Permanently Mount an S3 Bucket on Ubuntu EC2 with fstab
-
Install the required dependencies.
bashsudo snap install aws-cli --classic sudo apt install s3fs fuse -y -
Configure the credentials required to connect to S3. The s3fs configuration reference describes several options:
- Use
aws configureor.aws/credentials. This option is useful for temporary session credentials, such as AWS Academy accounts. - Use
$HOME.passwd-s3fswithACCESS_KEY_ID:SECRET_ACCESS_KEYand permission600. - Use
/etc/passwd-s3fswithACCESS_KEY_ID:SECRET_ACCESS_KEYand permission640. - Use the
AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEYenvironment variables, which s3fs reads automatically.
In this example, I use
aws configureand.aws/credentialsbecause the environment uses a temporary AWS Academy account. - Use
-
Attach an IAM role with S3 permissions to the EC2 instance. You can create a dedicated role or use an existing one. This example uses the role provided by AWS Academy.
-
Test the S3 connection manually first. With
iam_role=auto, s3fs uses the IAM role attached to the EC2 instance.bashs3fs bucket-name directory-mount -o iam_role=autoExample:
bashs3fs test-bucket /etc/test-s3 -o iam_role=auto -
Verify whether the mount succeeded by using either command below.
bashdf -hFor more detail, use
mountto inspect the mounted filesystems.bashmount -
Once the manual mount works, make it persistent in
/etc/fstabso it is restored after an EC2 reboot.bashsudo nano /etc/fstabbashs3fs#bucket-name:/ /dir-mount fuse _netdev,allow_other,nonempty,iam_role=auto 0 0The following format is equivalent:
bashbucket-name:/ /dir-mount fuse.s3fs _netdev,allow_other,nonempty,iam_role=auto 0 0_netdevmarks the filesystem as a network-backed mount.allow_otherallows users other than the mounting user to access it.nonemptyallows the mount point to contain existing files.iam_role=autoauthenticates with the IAM role attached to the EC2 instance. This option is required in this setup; omitting it can cause credential errors.
Keep the colon after the bucket name. Otherwise, s3fs may report
s3fs - bucket name contains illegal character. To mount a specific S3 prefix, append it after the colon, for examplebucket-name:/test.Example:
bashs3fs#test-bucket:/ /etc/test-s3 fuse _netdev,allow_other,nonempty,iam_role=auto 0 0 -
Because this configuration uses
allow_other, enableuser_allow_otherin/etc/fuse.confby removing the comment marker before it.yamluser_allow_other -
Reload systemd.
bashsudo systemctl daemon-reload -
Validate the fstab entry without rebooting. A successful mount produces output similar to the following; errors are also reported directly.
bashmount -fav /etc/test-s3 : successfully mounted -
If the mount still fails even though
mount -favreportssuccessfully mounted, inspect the system journal.bashsudo journalctl -b | grep mountA missing
iam_roleoption can produce an error such as:text... systemd[1]: Mounting home-ubuntu-testaja.mount - /home/ubuntu/testaja... ... mount[537]: s3fs: could not determine how to establish security credentials. ... systemd[1]: Mounted home-ubuntu-backup\x2ds3.mount - /home/ubuntu/backup-s3. ... systemd[1]: home-ubuntu-testaja.mount: Mount process exited, code=exited, status=1/FAILURE ... systemd[1]: home-ubuntu-testaja.mount: Failed with result 'exit-code'. ... systemd[1]: Failed to mount home-ubuntu-testaja.mount - /home/ubuntu/testaja.
- Update the Instance Metadata Service configuration if the environment requires compatibility with both IMDSv1 and IMDSv2.