You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用AWS CLI为现有S3桶策略添加强制SSL访问语句

How to Update S3 Bucket Policy via AWS CLI to Retain Existing Deny Rule and Enforce SSL Access

Got it, let's walk through the exact steps to update your S3 bucket policy while keeping the existing deny statement for the specific user and adding the SSL enforcement rule using the AWS CLI. Here's a straightforward breakdown:

Step 1: Export the Current Bucket Policy to a Local File

First, pull your existing bucket policy into a local JSON file so you can safely edit it without messing up the original. Run this command:

aws s3api get-bucket-policy --bucket my-bucket --query Policy --output text > bucket-policy.json

The --query Policy flag extracts the raw policy JSON (not wrapped in extra metadata), and --output text removes any surrounding quotes that would make editing a hassle.

Step 2: Edit the Policy File to Add the SSL Enforcement Rule

Open the bucket-policy.json file in your favorite text editor. You'll see your existing deny statement already in the Statement array. Simply append the new SSL deny object to this array (make sure to add a comma after the first statement to keep valid JSON syntax).

Your final bucket-policy.json should look exactly like the policy you provided:

{
  "Version": "2012-10-17",
  "Id": "123",
  "Statement": [
    {
      "Effect": "Deny",
      "Principal": {
        "AWS": "arn:aws:iam::9876543211:someuser"
      },
      "Action": "s3:*",
      "Resource": [
        "arn:aws:s3:::my-bucket",
        "arn:aws:s3:::my-bucket/*"
      ]
    },
    {
      "Action": "s3:*",
      "Effect": "Deny",
      "Principal": "*",
      "Resource": "arn:aws:s3:::my-bucket/*",
      "Condition": {
        "Bool": {
          "aws:SecureTransport": false
        }
      }
    }
  ]
}

Double-check that the JSON is valid (no missing commas or brackets) — a quick way to verify is running python -m json.tool bucket-policy.json in your terminal, which will format the JSON and flag any errors.

Step 3: Upload the Updated Policy Back to the S3 Bucket

Once your edited policy is ready, push it back to the bucket with this command:

aws s3api put-bucket-policy --bucket my-bucket --policy file://bucket-policy.json

The file:// prefix tells the CLI to read the policy content directly from your local file.

Important Notes

  • Permissions: Make sure your IAM user/role has the s3:GetBucketPolicy and s3:PutBucketPolicy permissions to perform these actions.
  • Verify the Policy: After uploading, confirm the policy is applied correctly by running aws s3api get-bucket-policy --bucket my-bucket and checking the output matches your edited file.
  • Test SSL Enforcement: You can test by attempting to access an object in the bucket via HTTP (not HTTPS) — this should be denied, while HTTPS access should still work as expected.

内容的提问来源于stack exchange,提问作者pkaramol

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:25:54