You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

S3关闭公共访问后,CloudFront能否正常提供文件服务?

Can CloudFront Serve Content if S3 Public Access is Disabled?

Absolutely! You can fully lock down your S3 bucket's public access and still have CloudFront serve your content seamlessly—in fact, this is the secure, recommended configuration for hosting static content with AWS. Here's why and how it works:

Core Concept

CloudFront doesn't rely on public S3 access to fetch your content. Instead, it uses a dedicated identity to authenticate with S3: either an Origin Access Control (OAC) (the modern, preferred option) or an older Origin Access Identity (OAI). As long as you grant this identity permission to access your S3 bucket, the bucket can remain completely private to the public.

Step-by-Step Secure Setup

  • Create an Origin Access Control (OAC) in the CloudFront console when configuring your S3 origin. OAC supports more features than OAI, like signed URLs and REST API access to S3.
  • Associate the OAC with your CloudFront distribution when linking it to your S3 bucket.
  • Update your S3 bucket policy to allow the CloudFront OAC to retrieve objects. Here's a sample policy (replace placeholders with your actual values):
    {
      "Version": "2008-10-17",
      "Id": "PolicyForCloudFrontPrivateContent",
      "Statement": [
        {
          "Sid": "AllowCloudFrontAccess",
          "Effect": "Allow",
          "Principal": {
            "Service": "cloudfront.amazonaws.com"
          },
          "Action": "s3:GetObject",
          "Resource": "arn:aws:s3:::your-bucket-name/*",
          "Condition": {
            "StringEquals": {
              "AWS:SourceArn": "arn:aws:cloudfront::your-aws-account-id:distribution/your-cloudfront-distribution-id"
            }
          }
        }
      ]
    }
    
  • Disable all public access settings for your S3 bucket: go to the S3 console, navigate to your bucket's "Permissions" tab, and enable all four options under "Block public access (bucket settings)".

Key Outcome

Once configured, direct public requests to your S3 bucket URLs will be denied, but CloudFront will still fetch and serve your content to end-users without any interruptions. This setup eliminates the risk of accidental public exposure of your S3 content while maintaining the performance benefits of CloudFront.

内容的提问来源于stack exchange,提问作者Francisco Carriedo Scher

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:13:48