You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFront访问第二个S3源站返回403问题求助

Troubleshooting CloudFront 403 Error for /relj Path After Authentication

Hey there! Let's walk through the 403 issue you're hitting with your CloudFront and S3 setup. Based on the details you shared, here are the most likely culprits and fixes to try:

1. Path Pattern Mismatch in CloudFront Behavior

You mentioned setting up a behavior for relj/, but you're accessing /relj/index.html. CloudFront's path patterns use prefix matching, and the way you've defined it might not cover subpaths under /relj/.

Fix:

Update your CloudFront behavior's path pattern to /relj/* instead of relj/. This ensures all requests starting with /relj/ (like /relj/index.html) are routed to the correct S3 origin and trigger your Lambda@Edge function.

2. Incorrect S3 Origin Configuration for the relj Bucket

Your relj bucket uses S3 static website hosting, but how you've configured it as a CloudFront origin might be causing issues:

  • When using S3 static website hosting as a CloudFront origin, you must use the static website endpoint URL (like www.xxx.com.relj.s3-website-us-east-1.amazonaws.com) as the origin domain.
  • Ensure the origin protocol policy is set to HTTP Only (since S3 static websites don't support HTTPS for custom endpoints).
  • If you're using the S3 REST API endpoint (e.g., s3.amazonaws.com/www.xxx.com.relj) instead, the static website's index document settings won't apply, and path mapping can break.

Fix:

Double-check your CloudFront origin for the relj bucket:

  1. Confirm the origin domain is the static website endpoint URL.
  2. Set the origin protocol policy to HTTP Only.
  3. Verify that the default root object (if configured in CloudFront) matches the index document you're trying to access (index.html).

3. Lambda@Edge Function's Request Handling

You noted the Lambda function is executing, but it might be modifying the request path incorrectly after authentication, leading to S3 not finding the resource.

Things to check:

  • Does your Lambda function rewrite the request path? For example, if it's stripping /relj/ from the path, S3 will look for index.html in the bucket root instead of the expected location.
  • Ensure the Lambda returns a 200 OK or allows the request to proceed to the origin after successful authentication. If it's returning a redirect or modifying headers incorrectly, that could cause a 403.

Fix:

Review your Lambda function code to confirm it preserves the original request path (including /relj/) when forwarding to the S3 origin. For reference, a basic authentication Lambda should pass through the request unmodified once credentials are validated.

4. OAI Bucket Policy Conflict with Static Website Hosting

This is a common gotcha for AWS beginners: CloudFront Origin Access Identities (OAI) don't work with S3 static website hosting endpoints. When you use the static website URL as a CloudFront origin, CloudFront accesses S3 as a regular HTTP client, not via the OAI. Your current bucket policy only allows the OAI to access objects, so S3 rejects CloudFront's requests even after Lambda authentication.

Fix Options:

Option 1: Switch to using the S3 REST API endpoint as the origin

  • Use www.xxx.com.relj.s3.amazonaws.com as the CloudFront origin domain.
  • Keep your existing OAI bucket policy (it will work with the REST endpoint).
  • Set the CloudFront behavior's default root object to index.html to handle requests to /relj/.

Option 2: Adjust the bucket policy to allow CloudFront access

  • If you want to keep using the static website endpoint, update your relj bucket policy to allow requests from your CloudFront distribution. You can use a condition to restrict access to your CloudFront distribution's ID:
    {
      "Version": "2008-10-17",
      "Id": "PolicyForCloudFrontAccess",
      "Statement": [
        {
          "Sid": "AllowCloudFrontAccess",
          "Effect": "Allow",
          "Principal": "*",
          "Action": "s3:GetObject",
          "Resource": "arn:aws:s3:::www.xxx.com.relj/*",
          "Condition": {
            "StringEquals": {
              "AWS:SourceArn": "arn:aws:cloudfront::ACCOUNT_ID:distribution/dXXjxu7k28es7y"
            }
          }
        }
      ]
    }
    
    Replace ACCOUNT_ID with your AWS account ID and dXXjxu7k28es7y with your CloudFront distribution ID.

Final Checks

After making these changes:

  • Invalidate the CloudFront cache (via the CloudFront console) to ensure old cached responses aren't causing issues.
  • Test accessing /relj/index.html again after authentication.

If you're still hitting issues, share a snippet of your Lambda@Edge function code (redact any sensitive info) and a screenshot of your CloudFront behavior configuration—this will help narrow things down further!

内容的提问来源于stack exchange,提问作者user3037484

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:44:07