You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

S3 GetBucketEncryption操作权限名称疑问:指定权限为何不生效?

Correct IAM Permission for S3 GetBucketEncryption Operation

I totally get where you're coming from—this is a super confusing gotcha in AWS's documentation that trips up a lot of folks.

The key issue here is that the correct IAM permission name for the GetBucketEncryption API operation is s3:GetBucketEncryption, not the s3:GetEncryptionConfiguration mentioned in that document you referenced. Same goes for the put operation: it's s3:PutBucketEncryption, not s3:PutEncryptionConfiguration.

Here's why you saw those weird behaviors:

  • When you used wildcards like s3:* or s3:Get*, the wildcard matched the actual valid permission s3:GetBucketEncryption, which is why the call worked.
  • The policy editor's "all S3 operations" checkbox might not have included the correct permission (or you might have missed it in the list), and the old GetEncryptionConfiguration name isn't recognized by the IAM policy engine at all—hence the AccessDenied error even when you tried that.

To fix this, update your IAM policy to use the correct permission names. Here's a working example:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "s3:GetBucketEncryption",
                "s3:PutBucketEncryption"
            ],
            "Resource": "arn:aws:s3:::your-target-bucket"
        }
    ]
}

Just manually type s3:GetBucketEncryption into the policy editor (it should recognize it without errors now), attach it to your Lambda execution role or IAM user, and your boto3 get_bucket_encryption() calls should start working as expected.

内容的提问来源于stack exchange,提问作者Indigenuity

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:16:57