AI Text-to-Speech using AWS Polly creates audio versions of WordPress posts with AWS Polly voices.
This is an independent plugin by iTRON. It is not affiliated with or endorsed by Amazon, AWS, or Amazon Polly.
Development and source code: https://github.com/hokoo/aws-polly
Key features:
Follow the steps below in order. They use the English names shown in the AWS and WordPress interfaces; translated interfaces place the same controls in the same sections.
You must sign in to AWS with an account that is allowed to create IAM policies, IAM users, access keys, and, when S3 storage is used, S3 buckets. In a company AWS account, these operations may be restricted; if AWS shows an authorization error, ask the AWS account administrator to complete the corresponding step.
The AWS terms used in this guide mean:
The plugin needs two credentials from AWS:
AKIA.These values are not the email address and password used to sign in to AWS. Never use an access key belonging to the AWS account root user. The instructions below create a separate user that can only call the AWS operations required by this plugin.
Choose one option before creating the AWS policy:
Amazon Polly is required in both cases and AWS usage may incur charges.
Polly and open Amazon Polly.us-east-1.Use this same Region for Polly, the optional S3 bucket, and the AWS Region setting in WordPress. A bucket’s Region cannot be changed after the bucket is created.
If you selected local WordPress storage in step 1, skip directly to step 4.
S3 at the top of the AWS Console.example-com-polly-audio-1234. Use only lowercase letters, numbers, and hyphens. The name must be unique across AWS, must not contain private information, and cannot be changed later. If AWS reports that the name already exists, add another random number and try again.example-com-polly-audio-1234; do not enter s3://, an ARN, or a web address in the bucket-name field.Official S3 bucket instructions: https://docs.aws.amazon.com/AmazonS3/latest/userguide/create-bucket-overview.html
An IAM policy is a document that tells AWS exactly what the plugin is allowed to do. Create one as follows:
IAM at the top of the AWS Console.For local WordPress storage, paste this policy exactly as shown:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "UseAmazonPolly",
"Effect": "Allow",
"Action": [
"polly:DescribeVoices",
"polly:SynthesizeSpeech"
],
"Resource": "*"
}
]
}
For Amazon S3 storage, first replace both occurrences of YOUR-BUCKET-NAME with the exact bucket name copied in step 3, then paste the complete policy. For example, arn:aws:s3:::YOUR-BUCKET-NAME becomes arn:aws:s3:::example-com-polly-audio-1234. Keep the arn:aws:s3::: prefix and keep the /* at the end of the second bucket resource.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "UseAmazonPolly",
"Effect": "Allow",
"Action": [
"polly:DescribeVoices",
"polly:SynthesizeSpeech"
],
"Resource": "*"
},
{
"Sid": "CheckAudioBucket",
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME"
},
{
"Sid": "ManageGeneratedAudio",
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:DeleteObject"
],
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME/*"
}
]
}
Resource: "*" value for the two Polly operations is expected; those operations require it and it does not grant access to other AWS services.WordPressPollyPlugin in Policy name. You can enter Permissions required by the AI Text-to-Speech WordPress plugin in Description.The S3 policy has three separate jobs: s3:ListBucket lets the plugin verify the bucket, s3:PutObject lets it upload MP3 files, and s3:DeleteObject lets it remove obsolete MP3 files. Do not use broad policies such as AdministratorAccess, AmazonPollyFullAccess, or AmazonS3FullAccess in place of the policy above.
Official policy instructions and permission references: https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_create-console.html, https://docs.aws.amazon.com/polly/latest/dg/api-permissions-reference.html, and https://docs.aws.amazon.com/AmazonS3/latest/userguide/using-with-s3-policy-actions.html
This is a technical user for the plugin. It does not need a password and nobody should use it to sign in to the AWS Console.
wordpress-polly-plugin or wordpress-polly-example-com.WordPressPollyPlugin.WordPressPollyPlugin must be listed under Permissions policies. If it is not listed, choose Add permissions, choose Attach policies directly, select it, and save.Official IAM user instructions: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html
wordpress-polly-plugin user, open the Security credentials tab.www.example.com, so the key can be identified later.If the secret is lost, do not try to recover it. Create a new access key, update WordPress, verify that it works, and then deactivate and delete the old key. An IAM user can have at most two access keys at the same time.
Official access-key instructions: https://docs.aws.amazon.com/IAM/latest/UserGuide/access-key-self-managed.html
The Access key ID and Secret access key must come from the same access key. Mixing an ID from one key with a secret from another key will always fail.
Complete this step only when Store audio in Amazon S3 is enabled. The plugin uploads MP3 files but does not change the bucket’s public-access settings.
The easiest direct-delivery setup uses a dedicated public bucket:
confirm.YOUR-BUCKET-NAME in the policy below with the exact bucket name. Do not remove the /* from the end of the resource.Paste the complete policy into the editor and choose Save changes.
{
“Version”: “2012-10-17”,
“Statement”: [
{
“Sid”: “PublicReadGeneratedAudio”,
“Effect”: “Allow”,
“Principal”: ““,
“Action”: “s3:GetObject”,
“Resource”: “arn:aws:s3:::YOUR-BUCKET-NAME/”
}
]
}
Use a bucket dedicated to plugin audio because this policy makes every object in that bucket downloadable by anyone who knows its URL. If AWS refuses to save the policy, the account-level Block Public Access setting may still prohibit public buckets. Do not change an account-wide security setting unless you understand how it affects the account’s other buckets. In that situation, ask the AWS account administrator for help or use Amazon CloudFront with a private S3 origin and Origin Access Control, then enter the CloudFront distribution domain in the plugin settings.
Official public-read instructions: https://docs.aws.amazon.com/AmazonS3/latest/userguide/WebsiteAccessPermissionsReqd.html
itron_polly_tts_123.mp3, optionally inside year/month folders.Common problems:
WordPressPollyPlugin is attached to the IAM user, and the selected Region supports Amazon Polly.WordPressPollyPlugin contain that exact name and that Store audio in Amazon S3 is enabled only when a bucket is configured.arn:aws:s3:::example-com-polly-audio-1234; an object ARN must have /* at the end.The steps above save the credentials in WordPress so that the setup is straightforward. For a production site, an administrator can instead define them in wp-config.php or another PHP config file loaded before WordPress finishes bootstrapping. This keeps them out of the WordPress options table. The configuration file must be outside version control and readable only by the server account that needs it:
define( 'ITRON_POLLY_TTS_S3_ACCESS_KEY', 'your-access-key' );
define( 'ITRON_POLLY_TTS_S3_SECRET_KEY', 'your-secret-key' );
You can also lock the bucket and region in PHP the same way:
define( 'ITRON_POLLY_TTS_S3_BUCKET_NAME', 'your-s3-bucket' );
define( 'ITRON_POLLY_TTS_S3_REGION', 'us-east-1' );
When these constants are present, the plugin uses them instead of saved options and shows the related admin fields as defined by PHP constant. Do not commit real secrets into version control.
Use the IAM user and access key only for this plugin. Review the key’s last-used date, rotate it periodically, and deactivate or delete it immediately if it is exposed or no longer needed. Do …