> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# S3 Batch Operation

> Hands-on lab · 45m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/s3-batch-operation" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Lab Details

* In this lab, you will configure and test Amazon S3 Batch Operations to update object access permissions. You'll create a manifest listing multiple JPG objects stored in an S3 bucket and define a batch job to replace their ACLs. The job will run using a dedicated IAM role with the required permissions, making the objects publicly accessible. Finally, you'll verify the completion report to ensure all target objects have been updated successfully.
* Duration:  **45 minutes**
* AWS Region: **US East (N. Virginia) us-east-1**

### Introduction

###### Amazon S3 Batch Operations :

* Amazon S3 Batch Operations is a feature that allows you to perform large-scale actions on multiple S3 objects at the same time  as long as the objects are in the same bucket.
* You can use it to update object permissions, copy objects, or invoke AWS Lambda functions across thousands or millions of objects.
* All objects in the manifest are processed uniformly, which means changes like making JPG files public are applied consistently.
* It is designed for bulk object management tasks, reducing manual effort and ensuring accurate, auditable operations.

#### Lab Feature :

* This lab shows how to configure Amazon S3 Batch Operations to perform bulk actions on multiple objects in a single bucket. You'll use a manifest to select specific files (e.g., JPGs) and update their permissions to make them public. It demonstrates proper use of CSV manifests and ACL replacement, ensuring consistent and auditable changes across all selected objects.

#### Benefits:

* Efficiently apply operations to thousands of objects in S3 without manual updates.
* Ensures consistency by using a manifest to target specific files, like JPGs.
* Reduces human error and saves time compared to individual object management.
* Provides auditability with completion reports for all performed actions.

### Architecture Diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/001.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=607b182314b638da7aca5efa2eaf96a0" alt="" width="1275" height="528" data-path="images/labs/s3-batch-operation/001.png" />

### Task Details :

1. Sign in to the AWS Management Console.
2. Create S3 Bucket
3. Create Manifest file
4. Create Batch Operation
5. Run Batch Operation Job

### Launching Lab Environment

1. To launch the lab environment, click on the **Start Lab** button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the Lab is started, you will be provided with **IAM username, Password, Access Key,** and **Secret Access Key.**

> **Note :** You can only start one lab at any given time

## Lab guide

### Lab Steps:

#### Task 1: Sign in to AWS Management Console

1. Click on the Open Console button, and you will get redirected to AWS Console in a new browser tab.

2. On the AWS sign-in page,

a. Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.

b. Now copy your **User Name** and **Password** in the Lab Console to the **IAM Username and Password** in AWS Console and click on the **Sign in** button.

3. Once Signed In to the AWS Management Console, Make the default AWS Region as **US East (N. Virginia) us-east-1.**

#### Task 2 : Create S3 Bucket

1. Navigate to the Services menu at the top and click on **S3** in the **Storage** section.
2. In the left menu, choose Buckets, click Create Bucket and fill in the bucket details.

a. Bucket Type Select : **General purpose**
b. Bucket Name: Enter **whiz-batch-operation**

> **Note:** The Bucket Name must be Unique across all existing bucket names in Amazon S3

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/002.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=26a8b5c7c8fcc4a4590e1327980914b7" alt="" width="1397" height="402" data-path="images/labs/s3-batch-operation/002.png" />

* Object ownership: Select **ACLs Enabled** option then Choose **Object writer**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/003.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=dce1eb49e6490f0c09a1bc5617a0de7a" alt="" width="1404" height="374" data-path="images/labs/s3-batch-operation/003.png" />

* Bucket settings for Block Public Access: **Uncheck** the option, **Block** all **public access** and select the check box option of Acknowledgment.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/004.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=d85a359c8149e920861a23679202ae03" alt="" width="977" height="800" data-path="images/labs/s3-batch-operation/004.png" />

* Leave other settings as default.
* Click on the **Create Bucket** button.

> **Note:** if you are getting any error please ignore and follow further steps.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/005.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=f4f83f362066eeb5f18672560f47ad40" alt="" width="977" height="81" data-path="images/labs/s3-batch-operation/005.png" />

#### Task 3 : Create Manifest file

1. Click on your bucket name.
2. Click to download the [ZIP](https://labresources.whizlabs.com/85ca05f72e2bf05429f28cb47f4cb545/sample_files.zip) file, then extract it and upload the files to the S3 bucket.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/006.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=62fe56911442a2cd08226ef843e2f79f" alt="" width="1443" height="453" data-path="images/labs/s3-batch-operation/006.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/007.gif?s=c85d6af54bc333708e8210cf50dee714" alt="" width="1280" height="619" data-path="images/labs/s3-batch-operation/007.gif" />

3. The uploaded files are now visible in the S3 bucket.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/008.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=700b225409a533820c4178e668e56453" alt="" width="1444" height="700" data-path="images/labs/s3-batch-operation/008.png" />

4. Click the **photo1.jpg** object to copy its **Object URL**, then paste the URL into a new browser tab.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/009.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=76c4eb31dc5b30cb2339cce004dffa2f" alt="" width="1446" height="552" data-path="images/labs/s3-batch-operation/009.png" />

5. Now we can’t see this because the object is not public.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/010.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=efc20b4ecbbab2494d205dcf1edbf340" alt="" width="977" height="327" data-path="images/labs/s3-batch-operation/010.png" />

> **Note :** S3 Batch Operations are typically used with inventory configurations to create a manifest file. However, once an inventory configuration is created, AWS delivers the file within 24 hours. To avoid waiting, this time we create the manifest file manually using Python.

6. Open Cloud Shell present in the top right corner.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/011.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=5cede79b13b0c31534d3666f3078f3d7" alt="" width="1460" height="401" data-path="images/labs/s3-batch-operation/011.png" />

7. Paste the following in the cloudshell

```
nano main.py
```

* Replace the bucket name

import boto3

import csv

# Replace the bucket name

bucket\_name = 'my-batch-test-bucket'

output\_file = 'jpg\_manifest.csv'

prefix = ''

s3 = boto3.client('s3')

response = s3.list\_objects\_v2(Bucket=bucket\_name, Prefix=prefix)

with open(output\_file, 'w', newline='') as csvfile:

writer = csv.writer(csvfile)

for obj in response.get('Contents', \[]):

key = obj\['Key']

if key.endswith('.jpg'):

writer.writerow(\[bucket\_name, key])

print(" Manifest created.")

# Upload to S3

s3.upload\_file(output\_file, bucket\_name, 'manifests/jpg\_manifest.csv')

print("Uploaded manifest to S3.")

* Click Ctrl+X, Y and then Click **Enter**

```
python main.py
```

7. Now you can see: 'Manifest created. Uploaded manifest to S3.'

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/012.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=05f550ee578ae578390d50fabc33378a" alt="" width="361" height="250" data-path="images/labs/s3-batch-operation/012.png" />

8. Go to the S3 bucket **manifests/** to see the manifest file created: **jpg\_manifest.csv.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/013.gif?s=1c65c4452713db085cb6ac413412f815" alt="" width="1280" height="696" data-path="images/labs/s3-batch-operation/013.gif" />

#### Task 4 : Create Batch Operation

1. Go to **Batch Operation.** Click to **Create Job**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/014.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=9bf0c37afa143da5904df2165583fb2e" alt="" width="1444" height="404" data-path="images/labs/s3-batch-operation/014.png" />

2. Scroll down in the Manifest field, choose **CSV**, and in the **Manifest object**, select the S3 bucket where the **manifest file** is located. Then, click Next.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/tRuhen-qU3QM2UBZ/images/labs/s3-batch-operation/015.png?fit=max&auto=format&n=tRuhen-qU3QM2UBZ&q=85&s=d48a3c794552c520c45fc4b6594ee77d" alt="" width="1205" height="600" data-path="images/labs/s3-batch-operation/015.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/016.gif?s=b28fac3d6b17d54801b61df95748cccd" alt="" width="1280" height="362" data-path="images/labs/s3-batch-operation/016.gif" />

3. In the **'Choose Operation'** field, select **'Replace access control list (ACL)'**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/017.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=577ddc07043778a0fbfafb968765baa5" alt="" width="1200" height="234" data-path="images/labs/s3-batch-operation/017.png" />

4. Under 'Everyone (public access)', check the **'Read'** checkbox.

* Also, check the box acknowledging.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/018.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=d5a302aa7d89af4a34b1c906bbd2e79e" alt="" width="799" height="502" data-path="images/labs/s3-batch-operation/018.png" />

* Click Next

5. In the Configure Additional Options section, set the priority to 10.

* Check the box for **Generate completion report** and select **All tasks.**
* In the **Completion Report Destination**, choose your bucket and add **/batch-reports/jpg-acl-job/.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/019.gif?s=9967c4bdd25fdc4d0a63c6cbecc3be00" alt="" width="1280" height="547" data-path="images/labs/s3-batch-operation/019.gif" />

6. The **Permissions** field, choose **batch\_operation\_role-\<RANDOM-NUMBERS>,** then click Next

7. Click **Create Job**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/020.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=a9753520f5958a7de4e1d988e475d952" alt="" width="1208" height="336" data-path="images/labs/s3-batch-operation/020.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/021.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=2a34f82c76a600d98b3911882693dc26" alt="" width="2280" height="1160" data-path="images/labs/s3-batch-operation/021.png" />

### Task 5 : Run Batch Operation Job

1. Wait for 2 minutes, then the created job will show **'Awaiting your confirmation to run'.** Click to run the job.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/022.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=39e205b122c672b211e89baaab40a192" alt="" width="1452" height="338" data-path="images/labs/s3-batch-operation/022.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/023.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=5cff6078b3302c47ee94bd5a137ae3b8" alt="" width="1448" height="501" data-path="images/labs/s3-batch-operation/023.png" />

2. Now you can see that the job has been successfully completed.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/024.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=b6764abc026aa2ae347894e3c7e5d8e8" alt="" width="1441" height="349" data-path="images/labs/s3-batch-operation/024.png" />

3. Now go to the bucket, copy the **photo1.jpg** object URL, and paste it into a new browser tab.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/025.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=02b318374339f7dfc1c170c5ebbb1ccc" alt="" width="1172" height="558" data-path="images/labs/s3-batch-operation/025.png" />

* Now You can see this Image!

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/s3-batch-operation/026.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=346684dbd372aae6b23433ae9f9cffa3" alt="" width="977" height="502" data-path="images/labs/s3-batch-operation/026.png" />

> **Do You Know ?**
> S3 Batch Operations can process millions of objects in a single job, letting you perform tasks like copying, tagging, or updating ACLs efficiently. Completion reports help track success and failure for each object. It can also integrate with AWS Lambda for custom processing of your objects.

### Completion and Conclusion

* You have successfully created a manifest file listing the target JPG files in S3.
* You have configured an S3 Batch Operations job to update the ACL of those objects.
* You have run the Batch Operations job, making the JPG files publicly accessible.
* You have verified that the completion report confirms all objects were processed successfully.

### End Lab

1. Sign out of AWS Account.
2. You have successfully completed the lab.
3. Once you completed the steps, click on **End Lab** from your IP Lab Portal and wait till the process gets completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Create acl enabled S3 bucket** — Check whether an S3 Bucket is created with acl enabled or not
* **check s3 object** — Check whether an object is uploaded to the S3 bucket.

## Related help

* [FAQs and Troubleshooting](/aws-saa/support/faqs-and-troubleshooting)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.