Read from Amazon S3 Using a Rotating Credentials File
Updated: Oct 5, 2026
This example shows how to read a CSV file from Amazon S3 with credentials kept in a Java properties file. A FileCredentialsResolver reads the file each time the file system opens and re-reads it whenever its last-modified time changes, so a secret that an orchestrator rotates in place (a Kubernetes secret volume or a Vault Agent sidecar, for example) is used on the next connection without restarting the job.
Credentials file
Each property in the file becomes one credential entry, so the property names are the key names defined on Credentials: accessKey, secretKey and, optionally, sessionToken.
accessKey=YOUR ACCESS KEY secretKey=YOUR SECRET KEY
Java Code Listing
package com.northconcepts.datapipeline.examples.security;
import java.io.InputStreamReader;
import com.northconcepts.datapipeline.amazons3.AmazonS3FileSystem;
import com.northconcepts.datapipeline.core.DataReader;
import com.northconcepts.datapipeline.core.DataWriter;
import com.northconcepts.datapipeline.core.StreamWriter;
import com.northconcepts.datapipeline.csv.CSVReader;
import com.northconcepts.datapipeline.job.Job;
import com.northconcepts.datapipeline.security.FileCredentialsResolver;
public class ReadFromAmazonS3UsingRotatingCredentialsFile {
private static final String CREDENTIALS_FILE = "example/data/input/s3-credentials.properties";
private static final String BUCKET = "YOUR BUCKET";
private static final String KEY = "output/trades.csv";
public static void main(String[] args) throws Throwable {
AmazonS3FileSystem s3 = new AmazonS3FileSystem()
.setCredentialsResolver(new FileCredentialsResolver(CREDENTIALS_FILE));
s3.open();
try {
DataReader reader = new CSVReader(new InputStreamReader(s3.readFile(BUCKET, KEY)))
.setFieldNamesInFirstRow(true);
DataWriter writer = StreamWriter.newSystemOutWriter();
Job.run(reader, writer);
} finally {
s3.close();
}
}
}
Code Walkthrough
CREDENTIALS_FILEpoints at the properties file;BUCKETandKEYname the object to read.- An
AmazonS3FileSystemis created with aFileCredentialsResolveras its credentials resolver. s3.open()resolves the credentials and connects. The resolver checks the file's modification time on every resolve, so after the file is rewritten the nextopen()uses the new keys.s3.readFile(BUCKET, KEY)returns anInputStreamfor the object, wrapped in aCSVReaderwith field names in the first row.Job.run()transfers the records to aStreamWriterthat prints them to the console.s3.close()in thefinallyblock disconnects and clears the credentials snapshot held by the file system.
Console Output
Each record in trades.csv is printed to the console, followed by the record count.
