better-gigabyte-88039
07/23/2025, 2:20 PMtall-airline-16756
07/23/2025, 2:20 PMtall-airline-16756
07/23/2025, 2:21 PMbetter-gigabyte-88039
07/23/2025, 2:22 PMtall-airline-16756
07/23/2025, 2:23 PM{
"room_name": "my-room",
"file_outputs": [
{
"filepath": "recordings/{room_name}-{time}.mp4",
"s3": {
"access_key": "your-access-key",
"secret": "your-secret-key",
"assume_role_arn": "arn:aws:iam::123456789012:role/EgressUploadRole",
"assume_role_external_id": "optional-external-id",
"region": "us-west-2",
"bucket": "my-recordings-bucket"
}
}
]
}
Here's the magic behind how this works:
1. The egress service uses your access credentials to request a temporary role - think of it like a special guest pass!
2. With these temporary credentials, it can smoothly upload your files to S3.
Pro tip: If you want to make things even easier, you can set up default credentials in your egress service config. Less work for you!
For my Go SDK friends, here's a quick code snippet to help you out:
req := &livekit.RoomCompositeEgressRequest{
RoomName: "my-room",
FileOutputs: []*livekit.EncodedFileOutput{{
Filepath: "recordings/{room_name}-{time}.mp4",
Output: &livekit.EncodedFileOutput_S3{
S3: &livekit.S3Upload{
AccessKey: "your-access-key",
Secret: "your-secret-key",
AssumeRoleArn: "arn:aws:iam::123456789012:role/EgressUploadRole",
Region: "us-west-2",
Bucket: "my-recordings-bucket",
},
},
}},
}
Just a heads up - on LiveKit Cloud, the AssumeRole feature is only available for accounts with this feature enabled. So double-check that for your setup!
Sources: test/config-sample.yaml | s3.go | protobufs/livekit_egress.prototall-airline-16756
07/23/2025, 2:48 PMcrooked-agent-9740
07/23/2025, 2:48 PM