You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

执行GitHub Actions上传S3遇AccessControlListNotSupported错误求助

解决GitHub Actions上传S3时的AccessControlListNotSupported错误

问题分析

你遇到的AccessControlListNotSupported: The bucket does not allow ACLs错误,核心原因是当前S3桶的配置禁用了ACL功能,但上传代码中明确指定了ACL: 'public-read'参数。本地运行正常可能是因为本地使用的S3桶配置允许ACLs,或者本地凭证对应的权限/桶设置与GitHub Actions使用的不一致。

解决方案

1. 调整S3桶的对象所有权设置

进入S3桶的权限页面,找到对象所有权选项:

  • 将当前设置从Bucket owner enforced(默认禁用ACLs)修改为Bucket owner preferred或Object writer,这两种模式支持使用ACLs。
  • 保存设置后重新运行GitHub Actions工作流。

2. 移除代码中的ACL参数(推荐)

如果不需要通过ACL控制对象权限,或者希望保持Bucket owner enforced的默认安全配置,直接删除代码中的ACL字段:

return client.send(
  new PutObjectCommand({
    Bucket: bucket,
    Key: filename,
    Body: xlsxContent,
    ContentType:
      'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet',
    // 移除ACL参数
  })
);

若需要让对象公开可读,改用桶策略配置,在桶的权限页面添加如下策略(替换your-bucket-name):

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::your-bucket-name/*"
    }
  ]
}

3. 检查阻止公共访问设置

如果需要通过ACL控制公开访问,确保桶的阻止公共访问设置中:

  • Block public access to buckets and objects granted through any access control lists (ACLs)选项处于关闭状态。

4. 验证GitHub Actions的IAM权限

确认GitHub Actions使用的IAM角色/用户拥有以下权限:

  • s3:PutObject:允许上传对象到桶
  • 若使用ACL控制权限,额外需要s3:PutObjectAcl权限

内容的提问来源于stack exchange,提问作者Marwa Iben Khalifa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 18:35:00