---
title: "Setting up AWS S3 buckets to store Frameworks Attachments"
canonical: "https://kb.myframeworks.com.au/space/FRAM/28377956/Setting%20up%20AWS%20S3%20buckets%20to%20store%20Frameworks%20Attachments"
format: markdown
---
#  Overview

To store attachments and use the supplier invoice scanning function, AWS S3 buckets must be configured. This is already done if you are a Frameworks cloud customer; however, you can create an AWS S3 bucket if you are running Framework On-premise and require it for [Supplier Invoice Scanning](https://sterlandsupport.atlassian.net/wiki/spaces/FRAM/pages/28377968) and the Print Document Configuration of Document Storage.

> Macro (excerpt)
> 
> In addition, the [Supplier Invoice Emailing](https://sterlandsupport.atlassian.net/wiki/spaces/FRAM/pages/28413758) streamlines invoice processing by automatically extracting invoice data from email attachments sent to a designated address. When an invoice email is received, Frameworks retrieves the attachment, uses AWS Textract OCR to scan and extract key details, and seamlessly integrates this information into the invoice approval workflow.

## What are AWS S3 buckets?

Amazon Simple Storage Service (AWS S3) is an object storage service that offers industry-leading scalability, data availability, security, and performance. You can use Amazon S3 to store and retrieve any amount of data at any time, from anywhere. As Frameworks Cloud leverages AWS S3 buckets are required to store your data.

# Creating an AWS S3 Bucket

1. Sign in to your AWS Management Console by navigating to [https://console.aws.amazon.com/s3/](https://console.aws.amazon.com/s3/).
2. Search for **S3** and open the Amazon S3 console.
3. In the left navigation pane, select **Buckets** and Click **Create bucket**.
4. The **Create bucket** page opens and from the Create Bucket page perform the following:
  1. Under the **General configuration **section, name your bucket and nominate which region you want the bucket in.   
**Important: **Take note of the name and region for later, for example, ***Name****: attachments.frameworks.live* and ***Region****: ap-southeast-2*
    
  2. Under the **Block Public Access settings for this bucket **section enable the **Block all public access **checkbox
  3. Under the **Bucket Versioning **section, enable the **Disable **versioning option.
  4. All the other settings can remain as their default settings.
  5. Click **Create bucket **to set** **up the bucket.
5. Select the newly created bucket from the list so you can review the settings of your bucket.
  
6. By selecting the **Management **options, you can create a retention policy for your test environment buckets.

> ✅ Refer to [Step 1: Create your first S3 bucket - Amazon Simple Storage Service](https://docs.aws.amazon.com/AmazonS3/latest/userguide/creating-bucket.html) for additioninal information.

# Creating a Policy to restrict access to your Bucket.

1. From the AWS console search for and select **IAM**
2. Select **Policy **and **Create policy**
3. In the **Policy editor, **select **JSON **and **Add actions**
  1. "s3:PutObject", "s3:GetObject", "s3:PutObjectTagging", "s3:DeleteObject"
4. **Add a resource** by clicking **Add** and using your bucket name.
5. Name the Policy, Review and create.

# Creating a User with access to your Bucket.

1. Select **Users **and click **Add users.**
2. Enter the **User name **and ensure you disable **Provide user access to the AWS Management Console **and click **Next.**
3. Choose **Attach policies directly.**
4. Select the Policy you created earlier and click **Next.**
5. From the **Review and create** screen, review the details and click **Create user.**

# Creating an Access Key for Your User

1. Select the **User** >  **Security credentials** and under the **Access Keys** section, click** Create access key.**
  
  
2. Select** **the **Application running outside AWS** option and click **Next.**
  
3. Enter** S3 access for Frameworks Attachments** as the **Description tag value** and click **Create access key.**
  
4. **IMPORTANT** - **Copy the following information because you won’t see this again!**  
You will need the **Access key**, **Secret access key**,** bucket name** and **region **for the Frameworks configuration next.
5. Click **Download .csv file** and save it to your computer, then click **Done.**
  

# Setting up Attachments to use S3 Buckets

- For Frameworks on OpenEdge 12 the host.properties files already exist.  For systems using OpenEdge 11.7 you will need to create a conf directory under /prostix/live and then create a host.properties file in /prostix/live/conf.
- For a classic OE11.7 environment the file should contain the following entries:

```
# Does this server host multiple tenants?
isMultiTenant=false

############################################################################
# The Frameworks Attachment System can store attachments in an S3 bucket rather
# than an attachment directory on disk.
# If the value in the Misc Table Setting for "SysAttPath" is "AWSS3" then a S3 bucket is used.
# These settings define the keys and configurations used by Frameworks
############################################################################

#The AWS Access Key ID used to store FW attachments in a S3 bucket
attachments.awsAccessKey=
#The AWS Access Secret Key used to store FW attachments in a S3 bucket
attachments.awsSecretKey=
#The AWS S3 Bucket name used to store FW attachments in a S3 bucket
attachments.awsBucketName=
#The AWS Region used to store FW attachments in a S3 bucket
attachments.awsRegionName=

```

1. Update the **host.properties **file and fill in the values for the **attachments.aws*** properties from your AWS S3 setup, for example:
  1. attachments.awsAccessKey=ABCD
  2. attachments.awsSecretKey=dwwfre2323$#%
  3. attachments.awsBucketName=attachments.frameworks.live
  4. attachments.awsRegionName= ap-southeast-2
2. Make sure there are no spaces before or after the property values.
3. In Frameworks update the **System Setting - General **entry for “**SysAttPth**” and set to “**AWSS3**”
  ***Note****: SysAttUrl is no longer used.*
4. Restart the Appserver or trim the agents after setting up the host.properties file and if any changes are made to this file or when making the changes to SysAttPth.

# Test by adding an attachment to a customer.

1. Within Frameworks navigate to the **Customer Dashboard **and upload an attachment to the customer.
  
2. Refresh your S3 bucket and you should see the document uploaded:

![image](media://1160149d-b3af-4bc8-bf86-983f21529535)

> ℹ️ Your customer licence code is used as the root directory.

# Possible SSL Errors

If you get an error when uploading an attachment that refers to a missing certificate, then contact Sterland Tech Support to update the SSL certificates for your Progress OpenEdge install.