You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在不赋予公共访问权限的情况下在AWS S3上托管静态网站?

Secure Static Site Hosting on S3 Without Public Access

Absolutely, you can host a static website on S3 without enabling public bucket access—in fact, this is the secure, recommended approach these days, especially when your account has public access blocked at the account level. Let’s break down the best way to do this using CloudFront with Origin Access Control (OAC):

Step 1: Keep Your S3 Bucket Private

Since your account already blocks public access for all buckets, you don’t need to change anything here. Ensure:

  • The bucket has no public bucket policies attached
  • The "Block all public access" settings remain enabled (they should be, thanks to your account-level configuration)
  • Object permissions stay set to private (the default for new objects)

Step 2: Set Up CloudFront with Origin Access Control (OAC)

CloudFront acts as a secure intermediary between your users and S3—users access your site via CloudFront’s domain, and CloudFront fetches content from your private S3 bucket.

  1. Create a CloudFront Distribution:

    • Under "Origin domain", select your S3 bucket (use the REST API endpoint like your-bucket-name.s3.amazonaws.com, not the static website hosting endpoint)
    • For "Origin access", select "Origin access control settings (recommended)"
    • Click "Create control setting" to make a new OAC:
      • Name it something descriptive (e.g., MyStaticSiteOAC)
      • Origin type: S3
      • Check "Sign requests"
    • Save the OAC, and CloudFront will prompt you to update your S3 bucket policy—allow this (it adds a policy that lets CloudFront access your bucket’s content without making it public)
  2. Configure CloudFront Behavior:

    • In the "Default cache behavior" section:
      • Set "Viewer protocol policy" to Redirect HTTP to HTTPS (for better security)
      • Ensure "Allowed HTTP methods" includes GET and HEAD (these are the only methods needed for static sites)
      • Use the default cache policy, or create a custom one if you need specific caching rules for your content

Even though your bucket is private, you can still enable S3’s static website hosting feature to handle index/error pages properly:

  • Go to your S3 bucket’s "Properties" tab
  • Scroll to "Static website hosting" and enable it
  • Set your index document (e.g., index.html) and error document (e.g., error.html)
    This ensures that when CloudFront forwards requests to S3, S3 serves the correct pages for root paths or missing files.

Step 4: Test Your Site

Wait 10-15 minutes for CloudFront to deploy your distribution, then visit the CloudFront domain (found in the CloudFront console). You’ll see your static site load correctly, but if you try to access the S3 bucket directly (via its REST or static website URL), you’ll get an access denied error—confirming your bucket stays private.

Bonus: Alternative for Non-Public Sites

If you don’t need your site to be publicly accessible (e.g., internal team use only), you can use IAM authentication:

  • Grant specific IAM users/roles the s3:GetObject permission for your bucket
  • Users can access the site via AWS SDKs, the AWS CLI, or pre-signed URLs generated with their credentials
    This isn’t ideal for public sites, but works great for restricted access scenarios.

内容的提问来源于stack exchange,提问作者Aman Mulani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 10:17:45