Technical Post · Amazon Web Services
How to copy the contents of S3 buckets between different AWS accounts
In this post, we'll show how to transfer S3 objects from one AWS account to another.
Keywords
In this post, we'll show how to transfer S3 objects from one AWS account to another.

To carry out this process, we have a few prerequisites:
Prerequisites
- Access to two AWS accounts (one for the source S3 bucket and another for the destination S3 bucket);
- An IAM user in the destination AWS account (learn how to create an IAM user for the AWS account);
- The AWS CLI configured on your local machine with the credentials of the IAM user created earlier (learn how to configure the AWS CLI).
Step 1 — Get the 12-digit destination AWS account number
- Log in to the destination AWS account.
- Go to Support→ Support center and copy the account number from there.
Step 2 — Configure the source S3 bucket
- Log in to the source AWS account.
- Create a bucket in S3 (learn how to create an S3 bucket).
- Attach the following access policy (learn how to attach the access policy).
- Upload a few test files that should be copied automatically to the destination bucket.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DelegateS3Access",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::DESTINATION_BUCKET_ACCOUNT_NUMBER:root"
},
"Action": [
"s3:ListBucket",
"s3:GetObject"
],
"Resource": [
"arn:aws:s3:::SOURCE_BUCKET_NAME/*",
"arn:aws:s3:::SOURCE_BUCKET_NAME"
]
}
]
}
Step 3 — Configure the destination S3 bucket
- Log in to the destination AWS account.
- Create a bucket in S3 (learn how to create an S3 bucket).
Step 4 — Attach the policy to the IAM user in the destination AWS account
- Attach the following policy to the IAM user created earlier in the destination AWS account (learn how to attach the access policy).
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:GetObject"
],
"Resource": [
"arn:aws:s3:::SOURCE_BUCKET_NAME",
"arn:aws:s3:::SOURCE_BUCKET_NAME/*"
]
},
{
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:PutObject",
"s3:PutObjectAcl"
],
"Resource": [
"arn:aws:s3:::DESTINATION_BUCKET_NAME",
"arn:aws:s3:::DESTINATION_BUCKET_NAME/*"
]
}
]
}
Step 5 — Sync the S3 objects to the destination
- With the steps above completed, we can copy S3 bucket objects from the source account to the destination account using the following AWS CLI command.
aws s3 sync s3://SOURCE-BUCKET-NAME s3://DESTINATION-BUCKET-NAME — source-region SOURCE-REGION-NAME — region DESTINATION-REGION-NAME
The command above must be run with the credentials of the destination AWS IAM user account; otherwise, the objects copied into the destination S3 bucket will still carry the source account's permissions and won't be accessible to users of the destination account.
With that, we've seen how to copy S3 bucket objects from one AWS account to another.
If you have any questions or run into any problems with this tutorial, feel free to get in touch. ;-)
See you in the next post! =)
Comments
Every comment is moderated before it appears here. Nothing is published automatically.
Loading…