通过CloudFront访问S3网站出现Access Denied问题求助
解决S3+CloudFront访问拒绝(AccessDenied)问题
问题现象
浏览器访问CloudFront分发URL时出现以下错误:
return (<Error> <Code>AccessDenied</Code> <Message>Access Denied</Message> <RequestId>TKHNQGGSSHY3ZH6T</RequestId> <HostId>zXD7uBIpJUGHaUl8m5/9xtm2cnvX/Kok6rYp0oz6RFbqJeLreohaOWHx4jHJ/F675UGxo1SfEYs= </HostId> </Error> )
当前SAM模板配置
前端相关资源的SAM CloudFormation模板片段:
##################### FRONTEND StockMonitorFeBucket: Type: 'AWS::S3::Bucket' DeletionPolicy: Delete Properties: BucketName: osotnikov-stock-monitor-front-end-resources-s3-bucket AccessControl: Private PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true StockMonitorFeBucketDistributionOriginAccessIdentity: Type: 'AWS::CloudFront::CloudFrontOriginAccessIdentity' Properties: CloudFrontOriginAccessIdentityConfig: Comment: This is the origin access identity (simply user). StockMonitorFeBucketDistribution: Type: 'AWS::CloudFront::Distribution' DependsOn: - StockMonitorFeBucket - StockMonitorFeBucketDistributionOriginAccessIdentity Properties: DistributionConfig: Origins: - DomainName: !GetAtt - StockMonitorFeBucket - DomainName Id: StockMonitorFeBucketCloudFrontOrigin S3OriginConfig: OriginAccessIdentity: !Sub >- origin-access-identity/cloudfront/${StockMonitorFeBucketDistributionOriginAccessIdentity} Enabled: 'true' DefaultCacheBehavior: TargetOriginId: StockMonitorFeBucketCloudFrontOrigin ForwardedValues: QueryString: 'false' ViewerProtocolPolicy: allow-all StockMonitorFeBucketPolicy: Type: 'AWS::S3::BucketPolicy' DependsOn: - StockMonitorFeBucket - StockMonitorFeBucketDistributionOriginAccessIdentity - StockMonitorFeBucketDistribution Properties: Bucket: !Ref StockMonitorFeBucket PolicyDocument: Statement: - Sid: cloudFrontReadAccess Effect: Allow Principal: CanonicalUser: !GetAtt - StockMonitorFeBucketDistributionOriginAccessIdentity - S3CanonicalUserId Action: 's3:GetObject' Resource: >- arn:aws:s3:::osotnikov-stock-monitor-front-end-resources-s3-bucket/*
部署后实际生效的BucketPolicy:
{ "Version": "2008-10-17", "Statement": [ { "Sid": "cloudFrontReadAccess", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E1V8NTQPK5FD7P" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::osotnikov-stock-monitor-front-end-resources-s3-bucket/*" } ] }
错误配置尝试及问题
尝试拼接OAI ARN时出现语法错误:
Properties: Bucket: !Ref StockMonitorFeBucket PolicyDocument: Statement: - Sid: cloudFrontReadAccess Effect: Allow Principal: AWS: !Join - ' ' - - 'arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity' - - !GetAtt [ StockMonitorFeBucketDistributionOriginAccessIdentity, S3CanonicalUserId ] Action: 's3:GetObject' Resource: >- arn:aws:s3:::osotnikov-stock-monitor-front-end-resources-s3-bucket/*
收到错误:a string delimiter and (2) a list of strings to be joined or a function that returns a list of strings (such as Fn::GetAZs) to be joined.
修改后又收到主体无效错误:
Principal: AWS: !Join [' ', ['arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity', !GetAtt [StockMonitorFeBucketDistributionOriginAccessIdentity, S3CanonicalUserId]]]
错误信息:Invalid principal in policy
正确解决方案
方案:直接用!Sub生成OAI的ARN(简单可靠)
修改StockMonitorFeBucketPolicy的Principal配置,通过CloudFormation变量替换自动生成正确的OAI ARN,避免手动拼接错误:
StockMonitorFeBucketPolicy: Type: 'AWS::S3::BucketPolicy' DependsOn: - StockMonitorFeBucket - StockMonitorFeBucketDistributionOriginAccessIdentity Properties: Bucket: !Ref StockMonitorFeBucket PolicyDocument: Statement: - Sid: cloudFrontReadAccess Effect: Allow Principal: AWS: !Sub 'arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity ${StockMonitorFeBucketDistributionOriginAccessIdentity}' Action: 's3:GetObject' Resource: !Sub 'arn:aws:s3:::${StockMonitorFeBucket}/*'
额外检查项
- CloudFront Origin配置:现有
S3OriginConfig中的OriginAccessIdentity格式正确,无需修改。 - S3对象权限:上传的文件无需设置公开权限,CloudFront会通过OAI访问,仅需Bucket Policy授权即可。
- PublicAccessBlock配置:当前严格的PublicAccessBlock设置符合安全要求,无需调整。
验证步骤
- 重新部署修改后的SAM模板。
- 等待CloudFront分发完成部署(约10-15分钟)。
- 访问CloudFront分发URL,确认AccessDenied错误消失。
内容的提问来源于stack exchange,提问作者Bat0u89
相关产品推荐
相关产品推荐

