← All projects

Secure S3 Data Pipeline

S3 trigger connected to the ingestion Lambda.

Cloud & engineering / 2026

Secure S3 Data Pipeline

An educational serverless data ingestion architecture connecting S3, Lambda, and DynamoDB with explicit access and encryption controls.

My contribution

Built and documented an event-driven pipeline with least-privilege roles, encryption, and audit logging.

The approach

  • Read a JSON array from the first S3 event record.
  • Keep records containing device_id, timestamp, and value, then write them to DynamoDB.
  • Configure HTTPS-only S3 access, scoped IAM permissions, KMS encryption, and audit logging.

Scope & perspective

The sample implements a focused ingestion path. Its field-presence check is not full schema validation, and cloud deployment and service configuration are separate from the code.

AWSS3LambdaDynamoDBIAMKMS
Explore the repository ↗
Let’s talk about it ↗