You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Amazon S3存储桶以允许所有IP/设备及所有人访问?

Hey there! Let's tackle your S3 bucket access issues step by step—both allowing universal access and fixing the "unable to access" problem after creation.

解决Amazon S3存储桶公开访问及权限问题

首先:关闭默认的公共访问阻止设置

AWS enables strict public access blocks by default to keep your buckets secure, so we need to turn these off first:

  • Head to the AWS Management Console and navigate to the S3 service.
  • Find your target bucket, click into its Permissions tab.
  • Look for Block Public Access (bucket settings) and hit "Edit".
  • Uncheck all four options listed (Block new public bucket policies, Block public and cross-account access if bucket has public policies, Block new public ACLs, Block public access through any ACLs) then save the changes.

第二步:添加存储桶策略以允许所有人访问

Next, we'll add a bucket policy that grants public read access to all objects in your bucket. Here's the JSON you need—just replace your-bucket-name with your actual bucket's name:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::your-bucket-name/*"
    }
  ]
}
  • The Principal: "*" means any user/device (from any IP) can access the objects.
  • The Resource line with /* targets all objects inside the bucket (not the bucket itself).

如果需要明确指定允许所有IP访问(更严谨的写法)

If you want to explicitly restrict access to all IP addresses (though the above policy already does this), you can add a Condition to the statement:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::your-bucket-name/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": ["0.0.0.0/0", "::/0"]
        }
      }
    }
  ]
}
  • 0.0.0.0/0 covers all IPv4 addresses, while ::/0 covers all IPv6 addresses.

关于S3访问点的注意事项

When creating an access point, it inherits permissions from the bucket's policy by default. So as long as your bucket policy allows public access, the access point will also allow it. If you need a separate policy for the access point, you can attach one directly, but the core bucket-level permissions still need to be configured as above.

重要安全提醒

Warning: Making your bucket public means anyone on the internet can download all its contents. Only do this if your data is non-sensitive and intended for public access. Also, consider enabling S3 Access Logs to monitor who's accessing your bucket.

内容的提问来源于stack exchange,提问作者berriz44

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 18:27:36