使用Boto3通过Python访问AWS S3时遭遇AccessDenied错误,无法列出存储桶内容
Hey there! As someone who's fumbled through similar S3 permission snags when starting out with AWS and Boto3, let's break down the most likely reasons you're hitting this error and how to fix them.
1. Make Sure Your IAM Permissions Are Set Correctly
First things first: the IAM entity (user or role linked to your mfa_0729 profile) needs the s3:ListBucket permission specifically for your my-bucket-name bucket.
Double-check your IAM policy to ensure it includes something like this (adjust the resource and condition to match your setup):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::my-bucket-name", "Condition": { "StringLike": { "s3:prefix": "my-claim-name*" } } } ] }
The condition here ensures you can list objects starting with your StartAfter prefix. If you don't need the prefix restriction, you can omit the condition and just grant s3:ListBucket on the full bucket ARN.
2. Verify Your MFA Session Credentials Are Active
Even though you stored the session token in your profile, it's worth confirming the credentials your Boto3 session is using are valid and complete. Add a quick debug print to check:
print(f"Access Key: {credentials.access_key}") print(f"Secret Key: {credentials.secret_key}") print(f"Session Token: {credentials.token}")
- If the session token is empty or expired (MFA sessions usually last 12 hours), you'll need to generate a new set of credentials via STS (either using the AWS CLI or Boto3's STS client).
- Ensure your
~/.aws/credentials(orC:\Users\<YourUsername>\.aws\credentialson Windows) file for themfa_0729profile has all three required values:aws_access_key_id,aws_secret_access_key, andaws_session_token.
3. Check the Bucket Policy for Deny Statements
Bucket policies take priority over IAM policies, so even if your IAM user has permissions, a Deny statement in the bucket policy could block access.
Head to the S3 console, navigate to your bucket's Permissions tab, and review the Bucket Policy. Look for any statements that might deny s3:ListBucket access to your user/role ARN. If you find one, either remove it (if appropriate) or add an explicit Allow statement that overrides the Deny.
4. Test with AWS CLI to Isolate the Issue
To rule out code-specific problems, test the same operation using the AWS CLI:
aws s3 ls s3://my-bucket-name/my-claim-name --profile mfa_0729
- If the CLI throws the same AccessDenied error, the problem is with your credentials or permissions—not your Python code.
- If the CLI works, double-check your Boto3 code for typos (like a misspelled bucket name or
StartAftervalue) — your current code looks solid, but small typos happen!
5. Rule Out Higher-Level IAM Restrictions
If you're part of an AWS Organization, check if there's a Service Control Policy (SCP) that restricts S3 access for your account. Also, verify if your IAM user has a Permission Boundary that limits the permissions they can use. Both of these can override your individual IAM policy.
内容的提问来源于stack exchange,提问作者RB17

