There may be security, performance and/or maintenance reasons for not passing in the actual Document Template File or Data File to the Windward RESTful engine. For these reasons, the Windward RESTful engine allows the Document Template File and/or Document Data File to be provided by URI. If you decide to use AWS and S3 to hold your files needed for the RESTful engine you should be using private S3 buckets. The following explains how to use the Windward RESTful engine with private S3 buckets.
- AWS Account
- Private S3 Bucket
- EC2 instance hosting the Windward RESTful Engine
A private S3 bucket can be created by following the documentation on creating a private S3 bucket. The bucket will default to as not allowing public access. It can be verified by going to the bucket and then found under the “Permissions” tab.
Every AWS account has one default VPC for each AWS Region. Here’s an article on how to create the VPC endpoint for S3. The VPC Endpoint is a gateway endpoint. It adds an entry to the route table of a subnet and forwards S3 traffic to the S3 VPC endpoint. So that the communication between the RESTful engine and S3 stays on the VPC and will not communicate over the internet.
As shown in the article above, it contains the modifications to the bucket policy. Below is an example bucket policy that allows access from resources on the Virtual Private Cloud:
"Resource" will need to be changed to the name of the private bucket. The
aws:sourceVpce will need to be changed to your VPCID which can be found. It will be under “VPC” → “Endpoints” → “Endpoint ID” as shown in the image below:
The RESTful engine can then use the S3 URI for the private bucket the same way as a public bucket. The URL below is an example of what can be passed to the RESTful engine to reach a private S3 bucket.
Further information on the RESTful engine can be found in our RESTful Engine documentation. Or try out a working RESTful engine using a private S3 bucket on our swagger documentation for the RESTful engine.