You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨区域SageMaker容器访问S3时GetObject报AccessDenied求助

Troubleshooting AccessDenied Error with S3 get_object from SageMaker Container

Hey there! Let's break down why you're hitting that AccessDenied error when calling get_object, even though you can successfully list bucket objects.

1. The Key you're using isn't a valid object

First off, '2019/3/' is a prefix (simulated folder) in S3, not an actual object file. S3 doesn't have real folders—what looks like a folder is just a segment of an object's key path. The get_object API requires a specific object key (like '2019/3/your-file.csv'), not a prefix.

If you want to retrieve all objects under that prefix, use list_objects_v2 instead:

s3 = boto3.client('s3', region_name='us-east-1')
response = s3.list_objects_v2(Bucket='bucket-name', Prefix='2019/3/', Delimiter='/')
# Iterate through objects under the prefix
for item in response.get('Contents', []):
    print(f"Object key: {item['Key']}")

2. Double-check your permissions (even if you think they're set)

Since you can list objects, your IAM role has s3:ListBucket permissions, but s3:GetObject needs its own explicit access rules. Here are key checks:

  • IAM Role Permissions: Ensure the SageMaker execution role includes a policy that allows s3:GetObject for the target objects. The resource should cover the specific prefix or objects, like:
    {
        "Effect": "Allow",
        "Action": "s3:GetObject",
        "Resource": "arn:aws:s3:::bucket-name/2019/3/*"
    }
    
    (The * at the end matches all objects under the 2019/3/ prefix.)
  • Bucket Policy: Look for any Deny statements in the bucket policy—these take precedence over Allow rules, so even if you have explicit access, a Deny can block it.
  • Object ACLs: Individual objects might have their own ACL settings that restrict access. Confirm the object's ACL grants read access to your SageMaker role or the associated AWS account.

3. Verify bucket region consistency

Even though you specified region_name='us-east-1', double-check that your S3 bucket is actually hosted in us-east-1. If the bucket is in a different region, cross-region access might need additional configuration (though this is less likely to trigger an AccessDenied error directly, it's still worth confirming).

Example: Correctly using get_object for a specific file

Once you have the valid object key, use get_object like this:

s3 = boto3.client('s3', region_name='us-east-1')
# Replace with your actual object key
obj = s3.get_object(Bucket='bucket-name', Key='2019/3/sample-data.csv')
# Read the object content
content = obj['Body'].read().decode('utf-8')
print(content)

内容的提问来源于stack exchange,提问作者Ravi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 20:12:57