Connect to AWS S3 using SAP Cloud Connector for SAP Datasphere Replication flows
Share

[[{“value”:”

Introduction 

When integrating SAP Datasphere with AWS S3, traffic typically traverses the public internet. While TLS encryption protects data in transit, many enterprise security policies require that sensitive data never leave the private network boundary, even when encrypted. AWS Private Link addresses this by routing S3 traffic entirely within the AWS network through a VPC Interface Endpoint, eliminating exposure to the public internet at the network layer. Combined with the SAP Cloud Connector (SCC), this enables SAP Datasphere to access S3 buckets over a SAP Cloud Connector secure TLS tunnel, without any traffic leaving the AWS backbone.

This guide walks through the setup and verification of this architecture in a lab / POC-style environment.

Disclaimer: This blog is intended for informational and knowledge-sharing purposes only. The configurations described are demonstrated in a SAP lab environment and may not reflect production-ready setups. Please refer to official AWS S3 and SAP documentation.

Architecture 

venkat_madireddi_0-1790278538512.png

The key components are:

Component

Role

AWS S3 Bucket

Target data store; public access blocked 

VPC Interface Endpoint

Routes S3 traffic privately within the AWS network 

EC2 Instance

Hosts the SAP Cloud Connector; sits inside the VPC

SAP Cloud Connector

Bridges SAP Datasphere to the private S3 endpoint

 Prerequisites

  • An active AWS account with the VPC Interface Endpoint for S3 , allowing resources inside the VPC to reach S3 without routing traffic over the public internet.
  • AWS EC2 Instance to host the SAP Cloud Connector
  • An SAP BTP Subaccount for  SAP Datasphere (Cloud Foundry environment)

1.    Provision EC2 AWS instance 

Provision an EC2 instance inside the same VPC and subnet as the Interface Endpoint. This instance will host the SAP Cloud Connector.

Parameter

Recommended Value

Operating System

Red Hat Enterprise Linux 9.x or Amazon Linux 2023

Instance Type

Medium or larger (SCC requires at least 2 vCPU / 4 GB RAM)

VPC

Same VPC as the Interface Endpoint

Subnet

Same subnet as the Interface Endpoint

Security Group

The shared security group that controls access to the endpoint; shared with the EC2 instance

Public IP

Assign a public IP for initial SSH access

2.    Verify S3 Access via Private endpoints

SSH into the EC2 instance and verify that S3 is reachable through the private endpoint.

Install AWS CLI on the Instance

ssh -i <your-key.pem> ec2-user@<instance-public-ip>

sudo dnf install -y unzip wget
mkdir -p /data/awscli && cd /data/awscli
curl “https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip” -o “awscliv2.zip”
unzip awscliv2.zip
./aws/install
export PATH=$PATH:/usr/local/bin
aws –version

Configure Credentials and Test Access

aws configure set aws_access_key_id <YOUR_ACCESS_KEY_ID>
aws configure set aws_secret_access_key <YOUR_SECRET_ACCESS_KEY>
export REGION=eu-central-1
# Test standard S3 access
aws s3 ls s3://your-bucket-name

# Test access via the PrivateLink Interface Endpoint DNS
aws s3api head-object
–bucket your-bucket-name
–key test-file.txt
–endpoint-url https://bucket.vpce-<endpoint-id>.s3.eu-central-1.vpce.amazonaws.com

A successful response confirms that S3 traffic is routing through the private endpoint.

3.    Install and configure SAP Cloud Connector

Download SAP Cloud Connector

Download the SAP Cloud Connector Linux Portable package from SAP Development Tools. The package is a .zip file containing an RPM installer.

Transfer the package to the EC2 instance:

scp -i <your-key.pem> sapcc-<version>-linux-x64.zip ec2-user@<instance-public-ip>:/tmp/

Install SAP Machine JRE (Java Runtime)

SCC requires Java 17 or 21. SAP Machine JRE is the recommended runtime.

wget https://github.com/SAP/SapMachine/releases/download/sapmachine-21.0.5/sapmachine-jre-21.0.5_linux-x64_bin.tar.gz
tar zxf sapmachine-jre-21.0.5_linux-x64_bin.tar.gz -C /data/
export JAVA_HOME=/data/sapmachine-jre-21.0.5
export PATH=$JAVA_HOME/bin:$PATH
java -version

Install SCC

mkdir /data/sapcc && cd /data/sapcc
cp /tmp/sapcc-<version>-linux-x64.zip .
unzip sapcc-<version>-linux-x64.zip
rpm -Uvh –force com.sap.scc-ui-<version>.x86_64.rpm

Start and Access SCC

Once installed, SCC starts automatically as a service and is accessible on port 8443:

# Check service status
systemctl status scc_daemon

Open a browser and navigate to:  https://<instance-public-ip>:8443/

Log in with the default credentials and change the password immediately:

Field

Default Value

Username

Administrator

Password

Manage

4.    Connect SAP Datasphere Subaccount to SAP Cloud Connector

Set Installation Type

On first login, select Master as the installation type and save

venkat_madireddi_0-1790279711184.png

Register the SAP Datasphere BTP Subaccount

  1. Login into your BTP Cockpit, navigate to Connectivity → Cloud Connectors → Download Authentication Data 

            You will need to upload the authenticated data file in Step 4  

venkat_madireddi_2-1790369276860.png

     2. Login in into SAP Cloud Connector Admin UI  https://<instance-public-ip>:8443/

        Click Add Subaccount

venkat_madireddi_4-1790279969255.png

      3. Choose to Configure using Authentication data

venkat_madireddi_5-1790280141532.png

     4. Choose from file and browse to select the downloaded file from Step 1- Add subaccount authentication data

venkat_madireddi_6-1790280141534.png

      5. Set Location ID you want to use and a Display Name and Finish.

      6. Verify the connection appears as active in the BTP Cockpit under Connectivity → Cloud Connectors

venkat_madireddi_0-1790369166229.png

 

5.    Map Virtual Host to the S3 Private Endpoints

If you want to prevent your data from being routed publicly through the internet, you can use SAP Cloud Connector as a secure TLS tunnel between the customer virtual private network and SAP Datasphere to privately route the data.

Cloud Connector acts as a reverse proxy, create the following system mappings for the regional endpoints where your Amazon S3 bucket is located . you will need to map the virtual host to two separate S3 PrivateLink endpoints for CSV and Parquet files
 
1. In  SAP Cloud Connector, Select SubAccount and choose the Datasphere SubAccount
venkat_madireddi_0-1790282105137.png

2. Go to Cloud To On-Premise and click the Add button  

    Select Non-SAP System as back-end type 

venkat_madireddi_1-1790282197209.png

3. Set Protocol to TCP

4.  Set the internal host and port range for  Amazon S3 global endpoint for path-syle URL access (for example, s3.eu-central-1.amazonaws.com)

venkat_madireddi_4-1790286442372.png

5. Set the Virtual Host and port   – must be the same as the internal host and port 

venkat_madireddi_0-1790348252777.png

6. Click Finish to complete endpoint system mapping to enable path-style URL access

venkat_madireddi_2-1790349137103.png

7. Add endpoint system mapping to enable virtual-hosted-style URL access. Similar to Step 2 to Step 6 

    Go to Cloud To On-Premise and click the Add button  

  • Select Non-SAP System as back-end type 

    venkat_madireddi_3-1790349478950.png

  • Set Protocol to HTTPS
  • Set Internal Host and Port – Internal host for Amazon S3 regional endpoint including the name of the bucket that you want to access (for example, <bucket-name>.s3.eu-central-1.amazonaws.com)

venkat_madireddi_8-1790349898157.png

  • Set Virtual Host and Port                      

           Hostname must be the same as the internal host and port can be different 

venkat_madireddi_9-1790350672504.png

  • Deselect Allow Principal Propagation
  • set Host in Request Header to Internal Host

venkat_madireddi_10-1790351036033.png

  • Click Finish to complete endpoint system mapping to enable virtual-hosted–style URL access

8. Verify the connections for both mappings in SCC

venkat_madireddi_13-1790353517681.png

6.   Add  data source location to SAP  Datasphere

Login in SAP Datasphere and navigate to SYSTEM –> Administration

In the Data Source Configuration section add the defined SCC location to the locations listvenkat_madireddi_14-1790354040822.png

7.    Create AWS S3 connection in SAP Datasphere using SAP Cloud Connector 

1. Login in SAP Datasphere and switch to the HANA<Space> or HDLF <space> to Create a new Connection to AWS S3 in Connection Management

2. Click Amazon Simple Storage Service connection in Connection List

venkat_madireddi_15-1790355447660.png

3. Configure Connection parameters for Amazon Simple Storage with setting the Use Cloud Connector to True

    Make sure to select the created / corresponding Location for the  SAP Cloud Connector instance

venkat_madireddi_18-1790355612578.png

4. Choose Next and enter connection information and click on Create Connection

venkat_madireddi_19-1790355678947.png

5. Validate the Connection to verify the connection status 

venkat_madireddi_20-1790355794840.png

With these steps completed, your SAP Cloud Connector is successfully installed, connected, and configured to integrate and create a native connection type of Amazon simple storage service using private endpoints with SAP Datasphere . Now in data builder , you can configure and deploy a Replication Flow with Amazon simple storage service( AWS S3) as source .

Conclusion

Setting up private connectivity between SAP Datasphere and AWS S3 is straightforward when combining AWS PrivateLink with the SAP Cloud Connector. If you want to prevent your data from being routed publicly through the internet, you can use Cloud Connector as a TLS tunnel between the customer virtual private network and SAP Datasphere to privately route the data. The setup covered in this blog walks through each layer of the architecture: provisioning an EC2 instance inside the VPC to host the SAP Cloud Connector, routing S3 traffic through a VPC Interface Endpoint, and mapping virtual hosts to the private S3 PrivateLink DNS addresses.

 

References:

SAP Cloud Connector licensing, download and installation information

Amazon Simple Storage Service Connections 

 

 

“}]] 

 [[{“value”:”Introduction When integrating SAP Datasphere with AWS S3, traffic typically traverses the public internet. While TLS encryption protects data in transit, many enterprise security policies require that sensitive data never leave the private network boundary, even when encrypted. AWS Private Link addresses this by routing S3 traffic entirely within the AWS network through a VPC Interface Endpoint, eliminating exposure to the public internet at the network layer. Combined with the SAP Cloud Connector (SCC), this enables SAP Datasphere to access S3 buckets over a SAP Cloud Connector secure TLS tunnel, without any traffic leaving the AWS backbone.This guide walks through the setup and verification of this architecture in a lab / POC-style environment.Disclaimer: This blog is intended for informational and knowledge-sharing purposes only. The configurations described are demonstrated in a SAP lab environment and may not reflect production-ready setups. Please refer to official AWS S3 and SAP documentation.Architecture The key components are:ComponentRoleAWS S3 BucketTarget data store; public access blocked VPC Interface EndpointRoutes S3 traffic privately within the AWS network EC2 InstanceHosts the SAP Cloud Connector; sits inside the VPCSAP Cloud ConnectorBridges SAP Datasphere to the private S3 endpoint PrerequisitesAn active AWS account with the VPC Interface Endpoint for S3 , allowing resources inside the VPC to reach S3 without routing traffic over the public internet.AWS EC2 Instance to host the SAP Cloud ConnectorAn SAP BTP Subaccount for  SAP Datasphere (Cloud Foundry environment)1.    Provision EC2 AWS instance Provision an EC2 instance inside the same VPC and subnet as the Interface Endpoint. This instance will host the SAP Cloud Connector.ParameterRecommended ValueOperating SystemRed Hat Enterprise Linux 9.x or Amazon Linux 2023Instance TypeMedium or larger (SCC requires at least 2 vCPU / 4 GB RAM)VPCSame VPC as the Interface EndpointSubnetSame subnet as the Interface EndpointSecurity GroupThe shared security group that controls access to the endpoint; shared with the EC2 instancePublic IPAssign a public IP for initial SSH access2.    Verify S3 Access via Private endpointsSSH into the EC2 instance and verify that S3 is reachable through the private endpoint.Install AWS CLI on the Instancessh -i <your-key.pem> ec2-user@<instance-public-ip>

sudo dnf install -y unzip wget
mkdir -p /data/awscli && cd /data/awscli
curl “https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip” -o “awscliv2.zip”
unzip awscliv2.zip
./aws/install
export PATH=$PATH:/usr/local/bin
aws –versionConfigure Credentials and Test Accessaws configure set aws_access_key_id <YOUR_ACCESS_KEY_ID>
aws configure set aws_secret_access_key <YOUR_SECRET_ACCESS_KEY>
export REGION=eu-central-1
# Test standard S3 access
aws s3 ls s3://your-bucket-name

# Test access via the PrivateLink Interface Endpoint DNS
aws s3api head-object
–bucket your-bucket-name
–key test-file.txt
–endpoint-url https://bucket.vpce-<endpoint-id>.s3.eu-central-1.vpce.amazonaws.comA successful response confirms that S3 traffic is routing through the private endpoint.3.    Install and configure SAP Cloud ConnectorDownload SAP Cloud ConnectorDownload the SAP Cloud Connector Linux Portable package from SAP Development Tools. The package is a .zip file containing an RPM installer.Transfer the package to the EC2 instance:scp -i <your-key.pem> sapcc-<version>-linux-x64.zip ec2-user@<instance-public-ip>:/tmp/Install SAP Machine JRE (Java Runtime)SCC requires Java 17 or 21. SAP Machine JRE is the recommended runtime.wget https://github.com/SAP/SapMachine/releases/download/sapmachine-21.0.5/sapmachine-jre-21.0.5_linux-x64_bin.tar.gz
tar zxf sapmachine-jre-21.0.5_linux-x64_bin.tar.gz -C /data/
export JAVA_HOME=/data/sapmachine-jre-21.0.5
export PATH=$JAVA_HOME/bin:$PATH
java -versionInstall SCCmkdir /data/sapcc && cd /data/sapcc
cp /tmp/sapcc-<version>-linux-x64.zip .
unzip sapcc-<version>-linux-x64.zip
rpm -Uvh –force com.sap.scc-ui-<version>.x86_64.rpmStart and Access SCCOnce installed, SCC starts automatically as a service and is accessible on port 8443:# Check service status
systemctl status scc_daemonOpen a browser and navigate to:  https://<instance-public-ip>:8443/Log in with the default credentials and change the password immediately:FieldDefault ValueUsernameAdministratorPasswordManage4.    Connect SAP Datasphere Subaccount to SAP Cloud ConnectorSet Installation TypeOn first login, select Master as the installation type and saveRegister the SAP Datasphere BTP SubaccountLogin into your BTP Cockpit, navigate to Connectivity → Cloud Connectors → Download Authentication Data              You will need to upload the authenticated data file in Step 4       2. Login in into SAP Cloud Connector Admin UI  https://<instance-public-ip>:8443/        Click Add Subaccount      3. Choose to Configure using Authentication data     4. Choose from file and browse to select the downloaded file from Step 1- Add subaccount authentication data      5. Set Location ID you want to use and a Display Name and Finish.      6. Verify the connection appears as active in the BTP Cockpit under Connectivity → Cloud Connectors 5.    Map Virtual Host to the S3 Private EndpointsIf you want to prevent your data from being routed publicly through the internet, you can use SAP Cloud Connector as a secure TLS tunnel between the customer virtual private network and SAP Datasphere to privately route the data.Cloud Connector acts as a reverse proxy, create the following system mappings for the regional endpoints where your Amazon S3 bucket is located . you will need to map the virtual host to two separate S3 PrivateLink endpoints for CSV and Parquet files 1. In  SAP Cloud Connector, Select SubAccount and choose the Datasphere SubAccount2. Go to Cloud To On-Premise and click the Add button      Select Non-SAP System as back-end type 3. Set Protocol to TCP4.  Set the internal host and port range for  Amazon S3 global endpoint for path-syle URL access (for example, s3.eu-central-1.amazonaws.com)5. Set the Virtual Host and port   – must be the same as the internal host and port 6. Click Finish to complete endpoint system mapping to enable path-style URL access7. Add endpoint system mapping to enable virtual-hosted-style URL access. Similar to Step 2 to Step 6     Go to Cloud To On-Premise and click the Add button  Select Non-SAP System as back-end type     Set Protocol to HTTPSSet Internal Host and Port – Internal host for Amazon S3 regional endpoint including the name of the bucket that you want to access (for example, <bucket-name>.s3.eu-central-1.amazonaws.com)Set Virtual Host and Port                                 Hostname must be the same as the internal host and port can be different Deselect Allow Principal Propagationset Host in Request Header to Internal HostClick Finish to complete endpoint system mapping to enable virtual-hosted–style URL access8. Verify the connections for both mappings in SCC6.   Add  data source location to SAP  DatasphereLogin in SAP Datasphere and navigate to SYSTEM –> AdministrationIn the Data Source Configuration section add the defined SCC location to the locations list7.    Create AWS S3 connection in SAP Datasphere using SAP Cloud Connector 1. Login in SAP Datasphere and switch to the HANA<Space> or HDLF <space> to Create a new Connection to AWS S3 in Connection Management2. Click Amazon Simple Storage Service connection in Connection List3. Configure Connection parameters for Amazon Simple Storage with setting the Use Cloud Connector to True    Make sure to select the created / corresponding Location for the  SAP Cloud Connector instance4. Choose Next and enter connection information and click on Create Connection5. Validate the Connection to verify the connection status With these steps completed, your SAP Cloud Connector is successfully installed, connected, and configured to integrate and create a native connection type of Amazon simple storage service using private endpoints with SAP Datasphere . Now in data builder , you can configure and deploy a Replication Flow with Amazon simple storage service( AWS S3) as source .ConclusionSetting up private connectivity between SAP Datasphere and AWS S3 is straightforward when combining AWS PrivateLink with the SAP Cloud Connector. If you want to prevent your data from being routed publicly through the internet, you can use Cloud Connector as a TLS tunnel between the customer virtual private network and SAP Datasphere to privately route the data. The setup covered in this blog walks through each layer of the architecture: provisioning an EC2 instance inside the VPC to host the SAP Cloud Connector, routing S3 traffic through a VPC Interface Endpoint, and mapping virtual hosts to the private S3 PrivateLink DNS addresses. References:SAP Cloud Connector licensing, download and installation informationAmazon Simple Storage Service Connections   “}]] Read More Technology Blog Posts by SAP articles 

#SAPCHANNEL

By ali

Leave a Reply