如何在不赋予公共访问权限的情况下在AWS S3上托管静态网站?
Absolutely, you can host a static website on S3 without enabling public bucket access—in fact, this is the secure, recommended approach these days, especially when your account has public access blocked at the account level. Let’s break down the best way to do this using CloudFront with Origin Access Control (OAC):
Step 1: Keep Your S3 Bucket Private
Since your account already blocks public access for all buckets, you don’t need to change anything here. Ensure:
- The bucket has no public bucket policies attached
- The "Block all public access" settings remain enabled (they should be, thanks to your account-level configuration)
- Object permissions stay set to private (the default for new objects)
Step 2: Set Up CloudFront with Origin Access Control (OAC)
CloudFront acts as a secure intermediary between your users and S3—users access your site via CloudFront’s domain, and CloudFront fetches content from your private S3 bucket.
Create a CloudFront Distribution:
- Under "Origin domain", select your S3 bucket (use the REST API endpoint like
your-bucket-name.s3.amazonaws.com, not the static website hosting endpoint) - For "Origin access", select "Origin access control settings (recommended)"
- Click "Create control setting" to make a new OAC:
- Name it something descriptive (e.g.,
MyStaticSiteOAC) - Origin type:
S3 - Check "Sign requests"
- Name it something descriptive (e.g.,
- Save the OAC, and CloudFront will prompt you to update your S3 bucket policy—allow this (it adds a policy that lets CloudFront access your bucket’s content without making it public)
- Under "Origin domain", select your S3 bucket (use the REST API endpoint like
Configure CloudFront Behavior:
- In the "Default cache behavior" section:
- Set "Viewer protocol policy" to
Redirect HTTP to HTTPS(for better security) - Ensure "Allowed HTTP methods" includes
GETandHEAD(these are the only methods needed for static sites) - Use the default cache policy, or create a custom one if you need specific caching rules for your content
- Set "Viewer protocol policy" to
- In the "Default cache behavior" section:
Step 3: Optional (But Recommended) – Enable S3 Static Site Configuration
Even though your bucket is private, you can still enable S3’s static website hosting feature to handle index/error pages properly:
- Go to your S3 bucket’s "Properties" tab
- Scroll to "Static website hosting" and enable it
- Set your index document (e.g.,
index.html) and error document (e.g.,error.html)
This ensures that when CloudFront forwards requests to S3, S3 serves the correct pages for root paths or missing files.
Step 4: Test Your Site
Wait 10-15 minutes for CloudFront to deploy your distribution, then visit the CloudFront domain (found in the CloudFront console). You’ll see your static site load correctly, but if you try to access the S3 bucket directly (via its REST or static website URL), you’ll get an access denied error—confirming your bucket stays private.
Bonus: Alternative for Non-Public Sites
If you don’t need your site to be publicly accessible (e.g., internal team use only), you can use IAM authentication:
- Grant specific IAM users/roles the
s3:GetObjectpermission for your bucket - Users can access the site via AWS SDKs, the AWS CLI, or pre-signed URLs generated with their credentials
This isn’t ideal for public sites, but works great for restricted access scenarios.
内容的提问来源于stack exchange,提问作者Aman Mulani

