> ## Documentation Index
> Fetch the complete documentation index at: https://anaconda.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure an IAM role

export const Comments = ({children}) => {
  return <div class="my-4 px-5 py-4 overflow-hidden rounded-2xl flex gap-3 border border-zinc-500/20 bg-zinc-50/50 dark:border-zinc-500/30 dark:bg-zinc-500/10" data-callout-type="comments">
      <div class="w-4">
        <svg width="14" height="14" viewBox="0 0 640 640" fill="currentColor" xmlns="http://www.w3.org/2000/svg" class="w-5 h-5" aria-label="Comments">
            <path d="M320 112C434.9 112 528 205.1 528 320C528 434.9 434.9 528 320 528C205.1 528 112 434.9 112 320C112 205.1 205.1 112 320 112zM320 576C461.4 576 576 461.4 576 320C576 178.6 461.4 64 320 64C178.6 64 64 178.6 64 320C64 461.4 178.6 576 320 576zM280 400C266.7 400 256 410.7 256 424C256 437.3 266.7 448 280 448L360 448C373.3 448 384 437.3 384 424C384 410.7 373.3 400 360 400L352 400L352 312C352 298.7 341.3 288 328 288L280 288C266.7 288 256 298.7 256 312C256 325.3 266.7 336 280 336L304 336L304 400L280 400zM320 256C337.7 256 352 241.7 352 224C352 206.3 337.7 192 320 192C302.3 192 288 206.3 288 224C288 241.7 302.3 256 320 256z" />
        </svg>
      </div>
      <div class="text-sm prose min-w-0 w-full">
        {children}
      </div>
    </div>;
};

This tutorial walks you through creating an AWS IAM role and chaining it to Anaconda Platform so your flows and workstations can access AWS services with the permissions you define.

<Note>
  Creating a resource integration requires an administrator role. If you do not have administrator access, ask your administrator to create the integration before you begin.
</Note>

By the end of this tutorial, you will have:

* An IAM role with the permissions your workloads need
* The role registered as a platform integration
* Verified access to AWS services from a workstation or flow

## Create an IAM role

1. In the AWS IAM console, create a new role.

2. In Anaconda Platform, select **Integrations** in the left-hand navigation, then click **AWS** in the **Add an Integration** section.

3. Copy the trust policy statement shown in the integration panel and add it to your role's trust policy in AWS.

4. Tag your role in AWS with the key and value shown in the integration panel:

   * Key: `outerbounds.com/accessible-by-deployment`
   * Value: the value shown in the panel

5. Attach the AWS managed policies or custom policies your workloads need (Example: `AmazonS3ReadOnlyAccess`, `AWSAthenaFullAccess`).

6. Copy the role's ARN. You need it for the next step.

7. In the integration panel, enter a name, a description, and the role ARN, then click **Add**.

After the integration is created, the **How to use** tab shows a code snippet with the exact `role_arn` value for your flows.

## Test S3 access

To use your role with S3, pass the role ARN when creating the S3 client:

```python theme={null}
from metaflow import S3

s3 = S3(role='arn:aws:iam::<ACCOUNT_ID>:role/<ROLE_NAME>')

data = s3.get('s3://<BUCKET_NAME>/<FILE_NAME>')
```

<Comments>
  Replace \<ACCOUNT\_ID> with your AWS account ID, \<ROLE\_NAME> with the name of your IAM role, \<BUCKET\_NAME> with your S3 bucket name, and \<FILE\_NAME> with the path to your file.
</Comments>

## Test other AWS services

For other AWS services, use `get_aws_client` with your role ARN:

```python theme={null}
from metaflow import get_aws_client

# Example with EMR
emr_client = get_aws_client('emr', role_arn='arn:aws:iam::<ACCOUNT_ID>:role/<ROLE_NAME>')

# Example with Athena
athena_client = get_aws_client('athena', role_arn='arn:aws:iam::<ACCOUNT_ID>:role/<ROLE_NAME>')
```

<Comments>
  Replace \<ACCOUNT\_ID> with your AWS account ID and \<ROLE\_NAME> with the name of your IAM role.
</Comments>

This pattern works in workstation notebooks and in Metaflow tasks.

## Next steps

To build on this tutorial:

* Add additional AWS service permissions to the role as needed.
* Use the role in your Metaflow flows to access AWS services.
* For security guidance, see [AWS IAM best practices](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html).
