S3 GetBucketEncryption操作权限名称疑问:指定权限为何不生效?
I totally get where you're coming from—this is a super confusing gotcha in AWS's documentation that trips up a lot of folks.
The key issue here is that the correct IAM permission name for the GetBucketEncryption API operation is s3:GetBucketEncryption, not the s3:GetEncryptionConfiguration mentioned in that document you referenced. Same goes for the put operation: it's s3:PutBucketEncryption, not s3:PutEncryptionConfiguration.
Here's why you saw those weird behaviors:
- When you used wildcards like
s3:*ors3:Get*, the wildcard matched the actual valid permissions3:GetBucketEncryption, which is why the call worked. - The policy editor's "all S3 operations" checkbox might not have included the correct permission (or you might have missed it in the list), and the old
GetEncryptionConfigurationname isn't recognized by the IAM policy engine at all—hence the AccessDenied error even when you tried that.
To fix this, update your IAM policy to use the correct permission names. Here's a working example:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetBucketEncryption", "s3:PutBucketEncryption" ], "Resource": "arn:aws:s3:::your-target-bucket" } ] }
Just manually type s3:GetBucketEncryption into the policy editor (it should recognize it without errors now), attach it to your Lambda execution role or IAM user, and your boto3 get_bucket_encryption() calls should start working as expected.
内容的提问来源于stack exchange,提问作者Indigenuity

