创建S3存储桶后从EC2访问延迟超1小时的问题排查
Hey there, let's dig into why you're still having trouble accessing your private test-bucket from EC2 even after waiting an hour—propagation delay is almost certainly not the issue here. Here are the most likely culprits and step-by-step fixes:
1. IAM Instance Profile & Policy Misconfiguration
This is the most common root cause. Let's verify the basics first:
- Check if your EC2 instance is attached to the correct instance profile: Sometimes CloudFormation can fail to properly associate the profile, or you might have attached the wrong one. You can confirm this via the EC2 console (Instance > Details > IAM role) or run
aws ec2 describe-instances --instance-ids YOUR-EC2-IDand look for theIamInstanceProfilefield. - Validate your IAM policy content: Ensure your policy explicitly allows the actions you're trying to perform (e.g.,
s3:ListBucketfor listing the bucket,s3:GetObjectfor downloading objects) and targets the correct resources. For example, a valid policy should include:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["s3:ListBucket", "s3:GetObject"], "Resource": [ "arn:aws:s3:::test-bucket", "arn:aws:s3:::test-bucket/*" ] } ] } - Confirm the policy is attached to the instance role: Run
aws iam list-role-policies --role-name YOUR-INSTANCE-ROLE-NAMEto check if your policy is listed. If not, reattach it manually or update your CloudFormation stack to ensure the association is correct.
2. Conflicting S3 Bucket Policy
Even though you set AccessControl='Private', a bucket policy can override or restrict access:
- Check for deny statements: Bucket policies use an "allow/deny" logic where deny statements take precedence. Run
aws s3api get-bucket-policy --bucket test-bucketto retrieve the policy. Look for anyDenyentries that might block your EC2 instance's IAM role. - Remember the AND rule: IAM role permissions and bucket policies work together—both must allow the action for access to be granted. If either denies it, the request will fail.
3. CloudFormation Stack Execution Issues
Occasionally, CloudFormation stacks can report success even if a resource (like the IAM role-policy attachment) didn't fully apply:
- Check stack events: Go to the CloudFormation console, select your stack, and review the event log for any failed or stuck resources. If you see issues, try updating the stack (even with no changes) to force a reapplication of the configuration.
- Reattach the policy manually: As a test, detach and reattach the IAM policy to your instance role. This can resolve any lingering sync issues.
4. VPC Endpoint Restrictions (If EC2 Is In a VPC)
If your EC2 instance is running in a VPC with an S3 VPC endpoint, the endpoint's policy might be blocking access:
- Verify the endpoint policy: Run
aws ec2 describe-vpc-endpoints --vpc-endpoint-ids YOUR-ENDPOINT-IDand check thePolicyDocumentfield. Ensure it allows access totest-bucket. - Check routing configuration: Confirm your VPC's route table has an entry pointing to the S3 endpoint for the
com.amazonaws.region.s3service (replaceregionwith your AWS region). Without this, traffic might be routing over the public internet, leading to unexpected permission issues.
5. Object-Level ACL Conflicts
If you're trying to access specific objects in the bucket, check their individual ACLs:
- By default, objects inherit the bucket's private permissions, but if you uploaded objects manually (not via CloudFormation), they might have custom ACLs. Run
aws s3api get-object-acl --bucket test-bucket --key YOUR-OBJECT-KEYto verify.
Step-by-Step Debugging Command
To get granular details about why your request is failing, run this on your EC2 instance:
aws s3 ls s3://test-bucket --debug
The debug output will show exactly which policy or permission is blocking your request—this is often the fastest way to pinpoint the issue.
内容的提问来源于stack exchange,提问作者Noam Mansur

