You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用boto3的put_bucket_acl设置Ceph存储桶ACL时遇InvalidArgument错误

解决Ceph对象存储中boto3 put_bucket_acl的InvalidArgument异常

我之前也碰到过一模一样的问题,这本质是Ceph RADOS Gateway(RGW)的S3兼容API与AWS原生S3的行为差异导致的——AWS允许同时指定预定义ACL(比如'private')和自定义AccessControlPolicy参数,但Ceph的RGW不支持这种组合,会直接返回InvalidArgument: Unknown错误。

问题分析

你当前的调用同时传递了ACL='private'和AccessControlPolicy两个参数,这在AWS S3里是合法的(预定义ACL作为基础规则,再叠加自定义Grants),但Ceph RGW会把这种参数组合判定为无效输入。而当你移除AccessControlPolicy只保留ACL时,调用符合Ceph的参数要求,所以能成功执行。

解决方案

你需要二选一:要么只用预定义ACL,要么只用AccessControlPolicy来定义完整的权限规则。如果需要添加自定义Grants,推荐用第二种方式,具体修正如下:

修正后的代码示例

import boto3
import copy
from botocore.session import Session

s3_conf = {
    # 替换为你的实际配置
}
test_bucket = "your-target-bucket"
new_grants = {
    # 替换为你的实际权限规则,示例:
    # 'Grantee': {'Type': 'CanonicalUser', 'ID': 'your-user-id'},
    # 'Permission': 'READ'
}

# 使用Session方式的修正版本
session = Session(s3_conf["ak"], s3_conf["sk"])
s3_client = session.client("s3", endpoint_url=s3_conf["host"])

# 获取原有ACL规则
rsp = s3_client.get_bucket_acl(Bucket=test_bucket)
new_access_control_policy = copy.deepcopy({
    'Grants': rsp['Grants'],
    'Owner': rsp['Owner']
})

# 添加新的权限规则
new_access_control_policy['Grants'].append(new_grants)

# 关键:只传递AccessControlPolicy参数,不要同时传ACL
s3_client.put_bucket_acl(
    Bucket=test_bucket,
    AccessControlPolicy=new_access_control_policy
)

额外说明

如果你的目标是保持bucket私有性同时添加自定义权限,只需要确保AccessControlPolicy中的Owner拥有完整权限,自定义Grants只添加你需要的额外规则即可——这和ACL='private'的效果完全一致,同时兼容Ceph的要求。

boto3的官方文档是针对AWS S3编写的,Ceph作为S3兼容存储,在部分参数细节上会有差异,遇到这类问题时可以优先参考Ceph RGW的官方文档确认参数支持情况。

内容的提问来源于stack exchange,提问作者Joe Pal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:06:48