account_id="123456789012", bucket_name="my-data-bucket")Register a bucket with read-only access:
service.register_bucket(
org_id="org_12345", account_id="123456789012", bucket_name="my-readonly-bucket", readonly=True
)