You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

S3 Bucket策略能否覆盖IAM策略?及相关权限异常问题咨询

Why Your S3 Bucket Policy Isn't Blocking EC2 Access

Great question! Let's break this down clearly—this isn't about Bucket policies being unable to override IAM policies (they absolutely can, thanks to AWS's explicit Deny priority), but rather a small but critical mistake in how you defined your Bucket policy's Resource field.

The Root Cause: Incorrect Resource ARN

When you run aws s3 ls ananda-demo-bucket-1 from your EC2 instance, you're calling the s3:ListBucket API operation. This operation requires permissions targeted at the bucket itself, not the objects inside it.

Your current policy uses this resource ARN:

arn:aws:s3:::ananda-demo-bucket-1/

The trailing slash here tells AWS you're targeting objects within the bucket (specifically, all objects under the root prefix), not the bucket resource itself. So your Deny rule doesn't apply to the s3:ListBucket action—leaving the AmazonS3ReadOnlyAccess policy's Allow for that action intact.

Fixing the Bucket Policy

To block all actions on both the bucket and its contents, you need to include two resource ARNs in your policy:

  1. The bucket's base ARN (for bucket-level operations like ListBucket, CreateBucket, etc.)
  2. The bucket's object path ARN (for object-level operations like GetObject, PutObject, etc.)

Here's the corrected policy:

{
  "Action": "s3:*",
  "Effect": "Deny",
  "Resource": [
    "arn:aws:s3:::ananda-demo-bucket-1",
    "arn:aws:s3:::ananda-demo-bucket-1/*"
  ],
  "Principal": "*"
}

How AWS Permission Evaluation Works

Just to confirm: AWS follows a strict priority order for permissions:

  1. Explicit Deny (from any IAM policy, Bucket policy, or session policy) always takes precedence over any Allow.
  2. If no Deny exists, then check for Explicit Allow from any policy.
  3. If neither exists, access is denied by default.

So once you fix your resource ARNs, the Deny will override the IAM role's Allow, and your EC2 instance won't be able to list the bucket contents anymore.

Quick Test

After updating the policy, run this command from your EC2 instance to verify:

aws s3 ls ananda-demo-bucket-1

You should get an access denied error, confirming the policy is working as expected.

内容的提问来源于stack exchange,提问作者ananda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 19:27:39