跨区域SageMaker容器访问S3时GetObject报AccessDenied求助
Hey there! Let's break down why you're hitting that AccessDenied error when calling get_object, even though you can successfully list bucket objects.
1. The Key you're using isn't a valid object
First off, '2019/3/' is a prefix (simulated folder) in S3, not an actual object file. S3 doesn't have real folders—what looks like a folder is just a segment of an object's key path. The get_object API requires a specific object key (like '2019/3/your-file.csv'), not a prefix.
If you want to retrieve all objects under that prefix, use list_objects_v2 instead:
s3 = boto3.client('s3', region_name='us-east-1') response = s3.list_objects_v2(Bucket='bucket-name', Prefix='2019/3/', Delimiter='/') # Iterate through objects under the prefix for item in response.get('Contents', []): print(f"Object key: {item['Key']}")
2. Double-check your permissions (even if you think they're set)
Since you can list objects, your IAM role has s3:ListBucket permissions, but s3:GetObject needs its own explicit access rules. Here are key checks:
- IAM Role Permissions: Ensure the SageMaker execution role includes a policy that allows
s3:GetObjectfor the target objects. The resource should cover the specific prefix or objects, like:
(The{ "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket-name/2019/3/*" }*at the end matches all objects under the2019/3/prefix.) - Bucket Policy: Look for any
Denystatements in the bucket policy—these take precedence overAllowrules, so even if you have explicit access, a Deny can block it. - Object ACLs: Individual objects might have their own ACL settings that restrict access. Confirm the object's ACL grants read access to your SageMaker role or the associated AWS account.
3. Verify bucket region consistency
Even though you specified region_name='us-east-1', double-check that your S3 bucket is actually hosted in us-east-1. If the bucket is in a different region, cross-region access might need additional configuration (though this is less likely to trigger an AccessDenied error directly, it's still worth confirming).
Example: Correctly using get_object for a specific file
Once you have the valid object key, use get_object like this:
s3 = boto3.client('s3', region_name='us-east-1') # Replace with your actual object key obj = s3.get_object(Bucket='bucket-name', Key='2019/3/sample-data.csv') # Read the object content content = obj['Body'].read().decode('utf-8') print(content)
内容的提问来源于stack exchange,提问作者Ravi

