S3 / Iceberg connector
Discovery and metadata visibility. Enforcement and access intelligence are on the roadmap.
Before you start
- Your Iceberg tables registered in the AWS Glue Data Catalog.
- Either an IAM role Trinitis can assume (with a per-connection external ID), or a static access key.
- S3/Iceberg is discovery and metadata visibility only today. Enforcement, access intelligence and migration import are not available.
What Trinitis reads
- Glue databases, tables and partitions
- Iceberg table metadata from the S3 bucket
Trinitis stores metadata only. It never copies data values out of S3 / Iceberg.
What Trinitis writes
- Nothing — Trinitis does not change S3 or Glue today.
Required privileges
Grant only what you need for the capabilities you plan to use.
Discovery and metadata visibility
- s3:GetObject
- s3:ListBucket
- s3:GetBucketLocation
- glue:GetDatabase, glue:GetDatabases
- glue:GetTable, glue:GetTables
- glue:GetPartitions
Steps
- Create an IAM policy with the permissions above, and attach it to a role Trinitis can assume (using the external ID shown in the app) or to an access key.
- Sign in at app.trinitis.ai and open Connections → Add Connection → S3 / Iceberg.
- Choose IAM role assumption or static access key, and enter the matching details.
- Click Test Connection. A green banner means Trinitis has full visibility; a yellow banner means access is limited and lists the privileges to add.
- Click Scan Now. Discovered objects appear under Resources, with sensitive columns tagged automatically from their names.