I want to understand how egress works. I want to c...
# ask-ai
b
I want to understand how egress works. I want to configure my own S3 bucket to it, the bucket needs to be public?
t
Thanks for reaching out, Martín. I'm an AI assistant and I'm here to help. Give me a moment while I research this topic.
LiveKit Egress allows you to export recordings and media from your sessions to destinations like Amazon S3. You do not need to make your S3 bucket public for this to work. Instead, you provide AWS credentials (access key and secret) with permissions to upload objects to your bucket. LiveKit Egress uses these credentials to authenticate and upload files directly to your private S3 bucket. To configure S3 as an egress destination, you need to specify: • access_key – AWS access key ID • secret – AWS secret access key • region – AWS region of your bucket • bucket – Name of your S3 bucket Optionally, you can use IAM roles or instance profiles for authentication, in which case you can leave the access_key and secret fields empty. Make sure the credentials you use have permissions to put objects in the bucket and set metadata or tags if needed. This setup keeps your bucket private and secure while allowing LiveKit to upload egress files. Sources: README.md | protobufs/livekit_egress.proto | cmd/lk/examples/auto-track-egress.json
b
How can I use IAM roles? Do you have a code snippet?
t
Hey there! Let me walk you through a super handy way to handle S3 uploads with LiveKit Egress using AWS IAM roles. It's like giving your upload process a special backstage pass! 😊 Here's a friendly example of how you can set this up:
Copy code
{
  "room_name": "my-room",
  "file_outputs": [
    {
      "filepath": "recordings/{room_name}-{time}.mp4",
      "s3": {
        "access_key": "your-access-key",
        "secret": "your-secret-key",
        "assume_role_arn": "arn:aws:iam::123456789012:role/EgressUploadRole",
        "assume_role_external_id": "optional-external-id",
        "region": "us-west-2",
        "bucket": "my-recordings-bucket"
      }
    }
  ]
}
Here's the magic behind how this works: 1. The egress service uses your access credentials to request a temporary role - think of it like a special guest pass! 2. With these temporary credentials, it can smoothly upload your files to S3. Pro tip: If you want to make things even easier, you can set up default credentials in your egress service config. Less work for you! For my Go SDK friends, here's a quick code snippet to help you out:
Copy code
req := &livekit.RoomCompositeEgressRequest{
    RoomName: "my-room",
    FileOutputs: []*livekit.EncodedFileOutput{{
        Filepath: "recordings/{room_name}-{time}.mp4",
        Output: &livekit.EncodedFileOutput_S3{
            S3: &livekit.S3Upload{
                AccessKey:      "your-access-key",
                Secret:         "your-secret-key",
                AssumeRoleArn:  "arn:aws:iam::123456789012:role/EgressUploadRole",
                Region:         "us-west-2",
                Bucket:         "my-recordings-bucket",
            },
        },
    }},
}
Just a heads up - on LiveKit Cloud, the AssumeRole feature is only available for accounts with this feature enabled. So double-check that for your setup! Sources: test/config-sample.yaml | s3.go | protobufs/livekit_egress.proto
c

https://youtu.be/rYJb-YIeS1M?feature=shared▾

❤️ 1
t
I don't have the answer you're looking for. You could also try asking your question: • in one of the other Slack channels or • to https://deepwiki.com/livekit/livekit_composite which is trained on all LiveKit source code If you find the answer, please post it here to help others!
c
here he has shown step by step how to use s3 for egress
🙌 1