Prerequisites
Learn how to collect the information you need to deploy the S3 to IBM watsonx ReadyFlow, and meet other prerequisites.
For your data ingest source
- 
            You have the source S3 bucket and path. 
- You have performed one of the following to configure access to the source S3 bucket:- 
            You have configured access to the S3 bucket with a RAZ enabled environment. It is a best practice to enable RAZ to control access to your object store buckets. This allows you to use your Cloudera on cloud credentials to access S3 buckets, increases auditability, and makes object store data ingest workflows portable across cloud providers.- Ensure that Fine-grained access control is enabled for your Cloudera Data Flow environment.
- From the Ranger UI, navigate to the S3 repository.
- Create a policy to govern access to the S3 bucket and path used in your ingest workflow.
- Add the machine user that you have created for your ingest workflow to the policy you just created.
 For more information, see Creating Ranger policy to use in RAZ-enabled AWS environment. 
- 
            You have configured access to the S3 bucket using ID Broker mapping. If your environment is not RAZ-enabled, you can configure access to the S3 bucket using ID Broker mapping.- Access IDBroker mappings.- To access IDBroker mappings in your environment, click .
- Choose the IDBroker Mappings tab where you can provide mappings for users or groups and click Edit.
 
- Add your Cloudera Workload User and the corresponding AWS role that provides write access to your folder in your S3 bucket to the Current Mappings section by clicking the blue + sign.
- Click Save and Sync.
 
- Access IDBroker mappings.
 
- 
            
For Cloudera Data Flow
- 
            You have enabled Cloudera Data Flow for an environment. For information on how to enable Cloudera Data Flow for an environment, see Enabling Cloudera Data Flow for an Environment. 
- 
            You have created a Machine User to use as the Cloudera Workload User. 
- You have given the Cloudera Workload User the
              EnvironmentUser role.- From the Management Console, go to the environment for which Cloudera Data Flow is enabled.
- From the Actions drop down, click Manage Access.
- Identify the user you want to use as a Workload User.
- Give that user EnvironmentUser role.
 
- 
            You have synchronized your user to the Cloudera on cloud environment that you enabled for Cloudera Data Flow. For information on how to synchronize your user to FreeIPA, see Performing User Sync. 
- You have granted your Cloudera user the DFCatalogAdmin and DFFlowAdmin
            roles to enable your user to add the ReadyFlow to the Catalog and deploy the flow
              definition.- Give a user permission to add the ReadyFlow to the
                    Catalog.- From the Management Console, click User Management.
- Enter the name of the user or group you wish to authorize in the Search field.
- Select the user or group from the list that displays.
- Click .
- From Update Roles, select DFCatalogAdmin and click Update.
 
- Give your user or group permission to deploy flow definitions.- From the Management Console, click Environments to display the Environment List page.
- Select the environment to which you want your user or group to deploy flow definitions.
- Click to display the Environment Access page.
- Enter the name of your user or group you wish to authorize in the Search field.
- Select your user or group and click Update Roles.
- Select DFFlowAdmin from the list of roles.
- Click Update Roles.
 
- Give your user or group access to the Project where the ReadyFlow will be
                    deployed.- Go to .
- Select the project where you want to manage access rights and click .
 
- Start typing the name of the user or group you want to add and select them from the list.
- Select the Resource Roles you want to grant.
- Click Update Roles.
- Click Synchronize Users.
 
- Give a user permission to add the ReadyFlow to the
                    Catalog.
For your data ingest targets
- You have the IBM Project ID and IBM Cloud API Key.
- You have the destination S3 bucket and path. You have performed one of the following to
          configure access to the destination S3 bucket:- 
            You have configured access to the S3 bucket with a RAZ enabled environment. It is a best practice to enable RAZ to control access to your object store buckets. This allows you to use your Cloudera on cloud credentials to access S3 buckets, increases auditability, and makes object store data ingest workflows portable across cloud providers.- Ensure that Fine-grained access control is enabled for your Cloudera Data Flow environment.
- From the Ranger UI, navigate to the S3 repository.
- Create a policy to govern access to the S3 bucket and path used in your ingest workflow.
- Add the machine user that you have created for your ingest workflow to the policy you just created.
 For more information, see Creating Ranger policy to use in RAZ-enabled AWS environment. 
- 
            You have configured access to the S3 bucket using ID Broker mapping. If your environment is not RAZ-enabled, you can configure access to the S3 bucket using ID Broker mapping.- Access IDBroker mappings.- To access IDBroker mappings in your environment, click .
- Choose the IDBroker Mappings tab where you can provide mappings for users or groups and click Edit.
 
- Add your Cloudera Workload User and the corresponding AWS role that provides write access to your folder in your S3 bucket to the Current Mappings section by clicking the blue + sign.
- Click Save and Sync.
 
- Access IDBroker mappings.
 
- 
            
