You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Node.js(Node-RED)连接IBM COS遇403权限拒绝问题排查

Troubleshooting 403 Access Denied When Listing IBM COS Buckets via S3-Compatible API

Let's break down the issues you're facing with your curl request to list IBM Cloud Object Storage (COS) buckets, and fix the 403 error step by step:

Common Causes & Fixes

1. Missing or Incorrect IAM Permissions

This is the most frequent reason for 403 errors here. Your IAM token needs explicit permissions to list buckets for the target COS instance:

  • Head to the IBM Cloud Console, navigate to your COS instance, then go to Access policies.
  • Ensure the service ID or user linked to your IAM token has a role that includes the cos.list_buckets permission (e.g., Reader, Writer, Manager, or a custom policy with this specific action).
  • Double-check that the ibm-service-instance-id header value exactly matches your actual COS instance ID (you can retrieve this via the CLI command ibmcloud resource service-instances).

2. Invalid or Expired IAM Token

IAM tokens have a default 1-hour expiration window. Make sure you're using a freshly generated token:

  • Generate a valid token with the IBM Cloud CLI:
    ibmcloud iam oauth-tokens
    
  • Use the value labeled IAM token (not the UAA token) in your Authorization: Bearer header.

3. Redundant Request Headers

Your request has duplicate Host and cache-control headers, which might cause unexpected parsing issues. Clean up your headers to avoid conflicts—keep only one instance of each required header.

4. Endpoint & Region Mismatch

Confirm that the endpoint s3.us-south.cloud-object-storage.appdomain.cloud matches the region where your COS instance is provisioned. If your instance lives in a different region (e.g., eu-gb), you'll need to swap in the corresponding regional endpoint.

Corrected Curl Example

Here's a cleaned-up, valid curl command to list your buckets:

curl -X GET "https://s3.us-south.cloud-object-storage.appdomain.cloud/" \
  -H "ibm-service-instance-id: YOUR_CORRECT_INSTANCE_ID" \
  -H "Authorization: Bearer YOUR_FRESH_IAM_TOKEN"

Additional Verification Steps

  • Use the IBM Cloud IAM Policy Advisor to validate that your token has the necessary access rights to list buckets.
  • If you still hit a 403, check the IBM Cloud Activity Tracker logs for your COS instance—they’ll provide detailed context about why the request was rejected.

内容的提问来源于stack exchange,提问作者Itération 122442

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:33:40