Skip to main content

Privacera Documentation

Connect Kinesis to PrivaceraCloud

This topic describes how to connect Kinesis application to PrivaceraCloud.

Connecting to an AWS hosted data source requires authentication or a Trust relation with those resources. You will provide this information as one step in the AWS Data resource connection. You will also need to specify your AWS Account Region.


Connect the S3 application to the PrivaceraCloud before connecting the Kinesis application.

  1. Go to Settings > Applications.

  2. On the Applications screen, select Kinesis.

  3. Enter the application Name and Description, and then click Save.

    You can see Privacera Access Management with the toggle buttons.

Enable Privacera Access Management for Kinesis

  1. Click the toggle button to enable Privacera Access Management for your application.

  2. On the BASIC tab, enter values in the following fields:

    • With Use IAM Role disabled:

      1. AWS Access Key: AWS data repository host account Access Key.

      2. AWS Secret Key: AWS data repository host account Secret Key

      3. AWS Region: AWS S3 bucket region.

    • With Use IAM Role enabled:

      1. AWS IAM Role: Enter the actual IAM Role using a full AWS ARN.

      2. AWS IAM Role External Id: For additional security, an external ID can be attached to your IAM role configured. This assures that your IAM role can be assumed by PrivaceraCloud only when the configured external ID is passed.


        The external ID is stored encrypted. It is never reflected back to the UI or is made visible.

      3. AWS Region: AWS S3 bucket region.

  3. On the ADVANCED tab, you can add custom properties.

  4. Using the IMPORT PROPERTIES button, you can browse and import application properties.

  5. Click the TEST CONNECTION button to check if the connection is successful, and then click Save.

  6. Recommended: Install the AWS CLI.

    Open Launch Pad and follow the steps to install and configure AWS CLI to your workstation so that it uses the PrivaceraCloud Kinesis Data Server proxy.

  7. Recommended: Validate connectivity by running AWS CLI for Kinesis such as:

    aws kinesis list-streams