首次使用Boto3操作AWS S3遭遇访问拒绝问题求助
Let's break down your issue and fix it step by step:
First, the AccessDenied error on the ListBuckets operation tells us your AWS credentials don't have the s3:ListAllMyBuckets permission. But here's the key insight—you don't even need to list buckets to get your file, because you already have the bucket name from the provided URL!
Step 1: Extract the Bucket Name from the URL
The URL rkd.s3.amazonaws.com/file.csv follows S3's standard structure: the subdomain before .s3.amazonaws.com is always the bucket name. So your target bucket is rkd.
Step 2: Revise Your Code to Skip Bucket Listing
Instead of trying to list all buckets (which your credentials can't do), directly target the rkd bucket to download your CSV. Here's a adjusted version of your code focused on retrieving the specific file:
import boto3 from botocore.exceptions import ClientError class Storage(): """Connection to remote S3""" def __init__(self): self.s3 = boto3.resource('s3', aws_access_key_id=my_key_here, aws_secret_access_key=my_secret_key_here) # Use the known bucket name instead of listing all buckets self.bucket = self.s3.Bucket('rkd') def download_csv(self, remote_filename='file.csv', local_filename='local_file.csv'): try: self.bucket.download_file(remote_filename, local_filename) print(f"Successfully downloaded {remote_filename} to {local_filename}") except ClientError as e: if e.response['Error']['Code'] == "404": print("The target CSV file does not exist in the bucket.") else: # Re-raise other errors for debugging raise # Example usage storage = Storage() storage.download_csv()
Step 3: Confirm Required Permissions
Ensure your AWS credentials have the s3:GetObject permission for the target file. A minimal IAM policy for this task would look like:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::rkd/file.csv" } ] }
Why Your Original Code Failed
Your initial code calls self.s3.buckets.all(), which triggers the ListBuckets API. Most restricted AWS credentials don't grant this broad permission (it lets users see all buckets in the account), hence the AccessDenied error. By skipping this call and using the known bucket name, you avoid the permission issue entirely.
内容的提问来源于stack exchange,提问作者tadeo soresi

