[[{“value”:”
Introduction
When integrating SAP Datasphere with AWS S3, traffic typically traverses the public internet. While TLS encryption protects data in transit, many enterprise security policies require that sensitive data never leave the private network boundary, even when encrypted. AWS Private Link addresses this by routing S3 traffic entirely within the AWS network through a VPC Interface Endpoint, eliminating exposure to the public internet at the network layer. Combined with the SAP Cloud Connector (SCC), this enables SAP Datasphere to access S3 buckets over a SAP Cloud Connector secure TLS tunnel, without any traffic leaving the AWS backbone.
This guide walks through the setup and verification of this architecture in a lab / POC-style environment.
Disclaimer: This blog is intended for informational and knowledge-sharing purposes only. The configurations described are demonstrated in a SAP lab environment and may not reflect production-ready setups. Please refer to official AWS S3 and SAP documentation.
Architecture
The key components are:
|
Component |
Role |
|
AWS S3 Bucket |
Target data store; public access blocked |
|
VPC Interface Endpoint |
Routes S3 traffic privately within the AWS network |
|
EC2 Instance |
Hosts the SAP Cloud Connector; sits inside the VPC |
|
SAP Cloud Connector |
Bridges SAP Datasphere to the private S3 endpoint |
Prerequisites
- An active AWS account with the VPC Interface Endpoint for S3 , allowing resources inside the VPC to reach S3 without routing traffic over the public internet.
- AWS EC2 Instance to host the SAP Cloud Connector
- An SAP BTP Subaccount for SAP Datasphere (Cloud Foundry environment)
1. Provision EC2 AWS instance
Provision an EC2 instance inside the same VPC and subnet as the Interface Endpoint. This instance will host the SAP Cloud Connector.
|
Parameter |
Recommended Value |
|
Operating System |
Red Hat Enterprise Linux 9.x or Amazon Linux 2023 |
|
Instance Type |
Medium or larger (SCC requires at least 2 vCPU / 4 GB RAM) |
|
VPC |
Same VPC as the Interface Endpoint |
|
Subnet |
Same subnet as the Interface Endpoint |
|
Security Group |
The shared security group that controls access to the endpoint; shared with the EC2 instance |
|
Public IP |
Assign a public IP for initial SSH access |
2. Verify S3 Access via Private endpoints
SSH into the EC2 instance and verify that S3 is reachable through the private endpoint.
Install AWS CLI on the Instance
ssh -i <your-key.pem> ec2-user@<instance-public-ip>
sudo dnf install -y unzip wget
mkdir -p /data/awscli && cd /data/awscli
curl “https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip” -o “awscliv2.zip”
unzip awscliv2.zip
./aws/install
export PATH=$PATH:/usr/local/bin
aws –version
Configure Credentials and Test Access
aws configure set aws_access_key_id <YOUR_ACCESS_KEY_ID>
aws configure set aws_secret_access_key <YOUR_SECRET_ACCESS_KEY>
export REGION=eu-central-1
# Test standard S3 access
aws s3 ls s3://your-bucket-name
# Test access via the PrivateLink Interface Endpoint DNS
aws s3api head-object
–bucket your-bucket-name
–key test-file.txt
–endpoint-url https://bucket.vpce-<endpoint-id>.s3.eu-central-1.vpce.amazonaws.com
A successful response confirms that S3 traffic is routing through the private endpoint.
3. Install and configure SAP Cloud Connector
Download SAP Cloud Connector
Download the SAP Cloud Connector Linux Portable package from SAP Development Tools. The package is a .zip file containing an RPM installer.
Transfer the package to the EC2 instance:
scp -i <your-key.pem> sapcc-<version>-linux-x64.zip ec2-user@<instance-public-ip>:/tmp/
Install SAP Machine JRE (Java Runtime)
SCC requires Java 17 or 21. SAP Machine JRE is the recommended runtime.
wget https://github.com/SAP/SapMachine/releases/download/sapmachine-21.0.5/sapmachine-jre-21.0.5_linux-x64_bin.tar.gz
tar zxf sapmachine-jre-21.0.5_linux-x64_bin.tar.gz -C /data/
export JAVA_HOME=/data/sapmachine-jre-21.0.5
export PATH=$JAVA_HOME/bin:$PATH
java -version
Install SCC
mkdir /data/sapcc && cd /data/sapcc
cp /tmp/sapcc-<version>-linux-x64.zip .
unzip sapcc-<version>-linux-x64.zip
rpm -Uvh –force com.sap.scc-ui-<version>.x86_64.rpm
Start and Access SCC
Once installed, SCC starts automatically as a service and is accessible on port 8443:
# Check service status
systemctl status scc_daemon
Open a browser and navigate to: https://<instance-public-ip>:8443/
Log in with the default credentials and change the password immediately:
|
Field |
Default Value |
|
Username |
Administrator |
|
Password |
Manage |
4. Connect SAP Datasphere Subaccount to SAP Cloud Connector
Set Installation Type
On first login, select Master as the installation type and save
Register the SAP Datasphere BTP Subaccount
- Login into your BTP Cockpit, navigate to Connectivity → Cloud Connectors → Download Authentication Data
You will need to upload the authenticated data file in Step 4
2. Login in into SAP Cloud Connector Admin UI https://<instance-public-ip>:8443/
Click Add Subaccount
3. Choose to Configure using Authentication data
4. Choose from file and browse to select the downloaded file from Step 1- Add subaccount authentication data
5. Set Location ID you want to use and a Display Name and Finish.
6. Verify the connection appears as active in the BTP Cockpit under Connectivity → Cloud Connectors
5. Map Virtual Host to the S3 Private Endpoints
If you want to prevent your data from being routed publicly through the internet, you can use SAP Cloud Connector as a secure TLS tunnel between the customer virtual private network and SAP Datasphere to privately route the data.
2. Go to Cloud To On-Premise and click the Add button
Select Non-SAP System as back-end type
3. Set Protocol to TCP
4. Set the internal host and port range for Amazon S3 global endpoint for path-syle URL access (for example, s3.eu-central-1.amazonaws.com)
5. Set the Virtual Host and port – must be the same as the internal host and port
6. Click Finish to complete endpoint system mapping to enable path-style URL access
7. Add endpoint system mapping to enable virtual-hosted-style URL access. Similar to Step 2 to Step 6
Go to Cloud To On-Premise and click the Add button
- Select Non-SAP System as back-end type
- Set Protocol to HTTPS
- Set Internal Host and Port – Internal host for Amazon S3 regional endpoint including the name of the bucket that you want to access (for example, <bucket-name>.s3.eu-central-1.amazonaws.com)
- Set Virtual Host and Port
Hostname must be the same as the internal host and port can be different
- Deselect Allow Principal Propagation
- set Host in Request Header to Internal Host
- Click Finish to complete endpoint system mapping to enable virtual-hosted–style URL access
8. Verify the connections for both mappings in SCC
6. Add data source location to SAP Datasphere
Login in SAP Datasphere and navigate to SYSTEM –> Administration
In the Data Source Configuration section add the defined SCC location to the locations list
7. Create AWS S3 connection in SAP Datasphere using SAP Cloud Connector
1. Login in SAP Datasphere and switch to the HANA<Space> or HDLF <space> to Create a new Connection to AWS S3 in Connection Management
2. Click Amazon Simple Storage Service connection in Connection List
3. Configure Connection parameters for Amazon Simple Storage with setting the Use Cloud Connector to True
Make sure to select the created / corresponding Location for the SAP Cloud Connector instance
4. Choose Next and enter connection information and click on Create Connection
5. Validate the Connection to verify the connection status
With these steps completed, your SAP Cloud Connector is successfully installed, connected, and configured to integrate and create a native connection type of Amazon simple storage service using private endpoints with SAP Datasphere . Now in data builder , you can configure and deploy a Replication Flow with Amazon simple storage service( AWS S3) as source .
Conclusion
Setting up private connectivity between SAP Datasphere and AWS S3 is straightforward when combining AWS PrivateLink with the SAP Cloud Connector. If you want to prevent your data from being routed publicly through the internet, you can use Cloud Connector as a TLS tunnel between the customer virtual private network and SAP Datasphere to privately route the data. The setup covered in this blog walks through each layer of the architecture: provisioning an EC2 instance inside the VPC to host the SAP Cloud Connector, routing S3 traffic through a VPC Interface Endpoint, and mapping virtual hosts to the private S3 PrivateLink DNS addresses.
References:
SAP Cloud Connector licensing, download and installation information
Amazon Simple Storage Service Connections
“}]]
[[{“value”:”Introduction When integrating SAP Datasphere with AWS S3, traffic typically traverses the public internet. While TLS encryption protects data in transit, many enterprise security policies require that sensitive data never leave the private network boundary, even when encrypted. AWS Private Link addresses this by routing S3 traffic entirely within the AWS network through a VPC Interface Endpoint, eliminating exposure to the public internet at the network layer. Combined with the SAP Cloud Connector (SCC), this enables SAP Datasphere to access S3 buckets over a SAP Cloud Connector secure TLS tunnel, without any traffic leaving the AWS backbone.This guide walks through the setup and verification of this architecture in a lab / POC-style environment.Disclaimer: This blog is intended for informational and knowledge-sharing purposes only. The configurations described are demonstrated in a SAP lab environment and may not reflect production-ready setups. Please refer to official AWS S3 and SAP documentation.Architecture The key components are:ComponentRoleAWS S3 BucketTarget data store; public access blocked VPC Interface EndpointRoutes S3 traffic privately within the AWS network EC2 InstanceHosts the SAP Cloud Connector; sits inside the VPCSAP Cloud ConnectorBridges SAP Datasphere to the private S3 endpoint PrerequisitesAn active AWS account with the VPC Interface Endpoint for S3 , allowing resources inside the VPC to reach S3 without routing traffic over the public internet.AWS EC2 Instance to host the SAP Cloud ConnectorAn SAP BTP Subaccount for SAP Datasphere (Cloud Foundry environment)1. Provision EC2 AWS instance Provision an EC2 instance inside the same VPC and subnet as the Interface Endpoint. This instance will host the SAP Cloud Connector.ParameterRecommended ValueOperating SystemRed Hat Enterprise Linux 9.x or Amazon Linux 2023Instance TypeMedium or larger (SCC requires at least 2 vCPU / 4 GB RAM)VPCSame VPC as the Interface EndpointSubnetSame subnet as the Interface EndpointSecurity GroupThe shared security group that controls access to the endpoint; shared with the EC2 instancePublic IPAssign a public IP for initial SSH access2. Verify S3 Access via Private endpointsSSH into the EC2 instance and verify that S3 is reachable through the private endpoint.Install AWS CLI on the Instancessh -i <your-key.pem> ec2-user@<instance-public-ip>
sudo dnf install -y unzip wget
mkdir -p /data/awscli && cd /data/awscli
curl “https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip” -o “awscliv2.zip”
unzip awscliv2.zip
./aws/install
export PATH=$PATH:/usr/local/bin
aws –versionConfigure Credentials and Test Accessaws configure set aws_access_key_id <YOUR_ACCESS_KEY_ID>
aws configure set aws_secret_access_key <YOUR_SECRET_ACCESS_KEY>
export REGION=eu-central-1
# Test standard S3 access
aws s3 ls s3://your-bucket-name
# Test access via the PrivateLink Interface Endpoint DNS
aws s3api head-object
–bucket your-bucket-name
–key test-file.txt
–endpoint-url https://bucket.vpce-<endpoint-id>.s3.eu-central-1.vpce.amazonaws.comA successful response confirms that S3 traffic is routing through the private endpoint.3. Install and configure SAP Cloud ConnectorDownload SAP Cloud ConnectorDownload the SAP Cloud Connector Linux Portable package from SAP Development Tools. The package is a .zip file containing an RPM installer.Transfer the package to the EC2 instance:scp -i <your-key.pem> sapcc-<version>-linux-x64.zip ec2-user@<instance-public-ip>:/tmp/Install SAP Machine JRE (Java Runtime)SCC requires Java 17 or 21. SAP Machine JRE is the recommended runtime.wget https://github.com/SAP/SapMachine/releases/download/sapmachine-21.0.5/sapmachine-jre-21.0.5_linux-x64_bin.tar.gz
tar zxf sapmachine-jre-21.0.5_linux-x64_bin.tar.gz -C /data/
export JAVA_HOME=/data/sapmachine-jre-21.0.5
export PATH=$JAVA_HOME/bin:$PATH
java -versionInstall SCCmkdir /data/sapcc && cd /data/sapcc
cp /tmp/sapcc-<version>-linux-x64.zip .
unzip sapcc-<version>-linux-x64.zip
rpm -Uvh –force com.sap.scc-ui-<version>.x86_64.rpmStart and Access SCCOnce installed, SCC starts automatically as a service and is accessible on port 8443:# Check service status
systemctl status scc_daemonOpen a browser and navigate to: https://<instance-public-ip>:8443/Log in with the default credentials and change the password immediately:FieldDefault ValueUsernameAdministratorPasswordManage4. Connect SAP Datasphere Subaccount to SAP Cloud ConnectorSet Installation TypeOn first login, select Master as the installation type and saveRegister the SAP Datasphere BTP SubaccountLogin into your BTP Cockpit, navigate to Connectivity → Cloud Connectors → Download Authentication Data You will need to upload the authenticated data file in Step 4 2. Login in into SAP Cloud Connector Admin UI https://<instance-public-ip>:8443/ Click Add Subaccount 3. Choose to Configure using Authentication data 4. Choose from file and browse to select the downloaded file from Step 1- Add subaccount authentication data 5. Set Location ID you want to use and a Display Name and Finish. 6. Verify the connection appears as active in the BTP Cockpit under Connectivity → Cloud Connectors 5. Map Virtual Host to the S3 Private EndpointsIf you want to prevent your data from being routed publicly through the internet, you can use SAP Cloud Connector as a secure TLS tunnel between the customer virtual private network and SAP Datasphere to privately route the data.Cloud Connector acts as a reverse proxy, create the following system mappings for the regional endpoints where your Amazon S3 bucket is located . you will need to map the virtual host to two separate S3 PrivateLink endpoints for CSV and Parquet files 1. In SAP Cloud Connector, Select SubAccount and choose the Datasphere SubAccount2. Go to Cloud To On-Premise and click the Add button Select Non-SAP System as back-end type 3. Set Protocol to TCP4. Set the internal host and port range for Amazon S3 global endpoint for path-syle URL access (for example, s3.eu-central-1.amazonaws.com)5. Set the Virtual Host and port – must be the same as the internal host and port 6. Click Finish to complete endpoint system mapping to enable path-style URL access7. Add endpoint system mapping to enable virtual-hosted-style URL access. Similar to Step 2 to Step 6 Go to Cloud To On-Premise and click the Add button Select Non-SAP System as back-end type Set Protocol to HTTPSSet Internal Host and Port – Internal host for Amazon S3 regional endpoint including the name of the bucket that you want to access (for example, <bucket-name>.s3.eu-central-1.amazonaws.com)Set Virtual Host and Port Hostname must be the same as the internal host and port can be different Deselect Allow Principal Propagationset Host in Request Header to Internal HostClick Finish to complete endpoint system mapping to enable virtual-hosted–style URL access8. Verify the connections for both mappings in SCC6. Add data source location to SAP DatasphereLogin in SAP Datasphere and navigate to SYSTEM –> AdministrationIn the Data Source Configuration section add the defined SCC location to the locations list7. Create AWS S3 connection in SAP Datasphere using SAP Cloud Connector 1. Login in SAP Datasphere and switch to the HANA<Space> or HDLF <space> to Create a new Connection to AWS S3 in Connection Management2. Click Amazon Simple Storage Service connection in Connection List3. Configure Connection parameters for Amazon Simple Storage with setting the Use Cloud Connector to True Make sure to select the created / corresponding Location for the SAP Cloud Connector instance4. Choose Next and enter connection information and click on Create Connection5. Validate the Connection to verify the connection status With these steps completed, your SAP Cloud Connector is successfully installed, connected, and configured to integrate and create a native connection type of Amazon simple storage service using private endpoints with SAP Datasphere . Now in data builder , you can configure and deploy a Replication Flow with Amazon simple storage service( AWS S3) as source .ConclusionSetting up private connectivity between SAP Datasphere and AWS S3 is straightforward when combining AWS PrivateLink with the SAP Cloud Connector. If you want to prevent your data from being routed publicly through the internet, you can use Cloud Connector as a TLS tunnel between the customer virtual private network and SAP Datasphere to privately route the data. The setup covered in this blog walks through each layer of the architecture: provisioning an EC2 instance inside the VPC to host the SAP Cloud Connector, routing S3 traffic through a VPC Interface Endpoint, and mapping virtual hosts to the private S3 PrivateLink DNS addresses. References:SAP Cloud Connector licensing, download and installation informationAmazon Simple Storage Service Connections “}]] Read More Technology Blog Posts by SAP articles
#SAPCHANNEL