> For the complete documentation index, see [llms.txt](https://docs.teleskope.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.teleskope.ai/connectors/aws/efs.md).

# EFS

Teleskope's EFS connector scans Amazon Elastic File System (EFS) for sensitive data. Because EFS filesystems are mounted over NFS within a VPC, scanning requires a Teleskope **Outpost**, a lightweight agent deployed inside the same VPC as your EFS mount target. The Outpost handles all filesystem access locally. Depending on the deployment's classification mode, classification runs on the Outpost or content being classified is sent over TLS to your isolated Teleskope environment.

## Requirements

| Requirement            | Details                                                                                                    |
| ---------------------- | ---------------------------------------------------------------------------------------------------------- |
| Teleskope Role         | An IAM role in your AWS account with the EFS control-plane permissions below, trusted by the Teleskope hub |
| Teleskope Outpost      | A Teleskope Outpost deployed in the same VPC as your EFS mount target — required for filesystem access     |
| Network access         | The Outpost node must be able to reach the EFS mount target on port `2049` (NFS)                           |
| Teleskope account role | Admin role in the Teleskope platform                                                                       |

***

{% stepper %}
{% step %}

#### Grant Teleskope Read Access to EFS

Attach the following least-privilege policy to the Teleskope IAM role in your account. This allows the Teleskope hub to discover EFS filesystems via the AWS control plane — no VPC access is required for this step.

**Terraform**

```
resource "aws_iam_policy" "teleskope_efs_policy" {
  name        = "TeleskopeEFSPolicy"
  description = "Grants Teleskope read access to discover EFS filesystems"

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect = "Allow"
        Action = [
          "elasticfilesystem:DescribeFileSystems",
          "elasticfilesystem:DescribeMountTargets",
          "elasticfilesystem:DescribeMountTargetSecurityGroups",
          "elasticfilesystem:DescribeTags",
          "elasticfilesystem:ListTagsForResource"
        ]
        Resource = "*"
      }
    ]
  })
}

resource "aws_iam_role_policy_attachment" "teleskope_efs" {
  role       = "TeleskopeRole"
  policy_arn = aws_iam_policy.teleskope_efs_policy.arn
}
```

{% endstep %}

{% step %}

#### Deploy a Teleskope Outpost in your VPC

EFS filesystems are accessed over NFS and require a node in the same VPC as the mount target. Teleskope uses an Outpost, a self-managed agent deployed in your environment, to keep filesystem access inside the VPC.

* Follow the **Outpost setup guide** to deploy the Outpost in the same VPC and availability zone as your EFS mount target
* Ensure the Outpost node's security group allows outbound access on port `2049` to the EFS mount target security group
* The EFS filesystem is mounted at `/mnt/efs` on the Outpost via the EFS CSI driver — the Outpost crawler walks the directory tree over the local mount
* The Outpost communicates results back to the Teleskope hub via HTTPS — ensure the Outpost has outbound internet access or a VPC endpoint to the Teleskope API

Currently, each Outpost supports one EFS filesystem. If you have multiple filesystems, deploy one Outpost per filesystem.
{% endstep %}

{% step %}

#### Enroll the EFS Connector in Teleskope

Once the IAM role and Outpost are in place, enroll the connector from the Teleskope settings page.

* Navigate to **Settings → Connectors → AWS**
* Click **Enroll+**
* Enter your **AWS Account ID** and the **IAM role ARN** for the Teleskope role you configured
* Navigate to **EFS** and enroll the desired accounts
* Teleskope will call `DescribeFileSystems` to discover filesystems in your account and display them in the connector settings
* Your Outpost will begin crawling the assigned filesystem according to the set crawling schedule
  {% endstep %}
  {% endstepper %}
