AWS Copy

AWS Copy

Certified

Copy an object between S3 locations

Copies an object within or across buckets. Optionally deletes the source after copy. Supports versionId on source and SSE on destination.

yaml
type: io.kestra.plugin.aws.s3.Copy
yaml
id: aws_s3_copy
namespace: company.team

tasks:
  - id: copy
    type: io.kestra.plugin.aws.s3.Copy
    accessKeyId: "{{ secret('AWS_ACCESS_KEY_ID') }}"
    secretKeyId: "{{ secret('AWS_SECRET_KEY_ID') }}"
    region: "eu-central-1"
    from:
      bucket: "my-bucket"
      key: "path/to/file"
    to:
      bucket: "my-bucket2"
      key: "path/to/file2"
Properties

Access Key Id in order to connect to AWS

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.

Definitions
assetFailureBehaviorstring
Possible Values
IGNOREFAILWARN

Asset failure behavior

Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.

enableAutobooleanstring

Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.

inputsarray

The assets consumed as inputs.

id*string
Min length1
typestring
outputs

The assets produced as outputs.

id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*string
Min length1

Custom asset type

descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150

Enable compatibility mode

Use it to connect to S3 bucket with S3 compatible services that don't support the new transport client.

Defaultfalse

Delete source after copy

If true, deletes the source object once copy succeeds.

The endpoint with which the SDK should communicate

This property allows you to use a different S3 compatible storage backend.

Force path style access

Must only be used when compatibilityMode is enabled.

Source object

Bucket/key (and optional versionId) to copy from.

Definitions
bucket*string

Bucket

key*string

Key

kmsKeyIdstring

KMS Key ARN or Key ID to use when server side encryption is AWS_KMS

serverSideEncryptionstring
Possible Values
NONEAES256AWS_KMS

Server side encryption to apply to the target object

Example: AES256 or AWS_KMS

versionIdstring

The specific version of the object

AWS region with which the SDK should communicate

Secret Key Id in order to connect to AWS

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

AWS session token, retrieved from an AWS token service, used for authenticating that this user has received temporary permissions to access a given resource

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

The AWS STS endpoint with which the SDKClient should communicate

AWS STS Role

The Amazon Resource Name (ARN) of the role to assume. If set the task will use the StsAssumeRoleCredentialsProvider. If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

AWS STS External Id

A unique identifier that might be required when you assume a role in another account. This property is only used when an stsRoleArn is defined.

DefaultPT15M

AWS STS Session duration

The duration of the role session (default: 15 minutes, i.e., PT15M). This property is only used when an stsRoleArn is defined.

AWS STS Session name

This property is only used when an stsRoleArn is defined.

Destination object

Bucket/key to copy to; defaults to source when omitted.

Definitions
bucket*string

Bucket

key*string

Key

kmsKeyIdstring

KMS Key ARN or Key ID to use when server side encryption is AWS_KMS

serverSideEncryptionstring
Possible Values
NONEAES256AWS_KMS

Server side encryption to apply to the target object

Example: AES256 or AWS_KMS

Bucket

Key

The version of the object