
AWS Trigger
CertifiedTrigger on S3 object creation/update
AWS Trigger
Trigger on S3 object creation/update
Polls a bucket on a fixed interval, listing with prefix/regex filters. Downloads matched objects to internal storage and can move or delete them to prevent reprocessing. Maintains state per trigger to avoid duplicates.
type: io.kestra.plugin.aws.s3.TriggerExamples
Wait for a list of files on a s3 bucket and iterate through the files
id: s3_listen
namespace: company.team
tasks:
- id: each
type: io.kestra.plugin.core.flow.ForEach
values: "{{ trigger.objects | jq('.[].uri') }}"
tasks:
- id: return
type: io.kestra.plugin.core.debug.Return
format: "{{ taskrun.value }}"
triggers:
- id: watch
type: io.kestra.plugin.aws.s3.Trigger
interval: "PT5M"
accessKeyId: "{{ secret('AWS_ACCESS_KEY_ID') }}"
secretKeyId: "{{ secret('AWS_SECRET_KEY_ID') }}"
region: "eu-central-1"
bucket: "my-bucket"
prefix: "sub-dir"
action: MOVE
moveTo:
key: archive
bucket: "new-bucket"
Wait for a list of files on a s3 bucket and iterate through the files. Delete files manually after processing to prevent infinite triggering
id: s3_listen
namespace: company.team
tasks:
- id: each
type: io.kestra.plugin.core.flow.ForEach
values: "{{ trigger.objects | jq('.[].key') }}"
tasks:
- id: return
type: io.kestra.plugin.core.debug.Return
format: "{{ taskrun.value }}"
- id: delete
type: io.kestra.plugin.aws.s3.Delete
accessKeyId: "{{ secret('AWS_ACCESS_KEY_ID') }}"
secretKeyId: "{{ secret('AWS_SECRET_KEY_ID') }}"
region: "eu-central-1"
bucket: "my-bucket"
key: "{{ taskrun.value }}"
triggers:
- id: watch
type: io.kestra.plugin.aws.s3.Trigger
interval: "PT5M"
accessKeyId: "{{ secret('AWS_ACCESS_KEY_ID') }}"
secretKeyId: "{{ secret('AWS_SECRET_KEY_ID') }}"
region: "eu-central-1"
bucket: "my-bucket"
prefix: "sub-dir"
action: NONE
Properties
action *Requiredstring
MOVEDELETENONEThe action to perform on the retrieved files. If using 'NONE' make sure to handle the files inside your flow to avoid infinite triggering
bucket *Requiredstring
The S3 bucket where to download the file
accessKeyId string
Access Key Id in order to connect to AWS
If no credentials are defined, we will use the default credentials provider chain to fetch credentials.
allowConcurrent Non-dynamicboolean
falseSpecifies whether a trigger is allowed to start a new execution even if a previous run is still in progress.
compatibilityMode booleanstring
falseEnable compatibility mode
Use it to connect to S3 bucket with S3 compatible services that don't support the new transport client.
delimiter string
A delimiter is a character you use to group keys
encodingType string
The EncodingType property for this object
endpointOverride string
The endpoint with which the SDK should communicate
This property allows you to use a different S3 compatible storage backend.
expectedBucketOwner string
The account ID of the expected bucket owner
If the bucket is owned by a different account, the request fails with the HTTP status code 403 Forbidden (access denied).
filter string
BOTHFILESDIRECTORYBOTHThe type of objects to filter: files, directory, or both
forcePathStyle booleanstring
falseForce path style access
Must only be used when compatibilityMode is enabled.
interval Non-dynamicstring
PT1MdurationInterval between polling.
The interval between 2 different polls of schedule, this can avoid to overload the remote system with too many calls. For most of the triggers that depend on external systems, a minimal interval must be at least PT30S. See ISO_8601 Durations for more information of available interval values.
marker string
Marker is where you want Amazon S3 to start listing from
Amazon S3 starts listing after this specified key. Marker can be any key in the bucket.
maxFiles integerstring
25The maximum number of files to retrieve at once
maxKeys integerstring
1000Maximum number of objects returned across all paginated S3 calls
Total upper bound on the objects returned. It also sets the per-page size sent to S3, which AWS caps at 1000. The listing pages until this total is reached or the bucket is exhausted. Default 1000.
moveTo
The destination bucket and key for MOVE action
io.kestra.plugin.aws.s3.Copy-CopyObject
Bucket
Key
KMS Key ARN or Key ID to use when server side encryption is AWS_KMS
NONEAES256AWS_KMSServer side encryption to apply to the target object
Example: AES256 or AWS_KMS
on string
CREATE_OR_UPDATECREATEUPDATECREATE_OR_UPDATETrigger condition
Which object events fire the trigger; defaults to CREATE_OR_UPDATE.
prefix string
Limits the response to keys that begin with the specified prefix
regexp string
A regexp to filter on full key
ex:
regExp: .* to match all files
regExp: .*2020-01-0.\\.csv to match files between 01 and 09 of january ending with .csv
region string
AWS region with which the SDK should communicate
requestPayer string
Sets the value of the RequestPayer property for this object
secretKeyId string
Secret Key Id in order to connect to AWS
If no credentials are defined, we will use the default credentials provider chain to fetch credentials.
sessionToken string
AWS session token, retrieved from an AWS token service, used for authenticating that this user has received temporary permissions to access a given resource
If no credentials are defined, we will use the default credentials provider chain to fetch credentials.
stateKey string
State key
Key under which the trigger persists its dedup state; defaults to a stable per-trigger value.
stateTtl string
State TTL
How long persisted dedup state is retained before matched objects can trigger again; unset means no expiry.
stopAfter Non-dynamicarray
CREATEDSUBMITTEDRUNNINGPAUSEDRESTARTEDKILLINGSUCCESSWARNINGFAILEDKILLEDCANCELLEDQUEUEDRETRYINGRETRIEDSKIPPEDBREAKPOINTRESUBMITTEDList of execution states after which a trigger should be stopped (a.k.a. disabled).
stsEndpointOverride string
The AWS STS endpoint with which the SDKClient should communicate
stsRoleArn string
AWS STS Role
The Amazon Resource Name (ARN) of the role to assume. If set the task will use the StsAssumeRoleCredentialsProvider. If no credentials are defined, we will use the default credentials provider chain to fetch credentials.
stsRoleExternalId string
AWS STS External Id
A unique identifier that might be required when you assume a role in another account. This property is only used when an stsRoleArn is defined.
stsRoleSessionDuration string
PT15MAWS STS Session duration
The duration of the role session (default: 15 minutes, i.e., PT15M). This property is only used when an stsRoleArn is defined.
stsRoleSessionName string
AWS STS Session name
This property is only used when an stsRoleArn is defined.
when string
trueA condition that determines whether the trigger should run.
A Pebble expression evaluated at trigger time. The trigger fires only when the expression evaluates to a truthy value (true, a non-empty string, a non-zero number). Use this to gate trigger execution on dynamic runtime values such as execution labels, flow variables, or environment conditions.
Outputs
objects array
List of S3 objects that triggered the flow, each with its change type
io.kestra.plugin.aws.s3.Trigger-TriggeredObject
CREATEUPDATEChecksum algorithm
The checksum algorithm used for the object, if any.
Checksum value
The object's checksum value, if any.
ETag
The entity tag (ETag) of the object.
Key
The object key within the bucket.
date-timeLast modified
Timestamp of the object's last modification.
Owner
The object owner.
io.kestra.plugin.aws.s3.models.Owner
Display name
The S3 owner's display name.
Owner ID
The S3 owner's canonical user ID.
Size
The object size in bytes.
uriURI
Internal storage URI of the downloaded object, when applicable.