S3 / Iceberg connector

Discovery and metadata visibility. Enforcement and access intelligence are on the roadmap.

Before you start

  • Your Iceberg tables registered in the AWS Glue Data Catalog.
  • Either an IAM role Trinitis can assume (with a per-connection external ID), or a static access key.
  • S3/Iceberg is discovery and metadata visibility only today. Enforcement, access intelligence and migration import are not available.

What Trinitis reads

  • Glue databases, tables and partitions
  • Iceberg table metadata from the S3 bucket

Trinitis stores metadata only. It never copies data values out of S3 / Iceberg.

What Trinitis writes

  • Nothing — Trinitis does not change S3 or Glue today.

Required privileges

Grant only what you need for the capabilities you plan to use.

Discovery and metadata visibility

  • s3:GetObject
  • s3:ListBucket
  • s3:GetBucketLocation
  • glue:GetDatabase, glue:GetDatabases
  • glue:GetTable, glue:GetTables
  • glue:GetPartitions

Steps

  1. Create an IAM policy with the permissions above, and attach it to a role Trinitis can assume (using the external ID shown in the app) or to an access key.
  2. Sign in at app.trinitis.ai and open Connections → Add Connection → S3 / Iceberg.
  3. Choose IAM role assumption or static access key, and enter the matching details.
  4. Click Test Connection. A green banner means Trinitis has full visibility; a yellow banner means access is limited and lists the privileges to add.
  5. Click Scan Now. Discovered objects appear under Resources, with sensitive columns tagged automatically from their names.