{"id":22463224,"url":"https://github.com/aspose-pdf-cloud/aspose-pdf-for-aws-sdk","last_synced_at":"2025-03-27T14:24:02.123Z","repository":{"id":240193603,"uuid":"801920614","full_name":"aspose-pdf-cloud/aspose-pdf-for-aws-sdk","owner":"aspose-pdf-cloud","description":"Aspose.PDF for AWS Client SDKs","archived":false,"fork":false,"pushed_at":"2024-05-22T09:35:54.000Z","size":460,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":14,"default_branch":"main","last_synced_at":"2024-05-22T10:48:03.724Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/aspose-pdf-cloud.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-05-17T07:15:28.000Z","updated_at":"2024-06-11T11:06:14.123Z","dependencies_parsed_at":"2024-06-11T11:06:12.243Z","dependency_job_id":"14e26702-e0f1-473b-a420-5d16908247b3","html_url":"https://github.com/aspose-pdf-cloud/aspose-pdf-for-aws-sdk","commit_stats":null,"previous_names":["aspose-pdf-cloud/aspose-pdf-for-aws-sdk"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aspose-pdf-cloud%2Faspose-pdf-for-aws-sdk","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aspose-pdf-cloud%2Faspose-pdf-for-aws-sdk/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aspose-pdf-cloud%2Faspose-pdf-for-aws-sdk/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aspose-pdf-cloud%2Faspose-pdf-for-aws-sdk/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/aspose-pdf-cloud","download_url":"https://codeload.github.com/aspose-pdf-cloud/aspose-pdf-for-aws-sdk/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":245859941,"owners_count":20684248,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-12-06T09:12:33.202Z","updated_at":"2025-03-27T14:24:02.068Z","avatar_url":"https://github.com/aspose-pdf-cloud.png","language":"PHP","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Aspose.PDF for AWS Client SDKs\n\n\n  * [Pricing](#pricing)\n\n  * [Getting Started with Aspose.PDF for AWS](#getting-started-with-asposepdf-for-aws)\n    * [Reporting Issues](#reporting-issues)\n    * [Steps](#steps)\n\n  * [Using Swagger UI](#using-swagger-ui)\n\n  * [Conversion PDF to DOCX example](#conversion-pdf-to-docx-example)\n\n  * [Error Handling](#error-handling)\n\n  * [Installation](#installation)\n\n  * [Creating an AWS S3 Bucket](#creating-an-aws-s3-bucket)\n\n  * [Setup Container](#setup-container)\n\n  * [Environment Variables](#environment-variables)\n\n  * [Deploy Container on Amazon ECS](#deploy-container-on-amazon-ecs)\n\n  * [Deploy Container on Amazon EKS](#deploy-container-on-amazon-eks)\n\n  * [Monitoring Health of Instance](#monitoring-health-of-instance)\n\n  * [Handling Sensitive Customer Information](#handling-sensitive-customer-information)\n\n  * [Change Ports on ECS](#change-ports-on-ecs)\n  * [Changing Ports on EKS](#changing-ports-on-eks)\n\n  * [Setting Up HTTPS Certificate](#setting-up-https-certificate)\n\n  * [Document with Passwords](#document-with-passwords)\n\n  * [File Uploads via External and Internal Links](#file-uploads-via-external-and-internal-links)\n\n  * [AWS S3 File Storage Structure](#aws-s3-file-storage-structure)\n\n  * [Using Encrypted File Storage](#using-encrypted-file-storage)\n\n  * [Immediate Remove of processed files](#immediate-remove-of-processed-files)\n\n  * [Securing S3 Bucket](#securing-s3-bucket)\n\n  * [Rotating HTTPS Certificates on ECS](#rotating-https-certificates-on-ecs)\n\n  * [Integrating AWS Key Management Service on ECS](#integrating-aws-key-management-service-on-ecs)\n\n  * [Rotating HTTPS Certificates on EKS](#rotating-https-certificates-on-eks)\n\n  * [Integrating AWS Key Management Service on EKS](#integrating-aws-key-management-service-on-eks)\n\n  * [Client SDKs](#client-sdks)\n    * [[.NET 6.0](https://github.com/aspose-pdf-cloud/aspose-pdf-for-aws-sdk/tree/main/dotnet-client)](#net-60httpsgithubcomaspose-pdf-cloudaspose-pdf-for-aws-sdktreemaindotnet-client)\n    * [[Java 11](https://github.com/aspose-pdf-cloud/aspose-pdf-for-aws-sdk/tree/main/java-client)](#java-11httpsgithubcomaspose-pdf-cloudaspose-pdf-for-aws-sdktreemainjava-client)\n    * [[PHP 5.5](https://github.com/aspose-pdf-cloud/aspose-pdf-for-aws-sdk/tree/main/php-cLient)](#php-55httpsgithubcomaspose-pdf-cloudaspose-pdf-for-aws-sdktreemainphp-client)\n    * [[Kotlin 1.4.0](https://github.com/aspose-pdf-cloud/aspose-pdf-for-aws-sdk/tree/main/kotlin-client)](#kotlin-140httpsgithubcomaspose-pdf-cloudaspose-pdf-for-aws-sdktreemainkotlin-client)\n\n  * [Release Notes](#release-notes)\n    * [Support](#support)\n\n  * [**Version:** 1 **Release Date:** 1 Jul 2024](#version-1-release-date-1-jul-2024)\n\n\n  * [**Aspose.PDF for AWS Features**](#asposepdf-for-aws-features)\n    * [**Add Page Numbers to Document.**](#add-page-numbers-to-document)\n    * [**Change Fonts in Provided Files.**](#change-fonts-in-provided-files)\n    * [**Compare documents text.**](#compare-documents-text)\n    * [**Compress Document.**](#compress-document)\n    * [**Convert Document to Another Format.**](#convert-document-to-another-format)\n    * [**Convert Web Page to Document.**](#convert-web-page-to-document)\n    * [**Crop Document.**](#crop-document)\n    * [**Sign Document with Certificate.**](#sign-document-with-certificate)\n    * [**Extract Tables from Document.**](#extract-tables-from-document)\n    * [**Make GIF.**](#make-gif)\n    * [**Calculate Document Hash.**](#calculate-document-hash)\n    * [**Lock document.**](#lock-document)\n    * [**Merge Documents.**](#merge-documents)\n    * [**Read and Change Document Metadata.**](#read-and-change-document-metadata)\n    * [**Organize Document Pages.**](#organize-document-pages)\n    * [**Parse Document.**](#parse-document)\n    * [**Redact Document Text.**](#redact-document-text)\n    * [**Remove Document Annotations.**](#remove-document-annotations)\n    * [**Remove Document Watermark.**](#remove-document-watermark)\n    * [**Remove Pages from Document.**](#remove-pages-from-document)\n    * [**Repair Document.**](#repair-document)\n    * [**Resize Document.**](#resize-document)\n    * [**Rotate Document.**](#rotate-document)\n    * [**Search Document Text.**](#search-document-text)\n    * [**Make Scanned PDF Searchable.**](#make-scanned-pdf-searchable)\n    * [**Add Signature to Document.**](#add-signature-to-document)\n    * [**Split Document.**](#split-document)\n    * [**Split Image.**](#split-image)\n    * [**Unlock Document.**](#unlock-document)\n    * [**Verify Document Certificate.**](#verify-document-certificate)\n    * [**Add Watermark to Document.**](#add-watermark-to-document)\n    * [**Count Words and Characters in Document.**](#count-words-and-characters-in-document)\n    * [**Convert XFA Format to Another Format.**](#convert-xfa-format-to-another-format)\n\n\n[Aspose.PDF for AWS](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo) offers a modern solution for organizations looking to enhance their document processing capabilities. Whether it's converting formats, merging files, splitting documents, extracting data, or reordering content, our RESTful API, built on the powerful [Aspose.PDF .NET library](https://docs.aspose.com/pdf/net/) and optimized Linux packages, provides a streamlined and efficient approach.\n\nRecognizing the need for continuous improvement, many organizations explore ways to optimize their document workflows. Aspose.PDF for AWS enables them to achieve this by eliminating the need to develop custom code for complex tasks. With our API, users benefit from the Aspose.PDF .NET managed library, which addresses common issues associated with unmanaged code, such as stability and performance concerns. Enhanced with linux packages, our solution ensures fast processing speeds and comes with dedicated 24/7 [support](https://helpdesk.aspose.com/), giving you peace of mind and the reliability you need for mission-critical applications. The simplicity of saving documents to [Amazon S3](https://aws.amazon.com/s3/) further enhances the ease of setup and integration.\n\nUsers can quickly begin utilizing the API through the intuitive Swagger UI, facilitating manual document tasks without requiring extensive technical expertise. For developers, integrating the API into existing systems is straightforward with support for popular programming languages like [.NET](https://dotnet.microsoft.com), [Java](https://www.java.com), [PHP](https://www.php.net), and [Kotlin](https://kotlinlang.org).\n\nOrganizations looking to optimize their document processing can find real value in the pay-as-you-go model offered by Aspose.PDF for AWS. With no need for a initial payment to get started, you only pay for the resources you actually use to process. This flexibility makes it easier to scale your operations as demand fluctuates, ensuring that you’re not overpaying for unused capacity. By using [Aspose.PDF for AWS](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo), your organization can efficiently manage document workflows, adjust quickly to changing needs.\n\n## Pricing\n\nOur [pricing model](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo#pdp-pricing) offers a competitive and flexible structure based on the number of files processed within the same [S3 bucket](https://aws.amazon.com/s3/) of the account. The pricing is divided into tiers to accommodate various usage levels:\n\n**Tier 1:**      0 to 8,000 Files      $0.10\n\n**Tier 2:**      Next 80,000 Files     $0.02\n\n**Tier 3:**:     Next 160,000 Files    $0.01\n\n**Tier 4:**      Next 800,000 Files    $0.005\n\n**Tier 5:**      Any additional Files  $0.0002\n\nThis tiered pricing structure ensures that as your usage scales, the cost per file decreases, providing better value for higher volumes of processed files.\n\n\u003e __Units Usage Monitoring__\n\nOn the title page of the running container, you can view the count of processed files for the current hour in property 'Counter' and the total number of files processed across all containers for the same S3 bucket in property 'Total' and 'Tier'. This allows for real-time monitoring and better management of your file processing activities.\n\n\n## Getting Started with Aspose.PDF for AWS\n\nTo effectively manipulate PDF and other document formats using an API, follow this tutorial on [Aspose.PDF for AWS](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo). This guide will take you through setting up your environment, initializing the API, and executing various document manipulations. By the end of this tutorial, you will be proficient in using Aspose.PDF for AWS for all your document handling needs.\n\n\n### Reporting Issues\n\nIf you encounter any issues while using our API, report them to ensure they get resolved efficiently. Contact our support team on [forum](https://forum.aspose.com/) and provide detailed information about the problem, including any error messages received. This will help the support team diagnose and resolve your issue more effectively, ensuring a smoother experience with the API.\n\n- To find is processing failed you need to check 'statusCode' field of status JSON. Errored processing has status 500, in progress 204 and success has 200.\n- Error message is located in filed 'status'.\n- Details of error is located in filed \"errorCallStack\". The details is encoded and Aspose team will use it to help with issue.\n\nExample of processing response you can send with you issue\n```json\n{\n  \"statusCode\": 500,\n  \"status\": \"An error occurred trying to start process 'wkhtmltopdf' with working directory 'c:\\\\tempOutput\\\\6c821598-bccf-4ff6-9e06-9841ddf5aec6\\\\52fd9f2b-7dab-46a0-8a64-049d359210f7'. The system cannot find the file specified.\",\n  \"text\": null,\n  \"locked\": false,\n  \"updated\": null,\n  \"sharedFiles\": [],\n  \"fileProcessingErrorCode\": \"OK\",\n  \"fileCount\": 0,\n  \"fileName\": null,\n  \"folderName\": \"7bfd00d8-edab-4bfd-9688-a0cfef43d0e2\",\n  \"resultData\": null,\n  \"appInstanceId\": \"Aspose.PDF for AWS_a7ec362f-0300-4e0f-9673-e9d687450f1c\",\n  \"errorCallStack\": \"System.ComponentModel.Win32Exception (2): An error occurred trying to start process...\"\n}\n```\n\n### Steps\n\nThe following steps will guide you through the process of using our API:\n\n1. **Send a Document or Image:** Initiate the process by sending a document or image file via a POST request with the necessary query parameters to set up processing.\n\n2. **Check the processing Status:** After sending the POST request, check the status of the file conversion process by making a POST request with the folder name received in the upload response.\n\n3. **Download the Converted File:** Once the file processed, download the converted file using a GET request with the folder name received in the upload response.\n\n\n\n### Using Swagger UI\n\n[Swagger](https://swagger.io/) is a powerful tool for interacting with RESTful APIs. It provides a user-friendly interface that allows you to visualize and test the endpoints of your API without writing any additional code. This guide will walk you through the basics of using [Swagger UI](https://swagger.io/tools/swagger-ui/) to understand and interact with a Aspose.PDF for AWS from browser.\n\nSwagger UI is an open-source tool that allows you to interact with API through a web interface. Swagger UI can be accessed in several ways:\n\nAspose.PDF APIs provide a Swagger UI interface that you can access through a URL.\n\n**Accessing Swagger UI**\nLet's assume you have deployed Aspose.PDF for AWS container running at `http://127.0.0.1`. The Swagger UI for this API can be accessible at `http://127.0.0.1/swagger`.\n\nWhen you open Swagger UI, you will see several sections:\n- **Header:** Contains the API title, description, and version information.\n- **Servers:** Lists the base URLs where the API is available.\n- **Paths:** Shows the available endpoints (also called paths) of the API.\n- **Schemas:** Defines the data models used by the API.\n\n\u003e __Exploring Endpoints__\n\nEach endpoint is represented by a section that shows:\n- **HTTP Method:** The type of request (GET, POST, PUT, DELETE, etc.).\n- **Endpoint URL:** The path of the endpoint.\n- **Description:** A brief explanation of what the endpoint does.\n- **Parameters:** The inputs required for the request (query parameters, path parameters, headers, body, etc.).\n- **Responses:** The possible responses from the API, including status codes and example responses.\n\n**Example: Exploring an Endpoint**\n\nLet's explore a `POST /pdf/webapi/searchable` endpoint:\n1. Locate the `GET /pdf/webapi/searchable` endpoint in the Paths section.\n2. Click on the endpoint to expand it.\n3. You will see the description, parameters (if any), and responses for this endpoint.\n\nSwagger UI allows you to make requests directly from the interface:\n1. Expand the endpoint you want to test.\n2. Fill in any required parameters or request body fields.\n3. Add files to process with form data\n4. Click the \"Try it out\" button.\n5. Click the \"Execute\" button to send the request.\n\n\u003e __Viewing Response__\n\nAfter you execute a request, you will see the response from the server, including:\n- **Status Code:** Indicates the result of the request (e.g., 200 for success, 404 for not found).\n- **Response Body:** The data returned by the server in JSON format.\n- **Headers:** Metadata about the response.\n\n**Example: Testing a `POST /pdf/webapi/searchable` Endpoint**\n\n1. Locate and expand the `POST /pdf/webapi/searchable` endpoint.\n2. Click the \"Try it out\" button.\n3. Fill in the parameters language 'eng'.\n4. Add scanned pdf document to files in request body.\n5. Click the \"Execute\" button.\n6. View the response to see if the user was successfully created.\n\n**Example: Testing a `POST /pdf/webapi/searchable` Endpoint**\n\n1. Locate and expand the `POST /pdf/webapi/searchable` endpoint.\n2. Click the \"Try it out\" button.\n3. Fill in the parameter language \"eng\".\n4. Add scanned pdf document to files in request body.\n5. Click the \"Execute\" button.\n6. View the response to see if the processing was successfully created.\n7. In the response body JSON find \"folderName\", for example \"8550017d-6bba-428e-b641-25d8aeb16372\"\n\n**Testing a `GET /pdf/webapi/status` processing status**\n\n1. Locate and expand the `GET /pdf/webapi/status/{0}` endpoint.\n2. Click the \"Try it out\" button.\n3. Fill in the parameter id with folder name \"8550017d-6bba-428e-b641-25d8aeb16372\".\n4. Click the \"Execute\" button.\n5. View the response to see if the processing was successfully finished \"statusCode\": 200.\n7. In the response body JSON find  \"fileName\": \"Searchable_test.pdf\"\n\n**Download a `GET /pdf/webapi/download/{0}` processed document**\n\n1. Locate and expand the `GET /pdf/webapi/status` endpoint.\n2. Click the \"Try it out\" button.\n3. Fill in the parameter id with folder name \"8550017d-6bba-428e-b641-25d8aeb16372\".\n4. Fill in the parameter file with processed file name \"Searchable_test.pdf\"\n5. Click the \"Execute\" button.\n6. View the response link to download and Click to save the file.\n\nSwagger UI is a valuable tool for anyone working with RESTful APIs. It simplifies the process of exploring, understanding, and testing your API endpoints. By following this guide, you should be able to effectively use Swagger UI to interact with your API and enhance your development workflow.\n\n\n### Conversion PDF to DOCX example\n\nBy following these steps, you can successfully send, monitor, and retrieve converted files using the [Aspose.PDF AWS](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo)\n\n1. **Send a Document for Conversion**\n```bash\ncurl -X POST 'http://localhost/pdf/webapi/convert?inputType=pdf\u0026outputType=docx' -F 'files=@test.pdf'\n```\nResponse:\n```json\n{\n  \"statusCode\": 204,\n  \"status\": \"Processing\",\n  \"text\": null,\n  \"locked\": false,\n  \"updated\": null,\n  \"sharedFiles\": [],\n  \"files\": null,\n  \"fileProcessingErrorCode\": \"OK\",\n  \"fileCount\": 0,\n  \"fileName\": \"processing.pdf\",\n  \"folderName\": \"7088936f-bcf4-40b9-a06f-d7ca21f3f33e\",\n  \"resultData\": null,\n  \"appInstanceId\": \"Aspose Pdf Rest.API_05bfc9e8-2486-4a88-9c3d-58999e4f66d8\"\n}\n```\n\nResponse description:\n- **StatusCode:** 204 - The request has been successfully received, and file processing is initiated.\n- **Status:** A string indicating the status of the request. In this case, it is \"Processing\".\n- **Locked:** A boolean indicating whether the file is locked or not. In this case, it is false.\n- **FileProcessingErrorCode:** Custom error responses, this time is \"OK\", indicating no error.\n- **FolderName:** Unique identifier for the folder where the file is being processed.\n- **AppInstanceId:** A unique identifier for the application instance that processed the file. In this case, it is \"Aspose Pdf Rest.API_05bfc9e8-2486-4a88-9c3d-58999e4f66d8\".\n\n2. **Check the Status of File Conversion using folder name**\n```bash\ncurl -X POST 'http://localhost/pdf/webapi/status/7088936f-bcf4-40b9-a06f-d7ca21f3f33e'\n```\nResponse:\n```json\n{\n  \"statusCode\": 204,\n  \"status\": \"Processing\",\n  \"text\": null,\n  \"locked\": false,\n  \"updated\": null,\n  \"sharedFiles\": [],\n  \"files\": null,\n  \"fileProcessingErrorCode\": \"OK\",\n  \"fileCount\": 0,\n  \"fileName\": \"processing.pdf\",\n  \"folderName\": \"7088936f-bcf4-40b9-a06f-d7ca21f3f33e\",\n  \"resultData\": null,\n  \"appInstanceId\": null\n}\n```\n\nResponse description:\n- **StatusCode:** 200 - The request has been successfully received, and the response contains the requested data.\n- **Status:** A string indicating the status of the request. In this case, it is \"Complete\", indicating that the file conversion process has completed successfully.\n- **SharedFiles:** An array of shared files. In this case, it contains a single object with details about the converted file.\n- **FileProcessingErrorCode:** Custom error responses, this time is \"OK\", indicating no error.\n- **FileCount:** The number of files being processed. In this case, it is 1.\n- **FileName:** The name of the file being processed. In this case, it is \"test.docx\".\n- **FolderName:** A unique identifier for the folder where the file is being processed.\n\n3. **Receive error of processing.**\n```bash\ncurl -X POST 'http://localhost/pdf/webapi/status/7088936f-bcf4-40b9-a06f-d7ca21f3f33e'\n```\nResponse:\n```json\n{\n  \"statusCode\": 500,\n  \"status\": \"Incorrect file header\",\n  \"text\": null,\n  \"locked\": false,\n  \"updated\": null,\n  \"sharedFiles\": [],\n  \"files\": null,\n  \"fileProcessingErrorCode\": \"OK\",\n  \"fileCount\": 0,\n  \"fileName\": \"test.docx\",\n  \"folderName\": \"4beee097-d297-4e7e-ab08-6ab79ad111d2\",\n  \"resultData\": null,\n  \"appInstanceId\": \"Aspose Pdf Rest.API_05bfc9e8-2486-4a88-9c3d-58999e4f66d8\"\n}\n```\n\nResponse description:\n- **StatusCode:** The HTTP status code of the response. A status code of 500 indicates that there was an internal server error.\n- **Status:** A string indicating the status of the request. In this case, it is \"Incorrect file header\", indicating that there was an error with the file header during the file conversion process.\n- **FolderName:** A unique identifier for the folder where the file is being processed.\n\n4. **Download processed file using folder name and file name.**\n```bash\ncurl -X GET 'http://localhost/pdf/webapi/download/7088936f-bcf4-40b9-a06f-d7ca21f3f33e?file=test.docx' \u003e test.docx\n```\n\nResponse description:\nProvides stream that can be saved to file.\n\n\n\n### Error Handling\n\nIn the event of an error occurring during the processing of files, our system provides detailed error information to help diagnose and resolve issues efficiently.\n\nWhen an error occurs, the response will include an `ErrorCallStack` field. This field contains call stack information about the error and should be sent to our support team to assist in troubleshooting the issue.\n\n**Example Response with ErrorCallStack:**\n\n```json\n{\n  \"StatusCode\" : 500,\n  \"status\": \"error message\",\n  \"ErrorCallStack\": \"example error call stack details...\"\n}\n```\n\nPlease include the ErrorCallStack field in your communication with our support team.\n\nTo facilitate a quicker resolution, it is also beneficial to provide an example of the file that caused the error. This will help our team understand the context and specifics of the issue.\n\nWe do not encrypt customer data during processing. We do not have access to your customer data.\nObfuscation of call stack techniques are used to ensure data security of our code.\nBy including both the ErrorCallStack and an example of the file that caused the error, our [support team](https://forum.aspose.com/) can better assist you in resolving the issue efficiently.\n\n## Installation\n\nDeploying Aspose.PDF for AWS Marketplace container product with a [RESTful API](https://dotnet.microsoft.com/en-us/apps/aspnet/apis) requires a scalable and reliable setup using ECS of EKS.\nAmazon Elastic Container Service [ECS](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/Welcome.html) and Amazon Elastic Kubernetes Service [EKS](https://docs.aws.amazon.com/eks/latest/userguide/what-is-eks.html) are provided options, each suited for different needs.\n\n\u003e __When to Use ECS__\n\n- **Simplicity and Integration:** If you want a straightforward deployment with minimal management and deep integration with other AWS services, ECS is the best choice. \nIt handles scaling and operations, letting you focus on your application.\n\n\u003e __When to Use EKS__\n\n- **Advanced Configurations:** If your application needs complex configurations or you’re already using Kubernetes, EKS provides the flexibility and features you need.\nIt’s ideal for hybrid or multi-cloud environments and leverages the full Kubernetes ecosystem.\n\nBoth ECS and EKS offer robust scaling. \nECS uses AWS [Auto Scaling](https://docs.aws.amazon.com/whitepapers/latest/containers-on-aws/scaling.html) for effortless scaling. \nEKS leverages Kubernetes' built-in [scaling](https://docs.aws.amazon.com/eks/latest/userguide/autoscaling.html) features. \nSince the application processes tasks independently on each node, both services can efficiently handle increased demand.\n\nChoose ECS for simplicity and integration, and EKS for advanced configurations and flexibility. \nBoth ensure your application scales reliably and performs well.\n\n### Creating an AWS S3 Bucket\n\nThis guide walks you through creating a new [Amazon S3 bucket](https://aws.amazon.com/s3/) and setting up an [IAM user](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users.html) with permissions to access the bucket with Aspose.PDF for AWS to store processed files. These steps ensure secure and controlled access to your S3 resources.\n\n\u003e __Prerequisites__\n\n- An AWS account with sufficient permissions to create S3 buckets and IAM users.\n- Access to the AWS Management Console.\n\n\u003e __Step 1: Create a New S3 Bucket__\n\n1. **Log in to the AWS Management Console:**\n   - Navigate to the [AWS Management Console](https://aws.amazon.com/console/).\n   - Sign in with your AWS credentials.\n\n2. **Go to the S3 Service:**\n   - In the search bar, type \"S3\" and select **Amazon S3** from the list.\n\n3. **Create a New Bucket:**\n   - Click on the **Create bucket** button.\n   - Enter a unique name for your bucket in the **Bucket name** field (e.g., `my-new-bucket-123`).\n   - Choose the AWS region where the bucket should be created.\n\n4. **Configure Bucket Settings:**\n   - **Object Ownership:** Choose whether the bucket will use ACLs (default) or bucket owner enforced settings.\n   - **Block Public Access Settings:** Configure the bucket’s public access settings. It's recommended to block all public access unless needed.\n   - **Bucket Versioning:** Decide if you want to enable versioning (optional).\n   - **Tags:** Add tags to the bucket if necessary.\n   - **Default Encryption:** You can enable default encryption for all objects stored in the bucket.\n   - **Advanced Settings:** Configure other settings as required (e.g., logging, Object Lock).\n\n5. **Create the Bucket:**\n   - Once all settings are configured, click **Create bucket**.\n\nIn result, a new S3 bucket is created and ready for use.\n\n\u003e __Step 2: Create an IAM User for S3 Bucket Access__\n\n1. **Go to the IAM Service:**\n   - In the AWS Management Console, search for \"IAM\" and select **IAM** from the list.\n\n2. **Create a New User:**\n   - Click on **Users** in the left-hand menu, then click **Add users**.\n   - Enter a username (e.g., `aspose-pdf-user`).\n   - Select the **Access key - Programmatic access** option to generate an access key for this user.\n\n3. **Set Permissions for the User:**\n   - On the **Set permissions** page, choose **Attach policies directly**.\n   - Search for and select the **AmazonS3FullAccess** policy to give the user full access to S3.\n   - If you need more granular access, you can create a custom policy instead (see below).\n\n4. **Review and Create the User:**\n   - Review the settings and click **Create user**.\n   - Make sure to download or securely store the user’s access key ID and secret access key, as you will not be able to view the secret key again.\n\nIn result, an IAM user with programmatic access to S3 is created.\n\n\u003e __Step 3: (Optional) Create a Custom IAM Policy for Specific S3 Access__\n\nIf you need to grant more specific access to the S3 bucket, create a custom [IAM policy](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html).\n\n1. **Go to the IAM Policies Section:**\n   - In the IAM console, click on **Policies** in the left-hand menu, then click **Create policy**.\n\n2. **Write a Custom Policy:**\n   - In the JSON tab, paste the following JSON code, replacing `my-new-bucket-123` with your bucket name:\n\n```json\n   {\n     \"Version\": \"2012-10-17\",\n     \"Statement\": [\n       {\n         \"Effect\": \"Allow\",\n         \"Action\": [\n           \"s3:ListBucket\"\n         ],\n         \"Resource\": [\n           \"arn:aws:s3:::my-new-bucket-123\"\n         ]\n       },\n       {\n         \"Effect\": \"Allow\",\n         \"Action\": [\n           \"s3:PutObject\",\n           \"s3:GetObject\",\n           \"s3:DeleteObject\"\n         ],\n         \"Resource\": [\n           \"arn:aws:s3:::my-new-bucket-123/*\"\n         ]\n       }\n     ]\n   }\n```\n\nThis policy allows the user to list objects in the bucket and perform PutObject, GetObject, and DeleteObject actions on objects within the specified bucket.\n\nAttach the Policy to the User:\n\nAfter creating the policy, go to the IAM user you created, and [attach this custom policy](https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_managed-policies.html) to them.\n\nIn result, the IAM user now has specific access to the S3 bucket according to the custom policy.\n\n\u003e __Step 4: Test the IAM User Access__\n\nUse the AWS CLI or SDK:\n\nTest the IAM user's access to the S3 bucket using the AWS CLI or any AWS SDK by configuring the CLI with the user's access key and secret key.\n\nExample CLI command to upload a file:\n\n```bash\naws s3 cp myfile.txt s3://my-new-bucket-123/myfile.txt\n```\n\n**Verify Permissions:**\n\nEnsure the IAM user can perform the expected actions (e.g., uploading, listing, or deleting objects) and that permissions are working as intended.\nIn result, the IAM user is verified to have the correct access to the S3 bucket.\n\n### Setup Container\n\n\u003e __Configuration__\n\nOur RESTful API is designed to process documents efficiently and securely on the AWS platform. To achieve this, we need to manage sensitive information and optimize performance across various deployment environments.\n\nThe task at hand is to ensure that our API is secure, scalable, and robust while simplifying deployment and maintenance processes. This involves configuring environment variables to handle sensitive data, control resource utilization, and enhance overall system stability.\n\nTo address these challenges, we have implemented the following environment variables to configure:\n\n1. **Storage configuration**:\n   - **AWS_ACCESS_KEY** and **AWS_SECRET**: Stored in environment variables of container definition to grant access to AWS S3 storage for input and output files.\n   - **AWS_BUCKET** and **AWS_REGION**: AWS S3 storage name and region\n   \n2. **Performance and Scalability**:\n   - **MAX_BATCH_SIZE** and **MAX_BATCH_FILES**: Set to control the load on the API, preventing resource overload and maintaining consistent performance.\n   \n3. **Robustness and Reliability**:\n   - **COMPlus_GCHeapHardLimit**: Managed to control memory usage, preventing memory leaks and ensuring system stability under varying workloads.\n   - **OMP_THREAD_LIMIT**: Set the maximum number of threads for Tesseract OCR.\n\n4. **Security**\n   - **KEY_ENCRYPTION**: Enable AWS Key Management Service for AWS S3 environment variables\n   - **DISABLE_UNMANAGED_PROCESS**: Disallow external linux utils execution from the managed Aspose.DF for AWS product.\n   \nEnvironment variables are configured separately for each deployment environment (development, staging, production), streamlining the deployment process and simplifying configuration updates without altering the core application code.\n\n\n### Environment Variables\n\n**AWS_ACCESS_KEY**\n\nOutput storage key.\n\n**Required**\n\n\nTo store input and output files in an S3 bucket, you need an AWS access key. Ensure that you configure your environment with the correct AWS_ACCESS_KEY. If you work in different environments, you might need to change this value accordingly. By setting the appropriate access key, you will be able to store and retrieve files from your designated S3 bucket, ensuring smooth operation.\n\n\n**AWS_SECRET**\n\nOutput storage secret.\n\n**Required**\n\n\nTo store input and output files in an S3 bucket, you need an AWS secret key. Ensure that you configure your environment with the correct AWS_SECRET. If you work in different environments, you might need to change this value accordingly. By setting the appropriate secret key, you will be able to securely store and retrieve files from your designated S3 bucket, ensuring smooth and secure operations.\n\n\n**AWS_REGION_ENDPOINT**\n\nOutput storage region.\n\n**Required**\n\n\nTo store input and output files in an S3 bucket, you need to specify the correct AWS region. Ensure that you configure your environment with the appropriate AWS_REGION_ENDPOINT. If you work in different environments, you might need to change this value to switch between different regions. By setting the correct region endpoint, you will ensure that your files are stored and retrieved efficiently from the designated S3 region, optimizing performance and accessibility.\n\n\n**AWS_BUCKET**\n\nOutput storage backet.\n\n**Required**\n\n\nTo store input and output files in an S3 bucket, you need to specify the correct AWS_BUCKET. Ensure that you configure your environment with the appropriate bucket name. If you work in different environments, you might need to change this value to switch between different buckets. By setting the correct bucket, you will ensure that your files are stored and retrieved efficiently, enabling smooth operations across various environments.\n\n\n**TEMP_OUTPUT_DIRECTORY**\n\nPath temp files during processing.\n\n**Default Value:** ./tempOutput/\n\n\nSpecify the directory path for temporarily saving output files. All files in this directory will be removed after the results are saved to S3. Customize the TEMP_OUTPUT_DIRECTORY based on your application's requirements or environment setup. Changing this value might be necessary if you need to store output files in a different location or organize them differently, ensuring efficient file management during processing.\n\n\n**MAX_BATCH_SIZE**\n\nMax batch size.\n\n**Default Value:** 52428800\n\n\nSpecify the maximum total file size for batch processing in bytes. Adjusting the MAX_BATCH_SIZE can optimize batch processing performance and resource utilization. Change this value if you encounter performance issues with large files or need to limit resource usage, ensuring efficient and effective batch processing.\n\n\n**MAX_BATCH_FILES**\n\nMax files count in batch for processing.\n\n**Default Value:** 50\n\n\nSpecify the default number of files in a batch for processing. Adjusting the MAX_BATCH_FILES can optimize processing efficiency and resource usage. Change this value if you encounter performance issues with large batches or need to customize batch processing based on your workload, ensuring smooth and efficient batch processing.\n\n\n**MAX_INFLIGHT**\n\nMaximum number of tasks processed in parallel.\n\n**Default Value:** 10\n\n\nDefine the maximum number of tasks that can be processed simultaneously. If the number of tasks exceeds this value, additional tasks will wait in the queue until resources become available. Adjusting the MAX_INFLIGHT setting helps manage resource utilization and can improve system stability and performance. Increase this value to allow more parallel processing if your system can handle the load, or decrease it if you need to limit concurrent processing to avoid overloading resources.\n\n\n**OMP_THREAD_LIMIT**\n\nThis option useful for use with searchable pdf endpoint and Tesseract.\n\n**Default Value:** 1\n\n\nSet the number of threads for Tesseract to optimize performance. Adjusting the OMP_THREAD_LIMIT can improve processing efficiency based on your system resources and workload. Change this value if you encounter performance issues or need to optimize resource utilization, ensuring better performance and more efficient processing.\n\n\n**COMPlus_GCHeapHardLimit**\n\nIs for out of memory error message instead of reboot container in Kubernetes on exit memory limits.\n\n**Default Value:** 1800000000\n\n\nSet the GC heap hard limit for the .NET runtime in bytes to manage memory usage effectively. Adjusting the COMPlus_GCHeapHardLimit can help prevent avoid unnecessary container restarts in Kubernetes but large files will throws out-of-memory (OOM) errors. Change this value if you encounter OOM issues or need to fine-tune memory allocation to better suit your application's needs.\n| Instance Size   | Memory (GiB) | COMPlus_GCHeapHardLimit (85%) |\n|-----------------|--------------|-------------------------------|\n| medium      | 4                | 3652979000        |\n| large       | 8                | 7449801000        |\n| xlarge      | 16               | 14818270000       |\n| 2xlarge     | 32               | 28547688000       |\n| 4xlarge     | 64               | 73057954000       |\n| 8xlarge     | 128              | 149407489000      |\n| 12xlarge    | 192              | 109951163000      |\n| 16xlarge    | 256              | 1482827000000     |\n| metal       | 256              | 1482827000000     |\n\n\n**DISABLE_UNMANAGED_PROCESS**\n\nThis option allows you to disallow external process execution from the managed .NET application.\n\n**Default Value:** no\n\n\nYou are managing a .NET application that might need to execute external processes, but for security or performance reasons, you want to control or prevent this behavior. To address this, you need to configure the DISABLE_UNMANAGED_PROCESS option to restrict or permit the execution of external processes from the application. If you want to allow the execution of external processes, set the value to \"no\", which is the default. By setting the DISABLE_UNMANAGED_PROCESS option to \"yes\", you disable formats that nos sported by Aspose.PDF library.\n\n**KEY_ENCRYPTION**\n\nIn case it set to 'true', then enables KMS encryption for environment variables AWS_ACCESS_KEY, AWS_SECRET, AWS_REGION_ENDPOINT, AWS_BUCKET.\n\n**Default Value:** false\n\n\nYou are managing implementing KMS store for sensitive environment variables and need to enable it for Aspose.PDF for AWS.\n\n\n\n### Deploy Container on Amazon ECS\n\nThis guide provides step-by-step instructions on how to obtain an AWS Marketplace container and set it up in Amazon ECS with environment variables configured and using a host network on a public subnet.\n\n\u003e __Prerequisites__\n\n- Subscribe to [Aspose Pdf for AWS product](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo).\n- Select the latest version of the product to obtain link to container in Elastic Container Registry \n\n\u003e __1. Obtain the AWS Marketplace Container repository url__\n\nLogin to AWS Marketplace:\n\n- Navigate to the [AWS Marketplace](https://aws.amazon.com/marketplace/).\n- Search for [Aspose.PDF for AWS](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo) container product.\n- Click on the container product and subscribe to it.\n\nView Product in Amazon ECR:\n\nOnce subscribed, repository url to the container image will be available as instruction on summary page:\n\naws ecr get-login-password --region \u003cregion\u003e | docker login --username AWS --password-stdin \u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com\ndocker pull \u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e\n\nwhere '\u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e' is a Aspose.PDF for AWS container url. \n\n\u003e __2. Set Up ECS Cluster__\n\nCreate an ECS Cluster:\n\n- Go to the [Amazon ECS console](https://console.aws.amazon.com/ecs).\n- Choose Clusters from the left-hand navigation pane and click Create Cluster.\n- Select EC2 Linux + Networking as the cluster template.\n\nConfigure the cluster:\n\n- Choose an instance type (e.g., t3.large, m5.xLarge).\n- Select your desired VPC and subnets.\n\n**Only for test purpose** you can ensure the subnets are public to allow external access.\nTo allow public internet access you need to configure the Security Group.\nAdd inbound rules to the security group associated with the cluster instances:\n\n- Allow HTTP/HTTPS traffic (ports 80/443).\n- Ensure the security group allows traffic from your desired IP range (e.g., 0.0.0.0/0 for public access).\n\n\u003e __3. Create Task Definition__\n\nTask definition allows to deploy Aspose.PDF for AWS container for ECS cluster.\nTo define the Task:\n\n- In the ECS console, go to Task Definitions and click Create new Task Definition.\n- Choose EC2 as the launch type compatibility.\n\nConfigure the task:\n\n- Set a task role if needed for accessing other AWS services.\n- Define the task memory and CPU, usually xLarge EC2 instance will handle batch file processing quickly.\n\nAdd Container:\n\n- Under Container Definitions, click Add container.\n- Set the container name to 'aspose_pdf' for example\n- Enter repository url from subscribed summary: '\u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e'\n- Set the 80 Port mappings to map container ports to the host.\n- Set the Networking mode to host to use the host network.\n\nConfigure Environment Variables:\n\n- Scroll down to the Environment section.\n- Add the AWS S3 environment variables you need for the container to operate correctly.\n\t* AWS_ACCESS_KEY - IAM access key allowed to access S3 bucket.\n\t* AWS_SECRET - IAM access secret\n\t* AWS_BUCKET - your bucket to store processed files\n\t* AWS_REGION_ENDPOINT - your preferred region\n- Add optional environment variable to limit memory allocation for Restful API to do not reboot container.\n\t* [COMPlus_GCHeapHardLimit](https://learn.microsoft.com/en-us/dotnet/core/runtime-config/garbage-collector) - This soft limit allow to stop process to allocate memory bigger then available in cluster setup. Hexadecimal value, the maximum commit size, in bytes, for the GC heap and GC bookkeeping.\n\nLog Configuration:\n\n- Configure logging to [Amazon CloudWatch](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/WhatIsCloudWatch.html) if desired by specifying a log group and stream.\n\n\u003e __4. Run the Task__\n\nDeploy the Task in the ECS Cluster:\n\n- Go to the Clusters section in the ECS console.\n- Select your cluster, then choose Tasks and click Run new Task.\n- Select the task definition created earlier.\n- Choose the host network mode.\n- **Only for test** Ensure to select the appropriate public subnet(s) in the VPC.\n- Click Run Task.\n\nVerify the Task:\n\nOnce the task is running, you can check the logs and the status of the task from the ECS console.\nAccess the application using the public IP address of the EC2 instances in your cluster.\n\n\u003e __5. Test the Application__\n\nAccess the Application:\n\n\nOnce the stack is created, go to the outputs tab to find the link to the public IP. Access the web endpoint of the container solution and start using it.\nUsing this IP address or DNS of the EC2 instance, access your application via the browser or API client.\n**Access OpenAPI UI:** To discover the product API with OpenAPI UI, you need to use the `/swagger` route.\n\nMonitor and Troubleshoot:\n\nUse the ECS console to monitor task performance and troubleshoot any issues using logs and metrics.\n\n\u003e __6. Configure for production__\n\nConfigure security groups, IAM roles, and policies to control access to your ECS resources. Ensure that only authorized users and services can interact with the deployed container.\nRegularly update the container image to ensure security and performance. \n\n\n### Deploy Container on Amazon EKS\n\nThis guide outlines the steps to deploy an [Aspose.PDF for AWS](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo) AWS Marketplace container to Amazon Elastic Kubernetes Service [EKS](https://docs.aws.amazon.com/eks/latest/userguide/what-is-eks.html) using an EC2 instance from the client machine.\n\n\u003e __Prerequisites__\n\nSelect EKS as the delivery method. Retain the default software version setting and continue to launch.\n\n- Subscribe to [Aspose Pdf for AWS product](https://aws.amazon.com/marketplace/management/products/prod-u54zvr2umqvmo/overview).\n\nOnce subscribed, repository url to the container image will be available as instruction on summary page:\n\naws ecr get-login-password --region \u003cregion\u003e | docker login --username AWS --password-stdin \u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com\ndocker pull \u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e\n\nwhere '\u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e' is a Aspose.PDF for AWS container url. \n\n\u003e __1. Create a new deployment IAM user__\n\n- Go to the [AWS Management Console](https://aws.amazon.com/console/) and navigate to the [IAM](https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html) service.\n- Create a new user with AdministratorAccess policy.\n- Download the security credentials (Access Key ID and Secret Access Key) for the IAM user, as you'll need them in the next step.\n\n\u003e __2. Configure Linux Client Machine__\n\nInstall [AWS CLI](https://aws.amazon.com/cli/), [eksctl](https://eksctl.io/), and [kubectl](https://kubernetes.io/docs/reference/kubectl/):\n\n- Use the following user data script when launching the instance to automatically install the necessary tools:\n\n```bash\ncurl \"https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip\" -o \"awscliv2.zip\"\nsudo apt-get update\nsudo apt-get install unzip\nunzip awscliv2.zip\nsudo ./aws/install\ncurl --silent --location \"https://github.com/weaveworks/eksctl/releases/latest/download/eksctl_$(uname -s)_amd64.tar.gz\" | tar xz -C /tmp\nsudo mv /tmp/eksctl /usr/local/bin\ncurl -o kubectl https://amazon-eks.s3.us-west-2.amazonaws.com/1.21.2/2021-07-05/bin/linux/amd64/kubectl\nchmod +x ./kubectl\nsudo mv ./kubectl /usr/local/bin\n```\n\n- Verify the installation of the tools by running the following commands:\n\n```bash\naws --version\neksctl version\nkubectl version --short --client\n```\n\n- Configure the AWS CLI:\n\nRun **[aws configure](https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-configure.html)** and enter the IAM user credentials you created earlier.\n\n\u003e __3. Create an EKS Cluster__\n\nFor test purposes you need to create new EKS cluster or use existing staging environment for test deploy.\n\nUse eksctl to create an EKS cluster, run the following command to create the cluster:\n\n```bash\neksctl create cluster --name=mycluster \\\n                      --region=us-east-1 \\\n                      --zones=us-east-1a,us-east-1b \\\n                      --nodegroup-name mynodegroup \\\n                      --node-type=t3.xlarge \\ \n                      --nodes=2 \\  \n                      --nodes-min=2 \\\n                      --nodes-max=4 \\\n                      --managed\n```\n\n- **ECS Cluster Name:** The name of the ECS cluster where the product will be deployed.\n- **ECS Cluster Security Group:** The security group associated with the ECS cluster.\n- **Amazon VPC:** The Amazon Virtual Private Cloud (VPC) where the product will deploy.\n- **Subnets:** The subnets used by the ECS cluster.\n\nFor more information about eksctl, refer to the eksctl documentation.\n\n\u003e __4. Check Resources Created__\n\nThe eksctl create cluster command will create the following resources:\n\n- Custom VPC with public and private subnets.\n- EC2 instances and an Auto Scaling group.\n- CloudFormation stack.\n- EKS cluster and node group.\n\nThe cluster will have two worker nodes of type t3.xlarge, placed in the public subnet by default.\n\n\u003e __5. Check Created Kubeconfig__\n\nKubeconfig Setup:\n\n- The eksctl command automatically updates the kubeconfig file on the client machine.\n- The kubectl command uses this configuration to interact with the EKS cluster.\n- The kubeconfig file is located at $HOME/.kube/config and contains information about clusters, users, namespaces, and authentication mechanisms.\n\n\u003e __6. Deploy the Application__\n\nCreate a Kubernetes deployment and service:\n\nUpdate the deploy.yaml file with the appropriate container image URI from your AWS Marketplace container.\n\nExample deploy.yaml:\n\n```yaml\napiVersion: apps/v1\nkind: Deployment\nmetadata:\n  name: myaspose\nspec:\n  replicas: 2\n  selector:\n    matchLabels:\n      app: myaspose\n  template:\n    metadata:\n      labels:\n        app: myaspose\n    spec:\n      containers:\n        - name: myaspose\n          image: \u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e\n          ports:\n            - containerPort: 80\n          env:\n            - name: AWS_REGION_ENDPOINT\n              value: \"us-east-1\"\n            - name: AWS_ACCESS_KEY\n              value: \"\u003cmy key\u003e\"\n            - name: AWS_SECRET\n              value: \"\u003cmy secret\u003e\"\n            - name: AWS_BUCKET\n              value: \"\u003cmy bucket\u003e\"\n```\n\nExample of service.yaml:\n\n\n```yaml\napiVersion: v1\nkind: Service\nmetadata:\n  name: myasopseserv\nspec:\n  selector:\n    app: myasposepod\n  ports:\n    - protocol: TCP\n      port: 80\n  type: LoadBalancer\n```\n\nTo apply the deployment and service, run the following command to create the deployment, replica set, pod, and service:\n\n```bash\nkubectl apply -f deploy.yaml\n```\n\n\u003e __7. Verify the Deployment__\n\nUse the following commands to check the status of the deployment, replica set, pod, and service:\n\n```bash\nkubectl get deploy\nkubectl get rs\nkubectl get pod\nkubectl get svc\n```\n\nTo access the application, obtain the [Load Balancer DNS](https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/using-domain-names-with-elb.html) name from the service output and access it in your browser to view the application.\n\nOnce the stack is created, go to the outputs tab to find the link to the public IP. Access the web endpoint of the container solution and start using it.\n\n- **Http listening port:** To connect to the product API using HTTP, you need to use port 80.\n- **Https listening port:** To connect to the product API using HTTPS, you need to add a [certificate](https://learn.microsoft.com/en-us/aspnet/core/security/docker-https?view=aspnetcore-8.0).\n- **Access OpenAPI UI:** To discover the product API with OpenAPI UI, you need to use the `/swagger` route.\n\n\u003e __8. Delete the EKS Cluster after test__\n\nDelete the Kubernetes service:\n\nBefore deleting the cluster, manually delete the service or use the following command:\n\n```bash\nkubectl delete svc myasopseserv\n```\n\nDelete the EKS cluster using eksctl:\n\nRun the following command to delete the cluster and associated resources:\n\n```bash\neksctl delete cluster --name mycluster --region us-east-1\n```\n\nYou also need to delete instance of **[Elastic Cloud Balancer](https://aws.amazon.com/elasticloadbalancing/)**.\n\nAdhere to AWS security best practices by regularly updating Aspose.PDF for AWS container images, applying the latest security patches, and using IAM roles and policies to control access to your EKS resources. \nEncrypt sensitive data at rest and in transit, and regularly review and audit your security configurations to safeguard against potential threats.\n\n\n### Monitoring Health of Instance\n\nMonitoring the health of product ECS or EKS instances is essential for maintaining the reliability and performance of your applications. By leveraging [AWS CloudWatch Logs](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/WhatIsCloudWatchLogs.html), you can track the status and performance of the service, identify issues, and troubleshoot effectively:\n\n- An AWS account with the necessary permissions.\n- An cluster with one or more running Aspose.PDF for AWS services.\n- AWS CLI configured with your credentials.\n- CloudWatch Logs enabled for the service.\n\n**Steps to Monitor Aspose.PDF for AWS on ECS Using Logs:**\n\n\u003e __1. Create CloudWatch Log Group__\n\nCloudWatch Logs require a [log group](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/Working-with-log-groups-and-streams.html) to store log streams.\n\nTo create a CloudWatch log group for your ECS service logs:\n\n- Open the AWS Management Console and navigate to the CloudWatch section.\n- Select \"Logs\" from the sidebar and click on \"Create log group\".\n- Name the log group `/ecs/aspose_pdf` (matching the log configuration in the task definition).\n\nA CloudWatch log group is created to store ECS service logs.\n\n\u003e __2. Enable CloudWatch Logs for ECS Tasks__\n\n- Open the AWS Management Console and navigate to the ECS section.\n- Select your task definition and create a new revision.\n- In the \"Container Definitions\" section, add a log configuration.\n\n```json\n    \"logConfiguration\": {\n        \"logDriver\": \"awslogs\",\n        \"options\": {\n            \"awslogs-group\": \"/ecs/aspose_pdf\",\n            \"awslogs-region\": \"us-east-1\",\n            \"awslogs-stream-prefix\": \"ecs\"\n        }\n    }\n```\n\n- Save and update your task definition.\n\nYour ECS tasks are configured to send logs to CloudWatch Logs.\n\n\u003e __3. Update ECS Service to Use the New Task Definition__\n\nIn case the ECS service needs to use the updated task definition that includes CloudWatch Logs configuration:\n\n- Navigate to the ECS section in the AWS Management Console.\n- Select your ECS service and update it to use the latest task definition revision.\n- Deploy the updated service.\n\nThe ECS service is updated to use the new task definition with CloudWatch Logs enabled.\n\n\u003e __4. Access and Analyze ECS Service Logs__\n\nIn case you need to access and analyze the logs to monitor the health of your ECS service. Use CloudWatch Logs to view and analyze ECS service logs:\n\n- Open the AWS Management Console and navigate to the CloudWatch section.\n- Select \"Logs\" from the sidebar and find the log group `/ecs/aspose_pdf`.\n- Click on the log group to view log streams, which represent individual ECS tasks.\n- Click on a log stream to view the logs generated by a specific task.\n\nYou can access and analyze ECS service logs in CloudWatch Logs.\n\n\u003e __5. Set Up CloudWatch Alarms for ECS Service Logs__\n\nIn case you need to be alerted about potential issues with your ECS service. Create CloudWatch Alarms based on log metrics to monitor ECS service health:\n\n- In the CloudWatch section of the AWS Management Console, navigate to \"Alarms\".\n- Click \"Create Alarm\" and select \"Select metric\".\n- Choose \"Logs\" as the metric source and select the relevant log group `/ecs/aspose_pdf`.\n- Define a metric filter based on log patterns that indicate errors or issues.\n\n```json\n    {\n      \"filterPattern\": \"ERROR\",\n      \"metricName\": \"ErrorCount\",\n      \"metricNamespace\": \"ECS/Logs\"\n    }\n```\n\n- Set up the alarm with conditions such as threshold and period.\n- Configure notification actions, such as sending an email via Amazon SNS.\n\nCloudWatch Alarms are set up to monitor ECS service logs and notify you of potential issues.\n\n\u003e __6. Automate Log Analysis with CloudWatch Insights__\n\nFor analyzing large volumes of log data manually can be time-consuming. Use [CloudWatch Logs Insights](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CWL_QuerySyntax.html) to automate log analysis:\n\n- Open the AWS Management Console and navigate to the CloudWatch section.\n- Select \"Logs Insights\" from the sidebar.\n- Choose the log group `/ecs/aspose_pdf`.\n- Use query language to analyze logs. \n\nFor example, to find the count of error messages:\n\n```sql\n    fields @timestamp, @message\n    | filter @message like /ERROR/\n    | stats count() by bin(1m)\n```\n- Run the query to get insights into your ECS service logs.\n\nCloudWatch Logs Insights helps automate log analysis, providing quick insights into ECS service health.\n\n**Steps to Monitor Aspose.PDF for AWS on EKS Using Logs:**\n\n\u003e __1. Create CloudWatch Log Group__\n\nCloudWatch Logs require a log group to store log streams.\n\nTo create a CloudWatch log group for your EKS service logs:\n\n- Open the AWS Management Console and navigate to the CloudWatch section.\n- Select \"Logs\" from the sidebar and click on \"Create log group\".\n- Name the log group /eks/aspose-pdf-service (matching the log configuration in Fluent Bit).\n\nA CloudWatch log group is created to store EKS service logs.\n\n\u003e __2. Enable Fluent Bit for EKS Logging__\n\nTo centralize logs from your EKS cluster, use [Fluent Bit](https://fluentbit.io/) as a log router. Fluent Bit can collect logs from Kubernetes pods and send them to CloudWatch Logs.\n\n- Deploy Fluent Bit as a DaemonSet in your EKS cluster. Use the following YAML configuration:\n\n```yaml\napiVersion: apps/v1\nkind: DaemonSet\nmetadata:\n  name: fluent-bit\n  namespace: kube-system\nspec:\n  selector:\n    matchLabels:\n      k8s-app: fluent-bit-logging\n  template:\n    metadata:\n      labels:\n        k8s-app: fluent-bit-logging\n    spec:\n      containers:\n      - name: fluent-bit\n        image: amazon/aws-for-fluent-bit:latest\n        volumeMounts:\n        - name: varlog\n          mountPath: /var/log\n        - name: varlibdockercontainers\n          mountPath: /var/lib/docker/containers\n          readOnly: true\n      volumes:\n      - name: varlog\n        hostPath:\n          path: /var/log\n      - name: varlibdockercontainers\n        hostPath:\n          path: /var/lib/docker/containers\n```\n\nApply the configuration using kubectl:\n\n```sh\nkubectl apply -f fluent-bit-ds.yaml\n```\n\nFluent Bit is now deployed and collecting logs from your EKS cluster.\n\n\u003e __3. Configure Fluent Bit to Send Logs to CloudWatch__\n\nTo send logs to CloudWatch Logs, configure Fluent Bit with the appropriate output plugin.\n\nCreate a ConfigMap for Fluent Bit configuration:\n\n```yaml\napiVersion: v1\nkind: ConfigMap\nmetadata:\n  name: fluent-bit-config\n  namespace: kube-system\n  labels:\n    k8s-app: fluent-bit-logging\ndata:\n  fluent-bit.conf: |\n    [SERVICE]\n        Flush         1\n        Log_Level     info\n        Daemon        off\n        Parsers_File  parsers.conf\n\n    [INPUT]\n        Name              tail\n        Tag               kube.*\n        Path              /var/log/containers/*.log\n        Parser            docker\n        DB                /var/log/flb_kube.db\n        Mem_Buf_Limit     5MB\n        Skip_Long_Lines   On\n        Refresh_Interval  10\n\n    [FILTER]\n        Name                kubernetes\n        Match               kube.*\n        Kube_URL            https://kubernetes.default.svc:443\n        Kube_CA_File        /var/run/secrets/kubernetes.io/serviceaccount/ca.crt\n        Kube_Token_File     /var/run/secrets/kubernetes.io/serviceaccount/token\n        Kube_Tag_Prefix     kube.var.log.containers.\n        Merge_Log           On\n        Merge_Log_Key       log_processed\n        K8S-Logging.Parser  On\n        K8S-Logging.Exclude Off\n\n    [OUTPUT]\n        Name                cloudwatch_logs\n        Match               *\n        region              us-east-`\n        log_group_name      /eks/aspose_pdf\n        log_stream_prefix   eks-\n        auto_create_group   true\n```\n\nApply the ConfigMap using kubectl:\n\n```sh\nkubectl apply -f fluent-bit-config.yaml\n```\n\nFluent Bit is now configured to send logs to CloudWatch Logs.\n\n\u003e __4. Access and Analyze EKS Service Logs__\n\nTo access and analyze the logs to monitor the health of your EKS service, use CloudWatch Logs:\n\n- Open the AWS Management Console and navigate to the CloudWatch section.\n- Select \"Logs\" from the sidebar and find the log group /eks/aspose-pdf-service.\n- Click on the log group to view log streams, which represent individual EKS pods.\n- Click on a log stream to view the logs generated by a specific pod.\n\nYou can access and analyze EKS service logs in CloudWatch Logs.\n\n\u003e __5. Set Up CloudWatch Alarms for EKS Service Logs__\n\nTo be alerted about potential issues with your EKS service, create CloudWatch Alarms based on log metrics:\n- In the CloudWatch section of the AWS Management Console, navigate to \"Alarms\".\n- Click \"Create Alarm\" and select \"Select metric\".\n- Choose \"Logs\" as the metric source and select the relevant log group /eks/aspose-pdf-service.\n- Define a metric filter based on log patterns that indicate errors or issues.\n\n```json\n{\n  \"filterPattern\": \"ERROR\",\n  \"metricName\": \"ErrorCount\",\n  \"metricNamespace\": \"EKS/Logs\"\n}\n```\n\n- Set up the alarm with conditions such as threshold and period.\n- Configure notification actions, such as sending an email via Amazon SNS.\n\nCloudWatch Alarms are set up to monitor EKS service logs and notify you of potential issues.\n\n\u003e __6. Automate Log Analysis with CloudWatch Insights__\n\nFor analyzing large volumes of log data manually can be time-consuming. Use CloudWatch Logs Insights to automate log analysis:\n\n- Open the AWS Management Console and navigate to the CloudWatch section.\n- Select \"Logs Insights\" from the sidebar.\n- Choose the log group /eks/aspose_pdf\n- Use query language to analyze logs.\n\nFor example, to find the count of error messages:\n\n```sql\nfields @timestamp, @message\n| filter @message like /ERROR/\n| stats count() by bin(1m)\n```\n\nRun the query to get insights into your EKS service logs.\n\nCloudWatch Logs Insights helps automate log analysis, providing quick insights into EKS service health.\n\nThis guide describes for monitoring Aspose.PDF for AWS on Amazon EKS using logs, including steps to enable Fluent Bit, configure log forwarding, create CloudWatch log groups, access and analyze logs, set up alarms, and automate log analysis with CloudWatch Insights.\n\nMonitoring the health of Aspose.PDF for AWS service using logs is crucial for maintaining the reliability and performance of your applications. By enabling CloudWatch Logs, accessing and analyzing log data, setting up alarms, and using CloudWatch Logs Insights, you can effectively monitor and manage your ECS services, ensuring timely identification of issues.\n\n\n## Handling Sensitive Customer Information\n\nManaging sensitive customer information is critical in maintaining data security and compliance. Organizations need to ensure their document processing workflows are secure and protect customer data at every step.\n\nImplement a comprehensive approach to handle sensitive information securely within the Aspose.PDF for AWS RESTful API. This involves configuring ports, setting up HTTPS certificates, managing file inputs and outputs, and ensuring data is protected throughout the processing lifecycle.\n\nTo address these requirements, follow these guidelines:\n\n- Port Configuration: Ensure secure port changes to safeguard data transmission.\n- HTTPS Certificates: Set up HTTPS certificates for both development and production environments to encrypt data in transit.\n- File Handling: Use internal links to directly process files from customer S3 buckets, avoiding direct uploads via form data in the API.\n- S3 Folders: Organize input and output data in designated S3 folders, and use temporary working folders that are automatically deleted after processing.\n- Temporary Storage: Utilize EFS for temporary file storage to manage files securely during processing.\n- Folder Removal: Employ API calls for immediate S3 folder removal after processing and downloading to prevent unauthorized access.\n- Security Practices: Harden and secure customer S3 folders to protect data, and leverage AWS Key Management Service (KMS) for rotating secrets and environment variables to maintain secure operations.\n\nBy implementing these practices, organizations can effectively secure sensitive customer information throughout the document processing workflow. This approach ensures data integrity, compliance with security standards, and maintains customer trust.\n\n### Change Ports on ECS\n\nThis guide will help you modify and update ports for [Aspose.PDF for AWS](https://aws.amazon.com/marketplace/pp/prodview-zc64pent6p6lo) container deployed on Amazon ECS using task definitions. Proper port configuration ensures your applications run on the correct ports, maintaining consistency across different environments.\n\n\u003e __Step 1: Set Port Mappings in the Task Definition__\n\nIn the ECS task definition, navigate to the \"Container Definitions\" section where you define your container's settings. Here, you'll set the port mappings to ensure the container uses the correct ports.\n\n- Open the ECS Task Definition\n- Go to the ECS Console.\n- Choose your Task Definition.\n- Select the revision to update or create a new revision.\n- Edit the Container Definition\n- Under \"Container Definitions\", select the container you want to configure.\n- Scroll to the \"Port mappings\" section.\n- Define the Port Mappings\n- Container port: Enter the port on which your application listens inside the container (e.g., 80 or 8080).\n- Host port: Enter the port on the host machine that will forward traffic to the container (e.g., 8000).\n\nExample:\n\n```json\n\"portMappings\": [\n    {\n        \"containerPort\": 80,\n        \"hostPort\": 8000\n    }\n]\n```\n\n**Container port:** The port your application listens to within the container.\n**Host port:** The port on the ECS host that routes traffic to the container.\n\n\u003e __Step 2: Configure Environment Variables__\n\nNext, you'll need to set the necessary environment variables within the ECS task definition to ensure your ASP.NET application uses the correct ports.\n\n- Locate the Environment Variables Section\n- Within the same \"Container Definitions\" section, scroll down to the \"Environment variables\" section.\n- Add the environment variables ASPNETCORE_HTTP_PORTS, ASPNETCORE_HTTPS_PORTS, and ASPNETCORE_URLS to specify the desired ports.\n\nExample:\n\n```json\n\"environment\": [\n    {\n        \"name\": \"ASPNETCORE_HTTP_PORTS\",\n        \"value\": \"80\"\n    },\n    {\n        \"name\": \"ASPNETCORE_URLS\",\n        \"value\": \"http://*:80\"\n    }\n]\n\n```\n\n**ASPNETCORE_HTTP_PORTS:** Defines the HTTP port inside the container.\n**ASPNETCORE_URLS:** Configures the application to listen on the specified ports.\n\n\n\u003e __Step 3: Update Ports in the Task Definition__\n\nIf changing the default port (e.g., from 80 to 8080), ensure you update both the \"Port mappings\" and the \"Environment variables\" sections accordingly.\n\n- Change the containerPort and hostPort in the \"Port mappings\" section to the new port.\n\nExample:\n\n```json\n\"portMappings\": [\n    {\n        \"containerPort\": 8080,\n        \"hostPort\": 8000\n    }\n]\n```\n\n- Modify the ASPNETCORE_HTTP_PORTS and ASPNETCORE_URLS values to reflect the new port.\n\nExample:\n\n```json\n\"environment\": [\n    {\n        \"name\": \"ASPNETCORE_HTTP_PORTS\",\n        \"value\": \"8080\"\n    },\n    {\n        \"name\": \"ASPNETCORE_URLS\",\n        \"value\": \"http://*:8080\"\n    }\n]\n\n```\n\nConfiguring ports within your ECS task definition ensures that your Docker ASP.NET applications run on the desired ports. By properly setting the [Port mappings](https://docs.aws.amazon.com/AmazonECS/latest/APIReference/API_PortMapping.html) and \"Environment variables\" fields, you can maintain consistency and prevent port conflicts across different environments.\n\n### Changing Ports on EKS\n\nThis section guides you through modifying the ports used by Aspose.PDF for AWS deployed on Amazon EKS. Proper port configuration ensures the application listens on the correct ports within the Kubernetes cluster.\n\n\u003e __Step 1: Update Container Port in Deployment YAML__\n\nThe first step is to update the container port and set the necessary environment variables in your Kubernetes deployment YAML file.\n\n- Locate the Deployment YAML File\n- Open your Kubernetes deployment YAML file.\n- Modify the Container Port and Set Environment Variables\n- Under the spec section, find the containers field.\nUpdate the containerPort to the desired port number (e.g., from 80 to 8080).\n- Add the environment variables ASPNETCORE_HTTP_PORTS and ASPNETCORE_URLS to ensure the application listens on the correct ports.\n\nExample:\n\n```yaml\nspec:\n  containers:\n  - name: myaspose\n    image: \u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e\n    ports:\n    - containerPort: 8080\n    env:\n    - name: ASPNETCORE_HTTP_PORTS\n      value: \"8080\"\n    - name: ASPNETCORE_URLS\n      value: \"http://*:8080\"\n```\n\n**containerPort:** The port your application listens to inside the container.\n**ASPNETCORE_HTTP_PORTS:** Specifies the HTTP port inside the container.\n**ASPNETCORE_URLS:** Configures the application to listen on the specified port.\n\n\u003e __Step 2: Configure Service to Use New Port__\n\nEnsure that your Kubernetes service is configured to use the new port.\n\n- Locate the Service YAML File\n- Open your Kubernetes service YAML file associated with the deployment.\nUpdate the Target Port and Port:\n- Under the spec section, update the port and targetPort fields to the new port number.\nExample:\n\n```yaml\nspec:\n  ports:\n  - port: 80\n    targetPort: 8080\n```\n\nExplanation:\n\n**port:** The port exposed by the service.\n**targetPort:** The port that the service forwards traffic to inside the container.\n\n\u003e __Step 3: Modify Ingress Rules (If Applicable)__\n\nIf your application is exposed via an Ingress resource, update the Ingress rules to route traffic to the new port.\n\n- Locate the Ingress YAML File\n- Open the Ingress YAML file.\n- Update the Service Port\n- Under the rules section, find the service and update the servicePort to match the new service port.\n\nExample:\n\n```yaml\nspec:\n  rules:\n  - host: my-app.com\n    http:\n      paths:\n      - path: /\n        backend:\n          serviceName: my-app-service\n          servicePort: 80\n```\n\nExplanation:\n\n**servicePort:** The port that the Ingress controller directs traffic to in the service.\n\nBy updating the container port, service, and Ingress configuration, and setting the necessary environment variables, you ensure that your Docker ASP.NET application on EKS listens on the correct port, maintaining consistent access across your Kubernetes cluster.\n\nRefer to the official Kubernetes documentation for more detailed guidance on configuring ports and managing Kubernetes resources.\n\n### Setting Up HTTPS Certificate\n\nTo guide developers through the setup and configuration of HTTPS certificates for [ASP.NET](https://dotnet.microsoft.com/en-us/apps/aspnet) containers. This ensures secure communication and prevents potential security threats like person-in-the-middle attacks.\n\n\u003e __Step 1: Generate HTTPS Development Certificate__\n\nUse the following command to generate an HTTPS development certificate and export it to a specified path.\n\n```bash\ndotnet dev-certs https -ep ${HOME}/.aspnet/https/aspnetapp.pfx -p \u003cCREDENTIAL_PLACEHOLDER\u003e\n```\n\nExplanation:\n\n-ep ${HOME}/.aspnet/https/aspnetapp.pfx: Specifies the export path for the certificate.\n\n-p \u003cCREDENTIAL_PLACEHOLDER\u003e: Placeholder for the password to protect the certificate.\n\n\u003e __Step 2: Trust the HTTPS Development Certificate__\n\nRun the command to trust the generated development certificate on your machine.\n\n```bash\ndotnet dev-certs https --trust\n```\n\nExplanation:\n\nThis command adds the development certificate to the trusted certificate store on your machine.\n\n\u003e __Step 3: Pull the ASP.NET Sample Docker Image__\n\nPull the ASP.NET sample image from Microsoft's container registry.\n\n```bash\ndocker pull mcr.microsoft.com/dotnet/samples:aspnetapp\n```\n\nExplanation:\n\nThis command fetches the sample ASP.NET application image from the specified registry.\n\n\u003e __Step 4: Run the Docker Container with HTTPS Configuration__\n\nRun the Docker container with the necessary environment variables and volume mappings for HTTPS configuration.\n\n```bash\ndocker run --rm -it -p 8000:80 -p 8001:443 \\\n-e ASPNETCORE_URLS=\"https://+;http://+\" \\\n-e ASPNETCORE_HTTPS_PORTS=8001 \\\n-e ASPNETCORE_Kestrel__Certificates__Default__Password=\"\u003cCREDENTIAL_PLACEHOLDER\u003e\" \\\n-e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx \\\n-v ${HOME}/.aspnet/https:/https/ \\\nmcr.microsoft.com/dotnet/samples:aspnetapp\n```\n\nExplanation:\n\n--rm: Automatically remove the container when it exits.\n-it: Interactive terminal mode.\n-p 8000:80 -p 8001:443: Maps host ports 8000 and 8001 to container ports 80 and 443.\n\n-e ASPNETCORE_URLS=\"https://+;http://+\": Configures the application URLs.\n\n-e ASPNETCORE_HTTPS_PORTS=8001: Sets the HTTPS port.\n\n-e ASPNETCORE_Kestrel__Certificates__Default__Password=\"\u003cCREDENTIAL_PLACEHOLDER\u003e\": Provides the certificate password.\n\n-e ASPNETCORE_Kestrel__Certificates__Default__Path=/https/aspnetapp.pfx: Specifies the certificate path inside the container.\n\n-v ${HOME}/.aspnet/https:/https/: Maps the local certificate directory to the container.\n\n\u003e __Step 5: Update CA Certificates in Docker Container__\n\nIf you need to update the CA certificates in your Docker container, use the following command:\n\n```bash\ndocker run -v /host/path/to/certs:/container/path/to/certs -d IMAGE_ID \"update-ca-certificates\"\n```\n\nExplanation:\n\n-v /host/path/to/certs:/container/path/to/certs: Maps the host certificate directory to the container.\n\n-d IMAGE_ID: Runs the container in detached mode with the specified image ID.\n\n\"update-ca-certificates\": Command to update the CA certificates in the container.\n\nAdditional Resources:\n\n[SSL on Amazon Linux 2](https://docs.aws.amazon.com/linux/al2/ug/SSL-on-amazon-linux-2.html)\n\n[Certificate Signing on Amazon EKS](https://docs.aws.amazon.com/eks/latest/userguide/cert-signing.html)\n\n[End-to-End TLS Encryption on Amazon EKS](https://aws.amazon.com/blogs/containers/setting-up-end-to-end-tls-encryption-on-amazon-eks-with-the-new-aws-load-balancer-controller/)\n\n\u003e ___Security Recommendation___\n\nUse HTTPS (TLS) to ensure encrypted connections and protect against eavesdropping and network manipulation. Apply the aws:SecureTransport condition in your Amazon S3 bucket policies to enforce HTTPS-only connections.\nn in your Amazon S3 bucket policies to enforce HTTPS-only connections.\n\n\n### Document with Passwords\n\nYou may need to process [encrypted documents](https://docs.aspose.com/pdf/net/encrypt-pdf-file) through our containerized REST API, with support for various operations such as merging, converting, and splitting.\n\nTo ensure secure processing, a password is required to unlock encrypted documents before any operation.\n\nOur API supports the **documentPassword** form parameter across all endpoints, allowing you to specify the necessary password for your documents. In the current version, when submitting multiple documents in a single request, the same password must be used for all. If your documents have different passwords, you can achieve this by running multiple concurrent API calls, each handling one document at a time with its specific password.\n\nThis approach provides you with a secure and flexible way to process encrypted documents across all our REST API endpoints, ensuring that your operations run smoothly, whether you’re working with single or multiple documents.\n\n\n\n### File Uploads via External and Internal Links\n\nWhen working with various data sources, you often need a flexible approach to file management. Our RESTful API provides robust solutions for uploading files from external web links and internal S3 storage. Internal links are particularly useful for creating workflows, such as sending a file from one processing step (e.g., 'merge') to another (e.g., 'lock'), allowing for multiple operations on a document. Additionally, the API supports applying security measures like document locking, ensuring that you can effectively integrate, manage, and secure your files regardless of their source.\n\nUploading Files via External and Internal Links\nThe API supports uploading files from both external and internal sources. This capability allows you to handle files from diverse origins and manage them seamlessly within your application.\n\n\u003e __External Links__\n\n- Format: The URLs provided should be well-formed and follow the format specified by the inputFormat query parameter.\n- Form Data Key: Use unique keys that start with link_ to specify each external link. For example:\nlink_\u003cunique-identifier\u003e: URL of the external file.\n\n\u003e __Internal Links__\n\n- Format: Internal links should be formatted as {folderName}?file={fileName}.\n- Form Data Key: Use unique keys that start with link_ to specify each internal link. For example:\nlink_\u003cunique-identifier\u003e: URL of the internal S3 object.\n\n**Example** of Uploading Files\n\nExample of Document Locking from uploaded files, external url and internal link to S3 file.\n\n```sh\ncurl -X POST \"https://yourapiendpoint/pdf/webapi/lock?passw=yourpassword\" \\\n-H \"Content-Type: multipart/form-data\" \\\n-F \"files=@/path/to/document1.pdf\" \\\n-F \"files=@/path/to/additional_file.pdf\" \\\n-F \"link_1=https://example.com/file1.pdf\" \\\n-F \"link_2=feeba224-a78b-436c-bb2a-b515d3ed2369?file=file2.pdf\"\n```\n\nResponse:\n\n```json\n{\n  \"status\": \"Processing\",\n  \"folderName\": \"7088936f-bcf4-40b9-a06f-d7ca21f3f33e\"\n}\n```\n\n### AWS S3 File Storage Structure\n\n\u003e __Persistent storage__\n\n- **Input Documents:**\n  Input documents are stored in Amazon S3 in a folder named `in_\u003cfolder_id\u003e`, where `\u003cfolder_id\u003e` is the unique identifier for the folder.\n\n```sh\n  s3://your-bucket-name/in_\u003cfolder_id\u003e/\n```\n\n- **Output Documents:**\n\nOutput documents are stored in Amazon S3 in a folder named \u003cfolder_id\u003e.\n\n```sh\ns3://your-bucket-name/\u003cfolder_id\u003e/\n```\n\n\u003e __Temporary storage__\n\nThe application uses a temporary local directory for intermediate processing:\n\nTemporary Directory configured with **TEMP_OUTPUT_DIRECTORY** environment variable that have default path to /app/tempOutput/\n\nFiles in this directory are removed after processing to ensure efficient resource usage.\n\nRemark: For enhanced security, consider using encrypted file storage EFS for the temporary directory when running containers in ECS or EKS.\n\n\n\n### Using Encrypted File Storage\n\nTo use encrypted file storage for your temporary directory in Amazon ECS or EKS, follow these steps:\n\n\u003e __Amazon ECS__\n\n1. **Create an Amazon EFS [Elastic File System](https://docs.aws.amazon.com/efs/latest/ug/whatisefs.html):**\n   - Go to the [Amazon EFS console](https://aws.amazon.com/efs\n).\n   - Click on \"Create file system.\"\n   - Follow the steps to create a new file system. Ensure that you enable encryption at rest.\n\n2. **Mount the EFS to Your ECS Task:**\n   - In your ECS task definition, add a volume for the EFS.\n   - Specify the file system ID and the directory path you want to use.\n   - Update your container definition to mount the volume at the desired path (e.g., `/tempOutput/`).\n   - Update your container environment variable **TEMP_OUTPUT_DIRECTORY** to be `/tempOutput/`.\n\n\u003e __Amazon EKS__\n\n1. **Create an Amazon EFS (Elastic File System):**\n   - Go to the Amazon EFS console.\n   - Click on \"Create file system.\"\n   - Follow the steps to create a new file system. Ensure that you enable encryption at rest.\n\n2. **Install the Amazon EFS CSI Driver:**\n   - Follow the instructions in the [Amazon EFS CSI Driver documentation](https://docs.aws.amazon.com/eks/latest/userguide/efs-csi.html) to install the driver in your EKS cluster.\n\n3. **Create a Persistent Volume (PV) and Persistent Volume Claim (PVC):**\n   - Define a Persistent Volume (PV) that references your EFS.\n   - Create a Persistent Volume Claim (PVC) to request storage from the PV.\n\n4. **Mount the PVC to Your Pod:**\n   - In your Kubernetes pod definition, add a volume that references the PVC.\n   - Specify the mount path in the container (e.g., `/tempOutput/`).\n   - Update your container environment variable **TEMP_OUTPUT_DIRECTORY** to be `/tempOutput/`.\n\nBy following these steps, you can ensure that your temporary directory uses encrypted file storage, providing enhanced security for your data.\n\n\n### Immediate Remove of processed files\n\nThe [remove](/pdf/webapi/remove/{id}) endpoint in your RESTful API is crucial for ensuring data safety and proper data retention management. This endpoint allows for the immediate removal of processed files from storage, providing several key benefits:\n\n* Data Security: By enabling immediate deletion of files, sensitive information is promptly removed from storage, reducing the risk of unauthorized access or data breaches.\n* Compliance: Many regulations and industry standards require the timely deletion of data after processing. This endpoint helps ensure compliance with these legal and regulatory requirements.\n* Storage Management: Regular removal of unnecessary files helps in efficient storage management, preventing clutter and optimizing storage resources.\n* Performance Optimization: Keeping storage clean by removing outdated files can improve overall system performance, as the system can focus on managing active and relevant data.\n\ncURL Snippet:\n\n```sh\ncurl -X POST \"https://yourapiendpoint/remove/{id}\" \\\n-H \"Content-Type: application/json\" \\\n-d '{\"id\": \"your-folder-id\"}'\n```\n\nResponses:\n200: Returns a FileResponse object indicating that all files were successfully removed.\n400: Indicates the file does not exist or there was an error processing the request.\n500: Indicates a server error.\n\n\u003e __Other Methods for File Retention in AWS S3__\n\nIn addition to immediate removal, AWS S3 provides several other methods for managing file retention, ensuring data safety and compliance with retention policies:\n\nS3 Lifecycle Policies:\n\n* Automated Transition and Expiration: Define [S3 lifecycle rules](https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lifecycle-mgmt.html) to transition objects to different storage classes (e.g., from S3 Standard to S3 Glacier) or to expire objects after a specified period.\nCost Management: Helps reduce costs by automatically moving data to more cost-effective storage classes as it ages.\nObject Lock:\n\n* WORM (Write Once Read Many) Compliance: Enforces a write-once-read-many model, preventing objects from being deleted or overwritten for a specified retention period.\nRetention Periods and Legal Holds: Use retention periods and legal holds to protect objects from deletion for regulatory compliance and legal requirements.\nVersioning:\n\n* Object Versioning: Maintain multiple versions of an object, allowing you to recover from unintended user actions or application failures.\nData Recovery: Easily restore previous versions of objects to recover from accidental deletions or modifications.\nCross-Region Replication:\n\n* Data Redundancy: Automatically replicate objects across different AWS regions to enhance data durability and availability.\nDisaster Recovery: Ensure data resilience and support disaster recovery strategies by maintaining copies of data in different geographic locations.\nS3 Intelligent-Tiering:\n\n* Automated Cost Optimization: Automatically moves data between frequent and infrequent access tiers based on changing access patterns, optimizing storage costs.\nNo Retrieval Fees: Provides cost-effective storage management without retrieval fees for infrequently accessed data.\n\nBy utilizing these methods alongside the immediate remove feature, you can implement a comprehensive data retention strategy that balances cost, compliance, and performance while ensuring the safety and integrity of your data in AWS S3.\n\n\n### Securing S3 Bucket\n\nThis guide provides steps to create and configure [IAM policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html) for securing an S3 bucket such that users can delete files but not edit, and only upload new files without listing objects. \nFiles will be stored in a Guid folder to create unique random paths.\n\n\u003e __1. IAM Policies__\n\n- Policy for Allowing Deletion but Not Editing\n\nThis policy allows users to delete objects but not update or edit existing objects, and they cannot list objects in the bucket.\n\n```json\n{\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n        {\n            \"Effect\": \"Allow\",\n            \"Action\": [\n                \"s3:DeleteObject\"\n            ],\n            \"Resource\": \"arn:aws:s3:::your-bucket-name/*\"\n        },\n        {\n            \"Effect\": \"Deny\",\n            \"Action\": [\n                \"s3:PutObject\",\n                \"s3:ListBucket\"\n            ],\n            \"Resource\": [\n                \"arn:aws:s3:::your-bucket-name\",\n                \"arn:aws:s3:::your-bucket-name/*\"\n            ]\n        }\n    ]\n}\n```\n\n- Policy for Allowing Only Uploads of New Files\n\nThis policy allows users to upload new files but not delete or overwrite existing ones. Users cannot list objects in the bucket.\n\n```json\n{\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n        {\n            \"Effect\": \"Allow\",\n            \"Action\": [\n                \"s3:PutObject\"\n            ],\n            \"Resource\": \"arn:aws:s3:::your-bucket-name/*\",\n            \"Condition\": {\n                \"StringNotEqualsIfExists\": {\n                    \"s3:x-amz-copy-source\": [\n                        \"\",\n                        \"arn:aws:s3:::your-bucket-name/*\"\n                    ]\n                }\n            }\n        },\n        {\n            \"Effect\": \"Deny\",\n            \"Action\": [\n                \"s3:DeleteObject\",\n                \"s3:ListBucket\"\n            ],\n            \"Resource\": [\n                \"arn:aws:s3:::your-bucket-name\",\n                \"arn:aws:s3:::your-bucket-name/*\"\n            ]\n        }\n    ]\n}\n```\n\n\u003e __2. Attach Policies to IAM Roles or Users__\n\nTo restrict unwanted behavior for app container IAM, you need to select an IAM user/role that you want to assign the policies to. Attach the above policies to the user/role via the AWS Management Console, CLI, or SDK.\n\n\n### Rotating HTTPS Certificates on ECS\n\nRotating HTTPS certificates is a crucial security practice to ensure the ongoing protection of the Aspose.PDF for AWS RESTful API. This process involves replacing an existing HTTPS certificate with a new one before the old certificate expires or becomes compromised.\n\n\u003e __Prerequisites__\n\n- Access to the ECS cluster and the ability to update task definitions.\n- Administrative access to the server where your API is hosted.\n- A new HTTPS certificate issued by a trusted Certificate Authority (CA).\n\n**Steps to Rotate HTTPS Certificates**\n\n\u003e __Step 1: Obtain a New HTTPS Certificate__\n\nIf your existing HTTPS certificate is expiring or compromised, obtain a new certificate from a trusted Certificate Authority (CA).\n\n- Generate a Certificate Signing Request (CSR): Run the CSR generation command on your server.\n- Submit the CSR to a CA: Complete the validation process.\n- Download the Issued Certificate: Obtain the new certificate along with any necessary intermediate and root certificates provided by the CA.\n\nIn result, you have a new HTTPS certificate and any necessary intermediate and root certificates.\n\n\u003e __Step 2: Backup the Existing Certificate__\n\nBefore making any changes, it's essential to backup the existing certificate.\n\n- Locate the Current Certificate File: Identify the .pfx or .pem file on your server.\n- Copy to a Secure Location: Create a backup of the current certificate file.\n\nIn result, a backup of the existing certificate is safely stored.\n\n\u003e __Step 3: Update the ECS Task Definition__\n\nTo replace the certificate in an ECS environment, you must update the task definition.\n\n- Locate Your Current Task Definition\n- In the AWS Management Console, navigate to the ECS service.\n- Find and select the task definition used by your ASP.NET Core application.\n- Modify the Task Definition\n- Create a new revision of the task definition.\n- Under the volumes section, ensure a volume is defined for the certificate location.\n- In the containerDefinitions, update the mountPoints to use the new certificate path.\n\nExample:\n\n```json\n{\n  \"volumes\": [\n    {\n      \"name\": \"certs\",\n      \"host\": {\n        \"sourcePath\": \"/etc/ssl/certs\"\n      }\n    }\n  ],\n  \"containerDefinitions\": [\n    {\n      \"name\": \"myaspose\",\n      \"image\": \"\u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e\",\n      \"mountPoints\": [\n        {\n          \"sourceVolume\": \"certs\",\n          \"containerPath\": \"/etc/ssl/certs\",\n          \"readOnly\": true\n        }\n      ],\n      \"environment\": [\n        {\n          \"name\": \"ASPNETCORE_Kestrel__Certificates__Default__Path\",\n          \"value\": \"/etc/ssl/certs/new-certificate.pfx\"\n        },\n        {\n          \"name\": \"ASPNETCORE_Kestrel__Certificates__Default__Password\",\n          \"value\": \"your-certificate-password\"\n        }\n      ]\n    }\n  ]\n}\n```\n\nThe **volumes** section defines where the certificate is stored on the host.\nThe **mountPoints** section maps this volume to the container.\nThe **environment variables** are updated to point to the new certificate file and its password.\n\nIn result, the task definition is configured to use the new certificate.\n\n\u003e __Step 4: Deploy the Updated Task Definition__\n\nOnce the task definition is updated, you need to deploy it.\n\n- Update the ECS Service\n- Navigate to your ECS service.\n- Update the service to use the new task definition revision.\n- This will trigger a rolling update, where new tasks are started with the new certificate, and old tasks are drained and stopped.\n\nIn result, the new certificate is deployed, and the application begins using it.\n\n\u003e __Step 5: Verify the New Certificate__\n\nEnsuring the new certificate is correctly installed and functional is crucial.\n\n- Access the Application: Open a browser and navigate to your API's URL.\n- Check the Certificate: Click the padlock icon in the browser's address bar to view the certificate details.\n- Verify: Ensure the new certificate is displayed and the connection is secure.\n\nIn result, the new HTTPS certificate is correctly installed and operational.\n\n\u003e __Step 6: Monitor Certificate Validity__\n\nMonitoring the certificate's validity and documenting the process is important for future reference.\n\n- Set Up Monitoring: Use tools like AWS Certificate Manager or other monitoring solutions to alert you before the new certificate expires.\n- Document the Process: Record the steps taken during the certificate rotation for future use.\n\nIn result, continuous monitoring is in place, and the rotation process is documented.\n\n### Integrating AWS Key Management Service on ECS\n\nAmazon Web Services (AWS) Key Management Service (KMS) provides a secure and resilient service for creating and managing cryptographic keys. Integrating KMS with Docker environment variables in Amazon Elastic Container Service (ECS) ensures sensitive data, such as API keys and database credentials, are securely encrypted.\n\n\u003e __Prerequisites__\n\n- An AWS account with the necessary permissions.\n- An ECS cluster and a running ECS service.\n- AWS CLI configured with your credentials.\n- Docker installed on your local machine.\n- A KMS key created in AWS.\n\n**Steps to Integrate AWS KMS with Docker Environment Variables for ECS**\n\n\u003e __1. Create a KMS Key__\n\nIn case you need a KMS key to encrypt and decrypt sensitive data, create a new KMS key in AWS:\n\n- Open the AWS Management Console.\n- Navigate to the KMS section.\n- Click on \"Create key\" and follow the prompts to configure your key.\n- Note the Key ID or ARN of the newly created key.\n\nIn result, a new KMS key is created and ready for use.\n\n\u003e __2. Encrypt Environment Variables Using KMS__\n\nThe sensitive data needs to be encrypted using the KMS key. To encrypt the environment variables using AWS KMS:\n\n- Use the AWS CLI to encrypt your environment variables. Replace \u003cyour-kms-key-id\u003e and \u003cyour-secret-data\u003e with your KMS key ID and the data you want to encrypt.\n\n```bash\naws kms encrypt --key-id \u003cyour-kms-key-id\u003e --plaintext \u003cyour-secret-data\u003e --query CiphertextBlob --output text\n```\n\n- The command outputs a base64-encoded ciphertext. Note this value.\n\nIn result, your environment variables are securely encrypted.\n\n\u003e __3. Store Encrypted Variables in AWS Secrets Manager (Optional)__\n\nIn case, you want to securely store and manage encrypted variables, store the encrypted variables in AWS Secrets Manager:\n\n- Open the AWS Management Console and navigate to Secrets Manager.\n- Click on \"Store a new secret\".\n- Choose \"Other type of secret\" and input your encrypted data.\n- Follow the prompts to create the secret, and note the Secret ARN.\n\nIn result, encrypted environment variables are stored securely in Secrets Manager.\n\n\u003e __4. Configure IAM Roles and Policies__\n\nThe ECS tasks need permissions to use KMS for decryption, to attach the necessary IAM roles and policies:\n\n- Navigate to the IAM section in the AWS Management Console.\n- Create a new IAM policy with permissions to decrypt using the KMS key.\n\n```json\n{\n  \"Version\": \"2012-10-17\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": \"kms:Decrypt\",\n      \"Resource\": \"\u003cyour-kms-key-arn\u003e\"\n    }\n  ]\n}\n```\n\n- Attach this policy to the ECS task execution role.\n\nIn result, the ECS task has the necessary permissions to decrypt environment variables.\n\n\u003e __5. Update ECS Task Definition__\n\nYou need to pass the encrypted environment variables to your ECS tasks. To update the ECS task definition to include the encrypted environment variables:\n\n- Navigate to the ECS section in the AWS Management Console.\n- Select your task definition and create a new revision.\n- Under the \"Container Definitions\" section, add environment variables using the encrypted values.\n- If using Secrets Manager, reference the secrets.\n\n```json\n{\n  \"name\": \"MY_SECRET\",\n  \"valueFrom\": \"arn:aws:secretsmanager:region:account-id:secret:your-secret-name\"\n}\n```\n\nIn result, the task definition includes encrypted environment variables.\n\n\u003e __6. Update the ECS Service__\n\nThe ECS service needs to use the updated task definition, to update the ECS service to use the new task definition revision:\n\n- Navigate to the ECS section in the AWS Management Console.\n- Select your ECS service and update it to use the latest task definition revision.\n- Deploy the updated service.\n\nIn result, the ECS service uses the updated task definition with encrypted environment variables.\n\n\u003e __7. Decrypt Environment Variables in Aspose.PDF tor AWS__\n\nYou can configure the decryption of environment variables encrypted with AWS Key Management Service (KMS). To enable or disable the decryption of KMS environment variables, use the **`KEY_ENCRYPTION`** environment variable:\n\n- **`KEY_ENCRYPTION = 'true'`**: When set to `'true'`, the API will attempt to decrypt the environment variables using AWS KMS before use.\n- **`KEY_ENCRYPTION = 'false'`**: When set to `'no'`, the API will use the environment variables as-is without attempting decryption.\n\nIntegrating AWS KMS with Docker environment variables in Amazon ECS enhances the security of sensitive data in your applications. By following these steps, you ensure that sensitive environment variables are encrypted, securely stored, and decrypted only when needed by your application, thereby reducing the risk of exposure.\n\n\n### Rotating HTTPS Certificates on EKS\n\nRotating HTTPS certificates is a crucial security practice to ensure the ongoing protection of the Aspose.PDF for AWS RESTful API. This process involves replacing an existing HTTPS certificate with a new one before the old certificate expires or becomes compromised.\n\n\u003e __Prerequisites__\n\n- Access to your Kubernetes cluster on EKS.\n- Administrative access to the server where your API is hosted.\n- A new HTTPS certificate issued by a trusted Certificate Authority (CA).\n- Familiarity with Kubernetes deployment YAML files and configuration.\n\n**Steps to Rotate HTTPS Certificates**\n\n\u003e __Step 1: Obtain a New HTTPS Certificate__\n\nIf your existing HTTPS certificate is expiring or compromised, obtain a new certificate from a trusted Certificate Authority (CA).\n\n- Generate a Certificate Signing Request (CSR): Run the CSR generation command on your server.\n- Submit the CSR to a CA: Complete the validation process.\n- Download the Issued Certificate: Obtain the new certificate along with any necessary intermediate and root certificates provided by the CA.\n\nIn result, you have a new HTTPS certificate and any necessary intermediate and root certificates.\n\n\u003e __Step 2: Backup the Existing Certificate__\n\nBefore making any changes, it's essential to backup the existing certificate.\n\n- Locate the Current Certificate File: Identify the .pfx or .pem file on your server.\n- Copy to a Secure Location: Create a backup of the current certificate file.\n\nIn result, a backup of the existing certificate is safely stored.\n\n\u003e __Step 3: Update the Kubernetes Secrets__\n\nIn an EKS environment, certificates are often managed through Kubernetes secrets. You'll need to update these secrets with the new certificate.\n\n- Create a New Secret for the Certificate\n- Use kubectl to create a new secret that includes the new certificate and private key.\n\nExample:\n\n```bash\nkubectl create secret tls my-api-tls --cert=/path/to/new-certificate.crt --key=/path/to/private.key\n```\n\nThis command creates a new TLS secret named my-api-tls using the new certificate and private key files.\n\nIn result, the new certificate is stored as a Kubernetes secret.\n\n\u003e __Step 4: Update the Deployment to Use the New Secret__\n\nUpdate your Kubernetes deployment to reference the new certificate secret.\n\n- Locate the Deployment YAML File\n- Open your Kubernetes deployment YAML file for the ASP.NET Core application.\n- Modify the Deployment\n- In the spec section under containers, add a volumeMounts section to mount the secret containing the certificate.\n- Add a corresponding volumes section to define the secret.\n\nExample:\n\n```yaml\nspec:\n  containers:\n  - name: myaspose\n    image: \u003caccount_id\u003e.dkr.ecr.\u003cregion\u003e.amazonaws.com/aspose/aspose_pdf_for_aws:prod-\u003csha\u003e\n    volumeMounts:\n    - name: tls-secret\n      mountPath: /etc/ssl/certs\n    env:\n    - name: ASPNETCORE_Kestrel__Certificates__Default__Path\n      value: \"/etc/ssl/certs/tls.crt\"\n    - name: ASPNETCORE_Kestrel__Certificates__Default__Password\n      value: \"your-certificate-password\"\n  volumes:\n  - name: tls-secret\n    secret:\n      secretName: my-api-tls\n```\n\nThe **volumeMounts** section specifies where to mount the secret in the container.\nThe **volumes** section defines the secret to be mounted.\nThe **environment variables** ASPNETCORE_Kestrel__Certificates__Default__Path and ASPNETCORE_Kestrel__Certificates__Default__Password point to the new certificate and its password.\n\nIn result, the deployment is configured to use the new certificate stored in the Kubernetes secret.\n\n\u003e __Step 5: Deploy the Updated Configuration__\n\nOnce the deployment YAML is updated, apply the changes to your EKS cluster.\n\n- Apply the Deployment\n- Use kubectl to apply the updated deployment.\n\n```bash\nkubectl apply -f my-deployment.yaml\n```\n\nThis command updates the running pods to use the new certificate.\n\nIn result, the updated deployment is applied, and the application begins using the new certificate.\n\n\u003e __Step 6: Verify the New Certificate__\n\nEnsuring the new certificate is correctly installed and functional is crucial.\n\n- Access the Application: Open a browser and navigate to your API's URL.\n- Check the Certificate: Click the padlock icon in the browser's address bar to view the certificate details.\n- Verify: Ensure the new certificate is displayed and the connection is secure.\n\nIn result, the new HTTPS certificate is correctly installed and operational.\n\n\u003e __Step 7: Monitor Certificate Validity__\n\nMonitoring the certificate's validity and documenting the process is important for future reference.\n\n- Set Up Monitoring: Use tools like AWS Certificate Manager or other monitoring solutions to alert you before the new certificate expires.\n- Document the Process: Record the steps taken during the certificate rotation for future use.\n\nIn result, continuous monitoring is in place, and the rotation process is documented.\n\n### Integrating AWS Key Management Service on EKS\n\nAmazon Web Services (AWS) Key Management Service (KMS) provides a secure and resilient service for creating and managing cryptographic keys. Integrating KMS with Docker environment variables in Amazon Elastic Kubernetes Service (EKS) ensures sensitive data, such as API keys and database credentials, are securely encrypted.\n\n\u003e __Prerequisites__\n\n- An AWS account with the necessary permissions.\n- An EKS cluster and kubectl configured to interact with it.\n- AWS CLI configured with your credentials.\n- Docker installed on your local machine.\n- A KMS key created in AWS.\n\n**Steps to Integrate AWS KMS with Docker Environment Variables for EKS**\n\n\u003e __1. Create a KMS Key__\n\nIn case you need to protect AWS_ACCESS_KEY, AWS_SECRET, AWS_REGION_ENDPOINT, AWS_BUCKET,  you need a KMS keys to encrypt and decrypt sensitive data.\n\nTo create a new KMS key in AWS.\n\n- Open the AWS Management Console.\n- Navigate to the KMS section.\n- Click on \"Create key\" and follow the prompts to configure your key.\n- Note the Key ID or ARN of the newly created key.\n\nIn result, a new KMS key is created and ready for use.\n\n\u003e __2. Encrypt Environment Variables Using KMS__\n\nTo protect this sensitive data, it needs to be encrypted using the KMS key.\n\nTo encrypt the environment variables, use the AWS CLI to encrypt your environment variables. \nReplace \u003cyour-kms-key-id\u003e and \u003cyour-secret-data\u003e with your KMS key ID and the data you want to encrypt.\n\n```bash\naws kms encrypt --key-id \u003cyour-kms-key-id\u003e --plaintext \u003cyour-secret-data\u003e --query CiphertextBlob --output text\n```\n\n- The command outputs a base64-encoded ciphertext. Note this value.\n\nIn result, your environment variables are securely encrypted.\n\n\u003e __3. Store Encrypted Variables in AWS Secrets Manager (Optional)__\n\nIn case you want to securely store and manage encrypted variables, store the encrypted variables in AWS Secrets Manager:\n\n- Open the AWS Management Console and navigate to Secrets Manager.\n- Click on \"Store a new secret\".\n- Choose \"Other type of secret\" and input your encrypted data.\n- Follow the prompts to create the secret, and note the Secret ARN.\n\nIn result, encrypted environment variables are stored securely in Secrets Manager.\n\n\u003e __4. Configure IAM Roles and Policies__\n\nFor improve EKS pods to use KMS secrets, need permissions to use KMS for decryption. To attach the necessary IAM roles and policies:\n\n- Navigate to the IAM section in the AWS Management Console.\n- Create a new IAM policy with permissions to decrypt using the KMS key.\n\n```json\n{\n  \"Version\": \"2012-10-17\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": \"kms:Decrypt\",\n      \"Resource\": \"\u003cyour-kms-key-arn\u003e\"\n    }\n  ]\n}\n```\n\nAttach this policy to the IAM role associated with your EKS nodes or configure IAM roles for service accounts (IRSA) for specific pods.\nIf using IRSA, create a Kubernetes service account and annotate it with the IAM role ARN.\n\nIn result, the EKS pods have the necessary permissions to decrypt environment variables.\n\n\u003e __5. Update Kubernetes Secrets__\n\nTo pass the encrypted environment variables to your EKS pods, create or update Kubernetes secrets with the encrypted environment variables:\n\n- Create a Kubernetes secret with the encrypted environment variables.\n\n```yaml\napiVersion: v1\nkind: Secret\nmetadata:\n  name: secret\ndata:\n  MY_SECRET: \u003cbase64-encoded-ciphertext\u003e\n```\n\n- Apply the secret to your cluster.\n\n```bash\nkubectl apply -f secret.yaml\n```\n\nIn result, the Kubernetes secret containing encrypted environment variables is created.\n\n\u003e __6. Update Kubernetes Deployment__\n\nTo enhance EKS deployment with Kubernetes secret, update the Kubernetes deployment to include the secret as environment variables:\n\n- Edit your Kubernetes deployment to reference the se","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faspose-pdf-cloud%2Faspose-pdf-for-aws-sdk","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Faspose-pdf-cloud%2Faspose-pdf-for-aws-sdk","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faspose-pdf-cloud%2Faspose-pdf-for-aws-sdk/lists"}