Setting up EMR Serverless - Amazon EMR
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China.

Setting up EMR Serverless

Sign up for your Amazon Web Services account

When you sign up for Amazon, you automatically sign up your Amazon Web Services account for all services, including the generally available Amazon EMR deployment options. If you have an Amazon Web Services account already, skip to Create a user and grant permissions. If you don't have an Amazon Web Services account, use the following procedure to create one.

To create an Amazon Web Services account

  1. Open

  2. Follow the online instructions. Part of the sign-up procedure involves receiving a phone call and entering a verification code on the phone keypad.

Create a user and grant permissions

As a best practice, create an Amazon Identity and Access Management (IAM) user with administrator permissions, and then use that IAM user for all work that doesn't require root credentials. Navigate to the IAM console at, create a password for console access, and create access keys to use command line tools. For instructions, see Creating your first IAM admin user and group in the IAM User Guide.

After you create an IAM user or role to work with EMR Serverless, attach an IAM policy to the user so that the user has sufficient permissions to invoke EMR Serverless actions. A policy similar to the following policy is ideal to get started.

{ "Version": "2012-10-17", "Statement": [ { "Sid": "EMRStudioCreate", "Effect": "Allow", "Action": [ "elasticmapreduce:CreateStudioPresignedUrl", "elasticmapreduce:DescribeStudio", "elasticmapreduce:CreateStudio", "elasticmapreduce:ListStudios" ], "Resource": "*" }, { "Sid": "EMRServerlessFullAccess", "Effect": "Allow", "Action": [ "emr-serverless:*" ], "Resource": "*" }, { "Sid": "AllowEC2ENICreationWithEMRTags", "Effect": "Allow", "Action": [ "ec2:CreateNetworkInterface" ], "Resource": [ "arn:aws:ec2:*:*:network-interface/*" ], "Condition": { "StringEquals": { "aws:CalledViaLast": "" } } }, { "Sid": "AllowEMRServerlessServiceLinkedRoleCreation", "Effect": "Allow", "Action": "iam:CreateServiceLinkedRole", "Resource": "arn:aws:iam::*:role/aws-service-role/*" } ] }

In production environments, we recommend that you use finer-grained policies. For examples of such policies, see User access policy examples for EMR Serverless. To learn more about access management, see Access management for Amazon resources in the IAM User Guide.

You can use this same process to create more groups and users and to give your users access to your Amazon Web Services account resources.

Install and configure the Amazon CLI

If you want to use EMR Serverless APIs, you must install the latest version of the Amazon Command Line Interface (Amazon CLI). You don't need the Amazon CLI to use EMR Serverless from the EMR Studio console, and you can get started without the CLI by following the steps in Getting started from the console.

To set up the Amazon CLI

  1. To install the latest version of the Amazon CLI for macOS, Linux, or Windows, see Installing or updating the latest version of the Amazon CLI.

  2. To configure the Amazon CLI and secure setup of your access to Amazon Web Services, including EMR Serverless, see Quick configuration with aws configure.

  3. To verify the setup, enter the following DataBrew command at the command prompt.

    aws emr-serverless help

    Amazon CLI commands use the default Amazon Web Services Region from your configuration, unless you set it with a parameter or a profile. To set your Amazon Web Services Region with a parameter, you can add the --region parameter to each command.

    To set your Amazon Web Services Region with a profile, first add a named profile in the ~/.aws/config file or the %UserProfile%/.aws/config file (for Microsoft Windows). Follow the steps in Named profiles for the Amazon CLI. Next, set your Amazon Web Services Region and other settings with a command similar to the one in the following example.

    [profile emr-serverless] aws_access_key_id = ACCESS-KEY-ID-OF-IAM-USER aws_secret_access_key = SECRET-ACCESS-KEY-ID-OF-IAM-USER region = us-east-1 output = text

Open the console

Most of the console-oriented topics in this section start from the Amazon EMR console. If you aren't already signed in to your Amazon Web Services account, sign in, then open the Amazon EMR console and continue to the next section to continue getting started with Amazon EMR.