arrow_backAll Posts·5 Min Read·2025-01-04

Permanently Mount an S3 Bucket on Ubuntu EC2 with fstab

AWSEC2UbuntuS3
  • Install the required dependencies.

    bash
    sudo snap install aws-cli --classic
    sudo apt install s3fs fuse -y
    
  • Configure the credentials required to connect to S3. The s3fs configuration reference describes several options:

    • Use aws configure or .aws/credentials. This option is useful for temporary session credentials, such as AWS Academy accounts.
    • Use $HOME.passwd-s3fs with ACCESS_KEY_ID:SECRET_ACCESS_KEY and permission 600.
    • Use /etc/passwd-s3fs with ACCESS_KEY_ID:SECRET_ACCESS_KEY and permission 640.
    • Use the AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY environment variables, which s3fs reads automatically.

    In this example, I use aws configure and .aws/credentials because the environment uses a temporary AWS Academy account.

  • Attach an IAM role with S3 permissions to the EC2 instance. You can create a dedicated role or use an existing one. This example uses the role provided by AWS Academy.

  • Test the S3 connection manually first. With iam_role=auto, s3fs uses the IAM role attached to the EC2 instance.

    bash
    s3fs bucket-name directory-mount -o iam_role=auto
    

    Example:

    bash
    s3fs test-bucket /etc/test-s3 -o iam_role=auto
    
  • Verify whether the mount succeeded by using either command below.

    bash
    df -h
    

    For more detail, use mount to inspect the mounted filesystems.

    bash
    mount
    
  • Once the manual mount works, make it persistent in /etc/fstab so it is restored after an EC2 reboot.

    bash
    sudo nano /etc/fstab
    
    bash
    s3fs#bucket-name:/ /dir-mount fuse _netdev,allow_other,nonempty,iam_role=auto 0 0
    

    The following format is equivalent:

    bash
    bucket-name:/ /dir-mount fuse.s3fs _netdev,allow_other,nonempty,iam_role=auto 0 0
    
    • _netdev marks the filesystem as a network-backed mount.
    • allow_other allows users other than the mounting user to access it.
    • nonempty allows the mount point to contain existing files.
    • iam_role=auto authenticates with the IAM role attached to the EC2 instance. This option is required in this setup; omitting it can cause credential errors.

    Keep the colon after the bucket name. Otherwise, s3fs may report s3fs - bucket name contains illegal character. To mount a specific S3 prefix, append it after the colon, for example bucket-name:/test.

    Example:

    bash
    s3fs#test-bucket:/ /etc/test-s3 fuse _netdev,allow_other,nonempty,iam_role=auto 0 0
    
  • Because this configuration uses allow_other, enable user_allow_other in /etc/fuse.conf by removing the comment marker before it.

    yaml
    user_allow_other
    
  • Reload systemd.

    bash
    sudo systemctl daemon-reload
    
  • Validate the fstab entry without rebooting. A successful mount produces output similar to the following; errors are also reported directly.

    bash
    mount -fav
    
    /etc/test-s3   : successfully mounted
    
  • If the mount still fails even though mount -fav reports successfully mounted, inspect the system journal.

    bash
    sudo journalctl -b | grep mount
    

    A missing iam_role option can produce an error such as:

    text
    ... systemd[1]: Mounting home-ubuntu-testaja.mount - /home/ubuntu/testaja...
    ... mount[537]: s3fs: could not determine how to establish security credentials.
    ... systemd[1]: Mounted home-ubuntu-backup\x2ds3.mount - /home/ubuntu/backup-s3.
    ... systemd[1]: home-ubuntu-testaja.mount: Mount process exited, code=exited, status=1/FAILURE
    ... systemd[1]: home-ubuntu-testaja.mount: Failed with result 'exit-code'.
    ... systemd[1]: Failed to mount home-ubuntu-testaja.mount - /home/ubuntu/testaja.
    
  • Update the Instance Metadata Service configuration if the environment requires compatibility with both IMDSv1 and IMDSv2.